Direct comparison
Foundation Models vs FDA's SaMD Framework
FDA admits its device rules weren't built for foundation models. See how the CDS carve-out and PCCP pathway compare to what's still missing for LLMs.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about Foundation Models vs FDA's SaMD Framework
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do CDS Software Carve-Out (§520(o)(1)(E)), Predetermined Change Control Plan (§515C), General-Purpose Foundation Models compare side by side?
The table below compares CDS Software Carve-Out (§520(o)(1)(E)), Predetermined Change Control Plan (§515C), General-Purpose Foundation Models across 5 procurement-relevant dimensions, from what it is through structural parallel in nikolai’s n1 track.
Side-by-side comparison
| Dimension | CDS Software Carve-Out (§520(o)(1)(E)) | Predetermined Change Control Plan (§515C) | General-Purpose Foundation Models |
|---|---|---|---|
| What it is | A statutory carve-out: software that displays/analyzes/prints medical information and lets a clinician "independently review the basis" for a recommendation is not a "device" at all. | A premarket mechanism: sponsor pre-specifies future modifications (e.g. retraining on new data) and how they’ll be validated, so in-plan updates skip a new submission. | No dedicated FDA pathway. FDA’s own site says it will "explore methods to identify and tag" devices built on foundation models -- a method for tagging them on a list, not a review pathway for them. |
| Governing text | FD&C Act §520(o)(1)(E) (21 U.S.C. §360j(o)(1)(E)); FDA Clinical Decision Support Software guidance, final, January 2026. | FD&C Act §515C (21 U.S.C. §360e-4), added by FDORA (2022); guidance docket FDA-2022-D-2628, first issued Dec. 4, 2024, reissued final Aug. 18, 2025. | FDA’s "Artificial Intelligence-Enabled Medical Devices" webpage -- an operational commitment to explore tagging methods, not a guidance document or statute. |
| What kind of model it assumes | A narrow tool producing a specific, traceable recommendation from legible inputs a clinician can independently check. | A model that adapts along one pre-specified, pre-validated axis the sponsor locked in before authorization. | A general-purpose model whose behavior, fine-tuning, and downstream uses can shift in ways no pre-2024-style change-control plan anticipated. |
| Does CASRAI’s guide to it mention LLMs/foundation models? | No. The SaMD guide covering this ground (WP 14899, ~47,500 characters) has zero mentions of "large language model," "foundation model," "generative AI," "LLM," or "GPT." | Indirectly. The FDA AI Guidance guide (WP 2602) has one FAQ paragraph: FDA’s frameworks are "written broadly enough to cover AI and machine learning generally" but neither guidance "names generative AI or large language models as a distinct regulatory category." | N/A -- this is the gap the two guides above don’t cover, because FDA hasn’t yet published the framework they’d cover it with. |
| Structural parallel in NIKOLAI’s N1 track | Assumes a single, fixed deployment surface -- one device function, cleared for one intended use. | Assumes a fixed coverage scope threshold -- a pre-specified if-then test for what counts as an in-plan change. | Breaks both assumptions: no single deployment surface, no single coverage-scope test currently determines when FDA’s device rules apply. |
Common questions
Common questions about CDS Software Carve-Out (§520(o)(1)(E)) vs Predetermined Change Control Plan (§515C) vs General-Purpose Foundation Models
Does FDA have a specific regulatory pathway for foundation models or LLMs in medical devices?
+
Not yet, as a dedicated category. FDA’s "Artificial Intelligence-Enabled Medical Devices" page states the agency "will explore methods to identify and tag medical devices that incorporate foundation models… from large language models (LLMs) to multimodal architectures" -- language describing a future tagging method on FDA’s device list, not an existing review pathway. Devices using foundation-model components are currently evaluated under FDA’s general AI/ML device framework, the same one built for narrow, single-task models.
What is the CDS software carve-out, and does it cover generative AI?
+
FD&C Act §520(o)(1)(E) (21 U.S.C. §360j(o)(1)(E)) excludes certain clinical decision support software from the legal definition of a "device," provided a health care professional can "independently review the basis" for its recommendations rather than relying on them primarily. FDA’s Clinical Decision Support Software guidance (final, January 2026) interprets that carve-out, and CASRAI’s own SaMD guide covering this ground contains zero mentions of "large language model," "foundation model," "generative AI," "LLM," or "GPT" -- the carve-out was not drafted with those systems in mind, and the "independently reviewable basis" test is a harder fit for a model whose basis spans a training corpus rather than a fixed input set.
Can a Predetermined Change Control Plan (PCCP) cover a foundation model that gets updated or fine-tuned?
+
PCCPs are built for a sponsor to pre-specify one or more defined future modifications -- for example, retraining a locked classifier on a new dataset -- and the exact methodology for validating each one, under FD&C Act §515C and guidance docket FDA-2022-D-2628 (issued Dec. 4, 2024, reissued final Aug. 18, 2025). That structure presumes the sponsor can name the coming change in advance. A general-purpose foundation model’s downstream fine-tuning, prompting surface, or emergent behavior after a base-model update is a much harder fit for a plan that has to be pre-specified at authorization time.
Is this the same as vetting an AI vendor for healthcare procurement?
+
No. CASRAI’s Assessing Third-Party AI Vendor Risk guide is a generic enterprise AI-procurement checklist -- checked line-for-line, it contains zero mentions of "hospital," "healthcare," "patient," "FDA," "SaMD," "medical device," or "EHR." This page is about whether a foundation model embedded in a clinical product has a defined FDA review pathway at all; vendor risk assessment is a separate, later question that applies once a product exists.
What does NIKOLAI have to do with FDA’s foundation-model gap?
+
CASRAI’s own NIKOLAI project -- an independent, unendorsed reference dictionary of frontier-AI-safety elements, not a standard FDA has adopted -- defines "Deployment Surface" and "Coverage Scope Threshold" in its N1 track as the general problem of pinning down where a model is made available and what if-then test decides whether a rule applies to it. Neither element’s crosswalk table currently carries an FDA row, and this page does not claim one exists. But FDA’s CDS and PCCP mechanisms both assume a fixed deployment surface and a fixed coverage-scope test, and a general-purpose foundation model breaks both assumptions the same way NIKOLAI’s N1 track exists to name in the abstract -- a structural echo, not a claim that FDA uses NIKOLAI’s terms.
Why does this matter for research administration?
+
A tech-transfer office trying to license an NIH- or NSF-funded foundation-model-based diagnostic algorithm to an industry partner needs to know, before executing that license, which FDA pathway (if any) the resulting product would need to clear — and this page's finding that FDA's own AI-enabled-device page admits it lacks a method to even tag foundation-model-based devices is directly relevant deal information. Separately, a clinical-research office or IRB reviewing a protocol that uses a foundation model for a diagnostic or triage function needs to know whether the CDS software carve-out's "independently reviewable basis" test can plausibly be satisfied by a general-purpose model.
Going deeper







