FDA Opens the Door on GenAI-Enabled Medical Devices: Why Quality Systems Need to Be Ready

On August 18, 2026, FDA issued a discussion paper seeking public feedback on how the agency should approach regulation of generative AI-enabled medical devices. The paper asks for input on risk assessment, premarket evaluation, postmarket monitoring, foundation models, agentic AI systems, and other topics relevant to this rapidly evolving area.

For medical device and combination product teams, this is an important signal. FDA is not simply asking whether GenAI can be used in healthcare. FDA is asking how these technologies should be evaluated, monitored, and controlled when they are part of a medical device.

For quality organizations, the message is clear: GenAI-enabled devices will need more than innovative technology. They will need a defensible quality and lifecycle-management strategy.

What FDA is signaling

FDA’s discussion paper describes several areas that could shape the future regulatory approach for GenAI-enabled medical devices.

One major concept is a possible two-axis framework for risk assessment, which could help inform regulatory expectations. FDA also discusses a potential approach to premarket evaluation based on competency assessment, including non-clinical device benchmarking and clinical confirmation to evaluate whether a GenAI-enabled device performs as intended before reaching patients.

FDA also raises important postmarket questions. Because GenAI-enabled devices may behave differently than traditional software or earlier AI-enabled devices, FDA is exploring risk-proportionate monitoring approaches that could help detect performance issues after deployment.

Importantly, FDA states that the discussion paper is intended to gather input and advance discussion. It does not establish draft or final regulatory expectations. Still, it gives industry a useful view into the questions FDA is asking now.

Why this matters for Quality

GenAI-enabled devices can introduce quality challenges that are different from traditional device software.

A conventional software function usually operates within a more predictable set of programmed outputs. A GenAI-enabled device may generate text, images, recommendations, summaries, or other outputs that depend heavily on prompts, context, model behavior, training data, and real-world use conditions.

That means quality teams need to think beyond “does the software work?” and ask:

  • What is the intended use of the GenAI function?
  • What outputs could influence clinical decisions?
  • What are the foreseeable failure modes?
  • How will performance be benchmarked before release?
  • How will drift, bias, hallucination, or unexpected outputs be detected?
  • What postmarket monitoring is needed?
  • How will updates to the model or system be controlled?

These questions connect directly to design controls, risk management, validation, cybersecurity, data governance, labeling, complaint handling, and postmarket surveillance.

What teams should do now

Even though FDA’s discussion paper is not yet guidance, device teams should not wait to build basic governance.

1) Define the GenAI function clearly

Teams should document what the GenAI function does, what it does not do, who uses it, what decisions it supports, and what outputs may affect patient care or user behavior.

2) Build risk assessment around real-world use

GenAI risk should be evaluated in context. Consider the user, use environment, clinical workflow, level of automation, degree of human review, and severity of potential harm if the output is incomplete, biased, misleading, or wrong.

3) Establish performance and competency evidence

If GenAI output is part of the device function, teams should be able to explain how performance was assessed. That may include benchmarking, test datasets, acceptance criteria, clinical confirmation, and rationale for why the evidence is appropriate for the intended use.

4) Plan for postmarket monitoring early

For GenAI-enabled devices, performance monitoring should not be an afterthought. Teams should define what will be monitored, what signals trigger investigation, how complaints will be evaluated, and when corrective action or change control is required.

5) Control model and system changes

Model updates, prompt changes, data-source changes, interface changes, and workflow changes may affect device performance. These should be evaluated through a defined change-control process tied to risk and regulatory impact.

6) Document the human role

If the system depends on clinician or user review, the limitations of that review should be defined and tested. “Human-in-the-loop” should not be a slogan. It should be supported by labeling, training, usability engineering, and real evidence that users can interpret and act on outputs appropriately.

Watch the October 19, 2026 comment deadline

FDA is accepting feedback on the discussion paper under docket FDA-2026-N-7874 through October 19, 2026. Manufacturers, clinicians, researchers, patients, and other interested parties can submit comments.

For companies developing or considering GenAI-enabled device functions, this is a valuable opportunity to provide input before FDA’s approach becomes more formalized. It is also a good time to review internal AI governance, product development processes, and postmarket monitoring plans.

A practical readiness checklist

Before developing or submitting a GenAI-enabled medical device, ask:

  • Is the GenAI function clearly defined?
  • Is the intended use specific and controlled?
  • Are foreseeable harms and failure modes documented?
  • Is performance evidence tied to the intended use and user population?
  • Are bias, drift, hallucination, and unexpected outputs addressed?
  • Is human review defined, tested, and documented?
  • Are model, prompt, and system changes controlled?
  • Is postmarket monitoring risk-based and actionable?
  • Are complaints and real-world signals linked to CAPA and change control?
  • Can the DHF and submission tell a clear, traceable story?

Bottom line

FDA’s discussion paper does not create new requirements yet, but it does show where the conversation is heading. GenAI-enabled medical devices will require more than strong algorithms. They will require strong quality systems.

The companies best positioned for this next phase will be the ones that can show clear intended use, risk-based design controls, performance evidence, controlled change management, and postmarket monitoring that actually detects and addresses real-world issues.

If your organization is developing AI- or GenAI-enabled medical device functions, QSN can help pressure-test your quality system, risk documentation, DHF traceability, validation strategy, and postmarket monitoring plan before regulatory expectations become harder to navigate.

Share This Story, Choose Your Platform!