The AI Learning Hub Journal

The Regulatory Landscape, Conceptually

How the regulatory picture fits together, conceptuallythe shape is broadly shared; the categories, duties and thresholds differ by jurisdictionIT ALL STARTS WITH THE INTENDED-USE STATEMENTClaims a clinical purposediagnose, treat, triage, or guide a clinical decisionClaims only information or administrationreference material, scheduling, record-keepingThe same software can land on either side of that line purely on the strength of its claimRISK-PROPORTIONATE CLASSIFICATIONScaled to what could go wrongSeverity of the harm, and howreversible it would be.Not every tool is treated alikeA reminder and a treatmentdecision sit far apart.Classification drives the restEvidence, depth of review andrecord-keeping all follow.PRE-MARKET EVALUATIONStated intended useWhat it is for, and for whom,written down in advance.Evidence must match the claimA broader claim calls forbroader evidence.Review before it reaches careHow deep that review goesfollows the class it landed in.POST-MARKET SURVEILLANCEApproval is not the finishReal-world performance iswatched after release.Problems get reportedThere are duties to noticeand to escalate.Changes can reopen reviewAn updated model may not bethe one that was approved.AND IN SOME PLACES, TWO LAYERS AT ONCEMedical-device style rules — triggered by the clinical claim being madeGeneral AI rules — triggered by the technology and its risk tier, whatever the sectorWhere both layers apply, the obligations add up rather than substitute for one anotherThe shape is broadly shared; the categories, the duties and the thresholds are notSpecifics differ by jurisdiction and change over time — check what applies where you are
Educational orientation only — a conceptual map, not regulatory advice for any jurisdiction

The Shared Logic Across Jurisdictions

The details differ substantially between jurisdictions, but the underlying architecture is broadly shared. Obligations are risk-proportionate: the greater the potential harm from a wrong output, the greater the evidence and the scrutiny required. Evidence must support the specific intended use rather than general capability. Quality management systems and technical documentation are required, so that how the product was developed is inspectable. And obligations continue after market entry through post-market surveillance and vigilance reporting. If you understand those four principles you can orient in any jurisdiction and ask sensible questions, even without knowing the specific instruments — which is the right posture, because they change.

  • Risk-proportionate obligations: higher potential harm, higher evidence burden
  • Evidence must support the stated intended use, not general capability
  • Quality management and technical documentation make the development process inspectable
  • Post-market surveillance and incident reporting continue after approval

United States and European Union, at a High Level

In the US, medical device software is overseen by the FDA through a risk-based framework with different routes to market, including pathways based on demonstrating equivalence to an existing device and pathways for novel low-to-moderate risk devices, alongside a more demanding route for the highest-risk category. In the EU, medical device software is classified under the Medical Device Regulation, with conformity assessment involving a notified body for higher risk classes, and the AI Act adds a further horizontal layer of obligations for AI systems classified as high-risk, which many medical devices are. The practical consequence in Europe is two overlapping regimes that must be satisfied together rather than one replacing the other.

  • US: a risk-based FDA framework with multiple routes to market depending on novelty and risk class
  • EU: MDR classification and conformity assessment, with notified body involvement above the lowest risk classes
  • The EU AI Act layers additional high-risk obligations on top of, not instead of, MDR
  • Approval in one jurisdiction confers nothing in another

What Approval Does and Does Not Tell You

A regulatory clearance or certification tells you a manufacturer met a defined standard of evidence for a defined intended use in a defined jurisdiction at a point in time. It does not tell you that the product will perform well in your institution, that it outperforms your current practice, that it was validated on patients like yours, that it is cost-effective, or that it is safe in a workflow different from the one contemplated. Regulatory status is a floor and a scope statement, not a recommendation. Institutions that treat it as sufficient skip local validation on the grounds that the regulator already checked — a category error, because the regulator checked something different from what the institution needs to know.

  • Approval means evidence met a standard for a specific use, jurisdiction, and point in time
  • It implies nothing about local performance, comparative benefit, or cost-effectiveness
  • Regulatory status is a floor and a scope statement, never a recommendation
  • Treating approval as a substitute for local validation is a category error

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.