Regulatory expectations for adaptive artificial intelligence in medical devices

Regulators in the US, EU, and UK are defining expectations for adaptive artificial intelligence in medical technologies, with emphasis on change control, post market surveillance, and cybersecurity. Companies are being pushed to design predictable update mechanisms and continuous monitoring around learning systems.

Regulatory authorities in the US, EU, and UK are converging on structured pathways for medical technologies that use adaptive artificial intelligence, aiming to keep innovation aligned with safety and performance obligations. Typical regulatory routes still follow established device classifications and conformity assessment mechanisms, but sponsors are expected to explain how learning systems behave over time, how model updates are controlled, and how clinical performance is assured as software evolves. This places particular emphasis on predictable change processes, documentation of training and validation data, and alignment between declared intended use and real world behavior.

Post market surveillance expectations are being expanded for products using adaptive artificial intelligence, reflecting regulators’ concern that real time learning and frequent updates can shift performance after initial approval. Manufacturers are expected to implement continuous monitoring frameworks, with clearly defined metrics for safety, effectiveness, and data quality, and to collect and analyze field performance data in a structured way. Feedback from users, incident reports, and real world evidence need to feed into a formal surveillance plan that can trigger corrective and preventive actions when performance drifts, and that supports regular reporting obligations to competent authorities.

Adaptive artificial intelligence and change control are increasingly organized under concepts such as predetermined change control plans, which define in advance what kinds of model or software changes are allowed without a new full regulatory submission. Required elements typically include clear change boundaries, predefined validation methods, and risk management approaches that address both functional and cybersecurity impacts of updates. Cybersecurity is treated as a core safety element, with expectations that manufacturers design secure architectures, maintain vulnerability management processes, and ensure that any remote or automated updates to artificial intelligence systems are authenticated, traceable, and resilient against malicious interference.

65

Impact Score

UK and EU Artificial Intelligence regulatory outlook for May 2026

The UK is moving ahead with targeted Artificial Intelligence measures in policing, online safety, cyber security and copyright policy, while the EU is refining how the EU Artificial Intelligence Act will apply in practice. Consultations, new offences and implementation deadlines are shaping the next phase of compliance on both sides.

Germany sets out national implementation of the Artificial Intelligence Act

Germany has published a draft law to implement the European Artificial Intelligence Act through new supervisory structures, clearer institutional responsibilities, and measures designed to support innovation. The proposal puts the Federal Network Agency at the center of enforcement while preserving sector-specific oversight in sensitive fields.

ECB warns banks about new Artificial Intelligence security risks

The European Central Bank has called major banks to an emergency meeting over cybersecurity risks tied to advanced Artificial Intelligence models. Regulators want banks to speed up security updates as newer tools make it easier to find and exploit vulnerabilities.

Anthropic keeps Mythos restricted after vulnerability findings

Anthropic says its cybersecurity model Mythos is powerful at uncovering software flaws but remains too risky for broad release. Early testing found large numbers of vulnerabilities across major software and open source projects, while fixes have lagged far behind discoveries.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.