Listen to this article · 9 min listen

Get your AI tool’s regulatory pathway wrong, and you can delay your market launch by years. What was a promising innovation becomes a regulatory nightmare. If you’re a digital health investor or a startup founder, you have to understand the line between regulated medical software and exempt clinical decision support (CDS), it’s not just a compliance checkbox, it’s what determines your time to market and your company’s valuation. This is a technical breakdown of the FDA’s line in the sand, showing how generative AI models can land on either side of it depending on their intended use and how transparent they are to the clinician using them.

The Four-Factor Test for Exempt Clinical Decision Support

The FDA’s whole game with software, especially under Section 3060 of the 21st Century Cures Act, comes down to one question: is the software trying to diagnose, treat, mitigate, or prevent a disease on its own, or is it just giving information to a healthcare professional (HCP) who makes the final call? The FDA January 2026 CDS Software Final Guidance gives us a four-factor test to see if a piece of software can be exempt from active regulation as a medical device. For any AI company in health, this test is everything. Here are the four factors:

  1. The software is not intended to acquire, process, or analyze a medical image, a signal from an in vitro diagnostic device, or a pattern or signal from a signal acquisition system. This one rule knocks a huge number of AI tools out of the running for CDS exemption right away. Think about an AI that reads an ECG to spot arrhythmias or scans an MRI for tumors, those don’t qualify. The output from these systems is a direct interpretation of raw medical data, which puts them squarely in the regulated SaMD (Software as a Medical Device) category. No way around it.
  2. The software is intended for the purpose of displaying, analyzing, or printing medical information about a patient or other medical information. This part is all about the kind of information the software touches. It means the software should be working with data that’s already established, like a patient’s chart, lab results, or published clinical guidelines, instead of creating new diagnostic data from scratch.
  3. The software is intended for the purpose of supporting or providing recommendations to a healthcare professional who can independently review the basis for the recommendation and does not rely primarily on the recommendation to make a clinical diagnosis or treatment decision. This is the big one, especially for generative AI. The key phrases are “independent review” and “does not rely primarily.” If a gen AI spits out a treatment plan, the doctor has to be able to see why, what data and logic it used. If the AI is a black box and the doctor is just supposed to click ‘accept’, the software starts looking a lot like a regulated device. The Coalition for Health AI (CHAI) is big on transparency and explainability for safe AI, which fits perfectly with what the FDA requires here.
  4. The software is not intended to create a record of a patient’s medical information, nor to modify patient medical information in an electronic health record. This factor separates tools that help a doctor think from tools that directly manage the patient’s record. If your software writes directly to an EHR or changes information in it, it’s probably not going to get the CDS exemption.

So, a generative AI that offers guidance on drug interactions could be exempt, but only if it shows the clinician the relevant pharmacological data and lets them make the final call on the prescription. But if that same AI started automatically changing medication dosages in the EHR based on its own analysis, without a clear way for a human to review and stop it, it would almost certainly be considered a regulated medical device.

Generative AI and the Transparency Imperative

That third factor about independent review is where generative AI really gets tricky. Unlike old-school, rule-based CDS, these new models can be “black boxes,” making it hard to see how they got from A to B. For a generative AI to stay in the exempt CDS lane, its output has to let the HCP:

  • Understand the source data: The AI needs to be upfront about what patient data, guidelines, or papers it used to come up with its suggestion.
  • Evaluate the reasoning: It doesn’t have to show every single neural network firing, but it must give a clear summary of its logic or the evidence it’s basing its recommendation on.
  • Override or ignore the recommendation: The whole point is to assist the HCP, not to replace their clinical judgment. The ‘off’ switch has to be obvious.

When a generative AI chatbot gives bad advice about drug interactions, which has been documented in news reports on AI health misinformation, it points to a problem with the model’s design or a failure to communicate its limits to the user. If that chatbot was built as a regulated medical device, those failures would set off post-market surveillance and get the FDA involved. If it was sold as exempt CDS, the manufacturer has to prove that the doctor could have spotted and fixed the bad advice on their own. That’s a huge difference when you’re assessing risk.

