Skip to content
Review Open access

Lifecycle answerability for artificial intelligence-enabled medical device software: a regulatory science perspective

Aug 2026 · Frontiers in Medicine · Vol 13 · 0 citations · 61 references
Medicine

TL;DR

This work provisionally defines the credible field signal that triggers answerability obligations, distinguishes the construct from established algorithmic accountability frameworks, applies it in parallel to sepsis early warning and large language model documentation, and examines what is distinctive about answerability obligations in critically ill populations.

Abstract

Artificial intelligence (AI)-enabled medical device software is increasingly expected to learn, update, explain, retrieve information, draft records, and support clinical reasoning across changing care environments. Regulatory science has responded with lifecycle-oriented tools, including software-as-a-medical-device risk categorization, quality management systems, medical device software lifecycle processes, risk management, post-market monitoring, and predetermined change control plans. These tools are necessary, but they do not by themselves specify who must respond when field experience shows that an AI-supported clinical decision, workflow, validation claim, or planned update no longer fits clinical reality. Documented deployments of sepsis early-warning software in critical care—an external validation that overturned a widely deployed model’s performance claims, the manufacturer’s subsequent model replacement, and a prospective multi-site study linking alert response latency to sepsis mortality—show that such field signals are common, consequential, and unevenly answered. We propose lifecycle answerability as a regulatory science construct for AI-enabled medical device software. It specifies standing, addressee, reason-giving, temporal trigger, and revision pathway. We provisionally define the credible field signal that triggers these obligations, differentiate the construct from established algorithmic accountability frameworks, apply it in parallel to sepsis early warning and large language model documentation, and examine what is distinctive about answerability obligations in critically ill populations. Future work should test answerability through deployment case reviews, post-market signal audits, escalation pathway simulations, and implementation studies. Lifecycle answerability complements existing lifecycle governance by specifying the institutional response architecture through which credible field signals become institutionally actionable across the software lifecycle.

Read PDF

Similar papers

Review Open access Jul 2026

Artificial intelligence-based software as a medical device: regulatory evolution toward continuous oversight

This structured narrative review examines how AI-SaMD regulation is moving beyond single-point premarket evaluation toward continuous and dynamic oversight, and synthesizes five evidence dimensions central to ongoing regulatory assurance: data evidence, algorithm evidence, software and cybersecurity evidence, clinical scenario and human factors evidence, and real-world data/real-world evidence with change management.

Yukun Dong, Ping Jiang, Xiao-Hua Zhou · 0 citations
Review Open access Jul 2026

Continuous assurance for AI-driven clinical decision support systems

This review discusses the evolving landscape of AI-CDSS audit, highlighting its transition from a technically focused lifecycle validation to an integrated paradigm centered on socio-technical resilience, and proposes the STRAICS framework, which integrates technical robustness, human-machine interaction safeguards, adaptive governance, and transparency-by-design infrastructure.

Rami A. Al-Horani, Amanuel F. Tadesse · 0 citations
Review Aug 2026

From Safety Documentation to Safety Knowledge Support: An Evidence-Grounded LLM Framework for Medical Devices

Medical devices are becoming more software-intensive, connected, and AI-enabled. Their development requires risk-management evidence aligned with ISO 14971 and, for software, IEC 62304. This evidence must be kept consistent across requirements, design decisions, software changes, verification results, complaints, and post-market data. These tasks are costly and depend on scarce safety and domain experts. Large language models (LLMs) may reduce parts of this effort because medical-device safety work is highly document-based. However, current LLM-based safety-engineering studies often address isolated methods, rely on generic prompting or public examples, and provide limited support for source links, traceability, uncertainty handling, lifecycle updates, and recorded expert review. This limits their use in regulated medical-device development. This paper argues that the central research problem is not safety-text generation, but source-linked safety-knowledge support. We propose an evidence-grounded framework that connects device artifacts, controlled knowledge storage and retrieval, method-specific generation of candidate safety items, critique and uncertainty checks, and recorded expert review. The framework prepares, links, checks, and updates candidate safety artifacts for expert decision-making. It does not decide whether a device is safe and does not provide regulatory approval. We also outline an evaluation strategy using non-public or newly built medical-device case studies and expert reference analyses to assess coverage, correctness, relevance, traceability, duplicate rate, unsupported claims, and review effort.

