Guides · Regulation

How AI in healthcare is regulated — from the primary sources.

No single authority regulates AI in healthcare. The FDA clears AI-enabled devices and is rebuilding its playbook around the total product lifecycle; the EU AI Act phases in obligations for high-risk health uses on a timeline that runs for years; the UK is testing adaptive tools inside the MHRA's AI Airlock; and the WHO has issued guidance on large language models that no regulator is obliged to follow. Below the device line sits everything the regulators barely touch — ambient scribes, HIPAA questions around LLMs, a patchwork of US state laws — where the governance burden lands on hospitals themselves.

These guides map that terrain from primary sources: the statutes, guidance documents, and device lists themselves, not press summaries of them. They cover what a Predetermined Change Control Plan actually permits, how liability falls when clinical AI errs, what transparency and labeling rules require, and how to build the governance committee and algorithmovigilance program that regulators increasingly expect hospitals to have. Each guide is dated, tied to numbered sources, and revised when the rules move — which, in this field, is constantly.

16 guides in this collection

Updated 1 Aug 2026

The CMS WISeR Model, explained: AI prior authorization reaches traditional Medicare

Since January 2026, six technology companies have been running AI-assisted prior authorization on select services in six US states — the first Innovation Center model built around the technology, and the first to survive a Senate repeal vote. How the model actually works, from the Federal Register notice itself. As of August 2026.

Updated 1 Aug 2026

EU AI Act on 2 August 2026: what now applies to healthcare

The Digital Omnibus is law, and the AI Act's general application date arrives with the healthcare high-risk obligations deferred to 2027 and 2028 — while the Article 50 transparency duties land on schedule. What each date now covers, tied to the amended Regulation. As of August 2026.

Updated 1 Aug 2026

The first FDA-cleared patient-facing LLM: what UpDoc's 510(k) actually says

In December 2025 the FDA cleared UpDoc, a prescription insulin-management device whose patient interface is a large language model — and the clearance went through as a drug dose calculator, with a predetermined change control plan attached. What the record shows, what it leaves open, and what it signals for every LLM heading toward the device pathway. As of August 2026.

Updated 1 Aug 2026

US state laws on AI mental-health chatbots: a tracker

Two legislative waves in two years: 2025 brought the first therapy restrictions in Illinois, Nevada and Utah and the first companion-chatbot safety statutes, and 2026 has added five more states restricting AI-delivered therapy — with 98 chatbot bills pending across 34 states. Every row tied to a statute or a primary tracker. As of August 2026.

Updated 23 Jul 2026

Building an algorithmovigilance program

A build sequence for watching clinical algorithms after they go live — the operating model, the four signals to instrument, the people to name, the cadence to run, and the escalation path — each step tied to a primary source. As of July 2026.

Updated 1 Aug 2026

EU AI Act for healthcare: a living timeline

A dated timeline of the EU AI Act as it lands on healthcare — the exact application dates after the Digital Omnibus entered into force: standalone health AI under Annex III now falls due 2 December 2027, and AI that is a medical device under Annex I on 2 August 2028. Each row tied to the Regulation itself. As of August 2026.

Updated 23 Jul 2026

The FDA AI-enabled device list: a statistics tracker

A dated read of the FDA's AI-Enabled Medical Device List — how many devices carry an authorization, which specialties dominate, which pathways they take, and how thinly they report performance and demographics — each figure tied to the FDA or a peer-reviewed census. As of July 2026.

Updated 23 Jul 2026

The FDA's total-product-lifecycle draft guidance for AI devices, explained

What the FDA's January 2025 draft guidance on AI-enabled device software functions actually asks of manufacturers across the total product lifecycle — its scope, its thirteen sections, its transparency-and-bias and representativeness demands, and its still-draft status. As of July 2026.

Updated 23 Jul 2026

HIPAA and LLMs: what is permitted

A decision map for putting patient data near a large language model under US health-privacy law — read straight from the 45 CFR Part 164 text: when data stops being protected, when a vendor becomes a business associate, what a permitted use is, and why training a model on records is still an open question. As of July 2026.

Updated 23 Jul 2026

The hospital AI governance committee playbook

A build sequence for standing up a hospital AI governance committee — charter, membership, intake, tiered review, a local-validation gate, monitoring, and board reporting — with every step cross-walked to a published governance framework. As of July 2026.

Updated 23 Jul 2026

Liability when clinical AI errs

When an AI-assisted clinical decision harms a patient, who answers for it — the clinician, the developer, or the health system? A fair-minded map of the three doors a claim can walk through, grounded in the peer-reviewed legal scholarship, and honest that the law is still unsettled. As of July 2026.

Updated 23 Jul 2026

Predetermined Change Control Plans in practice

How manufacturers actually build a PCCP and what health systems should check — the three required sections turned into what you write, the five guiding principles as design constraints, and what the first authorized plans reveal. As of July 2026.

Updated 23 Jul 2026

Transparency and labeling requirements for clinical AI

What US rules actually force a clinical-AI tool to disclose — the FDA device track and the ONC/ASTP HTI-1 certified-EHR track — mapped onto the single artifact both converge on, the model card, and read against how little devices disclose today. Each requirement tied to primary rule text. As of July 2026.

Updated 23 Jul 2026

The UK MHRA AI Airlock, explained

What the MHRA's regulatory sandbox for AI as a medical device actually is, how it works, and what its two published cohorts found — mapping each real regulatory gap to the case study that surfaced it, drawn from the pilot and Phase 2 reports themselves. As of July 2026.

Updated 23 Jul 2026

US state laws on AI scribes: a tracker

A dated, two-layer status table of the state laws that reach ambient AI scribes — the recording-consent rules that decide whether a scribe may capture the visit at all, and the newer generative-AI disclosure and governance statutes — each row tied to the legislature's own text. As of July 2026.

Updated 23 Jul 2026

WHO guidance on large language models in health

What the World Health Organization's 2024 guidance on large multi-modal models actually says — the five ways it expects these systems to be used in health, the risks it names, who it tells to do what, and the one thing to keep straight: it is advisory, and binding rules sit elsewhere. As of July 2026.