Abstract 🔗
FDA released 25 AI SaMD summary PDFs from 510(k)s cleared in September 2026. Standouts include ProNova's VIRTUE QA, which brings continuous learning into a cleared device, with a plan that retrains each machine's models daily under the premarket acceptance criteria, and Epic Systems received its first AI/ML clearance.
Summary of observations 🔗
- Continuous learning in a cleared device. VIRTUE QA retrains each machine's models daily.
- Incumbents' first AI clearances. Epic (K260008) and Align (K262196).
- Hardware makers with software-only AI. CapsoVision, Wellysis and Siemens.
- Software for another company's hardware. OtoCompanion (a Karl Storz camera) and Aevice (its own and other makers' cleared stethoscopes).
- Cross-modality predicate. TumorSight Risk (MRI on a slide predicate).
- PCCPs within existing indications. None of the five plans adds a finding.
- Reusable wording. a2z's processing-time qualifier and Aevice's device type with examples.
- Unpublished criteria or results. Wellysis, a2z, CapsoVision and Align.
Deterioration Index Version 2 (K260008, Epic Systems) 🔗
Epic's Deterioration Index Version 2 (K260008) estimates the risk that an adult inpatient or emergency department observation patient will die within 72 hours or will need escalation of care within 24 hours. A "static gradient boosted random forest (trained with LightGBM)" converts 195 chart inputs into a score from 0 to 100 for trained clinicians, and the device works only with the Epic EHR. FDA cleared it on September 18, 2026 under 21 CFR 870.2210 (product code QNL) [1], 259 days (about 8.5 months) after receipt. It is Epic's first AI/ML clearance and its first through CDRH, after four CBER 510(k)s for blood transfusion software, and its predicate is AgileMD's eCARTv5 (K233253).
I put Epic first because hospitals have used the first version of the Deterioration Index since at least 2020 without a clearance, and predictive scores inside the EHR have long sat in a regulatory gray zone. The EHR itself falls outside device regulation, while this function clearly falls inside it. FDA's 2022 Clinical Decision Support guidance lists software that analyzes EHR vital signs "to identify signs of patient deterioration and alert an HCP" as a device [2]. The January 2026 revision still keeps predictions of a cardiovascular event "in the next 24 hours" under FDA oversight [3], and the summary does not say why Epic sought clearance.
The retrospective validation uses about 10.7 million score observations from three US sites. Its primary endpoint requires the stratum-specific likelihood ratio to rise across the low, medium and high risk tiers with non-overlapping 95% confidence intervals, and the reported ratios of 0.55, 3.78 and 13.21 meet it. AUROC (0.83) is a secondary endpoint without a threshold. Epic deserves kudos for a statistics write-up far more detailed than most 510(k) summaries, although the summary omits patient counts, lead time, NPV and human factors results, several of which the special controls for 870.2210 require.
A company building an EHR-based predictive score now has three QNL predicates and a precedent for retrospective validation alone. The model is locked and the clearance carries no PCCP, so a retrained model will likely need a new 510(k) [4].
Continuous Learning in VIRTUE QA (K260597, ProNova Solutions) 🔗
ProNova's VIRTUE QA (K260597) is the clearance I expect to matter most over time, because it brings continuous learning into a cleared AI device. FDA's PCCP guidance uses that term for AI modifications "implemented automatically by software" [5], and VIRTUE QA's automated retraining and verification meet the definition, although the summary never uses the phrase.
The device performs patient-specific quality assurance (QA) for proton therapy. Its new function, SynthetIQ, "predicts treatment delivery parameters without requiring physical beam delivery," while the predicate, myQA iON (K201798), gets that information from a dry-run delivery. The technology table marks beamless predictive QA as a new capability, and the clearance gives future predictive QA products an AI predicate in product code LHN. "Each treatment machine maintains an independent training dataset." Under Modification 1 of the PCCP, "The six machine-specific predictive models are updated once daily using accepted delivery data accumulated during prior clinical operation," and "Only model weight parameters change."
