Regulation explainerHealthcare

When clinical AI software becomes a medical device in the US, EU and UK

Clinical AI becomes a regulated medical device when its intended use is diagnosing, treating or preventing disease and no exclusion applies. In the US, clinical decision support software stays outside device regulation only if it meets all four statutory criteria that the FDA's current guidance interprets. The EU classifies software under MDR Rule 11 and adds the AI Act, and the UK applies its own Medical Devices Regulations. The answer often differs between the three.

Reviewed 8 min read

On this page
  1. What this explainer covers, and where counsel takes over
  2. Why the device line changes the whole delivery plan
  3. The instruments that decide device status in each market
  4. Six hypothetical tools sorted against the US and EU tests
  5. A decision path to run before writing the intended-use statement
  6. Obligations that apply whether or not the tool is a device
  7. If the tool is a device: authorization routes and model updates
  8. Questions and answers
  9. Sources

What this explainer covers, and where counsel takes over

Why the device line changes the whole delivery plan

On one side of the line, a clinical AI tool is governed by your clinical governance, privacy law and procurement terms. On the other, it needs a quality management system, design controls, clinical evidence, a marketing authorization or conformity assessment, labeling, vigilance reporting and change control for model updates. The engineering is similar; the evidence is not.

The deciding factor is intended use, expressed in labeling, sales material, the user interface and the intended-use statement. Two tools built on the same model can land on opposite sides because one lists guideline options for a clinician to weigh and the other says it detects sepsis. Classification work starts with words, not code.

The instruments that decide device status in each market

Each instrument is named as officially titled and linked to its primary text.

Federal Food, Drug, and Cosmetic Act clinical decision support exclusion, with FDA guidance Clinical Decision Support Software

United States

Applies whenSoftware supports clinical decisions about individual patients. Section 520(o)(1)(E) of the Act excludes software that meets four criteria from the device definition2, and the FDA's revised guidance interprets them1.

  • It does not acquire, process or analyze a medical image, an in vitro diagnostic signal, or a pattern or signal from a signal acquisition system1.
  • It displays, analyzes or prints medical information, and supports or provides recommendations to a health care professional about prevention, diagnosis or treatment1.
  • The professional can independently review the basis for the recommendation, so does not rely primarily on it1.
  • Failing any criterion makes the function a device unless another exclusion or enforcement policy applies.

Regulation (EU) 2017/745 on medical devices (MDR), Annex VIII Rule 11

European Union

Applies whenSoftware has a medical purpose for individual patients and so qualifies as a medical device; Rule 11 then sets its risk class5. The Medical Device Coordination Group publishes qualification and classification guidance for software8.

  • Software giving information used for diagnostic or therapeutic decisions is Class IIa, rising to IIb or III where a wrong decision could cause serious deterioration, surgery or death5.
  • Software monitoring physiological processes is Class IIa, or IIb for vital parameters where variation could mean immediate danger.
  • Class IIa and above require a notified body conformity assessment before CE marking.

Artificial Intelligence Act, Regulation (EU) 2024/1689, with its Digital Omnibus amendment[^7]

European Union

Applies whenAn AI system is a medical device, or a safety component of one, that needs third-party conformity assessment under the MDR, which makes it high-risk under Article 6(1)6.

  • High-risk requirements such as risk management, data governance, logging, transparency and human oversight apply alongside the MDR6.
  • For Article 6(1) systems, those requirements apply from 2 August 2028 under the amending regulation7.

The Medical Devices Regulations 2002, with the MHRA Software and AI as a Medical Device Change Programme[^9]

United Kingdom (Great Britain)

Applies whenSoftware with a medical purpose is placed on the market in Great Britain9.

  • Classification, conformity assessment and registration with the MHRA under the Regulations as amended9.
  • MHRA guidance from the change programme covers qualification, classification, post-market change management including change control plans, and adaptive AI10.

Six hypothetical tools sorted against the US and EU tests

Invented tools that show the reasoning; real classification depends on the exact intended use and claims.

Hypothetical toolUS: FDA CDS criteriaEU: MDR qualification and Rule 11Likely position
Inpatient sepsis alert that pages a rapid response nurseFails criteria 3 and 4: the FDA lists such alarms as device functions1Diagnostic information where errors could be fatal: high classDevice in both markets
Chest X-ray nodule detection for radiologistsFails criterion 1: it analyzes a medical image1Qualifies; at least Class IIaDevice in both markets
Guideline-based lipid therapy options with the guideline cited, shown at a routine visitCan meet all four if the basis is reviewable and not time-criticalPatient-specific therapeutic information: often qualifies, typically Class IIaPossibly non-device in the US but a device in the EU
Draft discharge summary assembled from the chart for a clinician to editUsually outside the device definition while it only drafts documentationUsually not a medical purpose unless it adds diagnostic claimsGenerally not a device; watch the claims
Care-management outreach list ranking members by predicted admissionsArguable; often treated as population management rather than individual diagnosisDepends on whether output drives individual treatment decisionsDocument the reasoning; get counsel

The third row is the one teams most often miss: US non-device status does not carry over to the EU.

A decision path to run before writing the intended-use statement

  • If

    It analyzes an image, an ECG waveform, a glucose sensor stream, sequencing output or another signal.

