The landscape of artificial intelligence in healthcare is rapidly evolving, bringing with it unprecedented opportunities for innovation but also a complex web of regulatory challenges. As we approach 2026, the question for investors and policymakers alike is not if, but when and how, the regulatory hammer will fall on AI health companies that have sidestepped established pathways. The trajectory of FDA enforcement, coupled with increased scrutiny from other federal agencies, signals a critical juncture for the industry.
The Rising Tide of Enforcement: From SaMD to FTC Scrutiny
The FDA’s commitment to regulating AI as a medical device, particularly through the Software as a Medical Device (SaMD) framework, has been clear. Jeffrey Shuren, who served as Director of the FDA’s Center for Devices and Radiological Health (CDRH) until July 2024, consistently emphasized the need for robust oversight to ensure the safety and effectiveness of AI/ML-driven health tools. This stance is further solidified by the FDA AI/ML Action Plan, which outlines the agency’s strategy for advancing regulatory science for AI/ML-enabled medical devices. Companies that have proactively engaged with this framework, understanding that their AI tools fall squarely within the definition of a medical device, are better positioned for long-term success and market access.
Conversely, companies operating without a defined FDA SaMD pathway face escalating risks. The cases of Purolea and Exer Labs AI serve as a stark precedent for FDA AI enforcement. On April 2, 2026, the FDA issued a warning letter to Purolea Cosmetics Lab, explicitly citing the misuse of AI in pharmaceutical manufacturing. Similarly, in February 2025, Exer Labs received a warning letter for marketing an AI motion-analysis system without proper clearance and with quality system deficiencies. While the specifics of their situations may vary, the common thread is the FDA’s willingness to act when AI health tools are marketed without appropriate clearances or approvals. These instances underscore that the FDA CDRH is not merely issuing guidance; it is actively monitoring the market and prepared to issue FDA Warning Letters to non-compliant entities. For investors (A1), this translates directly into significant regulatory risk, impacting valuation and exit potential. Policymakers (A6) are observing these actions as indicators of market maturity and the efficacy of existing regulatory tools.
Beyond the FDA, other federal agencies are also intensifying their focus on AI health. The Federal Trade Commission (FTC), for instance, has demonstrated a keen interest in the data privacy practices of health technology companies. The relationship between BetterHelp and Cerebral, marked by FTC health data enforcement, illustrates the broader regulatory environment. The FTC settled with BetterHelp in 2023 over allegations of sharing client data without consent, and in April/May 2024, Cerebral faced FTC enforcement action for unauthorized disclosures of sensitive personal health information. The FTC Act Section 5, which prohibits unfair or deceptive acts or practices, is a powerful tool being wielded against companies that misrepresent their data handling or fail to adequately protect sensitive health information. This multi-pronged regulatory pressure from the FTC, DOJ, and HHS OCR, alongside the FDA, creates a formidable landscape for AI health companies.
Navigating the Regulatory Labyrinth: Lessons from Leading Companies
The divergence in regulatory preparedness is evident when examining companies like Viz.ai and Tempus AI, compared to those with less defined pathways, such as Hims & Hers in certain AI applications. Viz.ai, a pioneer in AI-powered stroke detection and care coordination, has actively pursued and achieved multiple FDA clearances for its SaMD products, including a De Novo clearance for its Viz.AI Contact application in 2018 and a 510(k) clearance for Viz Subdural Plus in June 2025. This strategic engagement with the FDA’s regulatory processes, particularly through 510(k) clearances and De Novo classifications, has allowed them to scale their offerings with a strong foundation of trust and compliance. Their proactive approach to the FDA SaMD Framework has been a key differentiator, influencing their ability to secure partnerships and reimbursement.
Tempus AI, with its focus on precision medicine and AI-powered genomic analysis, also exemplifies a strategy of regulatory engagement. While their offerings are diverse, their commitment to robust data governance and, where applicable, seeking appropriate regulatory oversight for diagnostic AI tools, positions them favorably. The insights from industry veterans like Bakul Patel, formerly a pivotal figure in shaping the FDA’s digital health policies and now Senior Director, Global Digital Health Strategy & Regulatory at Google Health, highlight the importance of designing AI tools with regulatory compliance in mind from inception. This “regulatory-by-design” philosophy is increasingly becoming a prerequisite for investor confidence and market acceptance.
