AI-Enabled Medical Devices in 2026: Regulation, Evidence and Deployment

AI-Enabled Medical Devices in 2026: Regulation, Evidence and Deployment

Artificial intelligence stopped being an exotic feature of medical devices some time ago. It is now embedded in mammography workstations, CT reconstruction pipelines, continuous glucose monitors, ECG algorithms, ultrasound guidance tools and triage software running quietly inside hospital networks. The regulatory scaffolding around those products, however, changed substantially between late 2024 and mid-2026 — and much of the published guidance professionals rely on is now out of date.

This matters to a wide group of readers. Clinicians are asked to act on outputs whose validation basis they rarely see. Procurement and biomedical engineering teams inherit lifecycle obligations that did not exist for a CT scanner bought a decade ago. Regulatory and quality professionals are working under a new US quality system rule and a shifting EU timetable. Health-system executives are signing contracts whose value depends on post-deployment performance that almost nobody is systematically measuring.

This article sets out what is established, what is genuinely contested, and what remains speculative. It covers how the category grew, the regulatory architecture as it stands in mid-2026, the well-documented weaknesses in the evidence base, what credible real-world deployment looks like, and the cybersecurity duties that now travel with connected devices. It is written for professionals who need to make decisions, not for readers looking for a forecast.

Executive Summary

  • The FDA's public AI-Enabled Medical Device List, updated to cover marketing decisions through 31 March 2026, contained 1,524 entries, up from 1,451 at the end of 2025. The agency states the list is not a comprehensive inventory.
  • Radiology dominates. Trade analysis of the same list counts roughly 1,164 radiology devices — about 76% of all entries, a share that has stayed remarkably stable for several years.
  • No generative-AI or large-language-model device had been authorised by the FDA for any clinical purpose as of the most recent public reporting reviewed here (March 2026). This is a frequent point of confusion.
  • Clearance is not clinical validation. A 2024 Nature Medicine analysis found that roughly 43% (226 of 521) of AI devices authorised between 1995 and 2022 reported no clinical validation data.
  • Reporting on populations is thin. A 2024 npj Digital Medicine scoping review found that only 3.6% of approvals reported race or ethnicity and 81.6% did not report subject age.
  • The US rulebook changed. The Quality Management System Regulation (QMSR) took effect on 2 February 2026, incorporating ISO 13485:2016 by reference and retiring the QSIT inspection approach.
  • The EU timetable moved. The Digital Omnibus on AI, adopted in June 2026, defers AI Act high-risk obligations for AI embedded in regulated products — including medical devices — to 2 August 2028. The obligations themselves are unchanged.
  • Cybersecurity is now a marketing-authorisation gate, not a recommendation. Section 524B of the FD&C Act requires a software bill of materials (SBOM) for "cyber devices."
  • Randomised evidence now exists for at least one screening use case: the Swedish MASAI trial reported both higher cancer detection and a lower interval-cancer rate. It is one trial, in one system, with one product.

From Novelty to Infrastructure: How the Category Grew

The first entry on the FDA's AI device list dates to 1995 — a cervical-smear rescreening system — but the category was negligible until the mid-2010s. Growth since then has been driven less by scientific breakthrough than by regulatory plumbing: once a novel device is authorised through the De Novo pathway, it can serve as a predicate for subsequent 510(k) submissions, which demonstrate substantial equivalence rather than independent clinical benefit. That predicate chain explains both the acceleration and much of the evidentiary criticism the field attracts.

The concentration is striking. Independent analysis of the FDA list published in June 2026 put GE HealthCare in front with 130 radiology AI authorisations, followed by Siemens Healthineers (95), Philips (58), Canon (48) and United Imaging (40) — figures that include devices acquired with companies. Specialist vendors such as Aidoc (33) and DeepHealth (29) sit alongside them. Consolidation is now a defining feature of the market, which has direct procurement consequences: a tool bought from a startup may be supported, or discontinued, by a large imaging vendor two years later.

