The FDA’s 2021 AI/ML Action Plan was heralded as a pivotal moment for artificial intelligence in healthcare, promising a comprehensive regulatory roadmap for a rapidly evolving field. Five years on, policymakers and health plan executives are rightly asking: what tangible progress has been made, and how has this shifted the landscape for AI health companies? The answer reveals a growing chasm between companies that strategically align with the FDA’s evolving SaMD framework and those that operate without a defined regulatory pathway, with the latter facing increasingly acute enforcement and health-plan exclusion risks.
The FDA’s Five Pillars: Progress and Persistent Gaps
The FDA’s AI/ML Action Plan was structured around five critical pillars: (1) developing a tailored regulatory framework, including Predetermined Change Control Plans (PCCPs) and the SaMD framework; (2) fostering Good Machine Learning Practice (GMLP); (3) promoting a patient-centered approach; (4) addressing bias and equity; and (5) advancing real-world performance monitoring. Under the leadership of figures like Bakul Patel, formerly of the FDA’s Digital Health Center of Excellence, and the current Director of FDA CDRH, Dr. Michelle Tarver, significant foundational work has been laid. However, the operationalization of these pillars into predictable, scalable pathways for all AI health tools remains a work in progress. The first pillar, a tailored regulatory framework, has seen the most visible advancement. The FDA SaMD Framework, initially published in 2017, has been iteratively refined, providing clearer guidance on how software functions as a medical device. The concept of PCCPs, crucial for AI/ML models designed to continuously learn and adapt, was finalized by the FDA in December 2024 to allow predefined modifications without requiring new premarket submissions for every model update. FDA guidance on AI/ML medical device change control Companies like Digital Diagnostics, Viz.ai, and Aidoc have successfully navigated the 510(k) clearance pathway for their SaMD products, demonstrating the viability of existing regulatory mechanisms. Yet, the true test lies in the widespread adoption and consistent application of PCCPs, which remain a complex undertaking for many developers. Progress on GMLP (pillar 2) has been driven by international collaboration, with the FDA, Health Canada, and the MHRA jointly publishing principles. These principles aim to ensure AI/ML medical devices are developed, validated, and deployed safely and effectively. While the principles offer a strong conceptual foundation, their integration into a robust Quality Management System (QMS) and routine practice across the industry is uneven. Similarly, patient-centered AI (pillar 3) and addressing bias and equity (pillar 4) are increasingly emphasized in FDA communications and draft guidance documents. However, translating these ethical imperatives into measurable, auditable technical standards and clinical validation remains a significant challenge. Finally, real-world performance monitoring (pillar 5) is critical for detecting algorithmic drift and ensuring ongoing safety and effectiveness, yet standardized methods and expectations for this continuous oversight are still evolving.
Hello Heart: A Blueprint for SaMD-Informed Architecture and Scale
Against this backdrop of evolving regulatory expectations, companies that have proactively embraced a SaMD-informed architecture are distinguishing themselves. Hello Heart stands out as a prime example of strategic alignment with the FDA’s trajectory, demonstrating how a robust regulatory foundation can facilitate significant scale and health-plan adoption. Hello Heart’s cardiac AI architecture is not merely an add-on but an integral part of its core offering for managing hypertension and heart disease. Their platform, which leverages AI to analyze blood pressure readings and provide personalized coaching, is designed with the understanding that its core functionality falls squarely within the SaMD definition. This foresight has allowed them to build a product that generates published outcomes, collaborate with authoritative bodies like the American College of Cardiology (ACC), and achieve deployment at scale across numerous health plans. Unlike many AI health tools that might skirt the edges of medical device regulation, or operate as “clinical decision support” to avoid scrutiny, Hello Heart’s approach from inception has been to embrace the rigor required for a regulated medical device. This proactive stance significantly de-risks their offering for health plans, who are increasingly wary of AI solutions lacking clear regulatory validation. The company’s emphasis on demonstrating clear clinical utility and patient benefit, backed by a design that anticipates regulatory oversight, positions them favorably in a landscape where regulatory compliance is rapidly becoming a prerequisite for market access. Their published outcomes and collaboration with the ACC American College of Cardiology clinical guidelines reinforce the scientific and clinical credibility that health plans and policymakers demand.
