◆ AI & Medical AI Daily
–
Wednesday · Regulation & Policy

Three windows open at once: FDA asks how to review generative-AI devices, CMS asks what the software is worth, and Brussels pushes its own answer to 2028

Regulators rarely put three questionnaires on the table at the same time. On August 18 the FDA opened docket FDA-2026-N-7874 with a discussion paper on regulating generative-AI-enabled medical devices, carrying 26 numbered questions and a comment deadline of October 19 (FDA press announcement, 2026-08-18). In parallel, CMS's new payment category for clinical software — Software as a Medical Service — has two comment windows: the outpatient rule CMS-1850-P closed on Monday, Aug 31, and the physician fee schedule CMS-1848-P closes September 14 (Applied Policy). Meanwhile the EU settled in May on pushing high-risk obligations for AI embedded in regulated products such as medical devices from August 2, 2027 out to August 2, 2028 (Gibson Dunn). The three windows are three faces of one question — how this gets reviewed, what it is worth, and when the rules bite — and the three answers do not fit together.

01 — Top Stories

Washington asks how to review it and how to pay for it, the states move on their own, Justice sues them, and Brussels hits pause
US · FDA FDA-2026-N-7874CDRH / DHCoE8/18

FDA writes down a review framework for generative-AI devices for the first time: a two-axis risk grid, ten competency benchmarks, and a master file for foundation models

What

On August 18 the FDA's Digital Health Center of Excellence released Considerations for the Regulation of Generative AI-Enabled Medical Devices and opened docket FDA-2026-N-7874, taking comments until October 19 (FDA DHCoE). The paper states plainly that it is not draft or final guidance but a request for feedback. Section IV sets out a two-axis risk grid: one axis for how independently a device function operates (informational through fully autonomous), the other for consequence severity (limited through severe). Section V proposes ten non-clinical competency benchmarks — escalation, staying in scope, calibration, clinical knowledge, information gathering, measurement, robustness, subgroup performance, agentic conduct and more — plus five clinical confirmation routes: retrospective evaluation, shadow deployment, standardized patients, clinician adjudication and prospective study, scaled to risk rather than mandated uniformly. Section VI offers to accept more premarket uncertainty in exchange for continuous postmarket monitoring. Section VII floats a voluntary Foundation Model Device Master File. Twenty-six numbered questions in all (Innolitics section-by-section).

Why it matters

Until now the industry complaint was that there was no path at all. MD+DI quotes industry figure Ashkon Rasooli: "there are currently no pathways to get a generative AI-enabled medical device on the market because FDA hasn't come to terms with quality assurance." (MD+DI) This paper is not a path, but it is the first public look at the map in the agency's head. DHCoE director Rick Abramson had trailed it a week earlier: "Our goal is formal policy guidance… the ecosystem can expect not only broad guidance on the overall topic of generative AI, but also some more narrowly constructed specialty guidance on particular generative AI topics of special interest or special complexity." (STAT, 2026-08-24) Acting commissioner Kyle Diamantas and CDRH director Michelle Tarver are both named in the announcement.

Discount this

A discussion paper carries no legal force and no committed timeline. As recently as April the FDA rejected a proposal to deregulate AI devices (STAT, 2026-04-09); direction here swings. The Section VII master file is voluntary — the paper's own Question 25 asks how the incentive structure should be designed, which is an admission that without one, foundation model vendors will not show up.

US · Payment CMS-1850-PCMS-1848-P8/31 · 9/14

Medicare opens a payment category of its own for clinical software: SaMS and status indicator O1 — outpatient comments closed Monday, physician-side closes Sep 14

What

In the CY 2027 Outpatient Prospective Payment System proposed rule, CMS swaps "Software as a Service" for Software as a Medical Service (SaMS) and creates status indicator O1 — separate payment for SaMS services with no multiple-procedure discounting, functionally like status indicator S. Table 61 designates 36 HCPCS codes as SaMS, of which 21 move out of clinical APCs into New Technology APCs priced to approximate their CY 2026 rates (Discoveries in Health Policy, Nixon Law Group). More consequential still, roughly 10 codes involving "only a computer analysis" and "no laboratory methods" would be pulled off the Clinical Laboratory Fee Schedule, with initial prices crosswalked from the most recent CLFS price (Applied Policy). Table 61 ranges widely: automated retinal image analysis, FFR derived from CT angiography, fracture-risk software, concussion eye-movement analysis, algorithmic ECG risk scoring, quantitative brain MRI, cardiac arrhythmia simulation, prostate cancer estimation mapping, perivascular fat cardiac risk, 3D anatomical segmentation. Outpatient comments closed Monday, August 31; the physician fee schedule proposal closes September 14 (Wilson Sonsini).

Why it matters

This is the biggest reshaping of medical-AI reimbursement architecture in a decade, and what it does is ontological: CMS is declaring that clinical software is neither a cloud service nor a lab test but a category of medical service in its own right. For digital pathology and algorithmic-test companies currently billing through the CLFS, this is the floor being pulled up and relaid. CMS itself concedes this is an interim framework, with a full valuation methodology to follow next year. Note the live conflict of direction: the AMA's CPT process is heading the opposite way, bringing digital pathology services under pathology coding with CLIA licensure and lab-director documentation (Discoveries in Health Policy, 2026-08). Same service: the payer wants to call it software, the coders want to call it a lab test.

Discount this

This is a proposed rule that would not take effect until January 1, 2027, and only if finalized. On the physician side CMS explicitly declines to set a national rate, leaving pricing to local Medicare Administrative Contractors — meaning the same algorithm may be worth different sums in different states. We were also unable to obtain the volume or content of comments actually filed before Aug 31; trade-association positions will have to wait for the final rule.

EU · AI Act Digital OmnibusMDR / IVDR5/13

The EU defers high-risk obligations for device AI a full year to Aug 2, 2028 — and lets sectoral law like the MDR offset AI Act requirements

What

The Digital Omnibus provisional agreement was reached on May 6, 2026 and confirmed by the Council on May 13, replacing the Commission's conditional trigger mechanism with fixed dates: stand-alone Annex III systems move to December 2, 2027, and AI embedded in regulated products under Annex I — medical devices among them — moves to August 2, 2028 (Gibson Dunn, DLA Piper). The agreement adds a further mechanism: the Commission is empowered to limit specific AI Act requirements where sectoral legislation already imposes equivalent obligations. For device makers already tightly bound by the MDR and IVDR, that is an acknowledgement of the duplicate-regulation problem.

Why it matters

The deferral moves the EU off the position of first jurisdiction to set hard rules for medical AI. The rules were, in fact, already written: MDCG 2025-6 / AIB 2025-1 established that devices requiring third-party notified body assessment under the MDR or IVDR — Class IIa and Class B and above, which is most AI devices — automatically qualify as high-risk under AI Act Article 6(1); that "Annex I of the AIA prevails" where both regimes apply; and that manufacturers can fold AI Act testing into existing MDR/IVDR conformity assessment rather than running a parallel process (Bird & Bird). The rulebook exists; it simply is not switched on. The consequence is that for the next two years, effective rule-setting for medical-device AI worldwide falls back to Washington.

US · Preemption DOJ AI Litigation Task ForcexAI v. Colorado4/24

Justice takes an executive order to court against the states: Colorado's AI Act suspended — and health care is not on the exemption list

What

The executive order "Eliminating State Law Obstruction of National Artificial Intelligence Policy" was signed on December 11, 2025, directing the Attorney General to stand up an AI Litigation Task Force within 30 days and the Commerce Secretary to publish an inventory of "onerous" state AI laws within 90 days. The task force is authorized to challenge state laws as unconstitutionally regulating interstate commerce, preempted by federal regulation, or otherwise unlawful (Maynard Nexsen). On April 24 the DOJ joined xAI's suit against the Colorado AI Act, and enforcement of that law was subsequently suspended (Axios, 2026-04-24, Jenner & Block).

Why it matters

The Maynard Nexsen analysis makes the key point: the order does not list health care among its exemptions. That leaves California's transparency and patient-consent requirements, Colorado's bias-audit mandates (named in the order itself), Utah's AI disclosure rules, Texas's AI malpractice standards, New York's algorithmic pricing disclosure and Washington's health data protections all exposed to federal funding withholding and litigation. Put another way: while the FDA is still circulating a discussion paper and CMS is still taking comments, the federal government is dismantling the layer the states have already built.

Discount this

Suspended enforcement is not a final judgment; the Colorado case is still live. We could not obtain the full procedural history (the Norton Rose Fulbright write-up is blocked by robots.txt), so the sequence above is assembled from Axios and law-firm client alerts.

US · State Law Prior AuthAI Therapy Bans2026

State legislatures have passed 15 health-AI laws this year: seven on prior authorization, five banning AI therapy — four of them taking effect this summer

What

On prior authorization: Alabama SB 63 (enacted Apr 17, effective Oct 1 — insurers must disclose AI use and denials must be made by licensed physicians); Colorado HB 1139 (enacted Jun 2, effective Jan 1, 2027); Georgia SB 444 (enacted May 5, effective Jan 1, 2027, barring coverage decisions made solely by AI); Iowa HF 2635 (enacted May 13, allowing AI first-pass review but no denial, delay or downgrade based solely on AI); Utah SB 319 (enacted Mar 19, effective Jan 1, 2027); Washington SB 5395 (enacted Mar 23, effective Jun 11 — "artificial intelligence shall not be the sole means used to deny, delay, or modify health care services"); Illinois SB 3114 (awaiting signature, barring automated downcoding without human review). On AI therapy: Colorado HB 1195 (enacted Jun 3, effective Aug 12); Maine LD 2082 (enacted Apr 13, effective Jul 29, violations constituting unfair trade practices); Rhode Island H 7349 and S 2197 (enacted Jun 22, effective Jan 1, 2027); Tennessee SB 1580 (enacted Apr 1, effective Jul 1, prohibiting AI systems from advertising as qualified mental health professionals); Vermont H 816 (enacted and effective Jun 17). Plus Iowa HB 475 (verbal disclosure before AI transcription, effective Aug 1) and Utah SB 150 (Transparency Coalition line-by-line).

Why it matters

Read alongside the previous story, this is the whole picture of US health-AI regulation today: states are landing a dozen-plus laws a year, and the federal government is taking them apart by executive order and litigation. For a health-AI company operating across state lines, the compliance cost comes not from any one statute but from the uncertainty about which ones still count. The mental-health chatbot segment is the sharpest case — the five bans are worded differently: some prohibit AI independently delivering therapy, some prohibit AI holding itself out as a professional, some restrict how licensed clinicians themselves may use AI. Those three framings demand entirely different product changes.

US · FDA CDS GuidanceGeneral Wellness1/6

Looking back at January's CDS guidance: FDA relaxed the single-recommendation rule but said nothing about generative AI — August's discussion paper is filling that hole

What

The revised Clinical Decision Support software guidance of January 6 made one substantive change: it reversed the 2022 prohibition on singular recommendations. A CDS tool that offers a single recommendation now falls within enforcement discretion where clinically appropriate. The guidance also clarified that software analyzing a radiologist's findings to generate report summaries and diagnostic recommendations qualifies, provided clinicians stay in the loop and recommendations derive from well-accepted sources. But Covington's read flags a conspicuous silence: an update the FDA framed as AI-focused contains no provisions at all on generative AI, LLM-based tools, or consumer-facing decision support (Covington & Burling). The same day, FDA also loosened the boundary around wearables and general wellness products (STAT, 2026-01-06).

Why it matters

January's silence explains why August's paper had to exist. Choosing to handle AI at the start of the year by relaxing the existing framework left the hardest part blank — and in regulation, blank defaults to unregulated, which is exactly the grey zone a great many generative health tools now occupy. August's two-axis grid is the first attempt to rule lines across that zone. The eight months from January's loosening to August's reclassification are themselves the record of the agency changing its mind about generative AI.

US · Access White OakFDA + CMS7/8

A closed-door "clinical AI demo day" at White Oak on July 8: ten companies showed AI doctors to the FDA and CMS in the same room

What

STAT reported on August 5 that FDA and CMS officials held an unannounced closed-door session at FDA's White Oak headquarters on July 8, letting officials try AI-doctor technology first-hand. The ten invited companies: Anthropic, Counsel Health, Curai, K Health, Microsoft AI, Amazon One Medical, Doctronic, Ellipsis Health, Hippocratic AI and Welldoc (STAT, 2026-08-05). The meetings had not been publicly announced before the reporting.

Why it matters

The sequence is worth noting: closed-door session July 8, two CMS proposed rules July 14–16, FDA discussion paper August 18. Not necessarily causal, but it tells you the information environment in which that two-axis grid and its "agentic conduct" benchmark were drafted. That FDA and CMS sat in the same room is not a small thing either — it means how-to-review and how-to-pay are being treated as one problem, and that industry saw the framework roughly six weeks before the public did. The thing to watch: after October 19, how much of the public docket comes from those ten.

Discount this

The STAT piece is paywalled; this account rests only on the publicly visible portion. We have no agenda, no presentation materials and no record of what officials said.

UK · MHRA AI Airlock£3.6m6/9

The UK takes a third route: the AI Airlock sandbox scales from pilot to standing pathway with £3.6m behind it

What

The MHRA secured £3.6m (about $4.8m) in April to expand its AI regulatory sandbox (Digital Health, 2026-04) and published Phase 2 findings from AI Airlock on the official MedRegs blog on June 9 (MHRA MedRegs, 2026-06-09). Analysts read the programme as moving from pilot sandbox to a scalable regulatory pathway for AI medical devices (Fieldfisher).

Why it matters

Three jurisdictions, three methodologies: the US consults then writes guidance (slow, but with a defined endpoint); the EU wrote the rules then postponed switching them on (clear rules, uncertain timing); the UK lets products actually run in a controlled setting and generates evidence as they go (fast, scalability unproven). The £3.6m figure argues against over-reading this — it is a small programme. But for a mid-sized market with limited regulatory resource, a sandbox is often the only affordable move, which makes how this one ends worth watching from Taipei.

02 — Product Analysis

One LLM device already cleared, and one regulatory mechanism still on paper — both answer the same question: when the foundation model changes underneath, who owns the risk

UpDoc (K253281)

First FDA-cleared LLM-enabled agent device · UpDoc (US) · 2025-12-23

Function and position. A prescription software medical device for insulin management in adults with type 2 diabetes, cleared via 510(k) on December 23, 2025, with Hygieia's d-Nav System (K181916) as predicate — also a type 2 insulin dosing calculator. Architecturally it is conversation on the outside, structured data in the middle, protocolized clinical decision support at the core. Providers configure dosing instructions, algorithms, glucose targets and safety protocols; the insulin-dosing logic itself is deterministic and not decided by the LLM (Innolitics teardown).

  • Strength : it demonstrates a clearable architecture — keep the LLM outside the deterministic core and let it handle only conversation and information gathering. Change controls that must "preserve deterministic insulin dosing logic and core clinical decision-making" effectively wall model drift off from clinical output. It is a worked example of the low-independence cell in August's two-axis risk grid.
  • Concern : the FDA public record does not identify the foundation model, prompt stack, temperature, top-p, model version, runtime orchestration pattern, validation harness or prompt/configuration management system. 2024 reporting mentioned GPT-4, Google Cloud MedLM and Vertex AI, but the clearance documents name none of it. Nobody outside can tell whose model runs under this device, or what happens when that model is revised. Which is precisely the problem the Foundation Model Device Master File is meant to solve.

Foundation Model Device Master File

Proposed regulatory mechanism (voluntary) · FDA DHCoE · Discussion paper Section VII

Function and position. It extends the existing Master File device mechanism to foundation models: a model vendor may voluntarily file confidential model information, and downstream device makers reference that file in their own submissions instead of having to obtain or disclose the upstream model's internals themselves. What it is designed to catch is the problem the paper's Question 24 states outright — how change management works when a third-party foundation model is revised (Innolitics).

  • Strength : it is the only concrete institutional design on the table for the fact that a device's upstream supply chain is now a closed model. The UpDoc case shows the problem is real — the clearance record simply does not contain the model's identity. A master file lets commercial confidentiality and regulatory visibility coexist, at least in principle, without either side conceding.
  • Concern : it is voluntary, and the FDA's own Question 25 asks how the incentive structure should be designed — an admission that no incentive currently exists. OpenAI, Google and Anthropic are under no legal obligation to file model information with the FDA, and health care is not where their main customers are. If the upstream does not participate, the mechanism simply pushes responsibility back onto the downstream device maker more explicitly: with no master file to reference, you must evidence the whole chain yourself. And the discussion paper is not guidance and commits to no timeline.

03 — Companies & Competition

Who stands where, on what, against whom
Company Recent state & numbers Position & moat
HeartFlow
FFR derived from CT angiography
The Medicare outpatient national rate is "just over $1,000" per analysis, among the highest paid to any imaging AI (STAT, 2025-11-11); CMS had previously raised its CCTA outpatient reimbursement (Cardiac Interventions Today). "FFR derived from CT angiography" is the SaMS Table 61 category it sits in. The moat is the reimbursement plus entrenched cardiology workflow, not the model. The weakness sits in the same place: if the final rule revalues SaMS, the revenue base is renegotiated.
Cleerly
Coronary plaque quantification
Named by STAT alongside HeartFlow and Elucid as a principal beneficiary of expanding Medicare coverage for AI heart scan analysis — in a piece that also asks whether the price is too high (STAT, 2025-11-11). Head-to-head with HeartFlow for the same cardiology accounts, differentiated by measuring plaque composition rather than flow. The external risk is identical for both: the payer's judgment about the whole category's worth.
Perspectum
LiverMultiScan · quantitative liver MRI
LiverMultiScan is named in the SaMS Table 61 of the CY2027 OPPS proposal (Discoveries in Health Policy), and would fall under the new O1 status indicator and New Technology APC pricing. The moat is the clinical validation behind its quantitative imaging biomarkers, an asset that becomes more valuable under SaMS, since the new category rewards exactly an independently priceable diagnostic output.
Optellum
Lung Cancer Prediction · nodule risk
Optellum Lung Cancer Prediction is likewise named in Table 61 (Nixon Law Group); the company secured a New Technology APC as far back as 2022 (The Imaging Wire, 2022). A small early mover — and CMS's proposed "equitable adjustment" freezing CY2026 rates for low-volume software exists precisely to keep products like this from being cut by thin claims data.
UpDoc
LLM agent · diabetes insulin management
K253281, cleared December 23, 2025, predicate Hygieia d-Nav (K181916) — on the public record, the first FDA-cleared LLM-enabled agent device (Innolitics). The moat is the regulatory precedent that clearance letter establishes, not the technology. Anyone can copy the LLM-outside, deterministic-core architecture — but UpDoc has a predicate to cite and later entrants do not.
Hippocratic AI · K Health · Counsel Health
AI clinicians / clinical agents, on the July 8 White Oak list
Among the ten invited to the July 8 FDA/CMS closed-door session alongside Anthropic, Microsoft AI, Amazon One Medical, Curai, Doctronic, Ellipsis Health and Welldoc (STAT, 2026-08-05). This group's moat right now is not being regulated as devices — the grey zone left by January's CDS guidance is their operating room. The moment August's independence axis hardens into guidance, that room gets a boundary drawn around it, and they are the ones it lands on.

Close the section in one sentence: today's competition is not model against model, it is "already on the fee schedule" against "not yet classified." The companies behind those 36 codes in Table 61 are fighting a price war, and the battlefield is the CMS final rule. The ten at White Oak are fighting a classification war, and the battlefield is the FDA's two-axis grid. The two deadlines are September 14 and October 19 — five weeks apart.

04 — Taiwan Angle

Taiwan's implementing rules will land in the gap between the FDA's comment deadline and the CMS final rule

(1) The timing coincidence is worth noting. Lee Chien-chang, director of the Ministry of Health and Welfare's Department of Information Management, said on August 6 that draft implementing rules for AI in health care are expected within three months, built around the seven principles of Taiwan's Basic Act on Artificial Intelligence — transparency, privacy, accountability, safety, equity, sustainability and human autonomy — defining "what conduct does not harm these seven principles, and what conduct counts as harm" (CNA, 2026-08-06). Three months lands in November: the FDA docket closes October 19, and the CMS final rule customarily arrives around the same time. Taiwan is not behind here — it is moving while everyone else's answer is still in draft.