Callout — Read the list carefully. The FDA is explicit that its AI-Enabled Medical Device List is assembled from AI-related terminology in public authorisation summaries, not from an exhaustive audit. It undercounts devices whose summaries do not use those terms and cannot be treated as a market census. Researchers have separately catalogued the limitations of regulatory AI databases across jurisdictions.

The Regulatory Architecture in 2026

Four distinct obligations now apply simultaneously to a connected, AI-enabled device sold in both the US and EU. Teams that treat them as one compliance workstream tend to discover the gaps late.

Table 1. Concurrent regulatory obligations for a connected AI-enabled device (mid-2026)

InstrumentJurisdictionWhat it governsStatus as of 2 Aug 2026Practical consequence
510(k) / De Novo / PMAUSMarket authorisationEstablishedDetermines evidence burden; De Novo creates future predicates
PCCP final guidance (4 Dec 2024)USPre-authorised model changesFinalUpdate models without a new submission — only within the declared envelope
AI-DSF lifecycle draft guidance (7 Jan 2025)USSubmission content, TPLC designStill draft; on FY2026 guidance agendaSignals expectations; not binding
QMSR, 21 CFR 820USQuality management systemEffective 2 Feb 2026ISO 13485:2016 incorporated by reference; new inspection programme
FD&C Act §524B + Feb 2026 cybersecurity guidanceUSConnected device securityIn forceSBOM and vulnerability management required for cyber devices
MDR 2017/745 / IVDR 2017/746EUDevice conformityIn force; transitions run to 2027–2028; reform proposed Dec 2025Notified body review; clinical evidence expectations
AI Act (EU) 2024/1689EUHigh-risk AI systemsHigh-risk duties for Annex I products deferred to 2 Aug 2028Runs in addition to MDR for most Class IIa+ AI devices

The United States: lifecycle thinking becomes explicit

The predetermined change control plan (PCCP) is the single most consequential change of the past two years. Finalised on 4 December 2024, it allows a manufacturer to specify in advance which modifications an AI-enabled device software function may undergo, how those changes will be validated, and how their impact will be assessed — and to implement them without a fresh marketing submission. The final version broadened scope from machine learning specifically to all AI-enabled device software functions and tightened expectations around independent test data and user-facing labelling.

For buyers, a PCCP is a document worth asking for. It tells you whether the product you validated last quarter is the product running today, and what boundaries the manufacturer committed to.

The QMSR transition, effective 2 February 2026, is less discussed but operationally larger. It replaces the decades-old Quality System Regulation with a framework built on ISO 13485:2016 and supplemental FDA requirements. Inspection scope expanded correspondingly: management review minutes, internal audit reports relating to device malfunctions and supplier audit reports are now within reach of FDA investigators in ways they generally were not before.

The European Union: two regimes, one product

An AI-enabled device in the EU is regulated as a device under MDR or IVDR and, where it requires notified body involvement, as a high-risk AI system under the AI Act. The Digital Omnibus on AI — proposed 19 November 2025, provisionally agreed 7 May 2026 and adopted by the Council on 29 June 2026 — deferred the high-risk application date for AI embedded in Annex I products from 2 August 2027 to 2 August 2028, and standalone Annex III systems to 2 December 2027. The substantive requirements did not change; the harmonised standards needed to demonstrate conformity were simply not ready.

Separately, the European Commission published a substantial MDR/IVDR reform proposal on 16 December 2025, addressing open-ended certificates, streamlined change control, breakthrough and orphan device pathways, and digitalised processes. MedTech Europe backed the direction in its 5 May 2026 position while requesting targeted changes. Legal analysts have cautioned that adoption is unlikely before 2027 and that the text will change materially in negotiation. Nothing in the proposal should be treated as current law.

The Evidence Gap: The Field's Most Serious Unresolved Problem

The strongest criticism of AI-enabled devices is not that they fail, but that we frequently cannot tell whether they work in the settings where they are used.

