Rialtes Logo
Rialtes Logo White
SAP SuccessFactors Performance and Goal Management
Agentic AI | Sep 16, 2026
LinkedIn
Twitter

Building Trusted AI Governance for Connected Medical Devices: A Practical Roadmap

Connected medical devices have become a standard expectation across the industry. Infusion pumps, imaging systems, continuous monitors, and diagnostic software increasingly incorporate embedded AI and persistent connectivity. For medical device executives, this evolution has expanded the definition of compliance.

A product can satisfy traditional design control requirements and still face challenges during regulatory review because the scope of evaluation now extends beyond device safety and efficacy. Regulators are examining algorithm behavior, data provenance, cybersecurity controls, and lifecycle change management alongside established device requirements.

What is AI Governance in Connected Medical Devices?

AI governance in connected medical devices refers to the framework of policies, controls, processes, and oversight mechanisms used to ensure that AI-enabled devices operate safely, transparently, securely, and in compliance with regulatory requirements throughout their lifecycle.

Unlike traditional medical device governance, AI governance extends beyond hardware and software validation. It addresses how AI models are trained, deployed, monitored, updated, and managed after the device reaches the market. This includes areas such as data quality, algorithm performance, cybersecurity, change management, human oversight, and regulatory compliance.

Here we examine how the regulatory environment has evolved in 2026 and outlines a practical roadmap for building AI governance that can withstand increasing scrutiny.

Why AI Governance Has Become a Board-Level Issue for Medical Device Makers?

Three major regulatory developments have reshaped expectations over the past eighteen months. Together, they have elevated AI governance from a regulatory affairs responsibility to a broader business and leadership priority.

The FDA has shifted from guidance-focused oversight to a stronger enforcement posture. As of early 2026, the FDA has authorized more than 1,350 AI-enabled devices, roughly double the number approved in 2022. Radiology, cardiology, and neurology remain the leading adoption areas. In August 2025, the agency finalized guidance on Predetermined Change Control Plans (PCCPs), providing manufacturers with a pathway to implement pre-specified algorithm updates without submitting a new filing for every modification. However, this flexibility depends on clearly defined and well-documented change boundaries. Broad or poorly specified PCCPs are receiving greater scrutiny during review.

Cybersecurity has also become a core regulatory requirement rather than a supporting consideration. The FDA's February 2026 cybersecurity guidance incorporated Software Bill of Materials (SBOM) requirements and security risk management directly into the Quality Management System Regulation (QMSR). For devices that meet the definition of a cyber device under Section 524B of the FD&C Act, the FDA can now reject submissions that contain inadequate cybersecurity documentation. Industry experience shows that cybersecurity deficiencies are among the most common reasons for first-cycle review findings, second only to software documentation and clinical evidence gaps.

In Europe, the EU AI Act now operates alongside MDR and IVDR requirements rather than replacing them. Under Article 6(1), AI systems embedded within products governed by the Medical Device Regulation or In Vitro Diagnostic Regulation are automatically classified as high-risk. Core obligations for high-risk systems became enforceable in August 2026, while devices requiring Notified Body conformity assessments under MDR or IVDR have until August 2027 to comply. Since a significant portion of AI-enabled medical devices already fall within MDR Class IIa and above, manufacturers must address AI Act obligations in addition to existing MDR requirements.

Taken together, these developments mean that AI-enabled medical devices are now subject to multiple documentation, governance, and compliance frameworks across major markets. Any of these frameworks can affect market access independently.

Explore Our Life Sciences & Medical Devices Solutions

What are the Requirements for a Good AI Governance?

Despite differences between regulatory frameworks, the underlying expectations are becoming increasingly consistent.

Good Machine Learning Practice (GMLP) principles continue to serve as a common foundation. These include multidisciplinary development, rigorous data management, appropriate human oversight, transparency, and lifecycle accountability.

1

Lifecycle-Aware Change Management

Manufacturers are increasingly expected to define how AI models will evolve after deployment. A PCCP-style approach, which documents acceptable model updates, validation requirements, and submission triggers in advance, is becoming standard practice.

Treating AI models as static assets that are validated once and left unchanged no longer aligns with regulatory expectations. Organizations need a clear process for managing ongoing model improvements while maintaining compliance.

