---
author:
- James Swink
cta_button_text: Discuss your AI device strategy
cta_case_studies: []
cta_hero_details: Innolitics connects regulatory strategy, software engineering, clinical
  evidence, cybersecurity, quality systems, and FDA submissions in one accountable
  team. Bring us your AI-enabled device concept, evidence plan, and timeline; we can
  help build a credible path from product strategy to clearance.
cta_hero_text: Turn regulatory uncertainty into an investable development plan.
date: '2026-09-26'
description: 'Key takeaways from the September 25 CDRH--MDIC meeting: regulatory predictability
  can help restore medtech investment; FDA trust in AI depends on validated methods,
  credible evidence, and clear revalidation thresholds; stronger postmarket surveillance
  may support a lighter premarket burden, but limited access to EHR and device-level
  data makes that surveillance difficult; and shared standards, UDI adoption, federated
  data access, and qualified regulatory science tools could reduce uncertainty across
  the industry.'
related: []
title: Notes from the September 25th CDRH MDIC Regulatory Science Meeting
topics:
- Regulatory
- AI/ML
- News
---

Ask a medical device founder how fundraising is going this year, and you will likely hear the same story. Investors are interested, just not in them. Private money is flowing to AI companies, where the markets look bigger, the build cycles shorter, and the regulatory path simpler. To many investment committees, medtech now reads as a sector that is too small, too slow, and too hard to predict.

That was the backdrop on September 25, 2026, when FDA\'s Center for Devices and Radiological Health (CDRH) and the Medical Device Innovation Consortium (MDIC) met at White Oak. The goal was to advance regulatory science for breakthrough and disruptive technologies and to identify the challenges likely to shape device development over the next decade.

I attended as someone who has seen these challenges from both sides. I spent 22 years at FDA, and today I work with Innolitics, a forward-looking, full-service SaMD firm whose founders built it on the same idea that ran through this meeting: modern software engineering and regulatory rigor belong together. We are all trying to move the industry forward in a way that is collaborative, least burdensome, and focused on the patient.

Underneath the meeting\'s goal sat a harder question. If capital is leaving medtech, can regulatory science help bring it back? I believe it can, but only if both sides accept a basic bargain. A least burdensome pathway is not owed. It is earned, through evidence and methods FDA can trust, built together, with the patient as the fixed point.

## The structural problem

Part of the uncertainty is built into the framework. AI products keep evolving, while FDA\'s framework was designed for devices with fixed performance. The opening panel framed the policy question as a joint one: how should FDA regulate these technologies, and what does FDA need in order to regulate them well?

Reimbursement is the other half of the investment case. A device that is cleared but not paid for has not reached a patient. The proposed CMS--FDA RAPID coverage pathway, which aims to align evidence for FDA authorization and Medicare coverage from the start, came up as a model for closing that gap.

## A true consensus meeting

FDA and MDIC deserve real credit for how this meeting was designed. It was a working session, not a series of presentations. Manufacturers, consultants, third parties, and FDA staff were collegial and candid, putting their cards on the table to find the gaps and work out how to fill them together.

Having spent more than two decades inside the agency, I can say this approach is not a given. A regulator asking industry to help set its research priorities for the next ten years is forward-thinking, and MDIC\'s role as a neutral convener makes that candor possible. Industry should treat this as an opportunity. The meeting docket, FDA-2026-N-8563, is open through November 24, 2026, and comments that describe a real dataset, barrier, or tool will carry the most weight.

FDA is also building the capacity to meet the moment. The agency still has its foundational reviewers, the experienced staff who understand how devices succeed and fail. It is adding to that bench by hiring AI experts and biomedical engineers, including recent additions to its digital health team. That combination of institutional memory and new technical depth is what trust requires as CDRH evolves with the technology.

## The trust bargain

The central idea of the day was simple. Industry has to prove its methods before FDA can adopt policies that make them routine. Those methods include:

- AI-enabled trial design
- rigorous verification and validation
- computational modeling
- real-world evidence

Once FDA trusts a method, the least burdensome route stops being an aspiration and becomes a pathway.