Two peer-reviewed analyses established the baseline. Chouffani El Fassi and colleagues, writing in Nature Medicine in 2024, examined FDA-authorised AI devices from 1995 to 2022 and found that 226 of 521 — about 43% — reported no clinical validation data at all. Separately, Muralidharan and colleagues found in npj Digital Medicine that among approvals reviewed, only 3.6% reported race or ethnicity, 81.6% omitted subject age, and fewer than half provided detailed performance results.

These are reporting gaps as much as evidence gaps, and the distinction matters: a manufacturer may hold data it does not publish. But from the position of a hospital deciding whether a device will perform on its own population, an unpublished study and a non-existent one are functionally identical.

Table 2. Four questions a device claim can answer — and which one you are usually shown

Evidence tierQuestion answeredTypical study designHow often it appears in public summaries
Analytical / technical validationDoes the model reproduce the intended measurement?Bench testing, retrospective datasetsAlmost always
Clinical validationDoes output correspond to the clinical condition in real patients?Retrospective multi-site, occasionally prospectiveFrequently absent
Clinical utilityDoes using it change decisions and outcomes?Prospective comparative or randomisedRare
Real-world performanceDoes it still work here, on this population, this year?Prospective monitoring, registriesRarer still; largely unregulated

The gap between tiers two and three is where most disappointment originates. A device may be statistically excellent and clinically inert if it flags findings clinicians already catch, or if alert volume drives users to ignore it.

What Credible Deployment Looks Like

The clearest counter-example to the evidence critique comes from breast screening. The Swedish MASAI trial, run within a national screening programme and enrolling more than 105,000 women, reported a 44% reduction in screen-reading workload in its 2023 interim safety analysis (The Lancet Oncology), a 29% increase in cancer detection without an increase in false positives in a 2025 analysis (The Lancet Digital Health; detection rate 6.4 versus 5.0 per 1,000), and — in final results published in The Lancet on 29 January 2026 — an interval-cancer rate approximately 12% lower in the AI-supported arm, meeting the trial's non-inferiority criterion.

That is a genuinely strong result and deserves to be described precisely. It is a screening-accuracy trial, not a mortality trial. It evaluated one commercial system, within one national programme, with a reading workflow specifically designed around the tool. Generalisation to other products, other populations or other workflows is a hypothesis, not a finding.

Two adjacent efforts test that hypothesis. A German group published a nationwide real-world implementation analysis of AI in population-based mammography screening in Nature Medicine in 2025. In the UK, the EDITH study has been reported as planning to evaluate five AI platforms across roughly 30 NHS sites in approximately 700,000 women, supported by around £11 million in government funding. Results were not available at the time of writing.

Figure 1 — proposed original diagram. Title: "Total Product Lifecycle of an AI-Enabled Medical Device." Purpose: show that regulatory obligation does not stop at authorisation. Layout: horizontal flow of six boxes — Intended Use Definition → Data Curation & Model Development → Analytical Validation → Clinical Validation → Marketing Authorisation (510(k) / De Novo / PMA) → Deployment. From "Deployment," a return arrow labelled "Real-world performance monitoring" loops back to "Data Curation," passing a decision diamond labelled "Change within PCCP envelope?" with two exits: "Yes → implement under PCCP" and "No → new marketing submission." Overlay a shaded band beneath the whole flow labelled "QMSR / ISO 13485 quality system" and a second labelled "Cybersecurity: SBOM, vulnerability management (§524B)." Caption: Authorisation is one checkpoint in a loop, not an endpoint.

Figure 2 — proposed original diagram. Title: "Post-Deployment Drift Monitoring Loop." Purpose: give clinical engineering teams a template. Components, in sequence: Site baseline (performance measured on local data before go-live) → Live inference → Sampled human review → Metric comparison against baseline (sensitivity, specificity, alert rate, case-mix distribution) → Threshold breach decision → three branches: Continue / Retune within PCCP / Escalate to manufacturer and consider suspension. Visual hierarchy: baseline box emphasised in the strongest colour; the escalation branch in a warning tone. Caption: Drift is detected by comparison against a local baseline — which must be captured before deployment, or not at all.