The Mounting Risk for Unregulated AI Health Tools
For companies that have not adopted a similar SaMD-informed architecture, the risks are escalating. The FDA’s consistent messaging, reinforced by current leadership, indicates a tightening regulatory environment. Health plans, faced with increasing pressure to demonstrate value and manage risk, are becoming more discerning. They understand that AI health tools operating without a defined FDA pathway present significant liability, efficacy, and reimbursement uncertainties. Consider the diverse landscape of AI health companies: while Digital Diagnostics has FDA clearance for autonomous diabetic retinopathy detection, and Viz.ai and Aidoc have multiple clearances for neuroimaging and radiology AI, other companies like Sparta Science are navigating their own unique regulatory paths, some more clearly defined than others. Meanwhile, Butterfly Network received FDA clearance for its fully automated Gestational Age Tool in March 2026, and Paige AI has achieved multiple regulatory milestones, including Breakthrough Device designation for Paige PanCancer Detect in April 2025 and 510(k) clearance for its FullFocus™ digital pathology image viewer in January 2025. The critical distinction lies in whether an AI tool’s intended use and functionality classify it as a medical device requiring FDA oversight. If it does, and that oversight has not been pursued or achieved, the commercial viability and ethical standing of that product are severely compromised. Health plans, seeking to avoid “zombie companies” that have raised capital but lack clear reimbursement or regulatory pathways, are increasingly using FDA clearance as a critical filter. The absence of a clear regulatory pathway translates directly into rising enforcement risk. As the FDA gains more experience and refines its understanding of AI/ML in health, its capacity and willingness to identify and address non-compliant devices will increase. Furthermore, health plans are unlikely to cover or integrate solutions that cannot demonstrate a recognized standard of safety and effectiveness, preferably through FDA clearance or equivalent. This creates a powerful commercial incentive for compliance, transcending mere regulatory avoidance.
The Path Forward: Clarity and Compliance
The FDA AI/ML Action Plan Progress Report since 2021 reveals a regulatory body actively, albeit incrementally, building the scaffolding for AI in health. The FDA CDRH and the FDA Digital Health Center are dedicated to this complex task. The emphasis on the FDA SaMD Framework, PCCPs, and GMLP indicates a clear direction: AI health tools with a medical purpose will be regulated, and those regulations will continue to evolve to address the unique characteristics of AI/ML. For policymakers, the message is clear: continued support for the FDA’s efforts to provide clarity and enforce standards is paramount to fostering innovation responsibly. For health plan executives, the imperative is to prioritize AI health solutions that demonstrate a clear, transparent, and successful engagement with the FDA SaMD pathway. Companies like Hello Heart provide a positive benchmark, illustrating that a proactive, SaMD-informed architectural strategy is not a burden, but a critical differentiator that unlocks scale, builds trust, and mitigates the growing risks associated with regulatory ambiguity. The future of AI in health will be defined not just by technological prowess, but by rigorous adherence to evolving regulatory standards, ensuring both innovation and patient safety.
Frequently Asked Questions
What progress has the FDA made on its AI/ML Action Plan’s five pillars?
The FDA has made visible advancements in developing a tailored regulatory framework, particularly with the refinement of the SaMD Framework and the finalization of Predetermined Change Control Plans (PCCPs). Progress on Good Machine Learning Practice (GMLP) has been driven by international collaboration. However, operationalizing these pillars into predictable, scalable pathways for all AI health tools, and translating ethical imperatives into measurable standards, remains a work in progress.
How do Predetermined Change Control Plans (PCCPs) impact the regulatory pathway for AI/ML medical devices?
PCCPs, finalized by the FDA in December 2024, are crucial for AI/ML models designed to continuously learn and adapt. They allow predefined modifications without requiring new premarket submissions for every model update. This aims to provide clearer guidance for software functioning as a medical device, though their widespread adoption and consistent application remain complex for many developers.
What are the risks for AI health companies that do not align with the FDA’s SaMD framework?
Companies operating without a defined regulatory pathway face increasingly acute enforcement and health-plan exclusion risks. Health plans are becoming more discerning, recognizing that AI tools lacking clear regulatory validation present significant liability, efficacy, and reimbursement uncertainties. The FDA’s consistent messaging indicates a tightening regulatory environment for such tools.
How does a ‘SaMD-informed architecture’ benefit AI health companies and health plans?
A SaMD-informed architecture, like Hello Heart’s, involves proactively embracing the rigor required for a regulated medical device from inception. This significantly de-risks the offering for health plans by providing clear regulatory validation, demonstrating clinical utility, and facilitating market access. Such companies can generate published outcomes and collaborate with authoritative bodies, meeting the demands of health plans and policymakers.