Health Policy

A Decade of Regulatory Evolution: Global AI Medical Device Rules and Research, 2015–2025

From the FDA's Predetermined Change Control Plan to the EU AI Act's risk classification, a review published in *Frontiers in Medicine* systematically mapped the regulatory pathways for AI medical devices across five major markets—the United States, the European Union, China, Japan, and South Korea—over a decade, while also exposing structural gaps in clinical validation and data diversity.

A Decade of Regulatory Evolution: Global AI Medical Device Rules and Research, 2015–2025

Introduction

When the algorithm of a Medical AI product updates every few months because of new data, what exactly should regulators approve? A fixed version of the software, or a set of rules that allow it to keep evolving within boundaries?

Over the past decade, this question has moved from an academic hypothesis to real policy engineering. On July 17, 2025, the Regulatory Science section of *Frontiers in Medicine* published the review *A decade of review in global regulation and research of artificial intelligence medical devices (2015–2025)*, jointly completed by researchers from Shenyang Pharmaceutical University and Peking Union Medical College Hospital, Chinese Academy of Medical Sciences. Using the PRISMA process, the study systematically reviewed AIMD regulatory policies and academic research across the five major markets of the United States, the European Union, China, Japan, and South Korea from 2015 to 2025, ultimately including 73 academic articles and 27 policy studies.

This is not a technical review. It discusses rules—and rules are becoming the most realistic variable in the industrialization of AI healthcare.

Industry Context

AI medical devices (AIMD) refer to software or software-hardware combinations that use machine learning algorithms to analyze multimodal medical data and are regulated as medical devices, with application scenarios covering areas such as real-time sepsis prediction, automated retinopathy screening, and cancer risk stratification.

The problem stems from two technical characteristics: adaptive learning and algorithmic opacity.

The regulatory logic of traditional Medical Devices is built on an implicit premise—that the form of a product at the time of approval is the form it will have after market launch. By contrast, machine learning–based SaMD (Software as a Medical Device) is the exact opposite: it continuously changes as data accumulates. This forces regulators to simultaneously answer two competing questions: how to ensure patient safety, and how not to stifle Healthcare Innovation in the approval process.

Key DevelopmentsUnited States: From the Pre-Cert Pilot to the Predetermined Change Control Plan. The FDA’s path is the most complete. The 2017 Digital Health Innovation Action Plan promoted regulatory modernization for digital health products and launched pilot programs such as Software Precertification (Pre-Cert); the 2019 discussion paper “Proposed Regulatory Framework for Modifications to AI/ML-Driven Software as a Medical Device” proposed a Total Product Lifecycle (TPLC)-oriented regulatory model, whose core mechanism is the Predetermined Change Control Plan (PCCP), allowing manufacturers to predefine algorithm update parameters in premarket submissions, thereby enabling postmarket modifications within approved safety boundaries. The 2021 AI/ML Software Action Plan formalized this framework and emphasized postmarket performance monitoring; the 2023 draft guidance on PCCP marketing submissions further clarified the permissible conditions and submission requirements for algorithm changes.

European Union: Starting with Risk Classification. The EU AI Act introduced risk-based classification requirements for AIMD, linking the compliance obligations of AI systems to their level of health and safety risk.

China: Technical Review Guidance Comes First. China’s National Medical Products Administration (NMPA) issued technical review guiding principles for AI medical devices in 2022, providing a relatively clear review basis for domestic AIMD submissions.

Japan: Designing a Framework for “AI That Changes.” Japan’s Pharmaceuticals and Medical Devices Agency (PMDA) built an adaptive AI regulatory framework, seeking to balance algorithmic accountability and regulatory flexibility.

South Korea: Advancing in Parallel. South Korea’s Ministry of Food and Drug Safety (MFDS) is also establishing its own AIMD regulatory pathway.

The review presents, in the form of a comparison table, the differences among the five jurisdictions’ regulatory approaches side by side—these differences are precisely the real source of compliance costs for multinational companies.The affected sectors are quite clear: medical imaging AI and SaMD developers bear the brunt; Digital Health platforms and wearable and remote monitoring device manufacturers with real-world data collection and performance monitoring capabilities will gain new value space as payers’ evidentiary requirements rise; hospitals are the ultimate bearers of the rules—procurement and health insurance reimbursement decisions increasingly rely on verifiable clinical evidence.

However, the review also presents two sets of sobering data. First, less than 30% of AIMD disclose the demographic diversity of their training datasets, leaving algorithmic bias without an auditable basis. Second, about 43% of AIMD already approved or cleared by the FDA lack clinical validation data, and only 28% have undergone prospective device validation testing.

For the Healthcare Industry, this means that regulatory leniency does not equal market leniency. Payers, hospital procurement committees, and clinical departments will screen Medical AI products using standards stricter than those of regulators.

Challenges And Risks

Globalization costs brought by divergent standards. Although the rules in the five major markets show signs of convergence, risk classification criteria, change control requirements, and evidence standards remain inconsistent, making duplicate investment in multinational submissions difficult to avoid.

Post-market oversight challenges of adaptive algorithms. When algorithms continuously learn in the real world, what regulators need is continuous monitoring capability, not a one-time approval conclusion—this places new demands on regulators’ own technical capabilities.

Data diversity and algorithmic fairness. Insufficient disclosure of training data makes bias difficult to quantify and difficult to hold accountable in regulatory documents.

Clinical validation gap. A large number of approved AIMD lack prospective validation; this gap will not be automatically filled by improvements to regulatory frameworks, but requires Healthcare Technology companies and medical institutions to jointly invest in real-world research.

The relative lag of regulatory science. Technology still evolves faster than rules iterate, which is a long-standing structural tension in Biotech Innovation and Medical Devices.

Future Outlook

Over the next 3 to 5 years, AIMD regulation will most likely advance along three lines.

First, shifting from “approval milestone” to “lifecycle governance.” Change management mechanisms based on the PCCP approach may be borrowed or locally adapted by more jurisdictions, and post-market performance monitoring will change from a voluntary activity to a mandatory compliance requirement.

Second, real-world evidence enters the core of regulation and payment. As the 43% validation gap is repeatedly mentioned, requirements from regulators, hospitals, and payers for post-market real-world performance data will rise in tandem.Third, cross-border coordination is moving from initiatives to the operational level. The EU AI Act's risk-tiering approach may become a reference template for other markets when designing AIMD classification rules, and mutual recognition of standards among the five major markets will be a key variable determining the pace of globalization of AI Healthcare products.

Conclusion

Over the past decade, AIMD regulation has undergone a paradigm shift: regulators no longer only ask, "Is this algorithm accurate?" but have begun to ask, "How will this algorithm change in real clinical settings, and who is accountable for those changes?" For HealthTech companies, this means compliance is no longer a pass-and-forget threshold, but a capability requiring long-term operational management. As rules begin to catch up with technology, the true watershed emerges—in the next stage of competition in AI healthcare, it is not about whose model has more parameters, but about who can continuously prove that their model remains safe, effective, and explainable in the real world.

Reader cross-check · medtechdaily

medtechdaily frames this note through Digital Health / AI Healthcare / Medical Devices - Source links should be opened before the summary is reused. dates, names and status changes still need checking; Digital Health / AI Healthcare / Medical Devices explains the local editorial angle.

Source links

  1. https://www.frontiersin.org/journals/medicine/articles/10.3389/fmed.2025.1630408/fullPrimary

Related articles

Back to channel