The Regulatory Landscape, Conceptually
The Shared Logic Across Jurisdictions
The details differ substantially between jurisdictions, but the underlying architecture is broadly shared. Obligations are risk-proportionate: the greater the potential harm from a wrong output, the greater the evidence and the scrutiny required. Evidence must support the specific intended use rather than general capability. Quality management systems and technical documentation are required, so that how the product was developed is inspectable. And obligations continue after market entry through post-market surveillance and vigilance reporting. If you understand those four principles you can orient in any jurisdiction and ask sensible questions, even without knowing the specific instruments — which is the right posture, because they change.
- Risk-proportionate obligations: higher potential harm, higher evidence burden
- Evidence must support the stated intended use, not general capability
- Quality management and technical documentation make the development process inspectable
- Post-market surveillance and incident reporting continue after approval
United States and European Union, at a High Level
In the US, medical device software is overseen by the FDA through a risk-based framework with different routes to market, including pathways based on demonstrating equivalence to an existing device and pathways for novel low-to-moderate risk devices, alongside a more demanding route for the highest-risk category. In the EU, medical device software is classified under the Medical Device Regulation, with conformity assessment involving a notified body for higher risk classes, and the AI Act adds a further horizontal layer of obligations for AI systems classified as high-risk, which many medical devices are. The practical consequence in Europe is two overlapping regimes that must be satisfied together rather than one replacing the other.
- US: a risk-based FDA framework with multiple routes to market depending on novelty and risk class
- EU: MDR classification and conformity assessment, with notified body involvement above the lowest risk classes
- The EU AI Act layers additional high-risk obligations on top of, not instead of, MDR
- Approval in one jurisdiction confers nothing in another
What Approval Does and Does Not Tell You
A regulatory clearance or certification tells you a manufacturer met a defined standard of evidence for a defined intended use in a defined jurisdiction at a point in time. It does not tell you that the product will perform well in your institution, that it outperforms your current practice, that it was validated on patients like yours, that it is cost-effective, or that it is safe in a workflow different from the one contemplated. Regulatory status is a floor and a scope statement, not a recommendation. Institutions that treat it as sufficient skip local validation on the grounds that the regulator already checked — a category error, because the regulator checked something different from what the institution needs to know.
- Approval means evidence met a standard for a specific use, jurisdiction, and point in time
- It implies nothing about local performance, comparative benefit, or cost-effectiveness
- Regulatory status is a floor and a scope statement, never a recommendation
- Treating approval as a substitute for local validation is a category error
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.