Listen to this article · 8 min listen

The specter of Theranos looms large over the burgeoning field of AI in healthcare, a stark reminder of the catastrophic consequences when innovation outpaces responsible oversight. The FDA’s warning letter to Theranos in 2015, arriving a staggering 12 years after the company began operating its blood-testing services, serves as a chilling case study: reactive regulation, however well-intentioned, fails patients and undermines trust. This historical parallel demands a proactive, robust regulatory framework for AI-powered health tools, lest we repeat the same costly mistakes.

The Theranos Precedent: A Regulatory Blind Spot That Endured for Years

Theranos, founded in 2003, promised a revolution in blood testing, claiming to perform a multitude of tests from a single drop of blood. For over a decade, until 2015, the company operated largely outside direct FDA oversight by exploiting a significant regulatory loophole: the classification of its tests as Lab-Developed Tests (LDTs). LDTs, historically developed and used within a single laboratory, were traditionally subject to less rigorous FDA scrutiny than commercial diagnostic kits. Theranos leveraged this distinction, deploying its proprietary Edison device and its associated assays without the premarket review and validation typically required for medical devices. The consequences were devastating. Years of inaccurate results endangered countless patients, potentially leading to misdiagnoses, delayed treatments, and unnecessary medical interventions. Elizabeth Holmes, the company’s founder, was ultimately convicted in 2022 for defrauding investors and patients, but the damage to public trust and individual health was already done. The Theranos saga unequivocally demonstrated that when novel health technologies operate in a regulatory gray area, the default outcome is not innovation, but peril. The FDA’s intervention, when it finally came, was a classic example of closing the barn door after the horses had bolted.

The AI Parallel: Navigating New Loopholes and Uncharted Territory

Today, we face a similar, perhaps even more complex, challenge with the rapid proliferation of artificial intelligence in healthcare. AI-powered tools, from diagnostic aids to drug interaction guidance systems, are being developed and deployed at an unprecedented pace. While many promise transformative benefits, the potential for “AI health misinformation” and “AI chatbot” failures is significant, echoing the inaccuracies that plagued Theranos. The core issue lies in the potential for AI health tools to exploit regulatory gaps analogous to the LDT loophole. Many AI applications may initially be categorized as Clinical Decision Support (CDS) tools, which, depending on their functionality and intended use, might not require the same level of stringent FDA oversight as a full-fledged Software as a Medical Device (SaMD). However, the line between a CDS tool offering recommendations and a diagnostic AI making independent determinations can be perilously thin and easily blurred. If an AI system, even if initially framed as CDS, directly influences patient management or diagnosis based on its output, its impact on patient safety warrants rigorous scrutiny. The inherent characteristics of AI also introduce novel regulatory challenges. Unlike static medical devices, many AI models are designed to be adaptive, continuously learning and evolving as they process new data. This “algorithmic drift”, the degradation of model performance over time as real-world data distributions shift away from training data, necessitates continuous monitoring and re-validation, a process for which traditional regulatory pathways were not designed. Furthermore, the opacity of some AI models, often referred to as “black boxes,” can make it difficult to ascertain the basis for their recommendations or diagnoses, complicating post-market surveillance and incident investigation.

Proactive Regulation: Bakul Patel’s Framework and Scott Gottlieb’s Vision

Recognizing these emerging challenges, forward-thinking regulatory leaders have advocated for a proactive approach to AI safety oversight. Bakul Patel, formerly of the FDA’s Center for Devices and Radiological Health (CDRH), has been a leading voice in shaping the FDA’s strategy for digital health. His framework emphasizes the importance of classifying AI-driven software as SaMD when appropriate, ensuring it undergoes the necessary premarket review. Crucially, Patel’s work has championed the concept of Predetermined Change Control Plans (PCCPs) FDA guidance on AI/ML medical device change control. A PCCP is a regulatory mechanism designed to allow adaptive AI/ML devices to make pre-specified modifications to their algorithms or datasets without requiring a new 510(k) submission for every iteration. This approach acknowledges the dynamic nature of AI while ensuring that changes remain within a validated and controlled framework, mitigating the risks of algorithmic drift and maintaining safety and effectiveness. Without a PCCP, every time an AI model retrains on new data, a new 510(k) could theoretically be required, an unscalable proposition that would stifle innovation. Similarly, Scott Gottlieb, during his tenure as FDA Commissioner, consistently pushed for a modernization agenda aimed at closing LDT-like loopholes for emerging technologies, including AI. His vision underscored the need for regulatory pathways that are agile enough to accommodate technological advancements while robust enough to protect public health. This involves not only clear classification guidelines but also fostering a culture of “Good Machine Learning Practice” (GMLP), a set of 10 guiding principles developed by regulatory bodies for the safe and effective development, deployment, and monitoring of AI/ML medical devices. Investors should scrutinize GMLP compliance during due diligence, as companies failing to build to these principles accumulate significant regulatory debt.