I wondered why ProNova learns delivery behavior from data when physics could simulate the path from plan to delivery log. VIRTUE QA already contains a Monte Carlo dose engine (MCsquare), which computes dose from spot parameters but does not model how a given machine delivers those spots. My view is that the model learns each machine specifically, including the quirks of its beam delivery, and that is why a physics simulation was not the right tool. Every treatment day also produces paired plans and delivery logs, so the training labels cost nothing.
Each candidate model set "must continue to meet the performance requirements in Section 7.4," which hold the premarket acceptance criteria for gamma pass rate, spot position, spot size and monitor units. An error-level candidate is never activated, the prior validated model set stays in use, and the summary describes no human release step. I think this is exactly how retraining should be governed, because the premarket acceptance criteria become the postmarket gate and nobody has to invent a second standard.
The loop also runs per site. Modification 2 names Varian, IBA and Hitachi proton platforms in advance. Each vendor release needs at least 50 unique beams and at least one month of parallel clinical evaluation, and each installed machine completes commissioning that includes shadow-mode operation. I welcome FDA's openness to this kind of ongoing postmarket verification, because proving before clearance that a model generalizes to every future site would require a massive study with little added effectiveness. ProNova builds the SC360 proton system (K162246), and because this PCCP names competitors' platforms, the company now holds a cleared path onto other vendors' machines.
The summary describes several types of bench and clinical testing. Walk-forward validation tests each day's predictions against deliveries that had not yet happened. A longitudinal evaluation of 324 patients and 15,565 beams reports mean gamma agreement of 99.59% to 99.92% by treatment room, and an analysis of 29,094,093 spots puts the 95% limits of agreement for spot position within ±0.24 mm. All 55 beams compared with independent array detector measurements met the study's 3%/3 mm gamma criterion. Perturbation testing challenged the production daily-retraining process over 24 treatment days and detected 97 of 98 scenarios, which is the direct evidence that the continuous loop works. In a retrospective study of 100 patients, predictive QA detected 52 of 68 deliverability issues and clinical log-file QA detected 15.
Other AI summaries in FDA Device Explorer mention continuous learning only to state that the model is locked, and Seg Pro V3 (K251306) retrains locally only after triggers such as documented performance degradation. VIRTUE QA is the first FDA-cleared AI device I could find that retrains its deployed models on a schedule, on each machine's own data, with automated verification and without a new submission.
VIRTUE QA also carries a personal connection. Mobius3D was one of the first medical devices I worked on, and as I recall, CBCT-to-planning-CT registration was among the first device code I wrote. Mobius3D is photon QA software that runs an independent 3D secondary dose check, and its MobiusFX add-on computes delivered dose from linac delivery logs. Innolitics helped build the Mobius3D CBCT module [6], which shipped in Mobius3D v2.0.0 (K153014). That release is the predicate of myQA iON and a reference device for VIRTUE QA, which makes it a grandparent of this device.
TumorSight Risk (K260023, SimBioSys) 🔗
TumorSight Risk (K260023) reads breast MRI, yet its predicate analyzes pathology slides. The device combines clinical variables with MRI data to estimate 5- and 10-year recurrence risk, with Low, Intermediate and High categories, for adult women with HR+/HER2-, N0 or N1, Stage I-IIIA breast cancer. Innolitics worked with SimBioSys on its first TumorSight Viz clearance (K231130), which the SimBioSys case study describes [7].
FDA reviewed TumorSight Risk, which cites ArteraAI Breast (K254115), through the Pathology panel because its regulation, 21 CFR 864.3755 [8], sits in the pathology part of 21 CFR. The De Novo order for ArteraAI Prostate (DEN240068) describes software that "analyzes acquired digital images to provide prognostic risk estimates in patients with previously diagnosed cancer." That definition names no modality, and the special controls name whole slide images and H&E staining only inside "e.g." parentheticals. The imaging input is "a validated output of the TumorSight Viz device (K251766)," which is a segmentation map from dynamic contrast-enhanced MRI.