Cybersecurity: No Longer a Post-Market Afterthought

Section 524B of the Federal Food, Drug, and Cosmetic Act, added by the Consolidated Appropriations Act, 2023 and effective from 29 March 2023, made cybersecurity an authorisation requirement for "cyber devices." Manufacturers must submit a plan for monitoring and disclosing vulnerabilities, demonstrate reasonable assurance the device is cybersecure, and provide a software bill of materials covering commercial, open-source and off-the-shelf components. FDA's final premarket cybersecurity guidance was reissued in February 2026, superseding the June 2025 version and reframing the document around quality management system considerations.

The scope is wider than most teams assume: a device with a USB port can fall within the "cyber device" definition. For health systems, the practical implication is that SBOMs are becoming a procurement artefact — the basis for answering, within hours rather than weeks, whether a newly disclosed library vulnerability affects a given fleet.

AI adds threat surface upstream of the deployed model. Data poisoning, model inversion, training-data leakage and performance drift attack the pipeline — training data, model registries, evaluation logic, deployment mechanisms — rather than the runtime binary that traditional penetration testing examines.

Frequently Misunderstood Concepts

  • "FDA-cleared" implies clinical proof. It does not. 510(k) clearance establishes substantial equivalence to a predicate device.
  • "The AI learns from our patients." Almost never. The overwhelming majority of authorised devices are locked models; changes occur through manufacturer-controlled releases, increasingly under a PCCP.
  • "There are FDA-approved LLM devices." As of the most recent public reporting reviewed, no generative-AI or LLM-based device had been authorised for any clinical purpose. FDA's Digital Health Advisory Committee discussed the question for hypothetical prescription mental-health chatbots on 6 November 2025.
  • "CE marking and AI Act compliance are the same exercise." They are separate obligations with separate evidence, on different timetables.
  • "Post-market surveillance covers model drift." Traditional vigilance systems capture adverse events, not gradual accuracy decay — which typically produces no reportable event at all.

Latest Developments

  • 4 December 2024 — FDA finalised PCCP guidance for AI-enabled device software functions (Docket FDA-2022-D-2628).
  • 7 January 2025 — FDA published draft guidance on AI-DSF lifecycle management and marketing submissions (Docket FDA-2024-D-4488). Still draft.
  • 27 June 2025 — Final premarket cybersecurity guidance issued, adding a section addressing §524B.
  • 6 November 2025 — FDA Digital Health Advisory Committee met on generative-AI-enabled digital mental health devices; recommendations addressed post-market registries, local data reporting and PCCP adaptation. Advisory, not binding.
  • 19 November 2025 — European Commission tabled the Digital Omnibus on AI.
  • 16 December 2025 — European Commission published its MDR/IVDR reform proposal. Proposal only.
  • 29 January 2026 — Final MASAI results published in The Lancet.
  • 2 February 2026 — QMSR took effect; QSIT inspection technique retired.
  • February 2026 — Revised FDA cybersecurity guidance published, superseding the June 2025 version.
  • 28 May 2026 — Several EUDAMED modules reported as becoming mandatory. Verify current status directly with the Commission.
  • 29 June 2026 — Council of the EU adopted the Digital Omnibus on AI. Official Journal publication was reported as pending in early July 2026.

Barriers, Trade-offs and Open Questions

Reimbursement remains the binding constraint in many systems: a device can be authorised, clinically useful and still unfunded. Notified body capacity in the EU continues to produce review timelines measured in quarters. Local validation capability is unevenly distributed — the practice of measuring a baseline before go-live is standard in a minority of well-resourced centres and absent almost everywhere else.

Open research problems worth watching: how to detect drift without a labelled ground truth in routine care; whether automation bias reduces the benefit of assistive tools over time; how to evaluate systems with open-ended outputs against fixed performance criteria; and whether PCCP monitoring, designed for locked models, extends coherently to generative systems. Expert opinion is divided on the last point and no consensus exists.

