On August 18, the Food and Drug Administration released a discussion paper titled "Considerations for the Regulation of Generative AI-Enabled Medical Devices," asking for public comment through October 19 under docket FDA-2026-N-7874. A week later, Rick Abramson, director of the FDA's Digital Health Center of Excellence, told STAT what the paper carefully does not promise: "Our goal is formal policy guidance." Broad guidance on generative AI overall, he said, plus narrower specialty guidance on topics of special interest or complexity.

The agency has been working toward this moment for years, and the paper is plainly written to be the last gathering of evidence before the rules arrive. It is also an admission, visible between the lines, that the ordinary way of regulating medical devices does not fit the technology in front of it. The FDA is about to write rules for a machine that changes after it is sold.

The agency is trying to miss two opposite failures

The FDA's timing problem has two edges. Write the rules too early, and they freeze a technology that is still moving. Generative AI capabilities, model architectures, and clinical use cases are being renegotiated every quarter, and a guidance written to last five years could describe a product that no longer exists by year two. Write the rules too late, and the market coalesces without the agency. Devices clear through the existing framework, companies build de facto standards in the absence of official ones, and the FDA ends up regulating by exception and enforcement rather than by design.

Neither failure is hypothetical. The agency has cleared hundreds of AI-enabled medical devices over the past several years under general software rules and special controls, most of them narrow, fixed-function tools: a detector here, a triage flag there. Generative AI does not fit that pattern. An FDA announcement accompanying the paper describes the effort as advancing regulatory science while protecting public health and preserving trust, which is the polite way of saying the agency knows the gap is real and growing.

Generative AI breaks the snapshot model

Traditional device regulation assumes something like a snapshot. A manufacturer submits a product with defined inputs, defined outputs, a fixed algorithm, and a stated intended use. The agency clears that product, and postmarket rules cover what happens next. Predetermined change control plans, a modern FDA innovation, allow manufacturers to describe anticipated software updates in advance and have them blessed with the original clearance. That works when the changes are foreseeable.

A generative model is not a snapshot. The same cleared system can produce different outputs from the same input, can be used for purposes beyond the ones listed in its submission, and can be extended by the manufacturer or the user into tasks nobody anticipated at clearance. The discussion paper takes this seriously enough to define agentic systems: those that autonomously plan and execute multi-step tasks, use external tools, or take actions across a sequence of steps. It asks when a human checkpoint must precede an irreversible step and how injection risks should be handled. These are not questions the 1976 device framework was built to answer, and the agency knows it.

The paper is a map of the agency's own uncertainty

The document is unusually candid for a regulatory precursor. It proposes a two-axis risk framework for sorting generative devices by their intrinsic risk and the consequences of their failures. It asks, in its agentic AI section, whether documentation and outreach agents are device functions at all, where human checkpoints must sit before irreversible steps, and how prompt injection should be treated. It floats a voluntary Foundation Model Device Master File, a confidential filing under which a model developer would submit architecture, training data provenance, known failure modes, guardrails, and update notification commitments for device makers to reference, with the careful caveat that the file would not authorize any model for any use. Its value is conditional, in other words, on the goodwill of the largest model developers, the same companies whose products the framework exists to regulate. Every section ends in questions rather than conclusions. The agency is soliciting the answers it does not yet have, under docket FDA-2026-N-7874, before October 19.

The competency answer

The most interesting idea in the paper is borrowed from medicine itself. The FDA proposes what it calls a competency-based approach to premarket evaluation, modeled on how physicians are trained and assessed: non-clinical benchmarking first, like an examination, then clinical confirmation, like supervised practice, to establish that the device performs as intended before it reaches patients. Regulate the machine's demonstrated competence rather than its frozen configuration.

That is a genuinely different object of regulation. A benchmark does not ask what a model is. It asks whether the model can do the job, under conditions that resemble the job, with a pass standard set before the test. A competency framework can survive updates, because the update must pass the same exam the original cleared. The paper pairs the idea with risk-proportionate postmarket monitoring and with a voluntary Foundation Model Device Master File, under which model developers could confidentially file model cards, training data provenance, failure modes, and update notification commitments for device makers to reference. The scaffolding is starting to look like a regulatory exam system for machines.

The analogy holds further than it first appears. Physicians are licensed once, then re-examined continuously through board maintenance and continuing education, and the paper's re-benchmarking concept, in which a modified device is tested against the same capabilities it cleared under, is maintenance of certification for software. That is the strongest hint of where the framework is heading: not a snapshot of a product at clearance, but a standing test of performance, retaken with every change. The agency has lived this problem before. Its software regulations date to a different computing era, and its artificial intelligence work so far, the action plans and discussion papers of the past several years, has been a series of temporary shelters. Predetermined change control plans, the modern mechanism for updating cleared software, assume the manufacturer knows the changes in advance. A foundation model updated by its developer, with new capabilities nobody listed, breaks that assumption.

What remains unwritten

The paper is explicitly not draft guidance, and the distance from here to rules is long. The comment period closes October 19. The foundation model file is voluntary, which means its value depends on whether model developers choose to file. The two-axis risk framework, which would sort generative devices by both their intrinsic risk and the consequences of their errors, is sketched but not settled. Abramson offered no timeline for the guidance documents, and the STAT interview, which is itself a STAT+ exclusive, suggests the details of the competency approach are still being debated internally.

The industry, meanwhile, is not waiting. Device makers are already building benchmark harnesses, negotiating model version pinning and update notification terms into vendor contracts, and planning shadow deployments as clinical confirmation, according to analysis of the paper circulating among regulatory professionals. The market is practicing the framework before it exists.

The stakes of the timing are easier to see from the industry side than the agency side. A device maker deciding today whether to launch a generative documentation assistant wants to know whether it is a device, what evidence the agency will want, and how updates will be treated. On all three, the honest current answer is that the market is waiting for the paper's questions to be answered. Every month of ambiguity is a month in which the de facto rules are written by the most cautious legal departments and the most aggressive competitors, and neither of those is the draft the public would choose. The paper's own framing names the administration's priority: accelerating innovation in medical products while preserving safety. That is the pair of obligations the agency is holding at once, and every sentence of the paper is a negotiation between them.

The exam is the regulation

The FDA cannot win the timing game, and the paper's real achievement is that it stops trying. Too early and too late are both wrong, so the agency is changing what gets regulated: not what the device is, but whether it performs. A competency test does not need the technology to hold still, any more than a medical licensing exam needs a physician's knowledge to stop changing after residency. The machine that updates must re-pass the same exam, and the exam, not the configuration, becomes the standard.

That is the shape of the guidance that is coming: less a description of what generative AI medical devices may be, more a specification of what they must be able to demonstrate. The technology will keep moving. The rules, if the paper's logic survives the comment period, will be built for that motion. The exam will itself be revised, as every good exam is; the difference is that the revisions will be docketed, argued in public, and published, instead of improvised one enforcement action at a time. That is the quiet promise underneath the discussion paper, and it is the part the industry should hold the agency to.

Primary sources

  1. The FDA discussion paper and its proposed framework, including the competency-based approach, the two-axis risk assessment, the predetermined change control plan concepts, and the Foundation Model Device Master File, from the agency's August 18, 2026 announcement and paper as covered by the FDA and the ASCO Post.
  2. Rick Abramson's statements about formal guidance from STAT's reporting by Mario Aguilar, a STAT+ exclusive.
  3. The industry preparation analysis from Innolitics' discussion of the paper.