A retrospective study includes 2,129 patients from 4 US sites that supplied no development data. Reported 10-year recurrence risk is 8.6% for Low, 13.4% for Intermediate and 26.4% for High. My reconstruction from the reported at-risk table gives an approximate log-rank p of 1e-10 and an approximate High-versus-Low hazard ratio of 3.2.
Predicates can therefore cross modalities when the regulation is written generally, and a company with a new input for an established output type can file a 510(k) where it might have planned a De Novo.
a2z-Abdo-Triage (K260906, A2z Radiology AI) 🔗
a2z-Abdo-Triage (K260906) reads adult abdominopelvic CT studies and flags suspected positive cases of 10 acute and traumatic findings. Its sole predicate is a2z's own K252366, which Innolitics reviewed in an earlier article [9], and the two devices share no findings.
Product codes QFM and QAS share 21 CFR 892.2080 and its special controls [10], but cleared QFM devices typically reorder worklists while cleared QAS devices often notify specialists directly.
Two U.S. board-certified radiologists classified each of the 965 test studies for every finding independently, a third radiologist broke ties, and the readers "were blinded to device output." I prefer this 2+1 design for retrospective truthing because most cases need only two readers and nobody has to schedule a consensus panel.
Three sites without training data supplied the test set, and Ohio contributed 10.5%. A common question I get is whether one site can contribute only 10% of the cases. The answer is yes, and the idea that sites must split 33/33/33 is a common misconception. FDA's AI draft guidance suggests at least three geographically diverse sites and sets no per-site share [12]. Geographic spread covers regional factors that no sponsor can list in advance, such as histoplasmosis and blastomycosis around the Ohio and Mississippi River valleys and coccidioidomycosis in the Southwest. Clients sometimes panic when their test set does not represent every scanner, and thin coverage is acceptable here (Fuji contributes 7 studies). CT is well standardized, so this matters less than in digital pathology, where 21 CFR 864.3750 requires a precision study across scanners and sites [13].
The PCCP covers retraining, architecture and preprocessing changes but "applies to the 10 conditions validated in this 510(k) submission." FDA's PCCP guidance says that "most modifications to the indications for use included in a PCCP would be difficult for FDA to assess prospectively" [5], and a new finding changes the indications list. FDA did accept neural network architecture changes inside this plan. In my view, FDA cares about how a change is tested more than about the architecture, at least for convolutional neural networks, and generative AI would be a different story.
The processing-time qualifier is reusable wording that I recommend to every triage company. A software-only company cannot know deployment-specific overhead before its device is installed, so it should measure processing time in a controlled environment and state the limit the way a2z did.
"This interval excludes deployment-specific overhead and does not represent end-to-end clinical-workflow turnaround."
A triage company that wants more findings should plan a new 510(k) for each batch, as a2z did less than four months after K252366 cleared.
Invisalign System (K262196, Align Technology) 🔗
Align Technology added AI to an established product line. K262196 adds "an optional AI-enabled prediction service to the backend 3D treatment planning software to support Invisalign treatment planning by optimization of aligner activation design." I did not find any of the 16 earlier Align and Cadent summaries mentions AI, and FDA's AI-Enabled Medical Devices list has no Align entry [14], although it lists Dentsply Sirona's CEREC Ortho Software (K171122, 2018) under the same product code. Align's closest precursor, K241412 from June 2024, automated treatment planning end to end without calling it AI.
The summary reports "no direct user interaction with the AI-enabled functionality," the model "is static and non-adaptive," and the doctor approves each plan before manufacturing. Align cleared the feature in 88 days through a Traditional 510(k) against its own predicate (K252380) with unchanged indications. The summary gives no dataset sizes, named endpoints or performance numbers.