Tuhinangshu Gangopadhyay, Rasmus Adler, Peter Liggesmeyer et al. · 0 citations
Open access Aug 2026

Overcoming the opaque side of AI in healthcare: a lifecycle based approach.

INTRODUCTION Transparency has emerged as a foundational condition for trustworthy Artificial Intelligence (AI) in healthcare. Despite its centrality, practical approaches to systematically operationalize transparency across the entire lifecycle of AI-enabled medical devices remain fragmented and insufficiently structured. This work addresses this gap by proposing a lifecycle-oriented operational approach to guide the consistent implementation and evaluation of transparency in AI-based medical technologies. AREAS COVERED A narrative synthesis of regulatory texts, international standards, and scientific literature related to software as a medical device (SaMD), the EU Medical Device Regulation (MDR), the EU Artificial Intelligence Act (AI Act), data-protection rules, and relevant ISO/IEC guidance. Using a SaMD lifecycle framework, we mapped transparency requirements to practical development, validation, and governance activities across ideation, data and design inputs, risk management, implementation/verification, technical and clinical validation, market placement, maintenance, and disposal. EXPERT OPINION Transparency must be engineered as a lifecycle property, not an afterthought. We propose nine operational measures - covering documented design assumptions and datasets, transparency-oriented risk and change control, traceability, subgroup and independent validation, usability-based explainability, calibrated clinical evaluation, structured labeling, version-controlled updates, and regulated end-of-life data handling - to support regulatory readiness, calibrated clinical trust, and safe real-world integration of AI in healthcare.

E. Bianchini, L. Billeci, Noemi Conditi et al. · 0 citations
2026

Reconceiving Safety Regulation for AI and ML Medical Software

This article explores the challenges of regulating AI and ML clinical decision support tools intended to assist trained health care professionals in delivering clinical care. Two old, twentieth-century regulatory models have dominated discussions of medical AI policy since 2013. Thinking inside these old regulatory boxes has not produced effective regulatory solutions to address the novel risks AI poses in clinical care. The first regulatory box treats software as a medical device, which tasks medical device regulators with making software safe but neglects the crucial roles physicians, nurses, administrators, medical practice regulators, and other health oversight bodies must also play to make AI-enabled health care safe for patients. The second box views AI-enabled healthcare as a complex sociotechnical system where the central regulatory challenge is to incentivize the creation of “slack” at the human-AI interface: that is, to inject buffers, redundancies, and checks and balances that enhance opportunities for human actors to intervene if the software runs amok. The 21st Century Cures Act of 2016 favored this latter model, but it has not been successfully implemented. This article then offers two more conceptualizations. Viewed through the lens of the old corporate practice of medicine doctrine, the central oversight challenge in AI-enabled health care is to prevent non-physician corporate actors (for example, software developers) from overriding or corrupting physicians’ ability to exercise independent medical judgment on behalf of their patients. The final conceptualization likens AI and ML tools to intelligent agents that are “colonizing” the health care system and threatening various harms to the indigenous humans—patients, health professionals, and administrators—who inhabit it. Protecting the safety, culture, and values of health care may require institutional and regulatory reforms that go far beyond merely repurposing old regulatory frameworks left over from the past century.

Barbara J. Evans, Eric S. Rosenthal, A. Bihorac · 0 citations
Open access 2019

Data Engineering for Predictive Analytics in Healthcare: Challenges and Solutions

Predictive analytics in healthcare has revolutionized medical decision-making by enabling early disease detection, risk stratification, and personalized treatment plans. However, the implementation of predictive analytics relies on robust data engineering processes to handle the vast amounts of structured and unstructured healthcare data. The integration of electronic health records (EHRs), genomic data, and real-time patient monitoring systems presents significant challenges related to data quality, interoperability, security, and computational efficiency. This paper explores the critical role of data engineering in predictive analytics, addressing key challenges such as data acquisition, cleaning, storage, and real-time processing. Furthermore, it discusses various solutions, including data integration frameworks, cloud-based infrastructures, and artificial intelligence (AI)-driven data processing techniques. The research highlights emerging trends such as federated learning, blockchain for data security, and automated data pipelines that enhance the scalability and accuracy of predictive models. The paper concludes by emphasizing the need for standardized data governance policies, cross-institutional collaborations, and advanced machine learning algorithms to overcome data engineering challenges and improve healthcare outcomes.

Sophia White · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.