Guide 15 min read

FDA AI Governance: A Practitioner's Guide

J

Jared Clark

August 27, 2026

FDA does not have a dedicated AI regulation. There is no AI portal, no AI checklist you can download and follow start to finish. That is not an oversight. FDA builds oversight the way it builds most oversight: through guidance documents issued by individual centers, layered on top of quality regulations that existed long before "machine learning" was a phrase anyone used in a submission.

I tell clients this up front, because most of them come in looking for one FDA AI rule to comply with. There isn't one. There probably will not be one for years. What exists instead is a working framework spread across three centers: the Center for Devices and Radiological Health (CDRH), the Center for Drug Evaluation and Research (CDER), and the Center for Biologics Evaluation and Research (CBER). Each publishes guidance for its own product category, on its own timeline. CDRH has produced the most AI-specific guidance by volume, because AI-enabled software is most often regulated as a medical device. CDER and CBER, by contrast, share a single 2025 draft guidance that governs how AI is used to generate or analyze the evidence behind drug and biological product applications — a document this guide covers in detail below. Understanding FDA AI governance means understanding that patchwork, not searching for a document that does not exist.

Why FDA Doesn't Have One AI Governance Rule

FDA regulates by product category, not by technology. There is no statutory basis for a general "AI rule" the way the EU AI Act attempts a horizontal law across every use case. FDA instead treats AI as a characteristic of a regulated product. It governs that characteristic with the same tools it uses for everything else: guidance documents, the Quality System Regulation, premarket review standards, and enforcement discretion.

That approach has a real upside. FDA can issue guidance quickly and revise it without notice-and-comment rulemaking every time the technology shifts. It also has a real cost for compliance teams. The requirements a reviewer will actually apply to your submission are scattered across a half-dozen documents. Each has different legal weight, different scope, and a different effective date. Nobody hands you the consolidated version. Building that consolidated version yourself is most of the work of standing up an AI governance program at a regulated company.

The Core Documents That Function as FDA's AI Governance Framework

The SaMD Action Plan (2021)

FDA published its Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan in January 2021. It is the closest thing FDA has to a public AI strategy statement for devices. It laid out five commitments:

  1. A tailored regulatory framework for adaptive algorithms
  2. Support for Good Machine Learning Practice
  3. A patient-centered approach that includes transparency to users
  4. Methods for evaluating and addressing algorithmic bias
  5. Real-world performance monitoring for AI-enabled devices

Nearly everything CDRH has published on device AI since traces back to one of those five commitments.

Good Machine Learning Practice (GMLP)

FDA, Health Canada, and the UK's Medicines and Healthcare products Regulatory Agency jointly published ten Good Machine Learning Practice guiding principles in October 2021. They are principles, not regulations. They carry no independent legal force, and no statute or regulation requires a manufacturer to follow them. In practice, though, FDA reviewers use them as a reference point when they assess a submission's design controls, so a device team that ignores them is negotiating from a weaker position, not violating a rule. Here are all ten:

  1. Multidisciplinary expertise is leveraged throughout the total product life cycle
  2. Good software engineering and security practices are implemented
  3. Clinical study participants and data sets are representative of the intended patient population
  4. Training data sets are kept independent of test data sets
  5. Selected reference datasets are based on best available methods
  6. Model design is tailored to the available data and reflects the device's intended use
  7. Focus is placed on the performance of the human-AI team, not the algorithm in isolation
  8. Testing demonstrates device performance during clinically relevant conditions
  9. Users are provided clear, essential information about the AI system's function and limits
  10. Deployed models are monitored for performance, and retraining risks are actively managed

Predetermined Change Control Plans (PCCP)

This is the mechanism that actually changes how adaptive algorithms get regulated. FDA finalized guidance on Predetermined Change Control Plans for machine-learning-enabled medical devices in December 2024. A PCCP lets a manufacturer specify, in advance, which future model modifications fall within the scope of an existing marketing authorization. The plan also documents how those modifications will be validated. A qualifying retrain then does not require a new 510(k) or PMA supplement every time.

Before PCCP existed, an adaptive model created a paradox. Improving it with new data could trigger a new submission just for improving. PCCP is FDA's answer to that paradox. It is the single most consequential AI-specific regulatory tool CDRH has produced.

Lifecycle Management Guidance (2025)

In January 2025, FDA issued draft guidance titled "Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations." It is broader than the PCCP guidance. It covers documentation expectations, risk management, and transparency across the total product lifecycle, not just the change-control mechanism. It is still draft, so it does not bind FDA or industry yet. Reviewers frequently apply draft principles informally well before finalization, though, so treating it as optional reading is a mistake.

