๐Ÿ“… Book a 30-min Demo๐Ÿ“ž Call/text (571) 293-0242
Healthcare ยท AI Course ยท MED-7

When Your AI Becomes a Medical Device: FDA and SaMD

The regulatory boundary between clinical software and a regulated device โ€” the CDS exemption, SaMD classification, and what changes when a model updates.

Last updated:

The Short Answer

Whether clinical AI is a regulated medical device turns on the CDS exemption's four criteria, and generative systems complicate the analysis. With ibl.ai you own all the code and the data, so an internally developed tool stays under institutional control and its predetermined change management is yours to define rather than a vendor's.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing โ€” so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below โ€” every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

Whether your clinical AI is a regulated device determines an enormous amount of downstream obligation, and the analysis is genuinely difficult for generative systems. This course covers SaMD classification, the four criteria of the clinical decision support exemption, predetermined change control for updating models, and institutional exemptions for internally developed tools.

Who is this course for?

  • Regulatory affairs staff in health systems and digital health
  • Clinical informatics leaders building internal tools
  • Quality and compliance officers
  • Counsel supporting clinical technology

What do I need before starting?

  • Familiarity with clinical software development or deployment
  • Regulatory context helpful but not required

What will I be able to do afterwards?

  • Classify clinical software under the SaMD framework
  • Apply the four criteria of the clinical decision support exemption
  • Explain why generative AI complicates the exemption analysis
  • Design a predetermined change control plan for an updating model
  • Assess whether an institutional exemption applies

What does each module cover?

1

How is software classified as a medical device?

45 min

The SaMD framework and the risk categorization that follows classification.

Objectives

  • Apply the SaMD classification framework
  • Determine risk categorization
  • Understand the obligations each category carries

Topics

SaMD frameworkRisk categorizationObligation tiersInternational harmonization

Activity. Classify three clinical software examples under the SaMD framework.

2

What are the four criteria of the CDS exemption?

55 min

The exemption's criteria and how each must be satisfied.

Objectives

  • State the four criteria precisely
  • Apply each to a real system
  • Identify which criterion typically fails

Topics

Four criteriaCriterion applicationCommon failuresDocumentation

Activity. Apply all four criteria to a real clinical AI system and document the analysis.

3

Why does generative AI complicate the exemption?

50 min

The criterion requiring the clinician to independently review the basis, and why generation strains it.

Objectives

  • Explain the independent review criterion
  • Assess whether generative output satisfies it
  • Design toward satisfying the criterion

Topics

Independent review criterionBasis transparencyGenerative complicationsDesign implications

Activity. Assess whether a generative system satisfies the independent review criterion.

4

How do you handle a model that updates?

50 min

Predetermined change control plans for AI that changes after clearance.

Objectives

  • Design a predetermined change control plan
  • Specify the modifications it covers
  • Define what falls outside and requires new submission

Topics

Change control plansCovered modificationsOut-of-scope changesResubmission triggers

Activity. Draft a change control plan specifying covered and uncovered modifications.

5

What clinical evaluation is required?

45 min

Clinical evaluation and real-world performance monitoring obligations.

Objectives

  • Determine clinical evaluation requirements
  • Design real-world performance monitoring
  • Handle performance degradation

Topics

Clinical evaluationReal-world performanceMonitoring obligationsDegradation response

Activity. Design the clinical evaluation and monitoring plan for one system.

6

What if you are the manufacturer?

45 min

Quality system obligations when the institution develops the software itself.

Objectives

  • Identify manufacturer obligations
  • Assess quality system requirements
  • Estimate the compliance burden honestly

Topics

Manufacturer statusQuality systemDesign controlsBurden estimation

Activity. Assess your organization's readiness for manufacturer obligations.

7

Does an institutional exemption apply?

40 min

Internally developed tools used within the institution, and the limits of that position.

Objectives

  • Assess whether an institutional exemption applies
  • Identify the limits of the position
  • Document the determination

Topics

Institutional exemptionPosition limitsDistribution triggersDocumentation

Activity. Assess an internally developed tool for institutional exemption applicability.

8

Producing the classification analysis

50 min

The workshop module: a documented classification analysis for one AI feature.

Objectives

  • Produce a complete classification analysis
  • Document the reasoning defensibly
  • Identify the follow-on obligations

Topics

Classification analysisReasoning documentationFollow-on obligationsCounsel review

Activity. Complete the analysis and have counsel review it.

What is the capstone project?

Regulatory classification analysis for one AI feature

Produce a complete classification analysis: SaMD categorization, the four-criteria CDS exemption analysis, an assessment of whether generative output satisfies independent review, a change control plan if applicable, and an institutional exemption determination โ€” all reviewed by counsel.

Deliverable: A documented classification analysis with counsel review and identified follow-on obligations.

How are learners assessed?

  • All four exemption criteria addressed individually with documented reasoning
  • Change control plan must specify what falls outside its scope
  • Analysis reviewed by regulatory counsel

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for healthcare.

Where does the course material come from?

Every module is grounded in primary sources โ€” the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • This course frames regulatory analysis and does not provide regulatory advice. State that explicitly and require regulatory counsel review of any classification determination.
  • Module 3's independent review criterion is the crux for generative systems and the analysis is genuinely unsettled. Present the reasoning rather than a conclusion.
  • FDA guidance in this area evolves. Verify current guidance documents at each revision rather than citing a specific version.
  • Module 6 should be honest about the burden. Institutions that become manufacturers take on quality system obligations most are not resourced for.
  • Module 7's institutional exemption is frequently over-relied upon. Be clear about what triggers distribution and ends the position.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter โ€” you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM โ€” Claude, GPT, Llama, Gemini, Command โ€” and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped โ€” including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the When Your AI Becomes a Medical Device: FDA and SaMD course cover?

Whether your clinical AI is a regulated device determines an enormous amount of downstream obligation, and the analysis is genuinely difficult for generative systems. This course covers SaMD classification, the four criteria of the clinical decision support exemption, predetermined change control for updating models, and institutional exemptions for internally developed tools. It runs 5.5 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Regulatory classification analysis for one AI feature.

Who should take When Your AI Becomes a Medical Device: FDA and SaMD?

It is written for Regulatory affairs staff in health systems and digital health, Clinical informatics leaders building internal tools, Quality and compliance officers, Counsel supporting clinical technology. Prerequisites: Familiarity with clinical software development or deployment; Regulatory context helpful but not required.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere โ€” cloud, private VPC, on-premise, or fully air-gapped โ€” and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for healthcare teams that cannot send work to a public AI tool.

How do we get access to When Your AI Becomes a Medical Device: FDA and SaMD?

Request access and we will set it up for your cohort โ€” hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for healthcare cost on ibl.ai?

There is no per-seat pricing โ€” you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

Request access to When Your AI Becomes a Medical Device: FDA and SaMD

Tell us about your cohort and we will set it up โ€” hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.