FDA's Center for Devices and Radiological Health released a discussion paper on August 18 on regulating generative AI enabled medical devices, opening docket FDA-2026-N-7874 for public comment through October 19, 2026. The paper is the earliest stage of the agency's policymaking on the technology.

It sketches three concepts. The first is a two-axis risk assessment framework that sorts generative AI functions into tiers running from informational software at the low end to fully autonomous devices at the top, with review depth scaled to where a product lands.

The second borrows from medicine itself: premarket evaluation as a competency assessment modeled on how physicians are trained, pairing non-clinical benchmarking of the model with clinical confirmation that the device performs as intended. The third concept covers risk-proportionate postmarket monitoring, and the paper extends to foundation models and agentic AI systems.

Cybersecurity and device updates sit inside the postmarket monitoring discussion. That placement tells product security teams where to focus: how a deployed generative model gets monitored, patched, and changed is where security obligations will attach as the framework hardens.

Acting FDA Commissioner Kyle Diamantas said artificial intelligence is transforming medicine and that the United States 'must lead in shaping how this technology is developed and used safely and responsibly.' CDRH Director Michelle Tarver described the docket as 'a transparent process to inform the development of an approach that safeguards patients and consumers.'

Discussion papers carry no binding weight, but they set the vocabulary the eventual draft guidance will use, and the comment file is where manufacturers get to argue with the risk tiers before they calcify. Put a position on the record by October 19. Nothing in the paper suspends section 524B: a generative model inside a device is software, and the cybersecurity submission expectations follow it into the review queue.