Your AI Algorithm Got Cleared. Now What Happens When It Learns Something New?
Congratulations -- your AI-powered medical device just received FDA 510(k) clearance. The algorithm is performing well, your clinical team wants to retrain it on a larger dataset, and your data scientists are confident the new model is meaningfully better. So you update it and ship the improvement, right?
Not so fast. If your algorithm is classified as locked, that update may constitute a change that requires a new premarket submission before you touch a single line of production code. Getting this wrong is not a paperwork problem -- it is a regulatory enforcement risk that can shut down your commercial operation.
This post breaks down exactly what the FDA means by a locked algorithm, why the distinction matters for your 510(k) or De Novo clearance, and what your options are when the algorithm you cleared yesterday needs to improve tomorrow.
What Does 'Locked' Actually Mean Under FDA's Framework?
The FDA's foundational thinking on AI and machine learning in software as a medical device (SaMD) is captured in its April 2019 discussion paper and, more formally, in the January 2021 action plan titled 'Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan.' These documents establish a critical binary distinction:
- Locked algorithms produce the same output every time they receive the same input. The model weights, decision thresholds, and logic are fixed at the time of clearance. Think of a traditional software algorithm or a trained neural network whose parameters are frozen before submission.
- Adaptive algorithms continue to learn and change their behavior after deployment -- either autonomously in real time or through periodic retraining cycles.
Under 21 CFR Part 820 (and its harmonized successor, the Quality System Regulation aligned with ISO 13485), your device's software is subject to design controls. The version of the algorithm that FDA reviewed is the version that is cleared. Any modification to that locked algorithm is a software change -- and software changes to cleared devices are governed by 21 CFR 820.30 and, critically, by the FDA's guidance document 'Deciding When to Submit a 510(k) for a Change to an Existing Device' (October 2017) as well as the software-specific companion, 'Deciding When to Submit a 510(k) for a Software Change to an Existing Device' (October 2017).
When a Model Update Triggers a New 510(k)
The 2017 software change guidance establishes a risk-based decision flowchart that every regulatory team should have memorized. For AI/ML devices specifically, the questions that matter most are:
- Does the change alter the intended use or indications for use?
- Does the change introduce new risks or significantly modify existing ones?
- Could the change affect the safety or effectiveness of the device in a way that was not already addressed in the cleared submission?
Retraining a locked algorithm on new patient populations, expanding the input data types, adjusting decision thresholds, or changing the model architecture are all changes that will almost certainly require you to work through this flowchart -- and many of them will land on the side of 'new 510(k) required.' The FDA has made clear that for high-risk AI functions, it expects changes to be evaluated with the same rigor as the original submission.
If your algorithm informs diagnosis, triage, or treatment decisions -- what FDA categorizes as SaMD at higher risk levels under the International Medical Device Regulators Forum (IMDRF) framework -- the bar is even higher.
The Predetermined Change Control Plan: Your Path to Iterative Improvement
Here is where strategy becomes invaluable. FDA's 2021 AI/ML action plan introduced the concept of a Predetermined Change Control Plan (PCCP), which was subsequently formalized in draft guidance issued in April 2023: 'Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions.'
A PCCP allows a manufacturer to describe, within the original marketing submission, the types of algorithm changes it anticipates making post-clearance -- and to pre-specify the performance standards and validation protocols that will govern those changes. If FDA accepts the PCCP, manufacturers can implement those pre-defined changes without submitting a new 510(k), provided the changes stay within the approved boundaries and the associated testing confirms performance targets are met.
This is not a loophole. It is a rigorous, prospective regulatory commitment that requires you to:
- Define the scope of anticipated modifications with specificity
- Specify the performance metrics and acceptance criteria that must be met before any change is deployed
- Describe the data governance, retraining procedures, and monitoring plans that will keep the algorithm within its validated envelope
For startups building AI-native devices, the PCCP should be a day-one architectural and regulatory consideration -- not an afterthought once the product is already on the market.
Practical Steps for Teams Managing Locked Algorithms Today
If you are already cleared and working with a locked algorithm, here is how to protect your clearance while building toward future improvements:
- Document every proposed change using a formal software change request process tied to your design control procedures under 21 CFR 820.30.
- Run the 2017 software change guidance flowchart for every change, and keep written records of your rationale. FDA investigators will ask for this during inspections.
- Assess whether a PCCP can be incorporated into an upcoming submission -- either a new clearance for the next generation or a PMA supplement if your device is Class III.
- Engage FDA early through Pre-Sub meetings (formally governed by FDA's 2021 Pre-Sub guidance) if you are unsure whether a specific algorithm change requires a new submission. These meetings are free, and the written responses carry significant weight.
- Align your software development lifecycle (SDLC) with IEC 62304, which FDA recognizes as the standard for medical device software development and is directly relevant to how you document algorithm versioning and change management.
The Bottom Line
A locked algorithm is not a limitation -- it is a regulatory contract between you and the FDA. The version that was cleared is the version that is safe and effective for its cleared indication. When you improve on it, you have an obligation to validate that the improvement does not introduce new risks and, in many cases, to tell FDA about it before deployment.
The companies that navigate this well are the ones that build their regulatory strategy alongside their AI development pipeline -- not after the fact. A PCCP negotiated upfront can be the difference between a nimble, continuously improving product and one that is frozen in time because the regulatory pathway for updates was never planned.
At ADB Consulting and CRO Inc., we work with medical device startups and established manufacturers to build AI/ML regulatory strategies that are designed for the real world -- where algorithms need to get better, markets evolve, and FDA expectations are constantly maturing. Whether you are preparing your first 510(k) for an AI-enabled device or managing post-market changes to a cleared algorithm, we can help you move fast without breaking your clearance.
Book a free discovery call with Andre Butler today at adbccro.com and let's map out a regulatory strategy that keeps your AI on the market and ahead of the curve.
Related reading: our AI/ML SaMD consulting practice covers this in more depth.
Ready to Navigate the FDA Process with Confidence?
Book a free 30-minute discovery call with Andre Butler. No sales pitch -- just expert regulatory guidance on your specific device and situation.
Book a Free Pathway Call