FDA released a discussion paper on generative AI devices on August 18, 2026 and opened Docket FDA-2026-N-7874 for comment through October 19. The paper is explicit that it is neither draft nor final guidance and proposes no policy change. It is the agency thinking out loud, which is the moment when a small company's comment carries the most weight.
The proposed risk framework has two axes. One runs from non-directive information, such as a cardiovascular risk score, through information that directs action, up to supervised and then autonomous action taking. The other runs from limited to severe harm if the output is wrong. Evidence expectations follow position on that grid rather than the mere presence of a language model, which would end the current situation where any generative feature invites maximal scrutiny.
The assessment concept borrows from clinician credentialing. A device would face standardized non-clinical benchmarking across ten elements covering safety, clinical proficiency, generalizability and agentic conduct, then clinical confirmation through one of five approaches: retrospective evaluation, shadow deployment, standardized patient interactions, clinician adjudication or a prospective study. Not every device would need the prospective study. For foundation models, FDA floats a voluntary master file where a model developer files architecture, training data provenance and update commitments that a device sponsor references with permission, which would address the awkward reality that most device companies do not control the model they build on.
CDRH Director Michelle Tarver framed it as keeping pace with the technology. The trade FDA appears willing to make is more postmarket obligation, periodic re-benchmarking, sampled clinician review of real outputs and drift detection, in exchange for accepting more premarket uncertainty.