I rank this clearance below Epic in importance, but it is a useful case. An incumbent with a cleared product can add AI as an optional backend service behind a clinician approval step and keep its indications, predicate and pathway. A competitor that cites K262196 gets a regulatory route without a benchmark for its own testing.
CapsoView and CapsoCloud (K254230, CapsoVision) 🔗
CapsoVision, Wellysis and Siemens cleared their AI as software separate from their hardware. CapsoVision's K254230 adds three AI reading tools to the CapsoCam Plus capsule endoscope software and "does not involve any changes to the hardware components cleared under K242643," although the regulation (21 CFR 876.1540) also allows hardware "to support interfacing with a capsule imaging system" [15]. In a multi-reader, multi-case study with no numeric margin, 15 gastroenterologists read 111 videos from 70 U.S. centers. With AI assistance, sensitivity rises from 71.0% to 92.3% and reading time falls from 45.7 to 34.4 minutes, while specificity falls from 56.2% to 26.4%.
Digestaid's Deep Capsule (K250655) already runs on other makers' capsules. A capsule maker can add AI through a software-only 510(k) tested on its own video archive, and an independent software company can sell across capsule brands, but both now have a 70-center, 15-reader study to match.
Tempus ECG-MR (K254297, Tempus AI) 🔗
FDA cleared Tempus ECG-MR (K254297) under 21 CFR 870.2380 (product code SIJ) [16] to flag signs of moderate or severe mitral regurgitation on a resting 12-lead ECG in patients 65 or older. Against criteria of 65% sensitivity and 65% specificity, Tempus reports 75% and 70% on 6,341 ECGs from four U.S. sites. The training set of 724,130 ECGs is large enough that some people would call the model a foundation model. Goals this modest pass because special control (b)(1)(iii) requires that they "be justified in the context of risks associated with follow-up testing," and the intended use limits the result to prompting "further referral or diagnostic follow up." The device "does not have a dedicated user interface (UI)," a boundary I discuss in my articles on the binary boundary [17] and command-line devices [18].
ECG-MR descends from the Viz HCM De Novo (DEN230003), and predicates in this 16-device family run in both directions between hardware and software. The CorVista System (K232686) is hardware with the software-only Viz De Novo as predicate, and Tempus ECG-PH (K253699) is software-only with a CorVista predicate. Regulation 870.2380 therefore gives hardware and software companies a platform for any single non-arrhythmia condition that an ECG can flag, provided the confirmatory test carries low risk.
S-Patch CardioAI (K254255, Wellysis) 🔗
Wellysis's S-Patch CardioAI (K254255) also returns results only to other software. Its single-lead arrhythmia analysis functions "are accessed exclusively through its Application Programming Interface (API) by third-party software systems." Wellysis prints no numeric goals and says only that "all pre-specified acceptance criteria" were met. On recordings from 496 adults at five sites, the lowest results are 90.2% positive predictivity for SVEB and 90.7% sensitivity for unreadable intervals, so Wellysis's goals cannot exceed those figures, and a company that predicates on this device has to set its own goals from those lows. The API boundary makes the device modular and lets one clearance serve many integrators, who can change their apps without changing the cleared device.
Aevice Wheeze Detection Module (K260140, Aevice Health) 🔗
If I wanted to add device support later, I would not bake specific devices into the indications. I would name the device type and give examples as a parenthetical, as Aevice Health did. Its Wheeze Detection Module (K260140) analyzes lung sound "recorded by FDA cleared compatible electronic stethoscope, such as AeviceMD," which names a device type and gives one example. The wording has limits. FDA's software change guidance lets a manufacturer document a compatibility change to file when performance specifications do not change [4], while its device change guidance says a new type of compatible device "will likely require submission of a new 510(k)" [19]. Tyto holds a PCCP for new stethoscope models (K252844), and Aevice has none.