Practical Takeaways

For clinical and biomedical engineering teams

  1. Measure a local performance baseline before go-live. Without it, drift is undetectable.
  2. Request the PCCP and the change log. Ask what the manufacturer is permitted to change without telling you.
  3. Track alert volume and override rates alongside accuracy. Ignored output is failed output.

For procurement and regulatory affairs

  1. Ask for the SBOM as a contractual deliverable, and for a defined vulnerability-disclosure timeline.
  2. Confirm which specialty and indication the authorisation actually covers — not what the marketing material implies.
  3. Assess vendor continuity risk explicitly, given consolidation.

For manufacturers and developers

  1. Treat the January 2025 draft guidance as a design specification, not a future obligation.
  2. Build the QMSR evidence trail for management review and supplier audits; inspection scope has widened.
  3. Report subgroup performance. It is the cheapest available differentiator in a market where most competitors do not.

Key Insights

  1. Regulatory authorisation answers a narrower question than most clinicians assume.
  2. The predicate chain explains both rapid growth and thin independent evidence.
  3. Radiology's ~76% share has been stable for years; diversification is slower than commonly claimed.
  4. PCCPs are the most practically useful new document for buyers, not just manufacturers.
  5. QMSR widened US inspection scope more than it changed underlying requirements.
  6. Cybersecurity is now a gate to market, and SBOMs are a procurement artefact.
  7. AI-specific threats sit upstream of the deployed model.
  8. MASAI shows the ceiling of what good evidence looks like — and how rare it is.
  9. Post-market drift is the field's largest unmonitored risk.
  10. EU deadline deferrals removed time pressure, not obligations.

Frequently Asked Questions

What is an AI-enabled medical device? A device — hardware, software, or software embedded in hardware — whose intended medical purpose depends on one or more AI models. In the US, FDA uses the term "AI-enabled device software function" (AI-DSF).

How many AI medical devices has the FDA authorised? The FDA's list contained 1,524 entries covering decisions through 31 March 2026. The agency notes the list is not comprehensive.

Does FDA clearance mean a device is clinically validated? No. Peer-reviewed analysis found roughly 43% of devices authorised between 1995 and 2022 reported no clinical validation data.

What is a predetermined change control plan? A pre-authorised description of planned modifications, their validation methodology and impact assessment, allowing updates without a new marketing submission. Final FDA guidance issued 4 December 2024.

Has the FDA authorised any generative AI or LLM device? Not as of the most recent public reporting reviewed here. Its advisory committee discussed the topic on 6 November 2025.

What changed on 2 February 2026? The Quality Management System Regulation took effect, incorporating ISO 13485:2016 by reference into 21 CFR Part 820 and replacing the QSIT inspection approach.

When do EU AI Act rules apply to medical devices? Following the Digital Omnibus adopted in June 2026, high-risk obligations for AI embedded in Annex I products apply from 2 August 2028. Verify current status before relying on this date.

Does an AI device need both MDR and AI Act compliance? Generally yes, where notified body involvement is required. They are parallel obligations.

What is a "cyber device"? Under §524B, broadly a device with software that connects — even indirectly — to a network. Interpretation has extended to devices with USB ports.

Why does an SBOM matter to a hospital? It allows rapid determination of whether a newly disclosed vulnerability affects your installed fleet.

What is model drift? Degradation of performance over time as the deployed population, imaging equipment or clinical practice diverges from training conditions.

How do we detect drift without ground truth? Imperfectly. Proxy monitoring — alert rates, case-mix distribution, override rates, sampled human review — is current best practice, not a solved problem.

Is there randomised evidence that AI improves screening? Yes, for one context: the MASAI trial. It is a single trial, one product, one national programme.

What is the biggest practical mistake teams make? Deploying without a local baseline, which makes subsequent performance questions unanswerable.

Are AI devices reimbursed? Variably, and often not. Reimbursement pathways lag authorisation in most health systems.