The Path Forward: Learning from Responsible Innovators

While the Theranos narrative highlights the dangers of unchecked innovation, the landscape also features companies that are actively pursuing proactive FDA engagement, setting a benchmark for responsible AI development in healthcare. These “safety-first” companies understand that rigorous clinical validation and transparent regulatory pathways are not obstacles, but rather accelerators for market adoption and long-term success. Consider HeartFlow, a company that developed an AI-powered, non-invasive technology to create a 3D model of coronary arteries and assess blood flow. HeartFlow pursued and received FDA clearance through the De Novo classification pathway for novel, low-to-moderate-risk devices with no predicate. This rigorous process, including extensive clinical trials and data submission, demonstrated the safety and efficacy of their AI, paving the way for broad clinical adoption and reimbursement. Their approach illustrates a commitment to proving clinical utility and safety through established regulatory channels, rather than attempting to circumvent them. Another example is AliveCor, known for its personal ECG devices. AliveCor has consistently engaged with the FDA, securing multiple 510(k) clearances for its AI-driven algorithms that detect atrial fibrillation and other cardiac arrhythmias. Their strategic regulatory engagement has allowed them to build a strong “data moat”, proprietary datasets of millions of labeled ECG recordings, which enhances their AI model performance and is difficult for competitors to replicate. This proactive stance, coupled with a focus on real-world evidence (RWE) to supplement pivotal trials, strengthens both their FDA submissions and their payer story, offering a clear “reimbursement pathway clarity” for investors. AliveCor regulatory clearances These companies illustrate that robust regulatory engagement, including the pursuit of 510(k) clearances, De Novo classifications, and even Breakthrough Device Designation where applicable, builds trust with both regulators and clinicians. This trust is invaluable for achieving market penetration and securing favorable reimbursement, ultimately de-risking the investment. Investors should view a clear “reimbursement pathway clarity” and strong clinical evidence as commercial predictors, not merely regulatory hurdles.

Conclusion

The FDA’s delayed intervention in the Theranos debacle serves as a powerful cautionary tale. The reactive approach, born from regulatory loopholes and a lack of foresight, cost patients dearly. As AI continues its inexorable march into healthcare, we must apply these lessons rigorously. Proactive regulatory frameworks, guided by principles like Bakul Patel’s SaMD classification and PCCPs, and championed by leaders like Scott Gottlieb, are essential. The industry must embrace a culture of transparency and rigorous validation, mirroring the commitment shown by companies like HeartFlow and AliveCor. Failure to do so risks not only a repeat of Theranos-level “documented AI health failures” but also a profound erosion of public trust in the transformative potential of AI in medicine. The time for proactive, rather than reactive, AI safety oversight is now. Eric Topol on AI in healthcare regulation

Frequently Asked Questions

How did Theranos operate for so long without direct FDA oversight?

Theranos exploited a regulatory loophole by classifying its tests as Lab-Developed Tests (LDTs). LDTs were historically subject to less rigorous FDA scrutiny than commercial diagnostic kits, allowing Theranos to deploy its devices and assays without typical premarket review.

What are the primary regulatory challenges presented by AI in healthcare that are analogous to the Theranos situation?

AI health tools may exploit regulatory gaps similar to the LDT loophole, particularly if categorized as Clinical Decision Support (CDS) tools which might not require stringent FDA oversight. The line between CDS and diagnostic AI can be perilously thin, impacting patient safety.

What is ‘algorithmic drift’ and how does it complicate AI regulation?

Algorithmic drift refers to the degradation of an AI model’s performance over time as real-world data shifts from its training data. This necessitates continuous monitoring and re-validation, a process for which traditional regulatory pathways were not designed.

What is a Predetermined Change Control Plan (PCCP) and why is it important for AI regulation?

A PCCP is a regulatory mechanism allowing adaptive AI/ML devices to make pre-specified modifications to their algorithms or datasets without requiring a new 510(k) submission for every iteration. This acknowledges AI’s dynamic nature while ensuring changes remain within a validated framework, mitigating algorithmic drift risks.