Reference · Healthcare
FDA's AI-Enabled Device Guidance: PCCP and Lifecycle, Explained
Predetermined Change Control Plans (final) · AI-Enabled Device Software Functions: Lifecycle Management (draft)
FDA regulates AI-enabled device software functions through the marketing-submission pathways, and two guidances shape how sponsors describe change and lifecycle management. The predetermined change control plan guidance was finalized in December 2024. The lifecycle management and marketing submission recommendations for AI-enabled device software functions were issued as a draft in January 2025 and remain a draft. Both address sponsors; a provider or payer that operates such devices can still prepare the deployer-side evidence.
Who it applies to
Sponsors of device software functions that use AI, through 510(k), De Novo, and PMA submissions. Hospitals and health systems that operate cleared devices are not the audience of either guidance, but they own the version in use, the workflow around the output, and the real-world performance signal.
The predetermined change control plan (final, December 2024)
- A description of the planned modifications to the AI-enabled device software function.
- A modification protocol: data management, re-training, performance evaluation, and update procedures.
- An impact assessment of the planned modifications.
- Once authorized, modifications within the plan can be implemented without a new marketing submission.
The lifecycle guidance (draft, January 2025)
- Data management: sources, collection, annotation, representativeness, and independence of test data.
- Human factors and human-AI interaction: display, workflow integration, automation bias, and the information users need.
- Post-market performance monitoring: real-world performance, drift and data shift, triggers for action.
- Version control and lifecycle record-keeping across development, validation, deployment, changes, and monitoring.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Version change control | Know when the model behind a device function changed and whether the change fell within the PCCP | Version history and the sponsor's plan and change communications |
| Post-market monitoring | Monitor real-world performance with triggers for action | The monitoring plan, metrics, and runtime inputs |
| Human factors | Design the human-AI workflow against automation bias | Workflow documentation and human-review records |
| Lifecycle record-keeping | Keep records across the lifecycle | The deployment record alongside the sponsor's development and validation records |
Key dates
- December 2024FDA finalizes the predetermined change control plan guidance for AI-enabled device software functions.
- January 2025FDA issues the draft AI-enabled device software functions lifecycle management guidance.
Primary sources
Common gaps
Where deploying organizations are least prepared.
- Nobody knows the version in use. A vendor pushes an update within its plan. The organization learns of it from a changed output, not a change communication.
- Monitoring without a plan. Over-read disagreement rates exist in someone's spreadsheet. No trigger, no cadence, no owner.
- Draft guidance quoted as requirement. The lifecycle guidance is a draft. Citing it as binding overstates the posture and misleads a reviewer.
Last reviewed September 5, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.