Regulation guide
Software as a medical device: the founder's primer
Plain language orientation to regulatory classification, clinical evidence and the AI specific rules.
7 min read · Updated 2026
Regulation is where health technology companies most often discover, late, that their roadmap and their legal position disagree. This is an orientation, not legal advice. Every serious product decision here should be reviewed by a qualified regulatory professional in the markets you sell in.
The question that determines everything
Does your software make or materially inform a clinical decision about an individual patient. If it does, it is likely a medical device in most jurisdictions. If it summarises, schedules, bills or documents without directing care, it usually is not, though the boundary is narrower than founders assume, and ambient documentation products live close to it.
Risk classification drives cost and timeline
Regulators classify by the harm that could result if the software is wrong and by how much the clinician can independently check it. Low risk tools carry light obligations. Higher risk tools require a quality management system, clinical evaluation, post market surveillance and, depending on the market and class, review by a notified body or a formal submission pathway. Plan for the quality system early. Retrofitting one is far more expensive than starting with it.
What is different about AI
Adaptive models create a specific problem for regulators: the thing they reviewed can change. Expect to define the intended use tightly, document your training and validation data, show performance across relevant subgroups, and describe how you will monitor drift after deployment. Predetermined change control plans are the mechanism regulators increasingly use to allow model updates without a new submission.
- Freeze and document a validation dataset that is genuinely separate from training data.
- Report performance by subgroup. Committees will ask, and so will regulators.
- Instrument post market monitoring before launch, not after the first incident.
Privacy is a parallel track
Regulatory clearance says nothing about lawful data handling. Health data rules apply independently, they differ by market, and they govern training data as strictly as production data. Establish your legal basis, your data processing agreements and your retention policy before you use customer data to improve a model. Contracts that quietly assume broad training rights are one of the most common causes of a stalled enterprise deal.
Key signals
- If software informs a clinical decision about a patient, assume device rules apply.
- Build the quality system early. Retrofitting is the expensive route.
- For AI, tightly define intended use and instrument drift monitoring before launch.
- Clearance and privacy compliance are separate obligations. You need both.