FDA Regulation of Post-Market Algorithm Changes: Predetermined Change Control Plans for AI/ML-Enabled Devices
Machine learning models embedded in medical devices are designed to change — retraining on new data, expanding scanner compatibility, adjusting thresholds — yet each modification has traditionally risked triggering a new 510(k) or PMA supplement. Predetermined change control plans (PCCPs) let sponsors obtain FDA authorization for a defined envelope of future modifications up front, making them a central planning consideration for any regulatory team bringing an AI-enabled device function to market or managing one already cleared.
The analysis below traces the statutory basis for PCCPs under section 515C of the FD&C Act, the required contents of a compliant plan, the boundaries FDA places on what a PCCP can and cannot cover, and what recent 510(k) and De Novo authorizations reveal about how manufacturers are using the mechanism in practice.
Want to ask Rhizome your own regulatory questions? Try it for free.
How FDA regulates post-market algorithm changes to AI/ML-enabled devices through predetermined change control plans
Machine learning models rarely stay still. Sponsors want to retrain on new data, add scanner or vendor compatibility, adjust decision thresholds, and improve sensitivity after a device is on the market. Under the traditional device framework, many of those changes would trigger a new 510(k) or a PMA supplement before they could be deployed. The predetermined change control plan (PCCP) is FDA's mechanism for authorizing a defined envelope of those future modifications up front, so a manufacturer can implement them without returning for a new marketing submission each time, provided the changes stay inside the plan FDA approved or cleared 10111213.
This article summarizes the regulatory architecture of PCCPs for AI-enabled device software functions (AI-DSFs), what a compliant plan must contain, the boundaries FDA places on it, and what a growing body of 510(k) and De Novo authorizations shows about how the mechanism is actually being used.
Statutory basis and where a PCCP lives
The PCCP mechanism is not purely a matter of guidance. Section 3308 of the Food and Drug Omnibus Reform Act (FDORA) added section 515C, "Predetermined Change Control Plans for Devices," to the Federal Food, Drug, and Cosmetic Act, codified at 21 U.S.C. 360e-4 10111217. That provision gives FDA express authority to approve or clear a plan describing changes a device will undergo, together with the methods to implement those changes.
A PCCP is submitted as part of a premarket submission. FDA guidance states that PCCPs may be approved or cleared for devices requiring premarket approval (PMA) or premarket notification (510(k)) 10111213. Once FDA authorizes the PCCP, a manufacturer may make the planned changes that fall within the plan's bounds, and no new PMA supplement or new 510(k) is required so long as each change is consistent with the authorized PCCP 1011121317. FDA also may require the plan to include labeling for safe and effective use, notification if the device does not function as intended, and specified performance requirements 1017. Because getting the plan right is central to the authorization, FDA recommends developing the PCCP through the Q-Submission process before it is included in the premarket submission 1417.
The three required components of a PCCP
FDA structures a PCCP around three interrelated components: a Description of Modifications, a Modification Protocol, and an Impact Assessment 6460.
1. Description of Modifications. This section enumerates each individual proposed modification and gives a specific rationale for each planned change, described in enough detail to be verified and validated 6449. It should state whether each modification is implemented automatically, manually, or in combination; whether it is uniform across all devices or a local/heterogeneous adaptation (and, for local adaptations, the local factors that warrant the change); and the expected frequency of updates 49. It should also define the specifications for the characteristics and performance of the planned modifications 64.
2. Modification Protocol. This is the methods section: how the planned modifications will be developed, validated, and implemented so the device remains safe and effective 604364. FDA identifies four practices that should generally be addressed for each planned modification 4264:
- Data management practices — how data will be collected (including clinical study protocols with inclusion/exclusion criteria), processed, stored, and retained; how the reference standard is determined; data quality assurance; and data sequestration strategies that prevent access to performance-test data during training and tuning 35.
- Re-training practices — the objective of re-training, a description of the AI model, which device components may be modified, the practices followed, and, where architecture is altered, the rationale for those changes 35.
- Performance evaluation — the applicable data, test methods, analysis methods, and specified acceptance criteria used to develop and validate each modification 4243.
- Update procedures — how software updates are implemented, how legacy users are affected, and how modifications are communicated to users, including transparency about performance differences, changed inputs, and known issues addressed in the update 44.
The Modification Protocol must also maintain traceability, linking each modification in the Description to the corresponding verification and validation activities, and ensure that the information that would otherwise be submitted to FDA is generated and retained under the manufacturer's quality system 424345.
3. Impact Assessment. This documents the benefits and risks of implementing the PCCP and the mitigations for those risks 454756. It compares the device with each modification implemented individually against the unmodified device, discusses the risks of each change (including harm and unintended bias), and explains how the verification and validation activities continue to reasonably ensure safety and effectiveness 455648. It must also address interactions: how implementing one modification affects another, the cumulative impact of implementing all of them, and effects on other software functions, hardware, and, for combination products, the drug or biologic constituent part 4856.
