AI Regulation Tracker / Guidance and standards
FDA Draft Guidance Maps the Full Lifecycle for AI-Enabled Medical Devices
On January 7, 2025, the FDA issued draft guidance titled "Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations." It is the agency's first attempt to tie together design, bias mitigation, cybersecurity, labeling, postmarket monitoring, and predetermined change control plans across the whole life of an AI-enabled device. It is a draft. It is not binding.
Let me set the date honestly up front. This draft guidance was published on January 7, 2025, and the comment window closed on April 7, 2025. It is not new this week. I am writing it up now because it is the clearest single statement the FDA has put on the table about what it wants to see from an AI-enabled device across its whole life, and because most device teams and the health systems buying from them still have not read it closely. The substance is evergreen. Draft guidance tends to preview where the final version and the review desk are heading.
The document comes out of the Center for Devices and Radiological Health, working with the Digital Health Center of Excellence. Its formal title is "Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations." The FDA describes it as the first guidance that would, if finalized, "provide comprehensive recommendations for AI-enabled devices throughout the total product lifecycle, providing developers an accessible set of considerations that tie together design, development, maintenance and documentation recommendations to help ensure safety and effectiveness of AI-enabled devices." That is the whole idea in one sentence. Instead of scattering AI expectations across a dozen documents, FDA is trying to put them in one place and organize them around the life of the device.
Why the agency wrote it
The FDA is not theorizing. It has been clearing these products for years. As Troy Tazbaz, director of the Digital Health Center of Excellence, put it, "The FDA has authorized more than 1,000 AI-enabled devices through established premarket pathways." The guidance is meant to distill what the agency learned from those authorizations into a first point of reference for the next wave of developers, from the earliest stages of development through the device's entire life cycle.
What the guidance actually asks for
The draft is organized around the total product life cycle, the FDA's shorthand for treating premarket and postmarket as one continuous obligation rather than two separate events. A few threads matter most for anyone building or buying these systems.
Design, development, and documentation. The guidance proposes recommendations for how to design, develop, and document an AI-enabled device so that a marketing submission actually lets FDA evaluate its safety and effectiveness. This is not a box-check at the end. The expectation is that the documentation trail starts at the beginning and follows the device through maintenance and updates.
Transparency and bias. This is one of the sharpest parts of the draft. The FDA writes that the guidance includes "the FDA's current thinking on strategies to address transparency and bias throughout the life cycle of AI-enabled devices," and it asks sponsors to show they have addressed the risk that a device does not perform equally well across relevant demographic groups. If your model was trained and validated on a narrow population, this is the section that tells you to prove otherwise or say so plainly.
Cybersecurity and labeling. The draft folds security and the information conveyed to users into the same lifecycle frame. FDA specifically asked for public comment on the type of information about AI-enabled devices that should be conveyed to users and the best way to deliver it, which is the labeling and transparency question that health systems care about most when they deploy a tool clinically.
Postmarket performance monitoring. AI models drift. The FDA knows it, and the guidance includes "recommendations for how and when, in marketing submissions, sponsors should describe the postmarket performance monitoring and management of their AI-enabled devices." In plain terms, you are expected to explain, before you ship, how you will watch the model in the field and what you will do when its performance slips.
Predetermined change control plans. The lifecycle draft is designed to work alongside FDA's separate final guidance on predetermined change control plans, the mechanism that lets a manufacturer pre-authorize certain future model updates without filing a new submission each time. The FDA says this lifecycle guidance "complements the recently issued final guidance on predetermined change control plans for AI-enabled devices, which provides recommendations on how to proactively plan for device updates once the product is on the market." Read together, the two documents describe how to build a device that is allowed to keep learning within bounds you set in advance.
What this is, and what it is not
I want to be precise about status, because it changes how you should act on it. This is a draft guidance. FDA guidance documents, draft or final, are not regulations. They represent the agency's current thinking and use recommending language rather than mandatory language. Nobody incurs a new legal duty because this draft exists, and a sponsor can use an alternative approach that satisfies the underlying statutory and regulatory requirements.
That said, guidance is how the FDA telegraphs what its reviewers will look for. When the review desk publishes a comprehensive, lifecycle-organized set of expectations and asks the public to comment on it, the smart read is that submissions built around these recommendations will move more smoothly, and submissions that ignore them will draw questions. The binding obligations still come from the Federal Food, Drug, and Cosmetic Act and FDA's device regulations. This guidance tells you how the agency currently expects you to meet them for AI.
What this means for device makers and their buyers
If you build AI-enabled device software, treat this as the outline of your next submission. Document design and development decisions as you make them, build a real bias and transparency story around your training and validation data, specify a postmarket performance monitoring plan before launch, and decide whether a predetermined change control plan fits your update strategy. Engaging with FDA early, which the agency openly encourages, is cheaper than reworking a submission after a refuse-to-accept or a deficiency letter.
If you run a hospital, a health system, or a clinical practice that buys these tools, this guidance is a procurement checklist in disguise. It tells you the questions the FDA thinks matter: how was bias addressed, what does the labeling actually disclose, how will the vendor monitor performance after you deploy, and does the product carry a change control plan that governs future updates. A vendor who can answer those in the FDA's own terms is a safer bet than one who cannot.
And for finance and legal leaders overseeing AI adoption, this is a clean example of where regulators keep landing. The obligation follows the product across its whole life, the developer has to document and monitor rather than ship and forget, and fairness across affected groups is treated as a safety issue, not a nicety. That posture is showing up well beyond medical devices.
Questions professionals are asking
Is this FDA guidance binding on device makers?
No. It is a draft guidance. FDA guidance documents, draft or final, describe the agency's current thinking and are not legally enforceable. Binding requirements come from the Federal Food, Drug, and Cosmetic Act and FDA's device regulations. That said, guidance signals what FDA reviewers will expect in a marketing submission, so building to it is the practical path to a smoother review.
What does the guidance actually cover?
It provides marketing submission recommendations plus total-product-lifecycle recommendations for AI-enabled device software functions: design and development, documentation, transparency, bias mitigation, cybersecurity, labeling and information conveyed to users, postmarket performance monitoring, and predetermined change control plans. FDA calls it the first guidance to tie these together across the device's entire life cycle.
How does it relate to predetermined change control plans?
It complements FDA's separate final guidance on predetermined change control plans (PCCPs) for AI-enabled devices. A PCCP lets a manufacturer pre-authorize certain future model changes without filing a new submission for each one. Read together, the lifecycle guidance and the PCCP guidance describe how to build a device that can keep updating within bounds set in advance.
Why does it emphasize bias and transparency?
The FDA states the guidance includes its current thinking on strategies to address transparency and bias throughout the life cycle of AI-enabled devices, and it asks sponsors to demonstrate they have addressed the risk that a device does not perform equally well across relevant demographic groups. The agency treats fairness across populations as a safety-and-effectiveness question, not an optional feature.
Is it still open for comment?
No. The FDA requested public comment by April 7, 2025, and that window has closed. The agency held a webinar on February 18, 2025. As of now the document remains a draft; a final version would supersede it, but the draft still reflects FDA's current expectations for AI-enabled devices.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal, regulatory, or medical advice. Confirm how FDA guidance and device regulations apply to your product with qualified regulatory counsel.