The most expensive mistake in European digital health often happens before the first patient enters a study.
A clinical AI company validates its product for one market, wins clearance, and only then asks whether the same evidence will travel across the Atlantic. It discovers that the comparator is wrong, the patient mix is too narrow, the quality system was built for a different audit, or the software logs cannot reconstruct how a model changed. What looked like a sensible sequence becomes a second study, a delayed launch and a financing problem.
Ahead of Web Summit Lisbon 2026, the sharper strategy is dual-track regulatory architecture: one product definition, one quality backbone and one evidence programme designed from the outset to support both US and European submissions. The goal is not to pretend the regimes are identical. It is to stop paying twice for the parts they share.
In this briefing
- The classification collision between FDA pathways and EU-MDR Rule 11
- What transatlantic medical AI companies reveal about dossier design
- How FDA change plans and European lifecycle governance can share one ModelOps layer
- The four pillars of a unified clinical evidence envelope
- Why clearance and reimbursement remain separate workstreams
- The milestones investors and healthcare leaders should watch
1. The classification collision: FDA 510(k) versus EU-MDR Rule 11
A dual-track strategy starts by mapping the same intended use across two regulatory taxonomies.
In the United States, many diagnostic or assistive software functions are Class II devices that reach market through a 510(k) Premarket Notification by demonstrating substantial equivalence to a predicate. Where no suitable predicate exists, the De Novo pathway can create a new Class I or Class II device type. Some clinical decision support functions fall outside the device definition under Section 520(o) of the Federal Food, Drug, and Cosmetic Act, but only when all statutory criteria are met, including the clinician's ability to independently review the basis for a recommendation. The FDA's current clinical decision support guidance makes clear that this is a defined boundary, not a blanket exemption.
In Europe, Annex VIII, Rule 11 of the Medical Device Regulation classifies software used to inform diagnostic or therapeutic decisions according to the possible consequence of a wrong decision.
| Clinical consequence of the software-informed decision | Typical MDR class under Rule 11 |
|---|---|
| Death or irreversible deterioration of health | Class III |
| Serious deterioration of health or surgical intervention | Class IIb |
| Other diagnostic or therapeutic decisions | Class IIa |
| Other software, including software outside the decision and vital-monitoring rules | Class I |
Software that monitors physiological processes is generally Class IIa, rising to Class IIb when it monitors vital parameters whose variation could create immediate danger. The European Commission's MDCG 2019-11 Rev.1 guidance is the practical reference.
The collision is straightforward. A product team may conclude that a narrowly framed US function is non-device CDS while the same clinical function, claims and workflow create a Class IIa or higher medical device in Europe. Dual-track planning forces that difference into the product requirements before it becomes a late-stage surprise.
For AI-enabled medical devices, the EU AI Act adds another layer. Article 6 links certain products governed by the MDR or IVDR to the high-risk regime when third-party conformity assessment is required. Teams should build the documentation, logging and oversight capabilities now, while tracking the Act's applicable dates and implementation measures rather than presenting every obligation as already enforceable.

2. What transatlantic leaders reveal
Public regulatory histories from medical imaging companies such as Gleamer, Viz.ai and Aidoc demonstrate the strategic value of reusable evidence, even though their products, indications and market sequences differ.
Gleamer has built a portfolio that includes FDA-cleared and CE-marked radiology products. Viz.ai's large-vessel occlusion software established a new device type through De Novo DEN170073, creating a regulatory foundation for later products. Aidoc has expanded through multiple indication-specific FDA clearances while operating a broader clinical AI platform internationally.
These companies should not be reduced to a claim that one trial automatically produced two approvals. Regulatory submissions remain product-specific, and public records rarely expose every internal design decision. The useful lesson is structural: maintain a shared quality system, define data provenance consistently, validate across relevant scanners and clinical settings, and preserve evidence in forms that can be repurposed without pretending the authorities ask identical questions.
3. The algorithm divide: FDA PCCPs and European lifecycle governance
Continuous model improvement creates a second dual-track problem. A model update that appears modest to an engineering team can alter device performance, risk controls or the approved intended use.
The FDA's final Predetermined Change Control Plan guidance, issued in December 2024, allows a manufacturer to describe planned modifications, the method used to develop and validate them, and an impact assessment within a marketing submission. An authorized PCCP can permit specified changes without a new submission when those changes stay inside the approved boundaries and acceptance criteria. The guidance applies across 510(k), De Novo and PMA submissions, but it is guidance, not an automatic authorization to deploy any retrained model.
European requirements emphasize lifecycle risk management, technical documentation, post-market surveillance and, where applicable, post-market clinical follow-up. The EU AI Act adds expectations around data governance, record keeping, transparency and human oversight for high-risk systems as its provisions become applicable.
