FDA Just Moved the Line Between a Clinical Tool and a Regulated Device
In January 2026, the FDA rewrote its clinical decision support guidance and pushed more AI software outside its oversight. Single recommendations are now allowed, documentation tools got clearer footing, and generative AI got almost no framework at all. Here is what changed — and why 'no FDA clearance needed' tells you nothing about whether a tool works.
There is a question that decides how much scrutiny an AI tool gets before it ever reaches your exam room: is it a medical device?
Get that answer wrong and the consequences are asymmetric. A tool that should have been FDA-cleared but isn't isn't just a paperwork problem — it means no premarket review of whether the thing actually works. A tool that stays outside the device definition can ship on a startup's timeline, with the vendor's own word as the only evidence.
On January 6, 2026, the FDA moved that line. Its revised final guidance on Clinical Decision Support Software superseded the version that had stood since September 28, 2022, and it moved in one direction: more software now falls outside FDA oversight.
Here is what actually changed, and what it means when you are the one evaluating the tool.
The four criteria, briefly
The 21st Century Cures Act carved certain decision-support software out of the legal definition of a device. FDA's guidance interprets that carve-out. To be non-device CDS, software must meet all four criteria:
- It does not acquire, process, or analyze medical images, signals from in vitro diagnostic devices, or patterns from signal acquisition systems.
- It displays, analyzes, or prints medical information about a patient, or peer-reviewed and guideline-based medical knowledge.
- It supports or provides recommendations to a health care professional about prevention, diagnosis, or treatment.
- It enables that professional to independently review the basis for the recommendation — so they do not rely primarily on the software to make the call.
All four. Miss one and you are a device.
Criterion 1 is why this whole framework matters less to imaging than people assume. Anything that reads the pixels is a device, full stop — which is why AI imaging and diagnostics tools like Pearl and Overjet go through FDA clearance and always will. The American College of Radiology reaffirmed exactly this after the update: software analyzing medical images to generate diagnostic recommendations stays under FDA oversight.
What actually changed
Single recommendations are now allowed
This is the big one. The 2022 guidance strongly implied that giving a clinician one answer rather than a list of options pushed you toward device territory — the logic being that a single directive output substitutes for judgment rather than informing it.
Vendors responded by engineering around it, padding outputs with alternatives nobody needed so the tool would present as a menu rather than an instruction.
The 2026 guidance drops that. FDA will now exercise enforcement discretion for software offering a single recommendation where only one option is clinically appropriate. The burden shifts to the developer to justify why no other appropriate option existed — but the artificial multiple-choice requirement is gone.
Documentation and summarization got clearer
FDA added examples confirming that a tool which analyzes a radiologist's clinical findings — the written findings, not the images — to draft a proposed summary including a specific guideline-based diagnostic recommendation can be non-device, provided a clinician reviews, revises, and finalizes it. Patient data reports and discharge summaries land in the same bucket.
This is the most directly useful change for ordinary practices. It puts a clearer floor under the documentation tools you are already using, and it echoes a pattern anyone following state AI disclosure laws will recognize: the clinician-in-the-loop is the thing that keeps you on the safe side of the line.
FDA also reversed itself on a specific example — software identifying patients eligible for chemotherapy from their medical information is now treated as non-device rather than device.
"Time-critical" moved but did not disappear
The 2022 guidance explicitly excluded software intended for time-critical decisions. That language came out of criterion 3 — which reads like a loosening until you notice where it went.
It reappears under criterion 4. FDA's position is that a clinician facing a time-critical decision cannot meaningfully perform independent review, so time-critical tools fail the fourth criterion instead of the third. Same destination, different door. And FDA still has not defined what "time-critical" means, which leaves a real gray zone around sepsis alerts, deterioration scores, and anything that fires an alarm.
The AI question FDA mostly declined to answer
Here is where you should be skeptical of the coverage this guidance received.
It was announced alongside a loosening of the general wellness policy — FDA Commissioner Marty Makary presented the digital health changes at CES in January 2026 — and was widely written up as an AI deregulation story. That framing is half right at best.
The guidance does gesture at AI. It puts new emphasis on transparency of data inputs and underlying logic, explicitly flagging automation bias as a concern for algorithmic or AI-driven CDS, and it says recommendations should rest on well-understood, accepted sources such as clinical guidelines and peer-reviewed literature.
What it does not do is lay out a framework for generative AI. There is no treatment of clinician-facing medical chatbots, of LLMs with unconstrained inputs and outputs, or of AI-drafted prescription renewals. FDA also confined this guidance to HCP-facing software — patient-facing symptom checkers and health chatbots got nothing.
So the practical situation is this: general-purpose clinical AI platforms sit in an unresolved gray zone. A tool like Glass Health that synthesizes literature for a clinician looks like classic non-device CDS. An open-ended model that will emit a specific diagnosis for any input is much harder to fit inside criterion 3 — and if its reasoning is opaque, criterion 4 becomes a problem too. Opacity pushes you toward device classification. The black-box tools have the weakest claim to the exemption, which is the opposite of what "deregulation" headlines suggest.
Enforcement discretion is not a clearance
A distinction worth internalizing, because vendors will blur it.
Enforcement discretion means FDA has decided not to enforce device requirements against a category right now. It is not a finding that the software is safe, not a clearance, not an authorization, and not permanent. FDA retains its authority.
So when a vendor tells you their tool "doesn't require FDA clearance," they may be entirely correct and it still tells you nothing about whether the tool works. Non-device status means nobody at FDA reviewed the evidence. The burden of asking for that evidence moves to you. This is the same trap covered in what the research says about AI scribe accuracy: absence of regulation is not evidence of performance.
For contrast, the FDA's AI-enabled device list had reached 1,524 authorized devices as of the end of March 2026, of which 1,164 — about 76% — are radiology. Those went through review. Most clinical AI you will be pitched did not, and now slightly less of it will.
What to ask a vendor
Five questions that cut through the marketing:
- "Is your product a regulated device, non-device CDS, or operating under enforcement discretion?" All three are legitimate answers. Vagueness is not.
- "If it's non-device, which criterion is the closest call?" A vendor who understands their own regulatory position can answer this. One who cannot has probably not done the analysis.
- "Can a clinician see the basis for each recommendation?" Criterion 4 is not just a legal test — it is the difference between a tool you can check and one you must trust blindly. Ask to see it on a real case.
- "What are the sources behind the recommendations?" Guidelines and peer-reviewed literature are what FDA expects. "Our proprietary model" is not a source.
- "Does it touch images or device signals at any point?" If yes and there is no clearance, ask hard questions.
The throughline
FDA loosened the rules for software that helps a clinician think and held the line on software that thinks for them. Summarization, synthesis, and guideline-grounded recommendations got easier. Image analysis, opaque prediction, and anything driving immediate action did not.
That maps almost exactly onto the distinction running through every other AI rule in healthcare right now — the same one at the center of the state disclosure laws and of HIPAA vendor diligence. Keep a licensed human genuinely in the loop, and make sure they can see why the software said what it said.
Regulators keep converging on that answer because it is the right one regardless of what the rules say.
Browse clinical decision support tools and AI imaging tools in our directory, or compare options for your specialty.
This article is for general information only and is not legal or medical advice. FDA guidance documents represent the agency's current thinking and are not binding law; regulatory status is fact-specific and changes over time. Confirm any tool's current regulatory status directly with the vendor and with qualified counsel.