AI Medical Device Registration: Global Regulatory Guide (2026)
How AI-enabled medical devices and SaMD get registered worldwide in 2026: FDA's PCCP pathway, EU MDR Rule 11 plus the AI Act, UK MHRA, ASEAN reliance routes, and the reimbursement question nobody can skip.

Artificial intelligence is the fastest-moving topic in medical device regulation. Every major market has now added an AI-specific layer on top of its existing device rules — the FDA asks for a Predetermined Change Control Plan, the EU stacks the AI Act on top of the MDR, and payers are writing new codes for AI products. This guide maps the registration route for AI-enabled medical devices and Software as a Medical Device (SaMD) across the US, EU, UK, and ASEAN, plus the reimbursement question that decides whether clearance turns into revenue.
This is planning intelligence, not legal or regulatory advice. It summarizes FDA guidance, EU regulations, and industry reporting as of September 2026. Requirements, guidance documents, and timelines change — confirm every detail with qualified regulatory counsel before committing a calendar or a budget. Nothing here guarantees clearance or market outcomes.
First, the vocabulary: AI device, SaMD, and SiMD
An AI-enabled medical device is any device whose software function uses artificial intelligence or machine learning — imaging analysis, triage and notification, predictive monitoring, or decision support. Regulators split software into two buckets. Software as a Medical Device (SaMD) performs a medical function on its own, without being part of a hardware device — a radiology AI app is the classic example. Software in a Medical Device (SiMD) drives or controls a hardware device, such as the algorithm inside a smart insulin pump. The distinction matters because it changes classification, the applicable standards, and sometimes the review team — but in 2026 both buckets face the same new AI-specific questions in every major market.
United States: 510(k), De Novo, PMA — and the PCCP
The FDA clears or approves AI devices through its standard routes: 510(k) premarket notification when a predicate exists, De Novo for novel low-to-moderate-risk devices without a predicate, and PMA for high-risk devices. What changed is the AI layer. In its final guidance on Predetermined Change Control Plans (PCCPs) — originally issued in December 2024 and reissued in August 2025 — the FDA created a way to pre-authorize the future modifications that make AI devices different from static hardware: retraining on new data, performance improvements within stated bounds, and expanded input sources.
A PCCP submitted with the marketing authorization has three required components: a Description of Modifications (exactly which changes are pre-authorized), a Modification Protocol (how each change will be developed, validated, and implemented — data management, retraining practices, performance evaluation, update procedures), and an Impact Assessment (what each change does to safety and effectiveness). Once authorized, changes inside the plan do not need a new submission. Changes outside it do — and anything that shifts the intended use or introduces a new clinical risk cannot live inside a PCCP at all.
- Decide early whether the algorithm is locked or adaptive — an adaptive device without a PCCP is the most common reason AI 510(k)s stall
- Write the Modification Protocol with engineering detail, not aspirations: retraining data, acceptance criteria, and re-validation methods
- Keep the intended use fixed — expanding indications belongs in a new submission, not in the PCCP
- Build cybersecurity in from the start: under FD&C Act §524B the FDA can refuse cyber-device submissions without a software bill of materials (SBOM) and a vulnerability monitoring and remediation plan
- Follow the FDA / Health Canada / MHRA Good Machine Learning Practice guiding principles for training data, bias evaluation, and transparency
European Union: MDR Rule 11 plus the AI Act
In the EU, SaMD is classified under MDR Annex VIII Rule 11, which is risk-based: the class follows the harm an incorrect software output could cause. Most diagnostic and therapeutic AI software lands in Class IIa, IIb, or III — and from Class IIa upward a notified body conformity assessment is mandatory. The MDR route itself is unchanged; what is new is the second regulation stacked on top of it.
