Blogs

AI in medical devices: What the FDA's predetermined change control plan actually covers

Written by Thomas Van Dorpe | Aug 17, 2026, 1:51:35 PM

Your medical device's AI algorithm will not stay the same after it reaches the market. It will be retrained, refined, and improved, and every one of those changes is a potential regulatory event. The FDA has a mechanism for handling this without forcing a new submission every time: the Predetermined Change Control Plan, or PCCP. Submit a solid PCCP up front, and your later algorithm updates move fast. Without one, most tweaks require a separate resubmission with the FDA.

Want the full walkthrough? We talk about PCCP mechanics and AI in medical devices in detail in our webinar on going to market in the US with medical devices. Watch the full recording.

Your algorithm will not stay the same, plan for that before you submit

The PCCP goes in with your initial FDA submission. It has to specify the types of changes you anticipate making to your algorithm, how you'll validate each of those changes before deploying them, and how you'll assess their safety impact. If the FDA accepts that plan up front, you can execute the changes it describes without going back for a new submission every time.

The catch: you cannot use the PCCP itself to authorize changes to the PCCP. If you need to expand or revise the scope of your plan after it's been authorized, that requires a new marketing submission, such as a PMA supplement or a new 510(k), depending on your pathway, which can include an updated PCCP. This means the plan you submit initially should be as comprehensive as you can make it for realistic near-term modifications, because changing the plan later is a full regulatory interaction, not a lightweight update.

Where the PCCP ends and a new submission begins

The dividing line is whether a change alters how the device fundamentally functions or what it's intended to do. An algorithm update that improves accuracy within its original scope, and that you described in your PCCP, may be covered. A change that shifts the device's core function or its intended use is material, and material changes require an updated 510(k) or a new PMA. More specifically, if a modification falls within the scope you defined in your PCCP, meaning it matches both the Description of Modifications (what you said you'd change) and the Modification Protocol (how you said you'd validate it) , you can implement it without a new submission. A modification that falls outside the PCCP's scope, or that changes the device's intended use, requires a new marketing submission, whether that’s a 510(k), a De Novo request, or a PMA supplement. No PCCP, however well-drafted, can pre-authorize a shift in what the device is intended to do; that is a statutory boundary, not a drafting limitation.

This is also where continuous training becomes a genuine risk area. Every algorithm update must be validated, assessed, documented, approved, and traceable. The FDA isn't only looking at the outcome of a change; it expects companies to demonstrate control over the process behind that change. A model that keeps ingesting new data and adjusting its output is doing exactly what makes machine learning valuable, but overtrain it past what your PCCP accounted for, and you may find yourself needing to resubmit. If a software-driven device isn't functioning as designed, it's a reportable complaint, it triggers your complaint-handling process, just as any other device malfunction would. And if the malfunction has caused or could cause serious injury or death, it's a mandatory Medical Device Report (MDR) to the FDA under 21 CFR Part 803. EU manufacturers familiar with the MDR's vigilance reporting obligations will recognize the parallel, though the triggering thresholds and timelines differ between the two systems.

AI in your device and AI in your surrounding software are the same regulatory problem

The parallel between AI inside the medical device itself and AI inside the software ecosystem around it, your QMS, your ERP, is closer than most companies expect. In our previous post on EU GMP Annex 11 and Annex 22, we covered why critical GxP processes need deterministic, explainable AI behavior: the same input has to produce the same output, every time. That principle doesn't stop at the device boundary. It applies just as directly to the systems managing your device's compliance data.

That's also why we keep generative AI out of manufacturing and quality processes that are patient-critical, and instead put it to work where its probabilistic nature is an advantage rather than a risk: forecasting, finance, and other areas where variability in the output isn't a safety concern.

AI governance is an operational challenge

That's where the challenge for many medical device companies tends to be underestimated. A PCCP may define what changes are allowed, but companies still need systems and processes that can prove who approved those changes, how they were validated, and whether they were implemented according to established procedures. Without that operational foundation, maintaining compliance becomes increasingly difficult as AI models evolve.

What the FDA and EU Regulators agree on

Earlier this year, around the time the FDA's updated Quality Management System Regulation took effect, two complementary sets of international AI principles emerged. In January 2026, the FDA and EMA jointly published ten guiding principles for AI in drug and biological product development, which is primarily focused on pharmaceuticals but relevant conceptually to any AI-driven compliance process. Separately, for medical devices specifically, the FDA has partnered with Health Canada and the UK's MHRA on Good Machine Learning Practice (GMLP) guiding principles, finalized through the International Medical Device Regulators Forum (IMDRF) in January 2025. The shared themes across both: account for bias, maintain change control discipline, and be transparent in your labeling about where AI is doing the work.

Where the two regulators diverge is scope. For AI and algorithm training, the EU's AI Act creates a more layered regime, with most medical AI falling under high-risk classification and explicit safety and performance obligations. The US folds AI oversight into the device's broader lifecycle controls instead, through mechanisms like the PCCP, without a dedicated AI-specific regulation on top.

Your Next Step

Getting your PCCP right assumes you've already confirmed your device's classification and pathway, which is exactly where a US launch starts. If you haven't read it yet, our previous post covers why your CE mark won't get you onto the US market.

Next, we'll walk through what the FDA's updated QMSR means for your quality systems, and lay out a practical roadmap for taking a device from the EU to a US launch, in Launching a Medical Device in the US? Start With These Four Steps.

Want the full walkthrough? We talk about PCCP mechanics and AI in medical devices in detail in our webinar on going to market in the US with medical devices. Watch the full recording.