There are precedents. OSEL\'s enrichment program and the Living Heart Project, essentially a digital twin of the human heart, were cited as proof that computational models can earn regulatory trust. Type 1 diabetes was another example. A large unmet need, combined with shared standards, produced the first interoperable continuous glucose monitor and paved the way for artificial pancreas systems. Methods earn trust fastest when they are aimed at a specific unmet need.

AI is next, and it is harder. For foundation models that shift over time, the key question is when a change is large enough to require revalidation, and how these systems should be monitored. Participants argued that some changes affect efficacy without affecting risk. If software is tested at the binary level and clinical behavior has not changed, a new submission may not be warranted. Manufacturers also pressed on how AI should be verified, with which tools, and whether the definition of software verification needs tightening. One suggestion stood out: as CDRH continues to evolve, it may need a dedicated Office of Health Technology (OHT) for AI.

## Where the meeting challenged both sides of the aisle

This is where the meeting challenged thinking on both sides of the aisle. Manufacturers are testing how far the benefit-risk rubric can stretch without compromising patient safety. The industry case is to use retrospective data as the least burdensome route, extend it to broader populations, and move remaining questions into the postmarket phase.

FDA\'s position was just as clear: the agency still wants prospective studies.

Both positions have merit. Retrospective data already trains AI and can support premarket submissions, especially in pediatrics, where a new randomized trial often never happens. But trust is won or lost in the details. The clinical evidence breakout named the questions that decide whether retrospective data is fit for purpose:

- **Validation.** When was the data validated?
- **Representativeness.** Does it reflect the right patients and the right users, whether a specialist, a generalist, or the patient at home?
- **Device identity.** Can you tell which device produced an outcome when there is no unique device identifier (UDI) in the record?
- **Comparators.** How are comparators selected and re-evaluated, and when are external controls or synthetic data appropriate?

FDA also called for more postmarket monitoring of devices already cleared. Postmarket evidence is part of the bargain, not a way around it. For lower-risk devices, that raises a fair question for both sides. Can a strong, well-designed postmarket plan justify a lighter premarket burden?

Patients have to be part of that bargain too. As evidence collection moves closer to real-world use, informed consent has to become more robust, so patients understand exactly what they are agreeing to.

The strongest path forward is to plan the full evidence strategy from beginning to end before a trial starts. That means deciding up front what will be proven premarket, what will be learned postmarket, and how the data will connect. This is where FDA\'s view across the whole industry is most valuable. Smaller companies in particular need early, practical feedback on the least burdensome approach that will still answer FDA\'s safety and effectiveness questions.

Pediatrics shows how closely evidence and capital are linked, and the lesson extends to every underserved, rare, or unique indication. Observational cohort data can carry the evidence for small populations, but only if the market has a reason to fund it. A transferable pediatric voucher, similar to vouchers used on the drug side and cited in the room at roughly \$350 million in value, was named as one such reason. Whatever the mechanism, the principle holds: if we want innovation for the patients the market overlooks, we have to make the evidence worth building.

## The biggest hurdle: getting to the data

EHR interoperability came up in all three breakout groups. It was the most persistent theme of the day and the hardest to solve. Real-world evidence depends on EHR data, and large companies and health systems were clear that they will not simply hand theirs over.

Ideas surfaced anyway. One was protected, shared data environments where contributors keep control of their own data. Another was the observation that manufacturers rarely use ClinicalTrials.gov to share what others could learn from, a missed opportunity as AI trials multiply.

The candid assessment in the room was that a national pool of EHR data available to any SaMD manufacturer may never happen. If companies won\'t share data, they have to share methods and infrastructure:

- common data standards
- UDI in the record
- federated approaches that bring the analysis to the data
- agreed rules for what makes a dataset trustworthy

Without that, the least burdensome real-world evidence path stays out of reach for everyone.