Glossary

510(k) — US premarket notification demonstrating substantial equivalence to a legally marketed predicate. AI-DSF — Artificial intelligence-enabled device software function; FDA's term for a device software function implementing one or more AI models. De Novo — US pathway for novel low-to-moderate risk devices without a predicate. GMLP — Good Machine Learning Practice; ten guiding principles issued jointly by FDA, Health Canada and MHRA in October 2021. IVDR — Regulation (EU) 2017/746 on in vitro diagnostic medical devices. MDR — Regulation (EU) 2017/745 on medical devices. PCCP — Predetermined change control plan. PMA — Premarket approval; the most demanding US pathway, for Class III devices. QMSR — Quality Management System Regulation; revised 21 CFR Part 820, effective 2 February 2026. SaMD — Software as a Medical Device; software with a medical purpose that is not part of a hardware device. SBOM — Software bill of materials. TPLC — Total product lifecycle. §524B — Section of the FD&C Act establishing cybersecurity requirements for cyber devices


References

Academic Papers

Chouffani El Fassi, S., Abdullah, A., Fang, Y., Kumari, S., Ghazi, A., Choudhury, S., & Henderson, G. E. (2024). Not all AI health tools with regulatory authorization are clinically validated. Nature Medicine, 30, 2718–2720. https://doi.org/10.1038/s41591-024-03203-3

Eisemann, N., Bunk, S., Mukama, T., et al. (2025). Nationwide real-world implementation of AI for cancer detection in population-based mammography screening. Nature Medicine, 31, 917–924.

Hernström, V., Josefsson, V., Sartor, H., et al. (2025). Screening performance and characteristics of breast cancer detected in the Mammography Screening with Artificial Intelligence trial (MASAI): A randomised, controlled, parallel-group, non-inferiority, single-blinded, screening accuracy study. The Lancet Digital Health, 7, e175–e183.

Interval cancer, sensitivity, and specificity comparing AI-supported mammography screening with standard double reading without AI in the MASAI study: A randomised, controlled, non-inferiority, single-blinded, population-based, screening-accuracy trial. (2026). The Lancet, 407(10527). Published online 29 January 2026. https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(25)02464-X/abstract

Lång, K., et al. (2023). Artificial intelligence-supported screen reading versus standard double reading in the Mammography Screening with Artificial Intelligence trial (MASAI): Clinical safety analysis. The Lancet Oncology.

Muralidharan, V., Adewale, B. A., Huang, C. J., Nta, M. T., Ademiju, P. O., Pathmarajah, P., … Olatunji, T. (2024). A scoping review of reporting gaps in FDA-approved AI medical devices. npj Digital Medicine, 7, 273. https://doi.org/10.1038/s41746-024-01270-x

Wu, E., Wu, K., Daneshjou, R., Ouyang, D., Ho, D. E., & Zou, J. (2021). How medical AI devices are evaluated: Limitations and recommendations from an analysis of FDA approvals. Nature Medicine, 27, 582–584.

Official Documentation and Government Sources

U.S. Food and Drug Administration. (2024). Marketing submission recommendations for a predetermined change control plan for artificial intelligence-enabled device software functions (Final guidance; Docket No. FDA-2022-D-2628). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence

U.S. Food and Drug Administration. (2025). Artificial intelligence-enabled device software functions: Lifecycle management and marketing submission recommendations (Draft guidance; Docket No. FDA-2024-D-4488). https://www.federalregister.gov/documents/2025/01/07/2024-31543/artificial-intelligence-enabled-device-software-functions-lifecycle-management-and-marketing

U.S. Food and Drug Administration. (2026). Cybersecurity in medical devices: Quality management system considerations and content of premarket submissions (Final guidance, February 2026; Docket No. FDA-2021-D-1158). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket

U.S. Food and Drug Administration. (2026). Quality Management System Regulation (QMSR). https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr

U.S. Food and Drug Administration. (2025). Digital Health Advisory Committee meeting summary: Generative artificial intelligence-enabled digital mental health medical devices, November 6, 2025. https://www.fda.gov/media/190450/download

