Healthcare has the oldest and best-developed regulator of algorithmic decisions of any sector, and it reaches a minority of the AI actually running in a hospital. Both facts have to be held at once, and the second one is where the risk lives.
Device regulation is genuinely mature: the FDA and Health Canada have converged on the same mechanism, the predetermined change control plan, which lets a manufacturer pre-authorise how a model will be updated after it ships. That is a more sophisticated answer to model drift than any financial regulator has produced. It also only applies if your AI is a regulated device, and most clinical AI is not.
Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.
The instinct is to ask which regulator covers clinical AI. For most of it, the honest answer is none of them, and that is not a loophole to exploit but the actual risk position. A model that never reaches the definition of a medical device can still deny a prior authorisation, reorder a triage queue or shape what a clinician sees first, and no submission pathway will ever examine it.
Which leaves the institution to govern it, using the instruments that do exist: ISO/IEC 42001 for the management system, the NIST AI Risk Management Framework for the risk process, ISO 14971 thinking for clinical harm, and the device regulators’ own predetermined change control logic applied voluntarily to models that will never be submitted. That last one is the highest-value borrowing available, because drift is the failure mode and PCCP is the only mature answer anyone has written down.
Usually the honest answer is no, and that is the finding that reframes the programme. A device pathway is triggered by intended use, by whether the software is intended to diagnose, treat, prevent or mitigate disease, rather than by how clever the model is. Ambient documentation, scheduling, capacity forecasting, coding support and most prior-authorisation automation fall outside it. The exposure does not fall outside with them: those systems still shape care and still produce decisions a patient can be harmed by, and nobody outside the institution will review them.
It is a plan, submitted and authorised in advance, describing what may change about a model after it ships, how each change will be validated, and what would fall outside the plan and require a new submission. The FDA finalised its guidance in December 2024 and Health Canada built the same mechanism into its February 2025 pre-market guidance. The convergence is the interesting part: two regulators independently concluded that the honest way to govern a system that learns is to govern its change process rather than to freeze a version. Every other sector is still trying to solve drift with periodic revalidation, and this is a better answer.
No. The predetermined change control plan guidance is final, from December 2024. The broader lifecycle management and marketing submission guidance was published on 6 January 2025 and is still a draft, sitting on the FDA’s B list for finalisation during FY-2026. The distinction matters when you are writing a governance programme: a draft states the direction of travel and can change before it lands, and citing it as settled law weakens the document that cites it.
Explicit disclosure. A Class II, III or IV application must state that machine learning is used, wholly or in part, rather than leaving it to be inferred from the technical file. The evidence must also describe how Good Machine Learning Practice was considered within the organisation and implemented across the product lifecycle, which is an organisational question rather than a product one and is answered badly by manufacturers who treat governance as documentation produced at submission time.
Regulated healthcare AI, built rather than advised on. SHAP and LIME explainability dashboards for FDA-cleared clinical decision-support systems, which lifted clinician adoption by 75 per cent; a privacy-preserving federated-learning platform across more than ten hospital systems with no data sharing; a regulated retrieval system automating prior authorisation, cutting manual work by 75 per cent at 85 per cent first-pass approval with SOC 2 logging across more than a hundred HITRUST sites; and MLOps with 21 CFR Part 11 audit trails. To be precise about the boundary: those decision-support systems were FDA-cleared and the explainability layer was built for them. Securing the clearance was not the work.
Governance an examiner can follow, in the jurisdiction that actually binds you.