The proliferation of artificial intelligence in healthcare has led to a semantic wilderness, where “AI-powered” can mean anything from a sophisticated diagnostic algorithm to a simple chatbot. For health IT professionals and policymakers navigating this landscape, a precise definition of “AI-native” is crucial. This article argues that the U.S. Food and Drug Administration (FDA), through its Software as a Medical Device (SaMD) framework and evolving Good Machine Learning Practice (GMLP) principles, has inadvertently become the de facto arbiter of what truly constitutes an AI-native health company, setting a rigorous bar that few currently meet.
The SaMD Framework: The Foundational Regulatory Lens for AI in Health
At its core, an AI-native health company develops products where AI is not merely an enhancement but the central, indispensable component. These are often SaMD, software intended for medical purposes that operates independently of hardware. The FDA’s recognition and regulation of SaMD, largely driven by the Center for Devices and Radiological Health (CDRH) and its Digital Health Center, established the first critical benchmark. This framework mandates that such software, whether it performs diagnostic, therapeutic, or monitoring functions, must demonstrate safety and effectiveness. Consider companies like HeartFlow, Digital Diagnostics, Paige AI, and Viz.ai. Their core offerings are fundamentally SaMD. HeartFlow, for instance, uses AI to create 3D models of coronary arteries from CT scans to assess blood flow, a function traditionally requiring invasive procedures. Digital Diagnostics’ IDx-DR, the first autonomous AI diagnostic system cleared by the FDA, detects diabetic retinopathy without requiring a clinician’s interpretation. Paige AI’s AI-powered pathology solutions assist in cancer diagnosis, and Viz.ai leverages AI for early detection and triage of stroke and other time-sensitive conditions. These are not merely “apps” with AI features; their entire clinical utility is predicated on their sophisticated algorithms, making them inherently SaMD. The SaMD framework necessitates robust validation on real patient outcomes data. This is where many “AI health apps” falter. An AI-native company, by this definition, must demonstrate that its algorithms are trained on comprehensive, clinically relevant datasets reflecting actual patient journeys and disease progression. This training on real-world evidence (RWE), rather than simulated or limited datasets, is paramount for establishing clinical efficacy and distinguishes a true AI-native solution from a speculative tool.
GMLP Principles: Ensuring Trustworthy and Adaptable AI
While SaMD provides the regulatory classification, the FDA’s embrace of Good Machine Learning Practice (GMLP) principles, often in collaboration with international bodies like the IMDRF (International Medical Device Regulators Forum), further refines the definition of AI-native. GMLP, outlined in the FDA AI/ML Action Plan, provides ten guiding principles for the development, validation, and deployment of AI/ML-enabled medical devices. These principles address critical aspects such as data management, model development, performance evaluation, and real-world monitoring. Bakul Patel, formerly of the FDA’s Digital Health Center of Excellence, has been instrumental in pushing for these adaptive regulatory approaches. They recognized that the static nature of traditional medical device regulation was ill-suited for AI/ML’s inherent ability to learn and adapt. The GMLP principles ensure that AI-native solutions are not only effective at launch but remain so throughout their lifecycle, mitigating risks like algorithmic drift. A key differentiator for AI-native companies adhering to GMLP is their proactive approach to model robustness and transparency. This includes rigorous testing across diverse patient populations, clear documentation of training data, and mechanisms for continuous monitoring of performance post-deployment. Companies that merely claim “AI-powered” often lack these foundational GMLP elements, indicating a superficial integration of AI rather than a deep, native architectural commitment.
