The FDA is not releasing one AI medical device rule in 2026. It finalized a pathway for planned AI model updates, rewrote its cybersecurity requirements, and opened public comment on how generative AI devices should be regulated at all. If you build or deploy AI in a regulated health product, all three now apply to your compliance file.
None of these three moves is final in the same way. The predetermined change control plan guidance and the cybersecurity guidance are both binding today. The generative AI discussion paper is not law yet, but it tells you where FDA's review standards are headed, and the agency is asking industry to help shape the final version before it locks in. Waiting until that becomes a proposed rule means reacting to a standard you had no hand in writing.
We see the same pattern across the regulated clients we work with. Leadership assumes AI governance is a documentation exercise that can happen after the product ships, then finds out during a submission review, an audit, or a due diligence request that the evidence does not exist in the form FDA now expects. Fixing that after the fact costs months. Building it into your existing quality system costs a few weeks of focused work now.
FDA is building AI device oversight in three separate pieces instead of one comprehensive rule. It finalized the predetermined change control plan guidance in August 2025, reissued its device cybersecurity guidance on February 3, 2026, and released a discussion paper on generative AI-enabled devices on August 18, 2026, with comments due October 19. Each piece answers a different question a device maker has to resolve before going to market.
A submission you file today is judged against a change control pathway that is already final, a cybersecurity standard that is already final, and a generative AI framework that is still being negotiated in public. Treating any one of those as optional, or as something to handle after the fact, is the mistake we see most often in client environments building AI-enabled health products.
A PCCP lets you describe future AI model updates inside your original marketing submission instead of filing a new 510(k) or PMA every time you retrain the model. FDA's guidance on predetermined change control plans requires the plan to name the specific modifications, describe how you will validate them, and assess their impact on safety and effectiveness. Once FDA authorizes that plan, you can ship the listed updates under your existing quality system rather than waiting on a new review.
The pathway covers all three FDA marketing routes, so a small diagnostics company faces the identical requirement as a large imaging manufacturer: describe the modification and its validation method up front, or refile every time the model changes. Where we see this go wrong in client environments is a PCCP written broadly enough to sound flexible but too vague for FDA to actually authorize. A plan that says the model will keep improving based on new data gets sent back.
A plan that names the specific retraining trigger, the validation dataset, and the acceptance threshold gets approved, and gives you the speed the pathway was built for. This is exactly the kind of gap our team looks for when we run an AI governance review for a regulated client, because the PCCP only pays off if it is specific enough to actually use.
A PCCP is also not a one-time document you file and forget. FDA expects you to follow the plan's own steps for data, training, testing, labeling, and cybersecurity under your quality system every time you use it, and an inspector can ask you to show that a given model update actually followed the plan you were authorized to run. Companies that keep that evidence current as part of normal operations move through updates quietly. Companies that treat the PCCP as a submission artifact end up reconstructing the record after the fact, usually under time pressure from a customer or an inspector who already found the gap.
FDA reissued its cybersecurity in medical devices guidance on February 3, 2026, superseding the version it had finalized only eight months earlier, this time to align with the new Quality Management System Regulation that took effect the day before. The update folds cybersecurity into the same quality system that governs your AI model documentation instead of treating it as a separate premarket checklist.
In practice, every submission for a covered cyber device now needs a machine-readable software bill of materials that tracks each component and its support status, a documented security risk management process, and a coordinated vulnerability disclosure plan. None of that is conceptually new. What is new is that a gap in your SBOM now shows up as a finding against your design controls and CAPA process during an FDA inspection, not just as a missing form in a submission. If you have not checked where your own documentation actually stands against that combined standard, our cybersecurity assessment is a fast way to find the gap before an auditor does.
The updated guidance also widens what counts as a cyber device in the first place. A component with dormant wireless capability, an inactive radio, or an unused debug port now falls inside FDA's cybersecurity expectations even if that connectivity is never turned on in the field. Device teams that scoped their cybersecurity documentation to active network features only are finding components they had not accounted for, which means the SBOM and risk assessment work is often larger than the original project plan assumed.