Under the EU AI Act (Regulation 2024/1689), an AI system that is a safety component of a device regulated under the MDR or IVDR and that requires notified body assessment is automatically classified as high-risk. That brings AI-specific obligations beyond the MDR: data governance for training, validation and testing datasets, transparency to users about AI capabilities and limitations, human oversight mechanisms, accuracy and robustness requirements, and post-market monitoring for performance drift. The obligations for this category apply from 2 August 2027, with the Commission's Digital Omnibus package proposing to extend the long-stop to 2 August 2028 — plan against the earlier date and treat the extension as contingency, not strategy.
One structural relief: Article 43(3) of the AI Act provides for the conformity assessment to be integrated with the sectoral legislation — the intent is one coherent assessment through the MDR notified body process, not two parallel certifications. In practice, manufacturers should plan a single technical documentation set that satisfies both the MDR and the AI Act's high-risk requirements, and confirm the integrated approach with their notified body early.
United Kingdom and ASEAN: sandboxes and reliance routes
- United Kingdom: the MHRA runs the AI Airlock, a regulatory sandbox where AI devices are tested with real-world evidence under regulatory supervision — a useful route for novel AI products to generate the evidence a submission needs
- Singapore and Malaysia: the MDA–HSA reliance pilot (September 2025 to February 2026) showed how prior approval by one regulator can shorten review at the other — reported at roughly 30 working days or about 30% faster through verification and abridged routes
- The broader 2026 trend is regulatory reliance: ASEAN and other regions are expanding frameworks where one regulator's assessment reduces duplication at another, which changes submission sequencing strategy for multi-market launches
The question nobody can skip: reimbursement
Clearance is not revenue. In the US, CMS has introduced new CPT codes for AI-based products and services, and the 2026 Medicare Physician Fee Schedule context includes a payment increase alongside a controversial efficiency adjustment — AI reimbursement is being built in real time, and coverage decisions increasingly hinge on real-world evidence generated after launch. Budget the evidence plan, not just the submission: the data that wins clearance and the data that wins payment are converging into one lifecycle evidence strategy.
For the full breakdown of how reimbursement gaps kill launches — and how to map payer evidence requirements before filing — see the ghmap.io guide on the medical device reimbursement gap.
Side by side: what each market asks for
| Market | Base pathway | AI-specific layer | Key document to prepare |
|---|---|---|---|
| United States | 510(k) / De Novo / PMA | PCCP final guidance; §524B cybersecurity | PCCP: modifications, protocol, impact assessment |
| European Union | MDR Rule 11 classification + notified body | AI Act high-risk obligations (from Aug 2027; long-stop proposed Aug 2028) | Integrated MDR + AI Act technical documentation |
| United Kingdom | MHRA medical device registration | AI Airlock sandbox; GMLP principles | Real-world evidence plan |
| ASEAN (SG/MY) | HSA / MDA device registration | Reliance pilot: verification and abridged routes | Prior-approval leveraging strategy |
Readiness checklist before you file an AI device
Checklist
AI medical device pre-submission checklist
- Intended use fixed and documented — locked vs adaptive algorithm decided
- PCCP drafted (US): modifications, modification protocol, impact assessment
- Training, validation, and test datasets documented with data governance
- Bias evaluation across intended patient populations
- Cybersecurity package: SBOM, vulnerability monitoring and remediation plan
- Clinical validation plan covering the AI function specifically
- Labeling discloses the AI nature of the device and its limitations
- Post-market performance monitoring plan for model drift
- EU: AI Act high-risk requirements mapped into the MDR technical file
- Reimbursement evidence strategy aligned with the regulatory evidence plan
Where do ghmap.io's pathway pages fit in?
For the structured pathway view — regulator, conformity route, and document logic — see the GHMAP regulatory pathways/united-states/class-ii page for the FDA 510(k) route and the EU Class III regulatory pathway page for the EU's highest-risk route on ghmap.io.
Next step
If you want to assess AI device market entry for your specific product — pathway selection, PCCP strategy, EU AI Act readiness, and evidence planning — book a ghmap.io strategy session. Sessions are planning conversations, not filing services or clearance guarantees.
Book a $500 strategy session