What modifications belong in a PCCP, and what does not
FDA's threshold principle is that a PCCP can include modifications intended to maintain or improve safety and effectiveness, provided they are specific and can be verified and validated 55. The AI-specific guidance describes three categories that may be appropriate 55:
- Performance modifications — changes to quantitative AI-DSF performance specifications, including improvements from re-training the model on new data drawn from the intended use population and the same type and range of input signal.
- Input and compatibility modifications — new sources of the same input signal type, limited additions of new input types, input transformations such as normalization, and updates for compatible software/hardware or interoperability.
- Use and performance modifications — for example, authorizing use in a specific subpopulation within the originally indicated population based on re-training on a larger subpopulation dataset.
The boundaries are equally important. Modifications must keep the device within its intended use, and, where applicable, the device must remain substantially equivalent to its predicate 55. FDA generally expects modifications to stay within the cleared indications for use, and considers most changes to the indications for use to be outside the appropriate scope of a PCCP 55. The draft PCCP guidance illustrates changes that are generally not appropriate for a plan: adding a new physiological parameter, adding a novel physiological or predictive index or algorithm, significant changes to alarm architecture or PCB design, adding an alternate type of input data, or adding a new clinical claim such as a new severity level 81. More broadly, if a modification could significantly affect safety or effectiveness and is not consistent with an authorized PCCP, a new marketing submission is required 6879.
Post-market monitoring, bias, and transparency
Because a PCCP shifts control of certain changes from premarket review to the manufacturer's quality system, FDA leans heavily on post-market discipline. The guidance recommends a risk-based postmarket performance monitoring plan to detect and respond to changes in safety, effectiveness, and real-world performance as modifications are deployed, and notes that monitoring may differ for manual versus automatic updates and for global versus local updates 171172.
Bias and subgroup performance receive specific attention. Sponsors should describe how changes in performance related to known bias will be communicated, how previously unknown biases will be identified, and how performance changes in patient subpopulations will be detected 168171. FDA flags model bias and incompletely characterized subgroup performance as risks that the plan must anticipate 169, and points to continuous monitoring under the quality system, with local acceptance testing or historical-data assessment before full deployment where appropriate 169170.
Transparency runs through the labeling recommendations. Labeling should be updated when modifications are implemented, should identify which sections are affected, and should stay consistent with the current version available to the user 171172. FDA specifically advises against including information about modifications that have not yet been implemented, because doing so could be misleading or render the device misbranded 171172. Updates should be communicated through updated labeling and release notes, with version information and, where appropriate, updated user training 171173.
What still requires a new marketing submission, and the "unlocked" question
The dividing line is consistency with the authorized plan. Changes that are consistent with an FDA-approved or cleared PCCP do not require a new marketing submission, even though they are the kind of change that would otherwise meet the new-submission threshold under the device-change regulations; changes that fall outside the plan follow the ordinary rules and generally require a new PMA supplement or new premarket notification 8316.
FDA has confirmed that its PCCP recommendations apply to AI-DSFs intended to be modified over time, including those where model modifications are implemented automatically by software, that is, continuous ("unlocked") learning 83. In practice, the authorizations to date describe controlled, bounded retraining that is trained, tuned, and locked before release rather than open-ended online learning.
The guidance landscape
Several documents now define this space, and a reviewer should keep the hierarchy straight:
- Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions — the AI-specific PCCP guidance, issued as final guidance dated August 18, 2025 94. This is the operative document for AI-DSF plans and supplies the three-component structure above.
- Predetermined Change Control Plans for Medical Devices — the broader, device-agnostic PCCP draft guidance dated August 22, 2024, which carries the cross-cutting scope examples (including changes generally not appropriate for a plan) 9581.
- Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations — a draft guidance dated January 7, 2025, situating PCCPs within a total product life cycle (TPLC) approach that spans design, development, deployment, and maintenance, and emphasizing proactive post-deployment monitoring for performance drift driven by demographic shifts, disease prevalence, input-data changes, data-pipeline corruption, and changes in user behavior 98253132. It ties back to Good Machine Learning Practice principles, including the principle that sponsors should evaluate the combined Human-AI Team rather than the model in isolation 2529.
- Content of Premarket Submissions for Device Software Functions — final guidance dated June 14, 2023, which sets the underlying software documentation expectations a PCCP builds on 97.
FDA describes a PCCP as a way to support the iterative development of AI-DSFs within the TPLC framework, and the lifecycle draft explicitly suggests sponsors consider a PCCP when planning updates or mitigations for changing device performance after deployment 2831.