The module flags suspected wheeze for healthcare professionals. If Aevice had claimed lay use, I am almost sure the test set would have grown considerably and human factors work would have been added, as in Tyto's eardrum De Novo (DEN250014). On 2,336 recordings from 131 patients and three stethoscopes, a fairly small study, sensitivity is 73.15% against a 70% criterion and specificity is 84.12% against 80%.
OtoCompanion (K261725, Ironsides Medical) 🔗
OtoCompanion reinforces the idea that a company can make a software medical device for hardware it does not own. Ironsides Medical's OtoCompanion (K261725) classifies otoscopic images as "Fluid Present" or "Dry" for patients aged 6 months to 21 years. The software "processes high-resolution otoscopic images captured by the Karl Storz IMAGE1 HD video endoscopy system," and Karl Storz cleared its IMAGE1 S camera for use "during general endoscopic and microscopic procedures" (K201135), a label that does not name the ear.
Ground truth comes from "direct surgical confirmation of middle ear fluid status during myringotomy." I think expert consensus would not have worked here, because experts are bad at finding fluid in the middle ear. The summary does not state the ground truth for training, and I found no ClinicalTrials.gov registration. In 181 ears from 93 children at six sites, sensitivity is 97.8% and specificity is 88.8%. A software company can therefore enter a market on a camera that another company has already cleared, although FDA's change guidance points to a new 510(k) for each new type of imaging device [19].
BoneXpert (K262390, Visiana) 🔗
BoneXpert (K262390) estimates Greulich-Pyle bone age from hand radiographs and returns an annotated DICOM image to PACS. In 1,285 images from five US sites, "BoneXpert demonstrated a lower RMSE than a single manual rater when compared against a three-rater reference" (0.55 versus 0.76 years). Bench studies tested robustness to image transformations and artifacts, repeatability and bone localization. FDA's generative AI discussion paper (p. 16) describes two comparators [20]. The first is "a panel of qualified clinicians whose consensus reflects the applicable standard of care," which is the higher bar because it reflects what a qualified expert panel agrees on. The second is "a median clinician in practice," which is the lower bar because it reflects what a typical clinician achieves. By analogy, BoneXpert's design uses both, with the three-rater consensus as the standard-of-care reference and the single rater as the median-clinician comparator. The predicate, EFAI Bonesuite (K234042), lists its primary output as a "JSON message with structured information on bone age estimation," and I discuss that boundary in my command-line device article [18]. A measurement product can therefore cite a predicate without a display.
HipStudio Analysis (K262442, Replasia) 🔗
Replasia's HipStudio Analysis (K262442) builds 3D hip models from CT, simulates hip motion and reports impingement points and shape parameters in a PDF. Its indications state that the software "is only operated by Replasia operators who have been specifically trained for this purpose." This is a good example of how to clear a software as a medical service, which combines staff and software. I would clear the software, specify the company's own staff as its users, and describe how clinicians use the outputs downstream, including the reasonably foreseeable clinical actions. Describing the whole service process is optional. HeartFlow FFRct (DEN130045) followed the same pattern with its own case analysts, and its special controls require testing by multiple operators who meet planned qualification criteria.
The indications copy the Zimmer Biomet predicate (K162559) almost word for word, including "skeletally mature individuals." Replasia inherited the phrase, and I like it because it does not lock the device into a fixed age bracket, although the labeling still has to define it. In my reading, the evidence is light because the claim is narrow. HipStudio reports established clinical parameters and claims no joint forces and no digital twin, so once segmentation is accurate the remaining computation is geometric and needs no outcome ground truth. A claim to predict joint forces would need heavy computational validation that is hard to build and adds little market value.
The summary also names the file transfer product LiquidFiles eight times and lists a service throughput time of "3 days." If it were my submission, I would describe file transfer generically, because a named vendor turns any vendor switch into a documented change assessment. I also see no need to disclose service turnaround time in a public summary, because FDA regulates the software and treats the service as relevant where it acts as a risk control.