On August 18, 2026, FDA's Digital Health Center of Excellence published a discussion paper on generative AI-enabled medical devices asking how it should eventually regulate devices built on generative AI and foundation models, with comments open under docket FDA-2026-N-7874 through October 19. It is not draft or final guidance. It proposes a two-axis framework that scores a device on how independently it acts and how severe the harm would be if its output turns out wrong.
A tool that summarizes clinical notes for a physician to review sits in a different risk position than one that adjusts a medication dose on its own, and the paper proposes calibrating review intensity to that position instead of applying one standard to every generative AI feature. For premarket evaluation, it floats a credentialing-style evaluation model, borrowing the logic FDA uses for physicians: standardized benchmarking, clinical confirmation, and ongoing assessment rather than a single point-in-time review.
It also asks for feedback on a voluntary Foundation Model Device Master File, which would let a foundation model developer submit architecture and benchmark details to FDA on a confidential basis for device sponsors to reference. Filing that master file does not authorize any specific use. The device sponsor still has to prove its own product is safe and effective.
| FDA action | Status | What it requires | Key date |
|---|---|---|---|
| Predetermined Change Control Plan guidance | Final | Named modifications, validation methodology, and safety impact assessment filed with the original submission | Finalized August 2025 |
| Cybersecurity in Medical Devices guidance | Final | Machine-readable SBOM, security risk management, and coordinated vulnerability disclosure inside the QMSR quality system | Reissued February 3, 2026 |
| Generative AI-Enabled Medical Devices discussion paper | Request for feedback | Two-axis risk framework, credentialing-style premarket evaluation, voluntary Foundation Model Device Master File | Comments due October 19, 2026 |
Read across the three rows and the direction is consistent. FDA is not asking whether AI-enabled devices need documented evidence. It has already answered that with two final guidances. What is still open is how much evidence a generative AI feature specifically needs, and that is the question the October comment period exists to shape.
Yes, if you build, license, or deploy a generative AI feature that could plausibly be regulated as a medical device. A discussion paper with an open docket is the one point in this process where the standard is not fixed yet, and companies that comment now carry more weight than companies that wait for a proposed rule and then react to it. The October 19 deadline is close enough that a response needs to start now.
Waiting is also a competitive decision. A device company that can show a regulator, an investor, or a hospital procurement committee a specific PCCP, a cybersecurity file that already meets the February 2026 standard, and a documented comment on the generative AI framework clears due diligence faster than one still assembling that evidence after the fact. If your team is weighing how much of this to build in-house versus bring in outside support, our cybersecurity buyer's guide is a useful place to start that comparison.
A useful comment does not need to answer every question in the paper. It needs to speak to the risk position your own product occupies on FDA's two-axis grid, backed by evidence from your own development and monitoring process. Cite your own benchmarking results, your own failure modes, and your own monitoring data instead of general statements of support or concern. That kind of specific, evidence-based comment is also, not incidentally, a rehearsal for the documentation your eventual premarket submission will need to contain.
FDA's approach here matches what regulators are doing with AI across other sectors in 2026: build the accountability structure in pieces, invite industry to help refine the hardest parts, and expect documented evidence once the framework lands rather than a general policy statement. A device maker that treats PCCP planning, cybersecurity documentation, and generative AI risk classification as three separate projects ends up rebuilding the same evidence three times. One that treats them as a single governance program already has most of what the next FDA guidance requires sitting in its quality system.
Before October 19, work through a short list:
Getting an honest read on where your program stands against that structure is the first real step, before a regulator, investor, or customer finds the gap for you.
FDA's 2026 framework rewards companies that already have their AI governance documented, not companies scrambling to produce it after a submission gets flagged. If your PCCP, cybersecurity file, or generative AI risk position still lives in someone's head instead of your quality system, that gap is worth closing before October 19.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.