Recent FDA Actions and the Regulatory Field

The FDA is paying more and more attention to unregulated tools making diagnostic claims. We haven’t seen a ton of action against generative AI specifically, but the agency has always been tough on software that claims to diagnose without going through the proper clearance process. The FDA’s recent actions against unregulated diagnostic tools show they are serious about patient safety, no matter what technology is under the hood. The 21st Century Cures Act was passed to speed up innovation while keeping patients safe. Section 3060, in particular, was written to create exemptions for software that just provides information, lowering the regulatory bar for low-risk tools. But the explosion of AI, and generative AI most of all, keeps pushing on those definitions. The FDA is talking with groups like the Coalition for Health AI, which shows they’re trying to keep their rules up to date with the tech. The line between a “clinical decision support” tool and a “diagnostic AI” is everything. If your AI’s output says “probable HFpEF, recommend referral,” you might be CDS. If it says “HFpEF confirmed,” you’re a regulated device. The words you choose have massive regulatory weight and determine whether you need to file for a 510(k) or De Novo classification.

Strategic Implications for Investors and Founders

For investors in digital health, a company’s regulatory strategy has to be solid. It’s a dealbreaker. Startups need to show they know where their product fits. It’s not enough to have a great idea. Key questions to ask:

  • Product Design for Exemption: Is the interface and output of the generative AI built from the ground up to make independent review by an HCP easy? This could mean showing confidence scores, citing sources, or being very clear about what the AI can’t do.
  • Transparency in Training Data: Being open about your training data isn’t a strict requirement for CDS exemption, but it makes your case much stronger. It helps you argue that a doctor can “independently review the basis” for a recommendation, which is vital if the model has biases from its training data. How else can a clinician account for that?
  • Clear Intended Use Statements: How you word your “intended use” statement can single-handedly decide your regulatory classification. Getting this wrong can cause huge delays or force you down the much more expensive regulated path.
  • Early Engagement with Regulatory Counsel: Don’t wait. Talking to regulatory consultants early can help you spot problems and build your product the right way for the pathway you’re targeting.

Making sure a company has a believable regulatory plan that matches its product isn’t about box-checking. It’s about taking risk off the table and getting to market faster. The difference between an exempt CDS and a regulated SaMD is a matter of years in development, running clinical trials, and raising a mountain of cash for a 510(k) or De Novo submission. This whole analysis comes from the FDA’s own documents, mainly the 21st Century Cures Act and the FDA Guidance on Clinical Decision Support Software (specifically the January 2026 Final Guidance). You need to know these documents cold to work in AI for healthcare.

Frequently Asked Questions

What is the primary factor determining if an AI tool for healthcare is regulated by the FDA?

The primary factor is whether the software is intended to diagnose, treat, mitigate, or prevent disease, versus merely providing information to a healthcare professional (HCP) who then makes an independent clinical judgment. Misclassifying this can significantly delay market launch and impact valuation.

How does the FDA’s four-factor test apply to generative AI in healthcare?

The third factor, concerning independent review and reliance by the HCP, is particularly critical for generative AI. For exemption, the generative AI’s outputs must allow the HCP to understand the source data, evaluate the reasoning, and override or ignore the recommendation, ensuring transparency and not replacing clinical judgment.

What types of AI functions are immediately excluded from the CDS exemption?

AI functions that acquire, process, or analyze medical images, signals from in vitro diagnostic devices, or patterns from signal acquisition systems are immediately excluded. For example, AI that analyzes ECGs or MRIs for diagnosis would fall under regulated Software as a Medical Device (SaMD).

What role does transparency play in generative AI qualifying for CDS exemption?

Transparency is imperative for generative AI to qualify as exempt CDS, especially regarding the ‘independent review’ factor. The AI must present its outputs in a way that enables the HCP to understand the source data, evaluate its reasoning, and retain the ability to override or ignore the recommendation.