Software as a Medical Device (SaMD) is software intended to be used for one or more medical purposes that performs those purposes without being part of a hardware medical device — a definition set by the International Medical Device Regulators Forum and applied by the FDA to regulate standalone clinical software 1.
Why the label matters in healthcare
The SaMD boundary decides whether a piece of software must clear regulatory review before it touches patients. An algorithm that reads a CT scan for intracranial hemorrhage, estimates stroke risk, or recommends an insulin dose is performing a medical purpose on its own — it is a regulated device, with premarket requirements, quality systems, and adverse-event obligations attached. A scheduling tool, a billing system, or a step-counting wellness app carries none of that burden. For anyone building or buying clinical AI, this is the first classification question, and everything downstream — evidence expectations, update rules, liability — follows from it.
How the boundary runs in practice
The FDA distinguishes SaMD from two neighbours: software that is integral to a hardware device (software in a medical device, such as the code inside an infusion pump), and software used to manufacture or maintain devices 1. Neither neighbour is regulated as standalone software.
Congress drew a further line in the 21st Century Cures Act, which amended section 520 of the FD&C Act to exclude certain software functions from the device definition altogether. The FDA's September 2022 guidance on clinical decision support software sets four criteria for the excluded category — broadly, software that displays existing information and lets a clinician independently review the basis for its recommendations 4. Decision support that analyzes signals or images, or that a clinician cannot independently verify, stays inside the device perimeter.
Where SaMD appears today
AI has made the category visible. The FDA maintains a public list identifying AI-enabled medical devices authorized for marketing in the United States 2, and the curve is steep: over 690 machine-learning-enabled devices were authorized between 1995 and 2023, and 2024 alone added a record 168 ML-enabled Class II devices 3. In that 2024 cohort, 94.6% were cleared through the 510(k) pathway, 5.4% through De Novo, and radiology accounted for 74.4% of clearances 3. Year-by-year counts and specialty splits live in our FDA-cleared AI devices tracker.
The regulatory machinery keeps adapting to software that changes after authorization. A predetermined change control plan lets the FDA review planned modifications up front, so pre-specified updates can ship without a fresh marketing submission for each change 6. And in January 2025 the agency issued draft guidance on lifecycle management and marketing submissions for AI-enabled device software functions, extending its recommendations across the total product lifecycle — from design and data management through postmarket monitoring 5. As of July 2026, that draft remains unfinalized.
Common misunderstandings
"SaMD" covers all software near a device. It covers standalone software only. Embedded software follows the hardware device it lives in 1.
Authorization proves clinical benefit. Most AI devices are cleared as substantially equivalent to an earlier device, on evidence that varies widely in depth 3. Clearance says the device met the applicable premarket standard; how it performs in a new hospital is a separate question — the reason post-deployment algorithmovigilance exists.
The term is the FDA's own. The definition comes from the IMDRF, a consortium of regulators; the FDA adopted it and, in recent guidance, often speaks of "device software functions" rather than SaMD 1. The concepts overlap heavily, and the IMDRF wording remains the cleanest test: medical purpose, performed by software, without hardware.
Related terms
See predetermined change control plan for how authorized AI devices update, clinical decision support system for the largest excluded-or-included boundary dispute, and algorithmovigilance for what happens after deployment.