Skip to main content
v2026.11,858 entries · CC-BY 4.0

Direct comparison

Foundation Models vs FDA's SaMD Framework

FDA admits its device rules weren't built for foundation models. See how the CDS carve-out and PCCP pathway compare to what's still missing for LLMs.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · free to try

Ask about Foundation Models vs FDA's SaMD Framework

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do CDS Software Carve-Out (§520(o)(1)(E)), Predetermined Change Control Plan (§515C), General-Purpose Foundation Models compare side by side?

The table below compares CDS Software Carve-Out (§520(o)(1)(E)), Predetermined Change Control Plan (§515C), General-Purpose Foundation Models across 5 procurement-relevant dimensions, from what it is through structural parallel in nikolai’s n1 track.

Side-by-side comparison

DimensionCDS Software Carve-Out (§520(o)(1)(E))Predetermined Change Control Plan (§515C)General-Purpose Foundation Models
What it isA statutory carve-out: software that displays/analyzes/prints medical information and lets a clinician "independently review the basis" for a recommendation is not a "device" at all.A premarket mechanism: sponsor pre-specifies future modifications (e.g. retraining on new data) and how they’ll be validated, so in-plan updates skip a new submission.No dedicated FDA pathway. FDA’s own site says it will "explore methods to identify and tag" devices built on foundation models -- a method for tagging them on a list, not a review pathway for them.
Governing textFD&C Act §520(o)(1)(E) (21 U.S.C. §360j(o)(1)(E)); FDA Clinical Decision Support Software guidance, final, January 2026.FD&C Act §515C (21 U.S.C. §360e-4), added by FDORA (2022); guidance docket FDA-2022-D-2628, first issued Dec. 4, 2024, reissued final Aug. 18, 2025.FDA’s "Artificial Intelligence-Enabled Medical Devices" webpage -- an operational commitment to explore tagging methods, not a guidance document or statute.
What kind of model it assumesA narrow tool producing a specific, traceable recommendation from legible inputs a clinician can independently check.A model that adapts along one pre-specified, pre-validated axis the sponsor locked in before authorization.A general-purpose model whose behavior, fine-tuning, and downstream uses can shift in ways no pre-2024-style change-control plan anticipated.
Does CASRAI’s guide to it mention LLMs/foundation models?No. The SaMD guide covering this ground (WP 14899, ~47,500 characters) has zero mentions of "large language model," "foundation model," "generative AI," "LLM," or "GPT."Indirectly. The FDA AI Guidance guide (WP 2602) has one FAQ paragraph: FDA’s frameworks are "written broadly enough to cover AI and machine learning generally" but neither guidance "names generative AI or large language models as a distinct regulatory category."N/A -- this is the gap the two guides above don’t cover, because FDA hasn’t yet published the framework they’d cover it with.
Structural parallel in NIKOLAI’s N1 trackAssumes a single, fixed deployment surface -- one device function, cleared for one intended use.Assumes a fixed coverage scope threshold -- a pre-specified if-then test for what counts as an in-plan change.Breaks both assumptions: no single deployment surface, no single coverage-scope test currently determines when FDA’s device rules apply.

Common questions

Common questions about CDS Software Carve-Out (§520(o)(1)(E)) vs Predetermined Change Control Plan (§515C) vs General-Purpose Foundation Models

Does FDA have a specific regulatory pathway for foundation models or LLMs in medical devices?

+

Not yet, as a dedicated category. FDA’s "Artificial Intelligence-Enabled Medical Devices" page states the agency "will explore methods to identify and tag medical devices that incorporate foundation models… from large language models (LLMs) to multimodal architectures" -- language describing a future tagging method on FDA’s device list, not an existing review pathway. Devices using foundation-model components are currently evaluated under FDA’s general AI/ML device framework, the same one built for narrow, single-task models.

What is the CDS software carve-out, and does it cover generative AI?

+

FD&C Act §520(o)(1)(E) (21 U.S.C. §360j(o)(1)(E)) excludes certain clinical decision support software from the legal definition of a "device," provided a health care professional can "independently review the basis" for its recommendations rather than relying on them primarily. FDA’s Clinical Decision Support Software guidance (final, January 2026) interprets that carve-out, and CASRAI’s own SaMD guide covering this ground contains zero mentions of "large language model," "foundation model," "generative AI," "LLM," or "GPT" -- the carve-out was not drafted with those systems in mind, and the "independently reviewable basis" test is a harder fit for a model whose basis spans a training corpus rather than a fixed input set.

Can a Predetermined Change Control Plan (PCCP) cover a foundation model that gets updated or fine-tuned?

+

PCCPs are built for a sponsor to pre-specify one or more defined future modifications -- for example, retraining a locked classifier on a new dataset -- and the exact methodology for validating each one, under FD&C Act §515C and guidance docket FDA-2022-D-2628 (issued Dec. 4, 2024, reissued final Aug. 18, 2025). That structure presumes the sponsor can name the coming change in advance. A general-purpose foundation model’s downstream fine-tuning, prompting surface, or emergent behavior after a base-model update is a much harder fit for a plan that has to be pre-specified at authorization time.

Is this the same as vetting an AI vendor for healthcare procurement?

+

No. CASRAI’s Assessing Third-Party AI Vendor Risk guide is a generic enterprise AI-procurement checklist -- checked line-for-line, it contains zero mentions of "hospital," "healthcare," "patient," "FDA," "SaMD," "medical device," or "EHR." This page is about whether a foundation model embedded in a clinical product has a defined FDA review pathway at all; vendor risk assessment is a separate, later question that applies once a product exists.

What does NIKOLAI have to do with FDA’s foundation-model gap?

+

CASRAI’s own NIKOLAI project -- an independent, unendorsed reference dictionary of frontier-AI-safety elements, not a standard FDA has adopted -- defines "Deployment Surface" and "Coverage Scope Threshold" in its N1 track as the general problem of pinning down where a model is made available and what if-then test decides whether a rule applies to it. Neither element’s crosswalk table currently carries an FDA row, and this page does not claim one exists. But FDA’s CDS and PCCP mechanisms both assume a fixed deployment surface and a fixed coverage-scope test, and a general-purpose foundation model breaks both assumptions the same way NIKOLAI’s N1 track exists to name in the abstract -- a structural echo, not a claim that FDA uses NIKOLAI’s terms.

Why does this matter for research administration?

+

A tech-transfer office trying to license an NIH- or NSF-funded foundation-model-based diagnostic algorithm to an industry partner needs to know, before executing that license, which FDA pathway (if any) the resulting product would need to clear — and this page's finding that FDA's own AI-enabled-device page admits it lacks a method to even tag foundation-model-based devices is directly relevant deal information. Separately, a clinical-research office or IRB reviewing a protocol that uses a foundation model for a diagnostic or triage function needs to know whether the CDS software carve-out's "independently reviewable basis" test can plausibly be satisfied by a general-purpose model.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →