Predetermined Change Control for Adaptive Medical AI Systems
Holding
Adaptive medical AI is not primarily a model problem. It is a change-control problem. A learning system can be useful only if the organization can describe which changes are allowed, how they will be validated, and when a new review is required.
Authority
FDA guidance on predetermined change control plans for AI-enabled device software frames iterative improvement as a planned and assessable activity. The relevant engineering implication is that updates should be treated as controlled modifications, not as informal retraining or routine maintenance.
Issue
The failure mode is unauthorized evolution. A model may be retrained on a larger cohort, a threshold may be tuned, a feature pipeline may change, or a drift correction may be introduced. Each change can alter clinical performance even when the product name and user interface remain unchanged.
Resolution
The system should maintain an approved change envelope. That envelope should specify eligible model modifications, validation datasets, performance acceptance criteria, rollback rules, release approval, and monitoring after deployment. Model registries and data lineage systems are not optional convenience layers; they are the mechanism by which the change plan becomes executable.
Evidence Package
The record should include the change description, rationale, training data lineage, validation report, impact assessment, release approval, monitoring thresholds, and rollback evidence. A medical AI update should be treated as defensible only when a reviewer can reconstruct what changed and why the residual risk remained acceptable.