The dual-track answer is one controlled ModelOps pipeline. Every released model version should carry its training-data lineage, locked validation set, subgroup performance, software bill of materials, risk assessment, approval record and production-monitoring plan. The verification package used to support an FDA-authorized PCCP can then feed the evidence trail needed for European conformity assessment and surveillance.
4. The four-pillar unified clinical evidence envelope
1. Multi-geography demographic sampling
Recruit across US health systems and European clinical centres when the intended populations and standards of care require it. The objective is not geographic decoration. It is evidence that performance survives differences in prevalence, equipment, workflow and patient characteristics.
2. Comparable ground truth
Pre-specify reference standards that both authorities can interrogate. For imaging AI, that may mean a multi-reader, multi-case design with adjudication. For predictive software, it means a clinically defensible endpoint, a locked time horizon and a clear account of missing data.
3. Unified privacy and security architecture
Design the data flow for both US health-data obligations and European GDPR requirements. Consent or another lawful basis, data minimisation, access controls, retention, cybersecurity and cross-border transfers cannot be added after the dataset has already been assembled.
4. One quality backbone
The FDA's Quality Management System Regulation took effect on February 2, 2026 and incorporates ISO 13485:2016 by reference. That alignment gives dual-track companies a stronger common foundation, although FDA-specific requirements and European conformity-assessment expectations still need explicit ownership.
5. Commercial reality: US coding versus European payer fragmentation
Regulatory authorization grants the legal ability to market a device for its cleared or certified intended use. It does not guarantee payment.
| United States | Europe |
|---|---|
| Existing or new CPT coding may support professional billing | Market access remains country-specific |
| Some inpatient technologies may seek NTAP | Germany operates DiGA for eligible digital health applications |
| Hospitals may buy software through operating or capital budgets | France offers the PECAN early-access route for eligible digital medical devices |
| Coverage and payment still vary by payer and setting | UK access depends on NICE guidance, NHS commissioning and procurement routes |
The distinction matters. A CPT code does not itself guarantee coverage, payment or adoption, and NTAP applies to qualifying inpatient technologies rather than functioning as a general AI reimbursement route. Germany's DiGA pathway also covers a defined subset of lower-risk digital health applications, not every CE-marked clinical AI device.
A synchronized strategy therefore runs evidence and reimbursement planning in parallel. US deployment may generate clinical and economic data useful in Europe, but each country still needs a credible budget holder, care pathway and value argument.

6. The HealthTech investor's signal
Regulatory literacy is becoming a useful proxy for execution. Investors meeting clinical AI founders in Lisbon should ask whether the company has mapped each claim, model change and clinical endpoint across its intended markets.
Single-market authorization can still support a strong business. The concern is unpriced expansion risk. If the evidence cannot travel, an investor or acquirer must account for additional studies, audit readiness, Notified Body capacity and a longer path to revenue. A unified ISO 13485 and QMSR quality backbone, a traceable model lifecycle and a credible FDA and CE-MDR sequence make that risk easier to diligence.
For global medtech strategics, the attractive asset is not a badge collection. It is a product whose clinical evidence, quality controls and software governance can survive deployment across multiple hospital systems and jurisdictions.
7. Four observable milestones for the next 12 months
- Notified Body capacity: Watch certification throughput and scope for Class IIa and IIb medical software.
- FDA PCCPs in public decisions: Read 510(k), De Novo and PMA documents for authorized change plans and the boundaries placed around model updates.
- European harmonisation work: Track standards and common specifications connecting MDR technical documentation with AI Act conformity requirements.
- Transatlantic study design: Look for prospectively registered protocols that recruit on both sides of the Atlantic under compatible endpoints, rather than assuming registry geography alone proves a dual filing.
The bottom line
The era of treating regulatory work as a final documentation sprint is over. MDR Rule 11, FDA software policy, QMSR and the EU AI Act now reach deep into product architecture, clinical evidence and model operations.
The winners at Web Summit will not simply be the companies with the fastest algorithms or the loudest launch. They will be the teams that can explain, in one coherent operating model, how a clinical claim becomes evidence, how evidence becomes authorization, how a model changes safely, and how authorization becomes payment.
That is the real dual-track advantage. It is not simultaneous paperwork. It is building one company capable of satisfying two demanding systems without rebuilding itself at the border.
Sources
- FDA: Clinical Decision Support Software
- FDA: Predetermined Change Control Plans for AI-Enabled Device Software Functions
- FDA: Quality Management System Regulation
- European Commission: MDCG 2019-11 Rev.1 on software qualification and classification
- European Commission: Regulatory framework for artificial intelligence