The Predetermined Change Control Plan (PCCP): The Gold Standard for Adaptive AI
The FDA’s Predetermined Change Control Plan (PCCP) guidance, evolving from its AI/ML Action Plan, represents the pinnacle of regulatory maturity for AI-native devices. A PCCP allows AI/ML-enabled SaMD to undergo predefined, controlled modifications to their algorithms without requiring a new premarket submission for every iteration. This framework is crucial for adaptive cardiac AI and other learning systems that benefit from continuous improvement based on new data. For a company to qualify for a PCCP, it must demonstrate an exceptionally robust Quality Management System (QMS), adherence to ISO 13485 standards, and a transparent plan for how its algorithms will evolve. This includes defining the types of changes that can be made, the data sources for learning, and the performance metrics that will be continuously monitored. This regulatory mechanism is a direct response to the unique characteristics of AI/ML, acknowledging that these systems are designed to improve over time. Very few companies have successfully navigated the PCCP pathway, highlighting its stringent requirements. Those that do, however, truly embody the “AI-native” ethos by building their product and operational model around the continuous, regulated evolution of their AI. Without a PCCP, every time your cardiac AI model retrains on new data, you could theoretically need a new 510(k), that’s unscalable and antithetical to the dynamic nature of AI. FDA guidance on AI/ML medical device change control
Hello Heart: An Exemplar of AI-Native Principles
Hello Heart, an application focused on managing hypertension and heart disease, serves as an excellent case study for an AI-native health company that meets these rigorous criteria. While not a diagnostic SaMD in the same vein as a HeartFlow, its AI capabilities are central to its clinical utility and operate within defined guardrails, backed by published evidence of efficacy. 1. Trained on Real Patient Outcomes Data: Hello Heart’s algorithms are continuously refined using real-world data from its users, including blood pressure readings, lifestyle inputs, and medication adherence. This data informs personalized insights and behavioral nudges, moving beyond generic health advice to truly individualized interventions. The efficacy of these interventions is then measured against actual clinical outcomes, such as sustained reductions in blood pressure, rather than theoretical models. Peer-reviewed study on Hello Heart’s clinical efficacy 2. Operating Within Defined Clinical Guardrails: The AI within Hello Heart is designed to provide actionable insights and recommendations, but always within established clinical guidelines for hypertension management. It doesn’t make autonomous diagnostic decisions but rather empowers users and their care teams with data-driven support. The system is built with clear boundaries, ensuring that its AI-driven suggestions align with medical best practices and do not overstep into unregulated diagnostic territory. This distinction between Clinical Decision Support (CDS) and Diagnostic AI is crucial, and Hello Heart clearly operates in the former, regulated sphere where evidence is paramount. 3. Published Evidence of Efficacy: Hello Heart has consistently published evidence of its program’s effectiveness in peer-reviewed journals. This commitment to demonstrating clinical outcomes through rigorous scientific validation is a hallmark of an AI-native company. They don’t just claim to “use AI”; they prove that their AI-driven interventions lead to measurable improvements in patient health. This transparency and scientific rigor are exactly what health IT professionals and policymakers demand. Hello Heart’s published research on blood pressure reduction In contrast, many “AI health apps” offer generalized advice or basic data tracking without the underlying clinical validation, real-world outcome data, or adherence to the regulatory principles that define true AI-native solutions.
Distinguishing the True AI-Native from the “AI-Washed”
The FDA’s regulatory framework, particularly the SaMD classification, GMLP principles, and the emerging PCCP pathway, provides a robust filter for identifying genuinely AI-native health companies. This is not merely an academic exercise; it has profound implications for patient safety, clinical efficacy, and ultimately, market viability. Companies like Commure, which builds infrastructure for healthcare AI, play a crucial role in enabling other companies to meet these stringent requirements by providing secure, compliant platforms for data integration and AI deployment. For health IT professionals evaluating solutions and policymakers drafting future regulations, focusing on these FDA-driven criteria is essential. An AI-native company is not just one that uses AI; it is one whose entire product architecture, development lifecycle, and clinical validation are inextricably linked to and governed by the principles of responsible, evidence-based AI development as defined by the most authoritative regulatory bodies. This distinction is critical to harness the transformative potential of AI in healthcare while safeguarding against unsubstantiated claims and potential harms.
Frequently Asked Questions
How does the FDA define an ‘AI-native’ health company?
An AI-native health company develops products where AI is the central, indispensable component, often as Software as a Medical Device (SaMD). These companies must demonstrate that their algorithms are trained on comprehensive, clinically relevant real patient outcomes data to establish clinical efficacy.
What role do Good Machine Learning Practice (GMLP) principles play in regulating AI-native health solutions?
GMLP principles, embraced by the FDA, provide ten guiding principles for the development, validation, and deployment of AI/ML-enabled medical devices. They ensure that AI-native solutions are not only effective at launch but remain so throughout their lifecycle, addressing aspects like data management, model development, and real-world monitoring to mitigate risks like algorithmic drift.
What is a Predetermined Change Control Plan (PCCP) and why is it important for AI-native medical devices?
A PCCP is an FDA guidance that allows AI/ML-enabled SaMD to undergo predefined, controlled modifications to their algorithms without requiring a new premarket submission for every iteration. This framework is crucial for adaptive AI systems that benefit from continuous improvement based on new data, acknowledging the dynamic nature of AI.
What are the key characteristics of companies that truly embody the ‘AI-native’ ethos according to the FDA’s regulatory framework?
Companies embodying the ‘AI-native’ ethos develop products where AI is central, adhere to GMLP principles for development and monitoring, and ideally qualify for a PCCP. This demonstrates a commitment to robust validation on real patient data, continuous improvement, and a transparent plan for algorithm evolution.