U.S. Food and Drug Administration. (2025). Cybersecurity in medical devices: Quality system considerations and content of premarket submissions (Federal Register notice, 27 June 2025). https://www.federalregister.gov/documents/2025/06/27/2025-11669/cybersecurity-in-medical-devices-quality-system-considerations-and-content-of-premarket-submissions

U.S. Food and Drug Administration, Health Canada, & Medicines and Healthcare products Regulatory Agency. (2021). Good machine learning practice for medical device development: Guiding principles. https://www.fda.gov/media/153486/download

Health Canada, U.S. Food and Drug Administration, & Medicines and Healthcare products Regulatory Agency. (n.d.). Transparency for machine learning-enabled medical devices: Guiding principles. https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/transparency-machine-learning-guiding-principles.html

Standards and Legislation

International Organization for Standardization. (2016). ISO 13485:2016 — Medical devices: Quality management systems — Requirements for regulatory purposes.

International Organization for Standardization. (2019). ISO 14971:2019 — Medical devices: Application of risk management to medical devices.

International Electrotechnical Commission. (2015). IEC 62304 — Medical device software: Software life cycle processes (incl. Amendment 1).

Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices (MDR).

Regulation (EU) 2017/746 of the European Parliament and of the Council on in vitro diagnostic medical devices (IVDR).

Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).

Consolidated Appropriations Act, 2023, § 3305, amending the Federal Food, Drug, and Cosmetic Act by adding § 524B.

Industry Reports and Trade Analysis

MedTech Europe. (2026, May 5). MedTech Europe backs EU device regulation overhaul but asks key changes. https://www.medtecheurope.org/2026/05/05/medtech-europe-backs-eu-device-regulation-overhaul-but-asks-key-changes/

MedTech Dive. (2026, May 27). AI in medtech is booming. Track new devices here. https://www.medtechdive.com/news/ai-medtech-track-new-devices-fda/748397/

The Imaging Wire. (2026, June 17). Top 10 radiology AI vendors by number of FDA authorizations. https://theimagingwire.com/2026/06/17/top-10-radiology-ai-vendors-by-number-of-fda-authorizations/

Note on sourcing: Counts of authorised AI-enabled devices derive from the FDA's public AI-Enabled Medical Device List as reported in the trade analyses cited above; the FDA states the list is not a comprehensive inventory. Where legislative instruments were adopted but pending Official Journal publication at the time of writing, this is stated in the text.

One Tech & AI · Sunday, August 2, 2026 · 22 min read

Accurate Diagnosis and Monitoring – Medical devices provide precise diagnostics, continuous patient monitoring, and real-time health data to support informed clinical decisions.

Advanced Technology Integration – Modern medical devices incorporate AI, sensors, connectivity, and automation to improve healthcare efficiency, accuracy, and patient safety.

Improved Patient Outcomes – From wearable health trackers to advanced imaging systems and life-support equipment, medical devices enable faster treatment, personalized care, and better overall healthcare outcomes.

The centre of gravity in AI-enabled medical devices has shifted from getting products authorised to keeping them trustworthy once deployed. The regulatory changes of 2024 to 2026 — PCCPs, QMSR, statutory cybersecurity duties, the EU's dual-track regime — all point the same direction: towards obligations that persist across a product's life rather than concentrating at a single approval moment.

The evidence base has not kept pace uniformly. MASAI demonstrates that rigorous randomised evaluation of a screening AI system is achievable at national scale, while the published analyses of FDA authorisations show how atypical that level of proof remains. Both things are true simultaneously, and professionals should resist summaries that pick one.

Two limitations of this article deserve stating. The FDA's device list is a curated sample, so all counts derived from it are approximations. And several European dates described here rest on legislation adopted but, at the time of writing, awaiting final publication — a category of fact that changes without notice.

The most defensible position available on current evidence is neither enthusiasm nor scepticism about AI-enabled devices as a class, but insistence on a narrower question: for this device, in this population, measured against what baseline, monitored by whom. Institutions that can answer it will be able to distinguish tools that help from tools that merely pass.

TOPIC

Health Tech