When clinical AI becomes a regulated device
If a software function diagnoses, screens, or drives a clinical decision, it is often a medical device, and the FDA regulates it as Software as a Medical Device. More than 1,000 AI-enabled devices have been authorized, the vast majority as Class II through the 510(k) pathway, with some De Novo authorizations and a few premarket approvals for higher-risk products. The distinctive challenge is that AI models change, and static regulation did not fit adaptive software. The FDA’s answer, finalized in December 2024 and expanded in August 2025, is the predetermined change control plan, which lets manufacturers pre-authorize specified model updates.
This guide explains SaMD classification, the PCCP, what clinical AI validation involves, and how to choose partners. It informs a shortlist rather than a ranking.
The regulatory building blocks
- Classification and pathway. Risk determines the pathway: most AI devices are Class II via 510(k); higher-risk or novel products use De Novo or premarket approval.
- Predetermined change control plan (PCCP). Authorized under FDORA Section 515C, a PCCP submitted with the initial application specifies planned modifications, the protocol to develop and validate them, and an impact assessment, so pre-authorized updates ship without a new submission.
- Good machine-learning practice and lifecycle management. A total-product-lifecycle approach to development, validation, and post-market monitoring, reflecting the FDA’s January 2025 lifecycle guidance.
- Clinical validation and bias. Evidence that the model performs as intended across the intended-use population, with subgroup performance and monitoring for drift.
What clinical AI validation involves
| Component |
What it covers |
Evidence produced |
| Data governance |
Provenance, quality, and representativeness of training and test data |
Documented, traceable datasets fit for intended use |
| Analytical validation |
Model performance against ground truth |
Performance metrics with confidence and limitations |
| Clinical validation |
Performance in the intended clinical context and population |
Clinical evidence supporting the intended use |
| Bias and subgroup testing |
Performance across demographic and clinical subgroups |
Subgroup results and mitigation record |
| PCCP |
Pre-authorized modifications, protocol, and impact assessment |
An FDA-authorized change plan for post-market updates |
| Post-market monitoring |
Real-world performance, drift, and safety signals |
Ongoing monitoring logs and update records |
Partners compared, by archetype
| Archetype |
Role |
Best for |
Watch-outs |
|
FDA regulatory-affairs consultants
|
Submission strategy and PCCP authoring
|
510(k)/De Novo/PMA strategy and FDA interactions
|
Regulatory strategy, not data and MLOps build
|
|
Clinical / CRO partners
|
Clinical validation studies
|
Generating clinical evidence
|
Study execution, not model engineering
|
|
AI/ML engineering & MLOps
|
Model development and deployment
|
Building and operating the model
|
Confirm regulated-data and validation rigor
|
|
Regulated-data & validation specialists
|
Data governance, validation, monitoring infrastructure
|
The data, validation, and monitoring foundation behind submissions and PCCP execution
|
Works alongside regulatory-affairs counsel, not in place of it
|
Where PiTech fits
PiTech Solutions provides the data, validation, and monitoring foundation that clinical AI depends on: data governance and provenance for training and test sets, validation infrastructure and performance documentation, bias and subgroup testing, and the post-market monitoring and MLOps that support a predetermined change control plan. It works alongside FDA regulatory-affairs counsel and clinical partners, owning the engineering and evidence rather than the submission strategy. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications, the disciplined, evidence-first posture a regulated device program needs. See AI, GenAI and ML, Data Solutions, and the healthcare practice. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
Clinical AI that diagnoses or drives decisions is usually a regulated device. Meeting FDA SaMD expectations requires governed data, clinical and analytical validation, bias testing, and lifecycle monitoring, and the PCCP formalizes how updates ship. Pair FDA regulatory-affairs counsel with a data and validation specialist that owns the evidence foundation.
Frequently Asked Questions (FAQs)