The Regulatory Ground Is Shifting Under AI-Driven Medical Devices
If your device uses a machine learning model that updates after commercialization, you are operating in one of the most scrutinized and rapidly evolving areas of FDA oversight. Continuous learning systems, sometimes called adaptive algorithms or continuously learning AI/ML, present a fundamental challenge to the traditional regulatory framework: how do you pre-specify a device's behavior when the algorithm is designed to change?
FDA has been wrestling with this question publicly since at least 2019, and the agency's thinking has matured considerably. If you are a founder, VP of Regulatory Affairs, or Quality leader at a small-to-mid-size device company, understanding where FDA stands today, and where it is heading, is not optional. It is a survival skill.
What FDA Means by 'Locked' vs. 'Adaptive' Algorithms
FDA's foundational document for this space is the April 2019 discussion paper titled 'Proposed Regulatory Framework for Modifications to Artificial Intelligence/Machine Learning-Based Software as a Medical Device' and the subsequent January 2021 action plan for AI/ML-based SaMD. These documents introduced a critical distinction that every regulatory professional should internalize.
- Locked algorithms produce the same output for the same input after deployment. These behave more like traditional software and can be evaluated under existing frameworks such as 21 CFR Part 820 and FDA's 2017 Software as a Medical Device (SaMD) guidance framework adapted from IMDRF.
- Adaptive algorithms continue to learn and change their behavior based on real-world data after deployment. These are the continuous learning systems that create the most regulatory complexity.
The core problem is structural: FDA clearance and approval processes under 21 CFR Part 807 (510(k)) and 21 CFR Part 814 (PMA) are designed to evaluate a device in a defined state. A model that retrains on live patient data post-market is, in a meaningful sense, a different device every time it updates.
The Predetermined Change Control Plan: FDA's Current Answer
FDA's most concrete response to this challenge is the Predetermined Change Control Plan (PCCP), which became the centerpiece of guidance finalized in December 2023 under the title 'Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions.'
The PCCP framework allows manufacturers to prospectively define the types of modifications their AI/ML device may undergo without requiring a new premarket submission for each change, provided those modifications fall within the boundaries described in the plan. This is a significant regulatory accommodation, but it comes with rigorous expectations.
A compliant PCCP must include:
- Description of Planned Modifications: Specific, bounded descriptions of what types of changes are anticipated, including modifications to model architecture, training data, or intended use boundaries.
- Methodology for Modifications: A detailed explanation of the development, validation, and performance testing approach that will govern each modification type.
- Impact Assessment: An analysis of how planned changes affect safety and effectiveness, including consideration of algorithmic bias and performance across patient subpopulations.
Critically, FDA expects your PCCP to align with your Quality Management System under 21 CFR Part 820, now harmonized with ISO 13485 through the Quality System Regulation update finalized in February 2024. Change control for AI modifications is not a standalone regulatory artifact. It must live inside your QMS.
Real-Time Updates: Where FDA Has Not Yet Drawn Clear Lines
Here is where the practical complexity intensifies for continuous learning systems specifically. The 2023 PCCP guidance contemplates planned, defined modifications, not fully autonomous real-time retraining loops. If your system is designed to retrain automatically on streaming clinical data without human intervention at each update cycle, you are in territory the guidance does not fully address.
FDA has signaled through public statements and advisory committee discussions that fully autonomous continuous learning, where no human review gate exists before a model update goes live, raises significant concerns under the agency's Total Product Life Cycle (TPLC) approach. The agency's expectation, consistent with the 2021 AI/ML action plan, is that manufacturers maintain meaningful human oversight and performance monitoring tied to predefined safety thresholds.
Practically, this means your architecture decisions have regulatory consequences. Designing a human-in-the-loop validation checkpoint before each model version goes to production is not just good engineering practice. It is increasingly a regulatory expectation, particularly for devices in higher-risk classifications under 21 CFR Part 860.
What Your Team Should Be Doing Right Now
The regulatory path for continuous learning devices is navigable, but it requires deliberate strategy early in your development cycle. Here is what we advise clients to prioritize:
- Classify your algorithm changes early. Work with regulatory counsel to determine whether your anticipated model updates constitute major, moderate, or minor modifications under FDA's existing software change guidance and the PCCP framework.
- Build your PCCP before your submission, not after. FDA reviewers want to see a PCCP that reflects genuine engineering constraints and clinical risk thinking, not a document retrofitted to describe what you have already built.
- Establish performance monitoring infrastructure. FDA expects ongoing surveillance of AI/ML device performance post-market. Under 21 CFR Part 803 and your MDR obligations, degraded algorithm performance resulting in patient harm has reporting implications. Your monitoring system should be designed to detect drift proactively.
- Address algorithmic bias explicitly. FDA has been explicit in multiple guidance documents that performance disparities across race, sex, age, and other demographic factors are a safety issue, not a fairness abstraction. Your validation datasets and ongoing monitoring must reflect this.
The Strategic Reality for Startups and Growth-Stage Companies
For founders building AI-driven diagnostics, clinical decision support tools, or autonomous treatment devices, the PCCP framework is genuinely enabling. It creates a mechanism to innovate post-market without returning to FDA for every model refinement. But it also means your regulatory strategy must be co-developed with your product and engineering teams from day one.
The companies that struggle are those that treat regulatory affairs as a documentation exercise at the end of development. The companies that succeed are those that build regulatory intelligence into their architecture decisions, their data governance frameworks, and their change management processes while the product is still being designed.
At ADB Consulting and CRO Inc., we work directly with founders and regulatory teams navigating exactly this landscape. Whether you are preparing a first submission for an AI-enabled device, developing a PCCP strategy, or responding to FDA questions about your adaptive algorithm architecture, our team brings the technical and regulatory depth your program needs.
Book a free discovery call with Andre Butler at adbccro.com. Bring your toughest AI/ML regulatory questions. That is exactly what we are here for.
For related guidance, see our Software as a Medical Device regulatory support.
Ready to Navigate the FDA Process with Confidence?
Book a free 30-minute discovery call with Andre Butler. No sales pitch -- just expert regulatory guidance on your specific device and situation.
Book a Free Pathway Call