In contrast, companies like Hims & Hers, while successful in direct-to-consumer healthcare, face a different set of regulatory considerations when incorporating AI into their services, particularly if those AI functions cross the line into medical device territory without proper clearance. The potential for an FDA Warning Letter or scrutiny from the FTC for claims or data practices could significantly disrupt their business model. The absence of a clear SaMD pathway for certain AI-driven features can lead to uncertainty for health plans and providers, hindering broader adoption and reimbursement. Scott Gottlieb, former FDA Commissioner, has frequently underscored the necessity of robust clinical evidence and regulatory clarity for novel health technologies to gain widespread acceptance Scott Gottlieb commentary on digital health regulation.
The Imperative of a Defined SaMD Pathway
For AI health companies, particularly those attracting significant investor capital, the absence of a defined FDA SaMD pathway is no longer a sustainable strategy. The regulatory environment is hardening, and the grace period for operating in a gray area is rapidly closing. The FDA’s evolving approach, as outlined in the FDA AI/ML Action Plan, emphasizes transparency, real-world performance monitoring, and the development of Good Machine Learning Practice (GMLP) principles. Companies that integrate these principles into their development and deployment cycles will be better equipped to meet future regulatory demands.
The implication for investors (A1) is clear: due diligence must increasingly prioritize regulatory risk. A robust regulatory strategy, including a clear plan for FDA SaMD clearance or approval, should be a non-negotiable component of any AI health investment thesis. For policymakers (A6), the ongoing enforcement actions and the proactive engagement of certain companies demonstrate the effectiveness of the current regulatory framework while also highlighting areas for potential refinement to foster responsible innovation. The collective actions of the FDA CDRH, FTC, DOJ, and HHS OCR are creating a unified front that demands accountability and transparency from AI health companies regarding their clinical claims, data privacy, and overall product safety and effectiveness FTC guidance on health apps and privacy.
Conclusion: De-risking for the Future
The period leading up to 2026 will likely see a significant acceleration in regulatory enforcement against AI health companies that have not adequately addressed the FDA SaMD framework. The precedents set by actions involving companies like Purolea and Exer Labs AI, coupled with the FTC’s scrutiny of practices exemplified by BetterHelp and Cerebral, signal a maturing regulatory landscape. Companies like Viz.ai and Tempus AI, through their strategic engagement with regulatory pathways, offer a blueprint for de-risking their operations and securing long-term market viability. Investors and policymakers must recognize that a well-defined FDA SaMD pathway is not just a regulatory hurdle, but a fundamental pillar for building trust, ensuring patient safety, and unlocking the full potential of AI in healthcare.
Frequently Asked Questions
What is the FDA’s stance on regulating AI in healthcare, and what are the implications for investors?
The FDA is committed to regulating AI as a medical device, primarily through the Software as a Medical Device (SaMD) framework, as outlined in their AI/ML Action Plan. For investors, this means significant regulatory risk for companies operating without a defined FDA SaMD pathway, impacting valuation and exit potential. Companies that proactively engage with this framework are better positioned for long-term success.
Beyond the FDA, what other regulatory bodies are scrutinizing AI health companies, and what are their areas of focus?
Beyond the FDA, the Federal Trade Commission (FTC) is intensifying its focus on data privacy practices of health technology companies. The FTC uses Section 5 of the FTC Act to prohibit unfair or deceptive acts, particularly concerning misrepresentation of data handling or failure to protect sensitive health information. This multi-pronged regulatory pressure creates a formidable landscape for AI health companies.
Can you provide examples of companies successfully navigating the regulatory landscape for AI health products?
Viz.ai and Tempus AI are examples of companies successfully navigating the regulatory landscape. Viz.ai has achieved multiple FDA clearances for its SaMD products, including De Novo and 510(k) clearances. Tempus AI focuses on robust data governance and seeks appropriate regulatory oversight for its diagnostic AI tools, demonstrating a ‘regulatory-by-design’ philosophy.
How do recent FDA enforcement actions, like those against Purolea and Exer Labs AI, inform policymakers about the market?
The FDA’s warning letters to Purolea and Exer Labs AI for marketing AI health tools without proper clearance or with quality system deficiencies serve as clear precedents. Policymakers are observing these actions as indicators of market maturity and the efficacy of existing regulatory tools. These cases demonstrate the FDA’s willingness to actively monitor and enforce compliance.
What are the key risks for policymakers if AI health companies sidestep established regulatory pathways?
If AI health companies sidestep established regulatory pathways, policymakers face risks related to patient safety and the efficacy of health tools. The lack of proper clearances or approvals can lead to the marketing of unsafe or ineffective products. This also undermines public trust in AI-driven healthcare innovations and the regulatory frameworks designed to protect consumers.