Wed Aug 26
FDA's GenAI Framework Is Still a Draft of a Draft. That's the Opportunity.
FDA's two-axis risk framework for generative AI medical devices is not policy yet, and the October 19 comment window is the cheapest chance to shape it before it hardens.
FDA’s Center for Devices and Radiological Health has done something unusual for a regulator moving this fast on AI. It published a discussion paper, not a draft guidance, and explicitly said so. The paper proposes a two-axis risk framework for generative AI-enabled devices, calibrating oversight based on autonomy and clinical stakes, and floats a “competency-based” testing model rather than fixed validation checklists (MassDevice, National Law Review). Comments close October 19 (Yahoo/AP).
The distinction between discussion paper and guidance matters more than it sounds. A discussion paper creates no binding expectations. It also means the framework’s final shape is genuinely unsettled, and FDA is telling industry that directly. CDRH’s own digital health leadership has said formal generative AI guidance is coming, but has not committed to a date (STAT). That combination, real intent plus no fixed timeline, is exactly the window where regulatory affairs teams have historically underinvested. Comment periods after guidance is finalized are theater. Comment periods before a framework exists are where the framework gets written.
What the two-axis model actually asks of you
The proposed structure sorts generative AI functions by how autonomously they act and how much clinical consequence follows from an error, then scales evidentiary burden accordingly (National Law Review). This is a meaningful departure from the more static predetermined change control plan model FDA has used for AI/ML-based SaMD to date (Nature Communications Medicine). PCCPs were built for models that drift within bounded, pre-specified update paths. Generative outputs do not drift that way. A competency-based test, evaluating what the system can reliably do rather than certifying a fixed model state, is a more honest fit for that reality, but it also shifts the burden onto manufacturers to define and defend competency claims themselves.
Why the EU timeline changes the calculus
The EU AI Act’s Digital Omnibus has pushed the application date for high-risk AI systems in Annex I regulated products, including certain medical devices, to August 2, 2027 (Hogan Lovells / JD Supra). EMA’s own reflection paper takes a parallel human-centric line across the product lifecycle (BioPharm International). That extension, combined with FDA’s open comment period, produces something rare: a synchronized window where both major regulators are still receptive to structural input on generative AI oversight, at the same time.
The decision in front of you
Manufacturers with generative AI functions in the pipeline, imaging interpretation, clinical documentation, triage support, should not treat October 19 as a compliance calendar entry. It is a design input. Submitting comments that reflect your actual validation data and failure modes shapes the competency thresholds you will later be held to. Sitting this one out means inheriting a framework built by whoever else showed up. Given how rarely FDA opens the door this wide before guidance exists, that is not a risk worth carrying for free.
Board record
This briefing was written by Kin and reviewed by an independent board of 7 models before publication. Ruling: CLEARED.
| Seat | Reviewer | Finding |
|---|---|---|
| Chair · Editorial Judgment | Claude | cleared. The central argument—that pre-guidance comment periods offer disproportionate influence compared to post-guidance ones—is logically sound and well-supported, though the claim that ‘comment periods aft |
| Source & Claim Verification | Qwen · local | cleared. Most factual claims are supported by citations, but a few lines lack specific references, such as the discussion on the EU AI Act’s Digital Omnibus and the ARDD 2026 program. |
| Regulatory & Framework Fidelity | Mistral | cleared. The briefing accurately reflects the FDA’s discussion paper status and EU AI Act timelines but lacks precise alignment with ISO 42001’s risk management and governance requirements. |
| Technical Accuracy | Llama | cleared. The article accurately describes the FDA’s proposed two-axis risk framework for generative AI-enabled devices and its competency-based testing model, but lacks technical depth in explaining the underl |
| Bias, Balance & Hype Control | Gemini | cleared. The briefing effectively highlights the opportunity for industry input without resorting to excessive vendor hype, though some sources lean promotional. |
| Novelty & Non-Duplication | Grok | held. Core facts, two-axis model, competency testing, and deadlines are straight wire repackaging from MassDevice/NatLawReview/STAT/AP with only a generic ‘comment window is the real opportunity’ frame that |
| Validation | DeepSeek | cleared. The central claim that the FDA’s framework is genuinely unsettled and open to influence is validated by the agency’s publication of a non-binding discussion paper and an open comment period, which are |
Sources cited: 15. Validation challenges: 0. Review cost: about $0.04. Learn how these briefings are written and verified.