India's AI Medical Software Rulebook Keeps the Filing Step | TLY

AI Regulation Tracker  /  Healthcare AI

India's AI Medical Software Rulebook Keeps the Filing Step

India's drug regulator has finalised its guidance on medical device software, and it formalises an Algorithm Change Protocol for AI and machine-learning tools. Trade coverage read that as permission to ship model updates without going back to the regulator. The document says the opposite: even under an approved protocol, a major change needs licensing-authority approval and a minor change needs notification. It also adds a duty that reaches every foreign vendor, requiring justification when a model was trained or validated outside Indian clinical settings.

The Leveraged Years AI Regulation News

India has had software inside its medical device regime since the Medical Devices Rules came into force in 2017. What it has lacked is a document telling manufacturers how the regulator reads those rules when the product is a model that changes after it ships. That document is now final.

The reporting around it has been optimistic. Several summaries describe the Algorithm Change Protocol as a mechanism that lets firms push iterative AI updates without returning to the regulator. That is not what the text says, and the gap matters, because a team that builds a release process on the optimistic reading will be shipping unapproved major changes into a licensed product.

What does the Algorithm Change Protocol actually require?

Start with how permissive the provision is. The guidance says an ACP "may be devised, wherever applicable, based on the nature and risks associated with the MDSW." That is discretionary language. There is no obligation to have one, and no promise attached to having one.

What the ACP must contain, if you write one, is specific. The guidance says it "shall include an overview of all the procedures to be followed so that any changes/modifications made in the MDSW do not compromise its safety and intended use," and then lists five components: a data management plan covering protocols, risk assessment, new data collection and quality assurance; a performance evaluation and monitoring plan with assessment metrics, a statistical analysis plan, assessment frequency and performance targets; an algorithm retraining plan where applicable, covering retraining objectives, methods, evaluation approach and potential impacts on intended purpose; a software update plan covering version tracking, verification and validation, update triggers and procedures, and how updates are communicated to end users; and a rollback plan covering triggers, backup and recovery, and communication to users.

Then comes the sentence that decides the compliance question. The guidance states: "In case any changes are to be made as per the approved ACP, the manufacturer/importer (on behalf of overseas manufacturer) shall submit an approval request/notification with the LA. PAC approval is mandatory for major changes, while notification is required for minor changes." An approved protocol changes the paperwork you have prepared. It does not remove the filing.

Which model updates are major, and which are minor?

This is the part worth putting in front of your release process, and the answer does not come from the guidance's own authority. The guidance points to the Sixth Schedule of the MDR-2017 and maps software onto it.

A version change "which affects intended use, safety and/or effectiveness, risk control measures" is a major change requiring approval. So are modifications to software design or system requirements "including the addition of a new clinical claim or a new data input type," and changes to intended use or indications for use. Adding a new input modality to a diagnostic model is therefore an approval event, not a patch.

On the other side, "revisions for bug fixes and security patches, etc., which does not affect intended use, safety and performance" are minor, as is a version change that does not affect intended use, safety or effectiveness, and "performance re-tuning within validated ranges." That last phrase is the real concession in the document. Re-tuning inside a validated envelope is a notification. Retraining that moves the envelope is not.

What the final guidance added over the October 2025 draft (term counts, draft to final)
Requirement areaDraft, 21 Oct 2025Final, CDSCO/MD/GD/MDSW/01/2026Why it matters
Algorithm Change ProtocolPresentPresent, unchanged in prominenceThe ACP is not new. What is new is that it now sits in a final document
Performance driftAbsentNamed, including "drift monitoring for AI" as a post-market activityCreates an ongoing monitoring expectation, not a one-time submission
AI biasAbsentListed as a risk to document alongside cybersecurity and misuse scenariosBias moves into the risk management file rather than an ethics annex
Software Bill of MaterialsAbsentDefined and usedSupply-chain disclosure for model and library dependencies
Real-world evidenceAbsentDefined, with real-world data distinguished from trial dataOpens a post-market evidence route and sets what does not qualify
Non-Indian training dataAbsentJustification required for applicability to Indian clinical environmentsDirectly reaches every imported AI model

Why should a US or EU vendor read this before exporting?

Because of one sentence that has no analogue in the draft: "Where models are trained or validated in non-Indian settings, justification shall be provided for applicability to Indian clinical environments."

Read plainly, that puts the burden on the applicant to explain why a model trained on, say, North American or European populations and imaging equipment performs as claimed in Indian clinical practice. It is a generalisability argument, and it is the kind of question that is far cheaper to answer during development than during a licence application. If your validation set has no Indian sites, that is now a documentation gap with a named regulator behind it.

Two things I am not going to tell you. I am not going to compare this to the change-plan mechanisms other regulators operate, because I did not open those instruments for this piece and a peer comparison built on memory is how errors enter. And I am not going to give you a compliance deadline, because the document does not carry one.

What does the guidance not do?

It does not create obligations. The notice on its own cover states that it "is aimed only for creating public awareness about Regulations of Medical Device Software and is not meant to be used for legal or professional purposes," and it tells readers to work from the Drugs and Cosmetics Act and the Medical Devices Rules, 2017. That is unusually explicit, and it should shape how you cite it. When you need the duty, cite the Rules. When you need the regulator's reading of the Rules, cite this.

It also does not change the risk classification scheme. Software is classified Class A through Class D under Rule 4 and the First Schedule of the MDR-2017, on the basis of intended use, exactly as before. And it does not resolve whether a given tool is a medical device at all: the guidance keeps a list of software that falls outside the Rules, including software that relies on data from a medical device without having a medical purpose.

For physicians and health systems, the practical consequence is narrower than the document's length suggests. You are not the filer. But the version of an AI tool running in your department is a licensed configuration, and if the vendor pushed a change that affected intended use without approval, that is a licensing problem attached to a device you are using on patients. Asking a vendor which tier its last release fell into is now a reasonable procurement question with a citable basis.

Last verified: July 29, 2026

Questions professionals are asking

Does the Algorithm Change Protocol let AI vendors update models without regulatory filing?

No. The guidance states that where changes are made under an approved ACP, the manufacturer or importer "shall submit an approval request/notification with the LA," and that post-approval change approval is mandatory for major changes while notification is required for minor changes. The protocol organises the evidence in advance. It does not remove the filing step, and reporting that describes it as removing re-licensing is wrong on the text.

Which AI model changes count as minor in India?

Under the Sixth Schedule mapping in the guidance, minor changes include revisions for bug fixes and security patches that do not affect intended use, safety and performance, a version change that does not affect intended use, safety or effectiveness, and performance re-tuning within validated ranges. Minor changes are notified to the licensing authority rather than approved in advance.

Which changes require approval before release?

Major changes require licensing-authority approval. These include a version change that affects intended use, safety or effectiveness or risk control measures, modifications to software design or system requirements including the addition of a new clinical claim or a new data input type, and any change to intended use or indications for use. Adding a new input type to a model is an approval event, not a patch.

What does the guidance require for models trained outside India?

It states that where models are trained or validated in non-Indian settings, justification shall be provided for applicability to Indian clinical environments. This sentence is new in the final document and does not appear in the October 2025 draft. In practice it asks importers to show why performance claims established on foreign populations, practice patterns and equipment hold in Indian clinical use.

Is this guidance binding law in India?

No. Its own notice says the document is aimed only at creating public awareness and is not meant to be used for legal or professional purposes, and it directs readers to the Drugs and Cosmetics Act and the Medical Devices Rules, 2017. The obligations it describes derive from those Rules. Cite the Rules for a duty and this document for the regulator's reading of them.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified professionals in the relevant jurisdiction.