What recent authorizations show
The mechanism is now in routine use across imaging, cardiology, sleep, ultrasound-guidance, and diagnostic AI. The authorizations below each established a PCCP defining the pre-authorized change envelope. The dominant pattern is bounded retraining on additional data to improve performance, plus expansion of input/scanner/vendor compatibility, while architecture, intended use, and clinical role are held fixed.
| Device | Number | Company | Pre-authorized change scope |
|---|---|---|---|
| Caption Interpretation Automated Ejection Fraction Software (De Novo) | DEN220063 | Caption Health | Training on additional data; additional 2D TTE views; core-algorithm implementation optimization; improved algorithm speed 150152154 |
| LINQ II / Zelda AI ECG Classification System | K210484 | Medtronic | Change the AF threshold; re-train on data labeled under original or alternate protocol; pre-train the algorithm 119 |
| Irregular Rhythm Notification Feature (IRNF) 2.0 | K231173 | Apple | Adjust AF threshold; retrain with additional data while holding architecture and parameter count; change number of sequential irregular tachograms and confirmation-cycle period 151 |
| MammoScreen BD | K241561 | Therapixel | Add GE and Siemens mammogram support; unsupervised pre-training of the backbone 117 |
| MammoScreen (4) | K243679 | Therapixel | GE mammogram support without retraining; new manufacturer support with retraining 137 |
| BoneMRI | K233030 | MRIguidance | Re-train with additional data; validate additional MRI vendor or field-strength support 118 |
| SleepStageML | K233438 | Beacon Biosignals | Updates to signal preprocessing, ML model, probability postprocessing, and signal-quality thresholds; retraining with updated datasets, hyperparameters, loss, optimizer, and architecture within limits 120 |
| Dreem 3S | K242094 | Beacon Biosignals | Update signal preprocessing, ML model, and probability postprocessing to improve sleep staging 121 |
| Cardiac Guidance | K243065 | Caption Health | Retrain/optimize core algorithms; add real-time guidance for additional 2D TTE views; tune thresholds, averaging logic, transfer functions, frequency, refresh rate 122 |
| HeartFocus (V.1.1.1) | K242807 | Deski | Retrain core algorithms without changing architecture; extend to new ultrasound systems and operating systems 126 |
| ScreenDx | K241891 | Imvaria | Update model architecture; change the positive/negative cut-off value 115 |
| Fibresolve | K252041 | Imvaria | Model architecture modification; new training data; incorporate ancillary inputs while keeping original inputs 127 |
| Clarius Prostate AI | K243853 | Clarius Mobile Health | Add data from current and future cleared Clarius scanners 130 |
| Clarius Ejection Fraction AI | K253593 | Clarius Mobile Health | Add data from current and future cleared Clarius scanners 131 |
| Clarius Median Nerve AI | K250226 | Clarius Mobile Health | Modify training hyperparameters (learning rate, width multiplier, dropout) 132 |
| ECG-AI Low Ejection Fraction 12-Lead | K250652 | Anumana | Periodic updates to enhance sensitivity and/or specificity 133 |
| FETOLY-HEART | K241380 | Diagnoly | Retrain on new datasets; modify hyperparameters; add/remove heart quality criteria 158 |
| FETOLY | K251368 | Diagnoly | Modify hyperparameters; retrain with new data; adjust quality criteria; add biometric parameters 136 |
| Seg Pro V3 | K251306 | Ever Fortune.Ai | Model-weight updates via retraining on verified real-world data; no architecture or pipeline changes; predefined retraining triggers 146 |
| SafeOp 3: Neural Informatix System | K252842 | Alphatec Spine | Retrain SSEP baseline classifier on site-specific nerve data; remove RAT state; enable tEMG via a specific clip; periodic bounded retraining 147 |
| MuscleView 2.0 | K251682 | Springbok Analytics | Retrain per-ROI model on additional data; tune hyperparameters and pre/post-processing; add virtual control-group data 153 |
| PVAD IQ Software | K252235 | Ultrasight | Retraining for accuracy; refine annotations; bounded architecture optimization; no input/output change 157 |
| Brainomix 360 Hyperdensity | K260406 | Brainomix | Retrain model weights on expanded data; trained, tuned, and locked before release; no change to clinical role 125 |
| syngo.CT Coronary Cockpit | K253786 | Siemens Medical Solutions | Add training data; modify training hyperparameters and pre-/post-processing parameters 129 |
Several common threads run through these authorizations. Retraining to improve a quantitative performance metric, on data from the existing intended use population, is the most frequently authorized change 119120133146. Extending compatibility to new scanners, vendors, or field strengths is the second recurring category, and sponsors typically pair it with a commitment to validate the added source 117118130137. Where architecture can be modified at all, sponsors tend to bound it and commit to locking the model before release 125127146. Changes to intended use or clinical claims are conspicuously absent, consistent with FDA's position that those fall outside the appropriate scope of a plan 5581.
Practical takeaways for regulatory teams
A well-constructed PCCP is less about listing everything a team might eventually want to change and more about defining a tightly specified, verifiable envelope with a credible method for staying inside it. The Modification Protocol carries most of the weight: FDA is authorizing the methods (data management, retraining, performance evaluation, update procedures) as much as the specific changes, and traceability from each modification to its verification and validation activities is what makes the plan reviewable 424345. The Impact Assessment should treat modification interactions and cumulative effect as first-class questions, not afterthoughts 4856. And because the plan front-loads trust into the quality system, the post-market monitoring, subgroup/bias surveillance, and transparent labeling commitments are integral to authorization rather than optional add-ons 171172168. For teams planning an AI-DSF submission, FDA's recommendation to develop the plan through a Q-Submission before filing is worth taking literally 1417.