(2) The gap in legal force between a guideline and implementing rules is the point of this story. The Ministry's Guidelines on the Use of Generative AI in Healthcare Institutions, issued May 29, 2026 (ref. 1151663164), set five core principles and nine specific items across three phases, covering chart-writing assistance, clinical decision support, administrative documentation and patient communication at public and private hospitals and clinics — but AI agent systems with autonomous decision-making are explicitly left out for now, and the whole document is administrative guidance without binding force (Lee and Li). Lee drew the distinction plainly: guidelines are for reference and do not bind; implementing rules do. Set that against the FDA discussion paper — which is also non-binding, and which also parks agentic systems in the unresolved pile (Question 24). Both are stuck at the same place.

(3) Taiwan has no SaMS slot, and that is the real bottleneck for adoption. What CMS is doing amounts to building clinical software its own room on the fee schedule. Taiwan's National Health Insurance architecture has no matching category, and clinician willingness plus NHI reimbursement have long been identified as the two gates on medical-AI adoption here (DIGITIMES). The TFDA has stood up a dedicated smart medical device project office (MOHW) and maintains an AI/ML device matchmaking platform and approvals list (AI/ML Medical Device Platform, TFDA approved AI/ML device list) — so the can-it-be-marketed half is institutionally handled. What is missing is who pays once it is.

(4) FHIR Box is Taiwan's own bet on the distribution layer. The same report notes the Ministry's cross-institution health record exchange platform, FHIR Box, is due to go live by the end of this year, targeting interoperability across all of Taiwan's medical centres and reaching roughly 80% of healthcare institutions within three to five years (CNA, 2026-08-06). Worth contrasting with the US: there the distribution layer sits with a handful of EHR vendors, here the regulator is building it. Whoever controls distribution effectively decides which AI tools reach the bedside — and that structural difference may shape Taiwanese medical AI for longer than any set of implementing rules.

05 — Further Reading

Chosen on one test: whether it lets you read the primary documents yourself before the September 14 and October 19 deadlines
  1. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback — FDA (2026-08-18)

    The primary document. Its 26 questions are the list of what the agency has not settled — more honest than any secondary read of it.

  2. FDA Releases Generative AI Medical Device Discussion Paper: What's Inside — Innolitics (2026-08)

    A section-by-section teardown that flattens out the ten benchmarks and five clinical confirmation routes — the most usable guide currently available.

  3. Health Reimbursement Signals: CMS Proposes Payment Frameworks for "Software as a Medical Service" — Wilson Sonsini (2026-07)

    Puts the OPPS and PFS proposals side by side and explains why the physician-side proposal is far more conservative than the outpatient one.

  4. EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn (2026)

    Brussels changed more than dates: it added a power to limit AI Act requirements where sectoral law already imposes equivalents. The long-run effect of that clause is widely underrated.

  5. States have passed new laws this year regulating the use of AI in health care — Transparency Coalition (2026)

    Enactment and effective dates state by state, bill by bill — the most usable compliance checklist around. Read it against the preemption fight to see where the exposure actually is.

  6. Navigating the interplay of MDR and AIA: New MDCG Guidance on Medical Device AI — Bird & Bird

    If your product is heading for the EU, this explains why most AI devices land in high-risk automatically, and how to fold AI Act testing into an existing MDR assessment.