Rapid Platform R6.7 (K261368, iSchemaView) 🔗
iSchemaView's Rapid Platform (K261368) hosts the company's imaging modules and "runs on a standard off-the-shelf computer or a virtual platform, such as VMware." R6.7 is the third platform-only clearance after K213165 (2022) and K233512 (2024). The structure keeps shared services and cybersecurity controls in the platform and performance testing in each module 510(k), which suits any company with several indications.
syngo.CT Brain Quantification (K260055, Siemens) 🔗
Siemens' K260055 reports intracranial hyperdensity volume and midline shift on adult non-contrast head CT, with Qure.ai qER-Quant (K211222) as predicate. I place quantification without detection or triage claims at the lowest-risk end of radiology AI, and Siemens cleared this module on standalone accuracy against neuroradiologist ground truth without a reader study. In my view, a quantification-only claim gives a company the lightest evidence package in radiology AI.
Discussion 🔗
The largest change in the month is continuous learning. VIRTUE QA shows that FDA will clear an automated per-machine retraining loop, provided every retrained model passes the premarket acceptance criteria before it goes live, and that moves part of the generalization burden into per-site commissioning and postmarket verification. New findings still require new 510(k)s, and narrow claims keep evidence light.
This review has limits. I worked from public summaries, clearance letters, regulations and guidance without FDA review memos or submission files, and I corrected Device Explorer metadata errors, such as the Tempus ECG-MR product code, against the FDA letters. The cohort ends at September 25, 2026, and derived numbers, including the reconstructed recurrence curves, are my calculations from published tables.
References 🔗
- 21 CFR 870.2210, Adjunctive predictive cardiovascular indicator. https://www.ecfr.gov/current/title-21/section-870.2210
- FDA. Clinical Decision Support Software: Guidance for Industry and Food and Drug Administration Staff. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/clinical-decision-support-software
- Innolitics. FDA Clinical Decision Support Software Guidance, 2026 revision. https://innolitics.com/articles/fda-guidance-clinical-decision-support-software-2026/
- FDA. Deciding When to Submit a 510(k) for a Software Change to an Existing Device (2017). https://www.fda.gov/media/99785/download
- FDA. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. https://www.fda.gov/media/166704/download
- Innolitics. Mobius3D case study. https://innolitics.com/portfolio/mobius/
- Innolitics. SimBioSys TumorSight Viz case study. https://innolitics.com/portfolio/emergency-fda-hold-ai-ml-samd/
- 21 CFR 864.3755. https://www.ecfr.gov/current/title-21/section-864.3755
- Innolitics. Review of K252366, a2z-Unified-Triage. https://innolitics.com/articles/K252366/
- 21 CFR 892.2080, Radiological computer aided triage and notification software. https://www.ecfr.gov/current/title-21/section-892.2080
- FDA. Product Classification database, product code QFM. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfPCD/classification.cfm?id=QFM
- FDA. Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations, draft guidance (January 2025). https://www.fda.gov/media/184856/download
- 21 CFR 864.3750. https://www.ecfr.gov/current/title-21/section-864.3750
- FDA. Artificial Intelligence-Enabled Medical Devices list (updated September 4, 2026). https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-enabled-medical-devices
- 21 CFR 876.1540. https://www.ecfr.gov/current/title-21/section-876.1540
- 21 CFR 870.2380. https://www.ecfr.gov/current/title-21/section-870.2380
- Innolitics. Everything Outside the Binary Is a Guess. https://innolitics.com/articles/everything-outside-the-binary-is-a-guess-stop-submitting-guesses/
- Innolitics. Command Line as a Medical Device. https://innolitics.com/articles/command-line-as-a-medical-device-clamd/
- FDA. Deciding When to Submit a 510(k) for a Change to an Existing Device (2017). https://www.fda.gov/media/99812/download
- FDA. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback (August 2026), p. 16. https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request. Innolitics review: https://innolitics.com/articles/fda-generative-ai-medical-devices-discussion-paper/