CDER and CBER's Shared AI Guidance for Drugs and Biologics

Device-side AI gets most of the attention, but CDER issued its own draft guidance in January 2025: "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products." The title matters. This guidance was written to cover biological products as well as drugs, which puts it squarely inside CBER's jurisdiction too — vaccines, gene therapies, blood products, and other biologics that CBER regulates fall under the same framework, even though CBER did not co-author the document.

It addresses a different problem than the device guidance. This is not about an AI-enabled product. It is about AI used internally to generate or analyze the data submitted in an application — models used in clinical trial design, real-world evidence analysis, or manufacturing process control. It introduces a risk-based credibility assessment framework. The more a model's output influences a regulatory decision, the more rigorous the validation and documentation FDA expects behind it.

Where FDA AI Governance Meets Existing Regulation

None of the AI-specific guidance operates in isolation. It sits on top of quality infrastructure FDA has enforced for decades, and that is the part teams most often miss. They treat "AI governance" as a new compliance track instead of an extension of the one they already run.

Design controls under 21 CFR 820.30 already require validation, risk analysis, and a documented design history for any device software function, AI-enabled or not. Electronic records generated or relied on by an AI system for a regulated decision fall under 21 CFR Part 11's requirements for audit trails and record integrity.

Starting February 2, 2026, the Quality Management System Regulation (QMSR) replaces Part 820 with a framework harmonized to ISO 13485:2016. Any AI governance program for a device manufacturer needs to be built against QMSR's compliance date. Build it against the outgoing Part 820 language instead, and it will be obsolete before it is ever audited.

For drug manufacturers, the relevant floor is current Good Manufacturing Practice. 21 CFR 211.100 governs production and process controls. It applies just as much when a control decision is informed by a model as when it is informed by a person. For biologics manufacturers, that floor runs through 21 CFR Part 600, the general biological product standards, and — where the product also meets the legal definition of a drug — through 21 CFR Part 211 as well. FDA's AI-specific guidance adds expectations on top of GMP. It does not replace it.

FDA Document Issuing Center Status Published What It Covers
AI/ML SaMD Action Plan CDRH Strategy document January 2021 Five commitments guiding FDA's device AI approach
Good Machine Learning Practice (10 principles) CDRH, Health Canada, MHRA Joint guiding principles October 2021 Lifecycle practices for ML-enabled devices
Predetermined Change Control Plans CDRH Final guidance December 2024 Pre-authorized model modification pathways
AI-Enabled Device Software Functions: Lifecycle Management CDRH Draft guidance January 2025 Total product lifecycle documentation and transparency
AI in Regulatory Decision-Making for Drug and Biological Products CDER, applies to CBER-regulated biologics Draft guidance January 2025 Risk-based credibility framework for AI used in submissions
Quality Management System Regulation (replaces 21 CFR 820) CDRH Final rule Effective February 2, 2026 Harmonizes device QMS with ISO 13485:2016

Building an FDA-Aligned AI Governance Program

A workable program treats these documents as inputs to one governance structure, not five separate compliance projects. In practice, that means working through four steps, in order, and producing a specific artifact at each one.

Step 1: Classify what you actually have. An AI-enabled device software function, an AI tool used to analyze trial data, and an internal AI tool used for manufacturing quality decisions trigger different guidance documents. Conflating them is the single most common design mistake I see in early-stage AI governance plans. Build a one-page classification rubric with three columns: system name, function (device feature, submission-evidence generator, or internal quality tool), and the guidance document that governs it. Every AI system in your portfolio should have a row. A system with no row is a system nobody has classified, which means nobody knows what applies to it.

Step 2: Map existing design control and CAPA processes against the ten GMLP principles. Identify where a genuinely new control is needed versus where an existing control just needs an AI-specific addendum. Most of the time it is the latter. A useful working artifact here is a two-page addendum to your existing design control procedure: one paragraph per GMLP principle, stating which existing procedure section already covers it and which section needs new language. Data representativeness (GMLP principle 3) is usually the one with no existing home — it typically needs a new subsection in your design history file template, not a new procedure.

Step 3: Draft your change control plan against the PCCP guidance from the start, if you are building or plan to build adaptive models. A PCCP scope statement should name, specifically, which parameters can change (for example, a retraining trigger tied to a defined performance metric threshold), what data will be used to validate a qualifying change, and what would push a modification outside the plan's scope and back into a new submission. Retrofitting a change control plan after your first submission is significantly more expensive than designing it in from day one.

Step 4: Treat the two January 2025 draft guidances as a forecast, not a formality. They are not enforceable yet, but building toward them now costs less than rebuilding toward them once they finalize. Track them the same way you would track a pending rule: assign an owner, review the docket for updates quarterly, and flag any submission in progress that would need rework if either guidance finalizes with material changes.

How FDA AI Governance Relates to ISO 42001 and NIST AI RMF

Teams researching FDA's expectations often end up asking a related question: how does any of this connect to the management-system frameworks — ISO 42001, NIST AI RMF — they have heard about elsewhere. The honest answer is that FDA's guidance and ISO/IEC 42001:2023 solve different, complementary problems.