2

Cybersecurity Embedded Into Design

Cybersecurity can no longer be addressed immediately before submission.

A current SBOM maintained in a machine-readable format such as SPDX or CycloneDX should be generated as part of the development process. Regulators are increasingly interested in an organization's ability to manage software supply chain risks continuously rather than simply documenting them at a single point in time.

3

Real-World Performance Monitoring

For AI-enabled devices, post-market surveillance extends beyond adverse event reporting.

Organizations need mechanisms to monitor model performance, identify degradation, and detect performance changes in real-world environments. Connected devices create opportunities to collect and analyze this information, but only if the monitoring framework has been designed into the product architecture from the outset.

4

Human Oversight and Transparency by Design

Regulatory expectations increasingly emphasize explainability and human oversight.

Users need sufficient visibility into how a system generated a recommendation, prediction, or decision to interpret the output appropriately. This requirement affects user interfaces, clinician-facing information, audit logs, and supporting documentation as much as it affects the underlying AI model.

5

Quality Management Systems That Incorporate AI Risk

AI governance should not operate as a separate process managed exclusively by data science teams.

The FDA's QMSR alignment and the EU AI Act's quality management requirements point toward the same conclusion: AI-related risks should be incorporated into existing quality management processes and managed alongside all other product risks.

AI Governance in Connected Medical Devices

A Practical Roadmap for Building Trusted AI Governance

1. Start With a Current-State Gap Assessmen

Organizations should assess FDA and EU AI Act requirements together rather than as separate initiatives.

Conducting a combined assessment of quality systems, design controls, cybersecurity practices, and documentation can reduce duplication while identifying controls that satisfy multiple regulatory requirements simultaneously.

2. Define PCCP Boundaries Early

Manufacturers developing AI-enabled products should determine their intended update strategy well before submission preparation begins.

Identifying anticipated model changes early allows teams to develop the necessary validation evidence during development rather than attempting to define acceptable boundaries late in the process.

3. Automate SBOM Generation

SBOM creation should be integrated directly into development pipelines.

Organizations that automate SBOM generation and maintenance often experience smoother cybersecurity reviews than those that rely on manual processes immediately before submission.

4. Design for Post-Market Monitoring From the Beginning

Regulatory expectations around real-world evidence and ongoing monitoring continue to increase.

Telemetry, model performance monitoring, drift detection, and escalation workflows should be included in the initial system architecture. Implementing these capabilities during development is significantly easier than retrofitting them after commercialization.

5. Establish Cross-Functional Governance

Effective AI governance requires input from regulatory, quality, engineering, cybersecurity, and data science teams.

Organizations that align these functions around shared processes and operating procedures tend to move more efficiently through regulatory reviews and maintain stronger governance maturity over time.

6. Strengthen Traceability and CAPA Integration

Traceability should connect model updates, cybersecurity patches, quality events, validation activities, and corrective actions within a single framework.

When traceability and CAPA processes operate as part of everyday business activities, audit readiness becomes a byproduct of normal operations rather than a periodic exercise.

Governance Is Part of the Product Strategy

A device that reaches submission quickly but lacks a clearly defined PCCP, an up-to-date SBOM, or a reliable post-market monitoring approach is likely to encounter delays during review or challenges after commercialization. Speed to market and governance maturity are no longer competing priorities. They are increasingly interdependent.

Rialtes supports medical device manufacturers. Our Regulatory Compliance & Quality Management services help organizations address evolving FDA and EU requirements, strengthen documentation and traceability processes, and maintain audit readiness throughout the product lifecycle. We also help integrate quality management and CAPA processes so that regulatory evidence becomes a continuous output of operational processes rather than a separate project before every filing.

Combined with our broader Medical Device IT capabilities across Salesforce Life Sciences Cloud, SAP S/4HANA, and AI-enabled patient and compliance workflows, we help manufacturers build governance into their products from the beginning of development.

For organizations preparing an upcoming AI-enabled submission in either the United States or Europe, the most effective time to define a governance strategy is before regulatory requirements become a deadline-driven exercise.

Frequently Asked Questions (FAQs)

Latest Blogs

rialtes-logo