    Then

    Plan for device regulation in the US from the start.

    The FDA treats image, signal and pattern analysis as failing criterion 1, whatever the output looks like1.

  • If

    It raises an alarm or gives a single directive in a time-critical situation.

    Then

    Assume device status and budget for a marketing submission.

    Automation bias rises when there is no time to review the basis, so the FDA does not treat such outputs as independently reviewable1.

  • If

    It offers recommendations with visible inputs, logic and sources, for decisions with time to reflect.

    Then

    Write down how each of the four criteria is met, and test with clinicians that they can see and understand the basis.

    The FDA notes that usability testing may be needed to show criterion 4 is met1.

  • If

    You will place the product on the EU or GB market.

    Then

    Run MDR qualification and Rule 11 classification separately, then check AI Act high-risk status and UK registration.

    Each regime asks its own question; one answer does not transfer.

  • If

    The model will be retrained or recalibrated after authorization.

    Then

    Draft a predetermined change control plan with the first submission.

    Without one, many model changes need a new submission before release3.

Obligations that apply whether or not the tool is a device

0 of 5 checked

If the tool is a device: authorization routes and model updates

In the US, most AI-enabled device software reaches the market through a 510(k) premarket notification where a predicate exists, or a De Novo request for novel low-to-moderate risk devices; high-risk devices need premarket approval4. The FDA's list of authorized AI-enabled devices is a practical way to find predicates and see how similar intended uses were worded11.

Machine learning adds a specific problem: the model you validated is not the model you will want in a year. A predetermined change control plan describes planned modifications, the protocol for developing, validating and implementing them, and their impact, reviewed with the original submission3. Changes inside the authorized plan can ship without a new submission; changes outside it cannot.

In the EU, a notified body assesses Class IIa and above, and significant changes to an AI device go back through it5. In Great Britain, the MHRA treats change management and adaptive AI as separate work packages, so check its current guidance before assuming a US plan will be accepted10.

Questions and answers

Does the FDA regulate AI tools a hospital builds in-house for its own clinicians?

Device status depends on the software's intended use and function, not on who wrote the code or whether it is sold. The statutory exclusion for clinical decision support applies to in-house tools on the same four criteria2. Run the same analysis on internally built models, keep the reasoning on file, and take regulatory advice where a tool analyzes images or signals or raises time-critical alerts.

Is a generative AI assistant for clinicians a medical device?

The criteria apply to the function, whatever the model. An assistant that answers general questions from cited reference material sits differently from one that reads a patient's record and proposes a diagnosis or dose. Generative tools also make criterion 4 harder to meet, because the clinician must be able to review the basis for the output1. Show the inputs and sources it relied on, and avoid single directive outputs.

If our tool is FDA cleared, can we sell it in the EU?

Not on that basis. The EU requires its own MDR qualification and Rule 11 classification, a notified body assessment for Class IIa and above, and CE marking5. Where the device is high-risk under the AI Act, its extra requirements apply from 2 August 20287. US evidence can be reused once it is organized against the EU's general safety and performance requirements.

What does a predetermined change control plan contain?

Under the FDA's final guidance, a plan has three parts: a description of the specific modifications you intend to make, a modification protocol setting out how each will be developed, validated and implemented, and an impact assessment of benefits and risks3. It is reviewed with the marketing submission. Retraining on new data, threshold changes and input expansions are typical candidates; changes to intended use are not.

Sources

  1. Clinical Decision Support Software: Guidance for Industry and Food and Drug Administration Staff — U.S. Food and Drug Administration · checked 10 October 2026
  2. 21 U.S. Code § 360j (FD&C Act section 520), including subsection (o) — Legal Information Institute, Cornell Law School · checked 10 October 2026
  3. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions — U.S. Food and Drug Administration · checked 10 October 2026
  4. Software as a Medical Device (SaMD) — U.S. Food and Drug Administration · checked 10 October 2026
  5. Regulation (EU) 2017/745 on medical devices — EUR-Lex · checked 10 October 2026
  6. Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  7. Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
  8. Guidance: MDCG endorsed documents and other guidance — European Commission · checked 10 October 2026
  9. The Medical Devices Regulations 2002 — legislation.gov.uk · checked 10 October 2026
  10. Software and AI as a Medical Device Change Programme: roadmap — Medicines and Healthcare products Regulatory Agency · checked 10 October 2026
  11. Artificial Intelligence-Enabled Medical Devices — U.S. Food and Drug Administration · checked 10 October 2026
  12. 45 CFR § 170.315 ONC certification criteria for health IT, including (b)(11) decision support interventions — eCFR · checked 10 October 2026
  13. 45 CFR § 92.210 Nondiscrimination in the use of patient care decision support tools — eCFR · checked 10 October 2026
  14. 45 CFR § 164.502 Uses and disclosures of protected health information: general rules — eCFR · checked 10 October 2026
  15. HTI-5 Proposed Rule Chart — Assistant Secretary for Technology Policy / ONC · checked 10 October 2026

More in Healthcare

Back to Healthcare

Next step

Pressure-test your intended-use statement before you build

Send the draft intended-use statement, a screenshot or mock-up of the output and where it appears in the clinical workflow. We will map it against the FDA criteria and Rule 11 and return a list of open questions to take to your regulatory counsel.

Send your intended use