FDA's documents are product-specific and enforcement-relevant. They tell you what a reviewer expects to see in a submission for a specific device or drug application. ISO 42001 is different. It is a certifiable management system standard, not a submission requirement. Clause 6.1.2 requires an organization to establish a documented AI risk assessment process. Clause 8.1 requires operational planning and control across the AI lifecycle. Both apply regardless of whether any single AI system is regulated by FDA at all.

An organization can be ISO 42001 certified and still fail an FDA submission, if its device-specific documentation does not match GMLP or PCCP expectations. The reverse is also true. A device can clear FDA review without the organization holding any AI management system certification, because FDA does not require one.

What ISO 42001 gives a regulated organization that FDA guidance alone does not is connective tissue: a single governance structure spanning every AI system in the portfolio, including the ones FDA has no jurisdiction over at all, like internal HR tools or vendor-selection models. NIST's AI Risk Management Framework plays a similar connective role, as a voluntary framework rather than a certifiable standard, and CDER's January 2025 draft guidance cites it directly as a reference point for risk-tiering AI used in regulatory submissions.

Framework Type Enforceable Certifiable Applies Beyond FDA-Regulated Products
FDA guidance documents (SaMD Action Plan, PCCP, GMLP) Regulatory guidance Informally, through review expectations No No — product-specific
ISO/IEC 42001:2023 Management system standard No (contractual/market driven) Yes Yes — organization-wide
NIST AI RMF Voluntary framework No No Yes — organization-wide

For a deeper walkthrough of what an AI management system actually requires day to day, our guide on what is an AI management system breaks down the ISO 42001 side of this pairing. And if your organization is specifically navigating device or drug submissions, our breakdown of FDA's approach to machine learning goes deeper into submission-level mechanics than this guide does.

Common Mistakes I See Regulated Teams Make

Treating FDA's guidance as static. Two of the six documents in the table above are still drafts. Draft guidance changes between draft and final more often than teams expect, sometimes substantially. Build a governance program against the draft language as though it were locked in, and you will be redoing work when it finalizes.

Scoping AI governance only to what FDA will actually review. A model used internally to support a regulatory decision, without ever appearing in the device labeling, still falls inside the credibility framework CDER described in its January 2025 guidance. If your risk assessment process only flags AI that is visibly part of the product, it will miss the AI that is quietly part of the evidence behind it.

Assuming GMLP compliance and design control documentation are the same artifact. They overlap, but they are not identical, and the overlap is worth being precise about. GMLP carries no legal force of its own — no statute or regulation cites it by name. But because FDA reviewers reference it when assessing design controls, treating it as effectively mandatory is the safer read for any team building a submission strategy. That is not a contradiction. It is the difference between what the law requires and what a reviewer will actually ask you to show. GMLP's ten principles ask questions traditional design controls were never written to answer. Data representativeness, for instance, has no clean home in a standard design history file. It needs its own section, built new rather than borrowed from an existing procedure.

Frequently Asked Questions

Does the FDA have an official AI governance framework?

Not a single one. FDA governs AI through a set of center-specific guidance documents — the SaMD Action Plan, Good Machine Learning Practice, Predetermined Change Control Plan guidance, and the 2025 draft guidances from CDRH and CDER — layered on top of existing quality regulations like the Quality Management System Regulation and 21 CFR Part 11.

Does CBER have its own AI guidance separate from CDER's?

Not currently. CBER-regulated biologics — vaccines, gene therapies, blood products — fall under the same January 2025 draft guidance CDER issued, because that document was written to cover both drug and biological products. CBER-regulated products remain subject to GMP requirements under 21 CFR Part 600 and, where applicable, 21 CFR Part 211.

Do I need ISO 42001 certification if I already follow FDA's AI guidance?

They serve different purposes. FDA guidance addresses what a specific submission needs to show. ISO 42001 addresses whether your organization has a repeatable, auditable governance structure across every AI system you operate, including ones FDA never reviews. Many regulated organizations pursue both.

Does FDA's Predetermined Change Control Plan apply to generative AI?

The PCCP guidance, finalized in December 2024, was written primarily with adaptive machine learning models in mind — the kind that retrain on new data over time. Generative AI functions can be covered if a manufacturer defines the modification protocol and performance criteria clearly enough for FDA to evaluate, but the guidance does not use generative-model examples as its primary case. Expect closer scrutiny in that scenario.

When does FDA's Quality Management System Regulation take effect?

The QMSR compliance date is February 2, 2026. It replaces 21 CFR Part 820 with requirements harmonized to ISO 13485:2016. Any AI-enabled device governance program should already be built against QMSR language rather than the outgoing Part 820 text.

Last updated: 2026-08-18

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.