## The big AI tent, and what it hides

\"AI\" has become a large tent. Under it sit agentic systems, systems that operate under human supervision, and fully autonomous systems, each with a different risk profile. At the same time, the home is becoming a place of medical care, where no specialist is in the room.

Grouping all of this under one label hides risks that no single study was designed to catch. These include over-reliance on outputs, performance that drifts silently, and training data that looks representative but is not. The human factors standard is being revised to address how users interpret AI outputs and the data used to train the model. Patient preference was flagged repeatedly as essential to the benefit-risk judgment.

FDA\'s mission has not changed. It protects people from devices that do not perform and promotes access to devices that do. One participant called FDA a decision factory. Industry\'s job is to bring it decisions it can make, with data that is relevant, reliable, and representative.

## The tools already exist. Industry has to use and build them.

FDA is not starting from zero. CDRH maintains a catalog of Regulatory Science Tools (RSTs), and the Medical Device Development Tools (MDDT) program qualifies tools that sponsors can use across submissions, including tools for cybersecurity.

The problem is that these tools are underused, largely because too few people are trained on them. The same is true of digital twins, synthetic models, alternatives to animal testing, and test methods for home-use devices. There is also a funding gap. Venture capital will not fund cybersecurity tools for medtech because there is no clear return.

That gap brings the argument full circle. The unglamorous infrastructure investors will not pay for is exactly what makes medtech investable. That includes:

- a list of known, accepted materials and methods that shortens the path to a clinical study
- standardized methodology
- benchmarking datasets for large language models
- global harmonization, so a trusted method does not have to be proven again in every market

Every qualified tool lowers the cost and uncertainty for the next company, and regulatory predictability is an asset investors can price.

One participant suggested that a major AI infrastructure company, NVIDIA for example, could solve much of this if it chose to. Big technology players can genuinely help. They can offer hardened computing platforms, simulation and synthetic data at scale, and monitoring tools that catch performance drift. But clinical validation, access to representative data, and device-specific threat modeling remain the manufacturer\'s job, and FDA holds the manufacturer accountable no matter whose platform the product runs on. A shared platform also adds a risk of its own: when many devices depend on one stack, a single vulnerability or flawed update reaches all of them at once.

## What to do now

The closing session offered a useful filter: which items are actionable, and where does each fall on an effort-versus-impact matrix? Measured that way, the next steps are concrete:

- **Plan the evidence path end to end** before the first patient is enrolled.
- **Build and submit candidate tools** for the RST catalog or MDDT qualification, and train teams to use the ones that already exist.
- **Invest in interoperability.** Adopt data standards and put UDI in the record, so real-world evidence becomes proof rather than anecdote.
- **Where applicable, keep pediatric and underrepresented populations in the data**, and in the incentives that fund it.

The day closed with a fitting question to the panel: if you had a billion dollars to fix AI in medical devices, what would you do with it?

My answer, after a full day in that room, is that I would not spend it on a better algorithm. I would spend it on the shared infrastructure no single company will fund alone. That means trusted datasets that are representative and properly identified, a real path to EHR data, validated tools any sponsor can use, and training so people actually use them.

None of this asks FDA to lower the bar. It asks industry to earn FDA\'s trust in AI through the studies and methods now underway, and it asks FDA to say clearly what evidence it will accept. Each side has to do the part only it can do, and each has to be ready to prove its case while keeping patients safe.

If medtech wants its capital back, the pitch cannot be only that the technology is exciting. It has to be that the path is known, the methods are trusted, and the patient is protected. That is where the billion dollars should go.

*My sincere thanks to FDA and MDIC for a genuinely collaborative day, especially Michelle Tarver, MD, PhD, and Suzanne Schwartz, MD, MBA, of CDRH, and Andrew Fish, JD, of MDIC, whose leadership set the tone. And to my former FDA colleagues: it was good to be back in the room with you, working on the same problem from a different seat.*