06 — References

References
  1. FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices. U.S. Food and Drug Administration, 2026-08-18. fda.gov
  2. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback (Docket FDA-2026-N-7874). FDA Digital Health Center of Excellence, 2026-08-18. fda.gov
  3. FDA Releases Generative AI Medical Device Discussion Paper: What's Inside. Innolitics, 2026-08. innolitics.com
  4. FDA Opens Comment Period on GenAI Device Regulation. MD+DI, 2026-08. mddionline.com
  5. FDA Seeks Input on the Future of GenAI-Enabled Medical Device Oversight. Hall Render, 2026-08-26. hallrender.com
  6. FDA digital health leader promises generative AI regulatory guidance is coming. STAT News, 2026-08-24. statnews.com
  7. Federal regulators invite industry, researchers, and lobbyists to closed-door meetings on clinical AI. STAT News, 2026-08-05. statnews.com
  8. STAT Health Tech: FDA rejects proposal to deregulate AI devices. STAT News, 2026-04-09. statnews.com
  9. FDA relaxes oversight of AI-enabled devices and wearables. STAT News, 2026-01-06. statnews.com
  10. Medicare will pay more than $1,000 for AI to analyze a heart scan. Is that too much? STAT News, 2025-11-11. statnews.com
  11. 5 Key Takeaways from FDA's Revised Clinical Decision Support (CDS) Software Guidance. Covington & Burling LLP, 2026-01. cov.com
  12. FDA "Cuts Red Tape" on Clinical Decision Support Software and Wearable Products for General Wellness. Arnold & Porter, 2026-01. arnoldporter.com
  13. UpDoc: First FDA-Cleared AI Agent and LLM Enabled Device Confirmed (K253281). Innolitics. innolitics.com
  14. Health Reimbursement Signals: CMS Proposes Payment Frameworks for "Software as a Medical Service". Wilson Sonsini, 2026-07. wsgr.com
  15. What is Software as a Medical Service (SaMS) under the 2027 OPPS Proposed Rule? Nixon Law Group, 2026. nixonlawgroup.com
  16. The 2027 OPPS Proposed Rule: CMS Wrestles Actively with Software as a Medical Service (SaMS). Discoveries in Health Policy, 2026-07. discoveriesinhealthpolicy.com
  17. Very Brief Blog: CMS OPPS CY2027 Comment Due Aug 31. Discoveries in Health Policy, 2026-08. discoveriesinhealthpolicy.com
  18. CMS Begins Building a New Medicare Payment Framework for Diagnostic Software. Applied Policy, 2026. appliedpolicy.com
  19. CMS Proposes an Interim Payment Policy for Software as a Medical Service in Outpatient Rule. Reed Smith, 2026. reedsmith.com
  20. Medicare and Medicaid Programs; CY 2027 Payment Policies Under the Physician Fee Schedule (CMS-1848-P). Federal Register, 2026-07-16. federalregister.gov
  21. Calendar Year (CY) 2027 Medicare Physician Fee Schedule Proposed Rule — Fact Sheet. CMS, 2026-07. cms.gov
  22. CY 2027 OPPS/ASC Payment System Proposed Rule Takeaways. McDermott+, 2026-07. mcdermottplus.com
  23. ATA Action Initial Comments on the CY2027 Physician Fee Schedule Proposed Rule. American Telemedicine Association, 2026. americantelemed.org
  24. EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes. Gibson Dunn, 2026. gibsondunn.com
  25. The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act. DLA Piper, 2026. dlapiper.com
  26. AIB 2025-1 / MDCG 2025-6: Interplay between the Medical Devices Regulation, IVDR and the AI Act. European Commission, 2025-06. health.ec.europa.eu
  27. Navigating the interplay of MDR and AIA: New MDCG Guidance on Medical Device AI under the EU AI Act. Bird & Bird. twobirds.com
  28. Trump's Executive Order on AI and the Potential Impact on State Healthcare Laws Governing AI. Maynard Nexsen, 2026. maynardnexsen.com
  29. Justice Department joins xAI challenge to Colorado AI law. Axios, 2026-04-24. axios.com
  30. DOJ Joins xAI in Lawsuit Challenging Colorado AI Act. Jenner & Block, 2026. jenner.com
  31. DOJ Intervenes in Lawsuit Challenging Colorado's 'Algorithmic Discrimination' Law. National Law Review, 2026. natlawreview.com
  32. States have passed new laws this year regulating the use of AI in health care. Transparency Coalition, 2026. transparencycoalition.ai
  33. States Continue Efforts to Regulate AI in Healthcare: A Review of Legislation Passed in 2026. Holland & Knight, 2026-05. hklaw.com
  34. AI therapy chatbots draw new oversight as suicides raise alarm. Stateline, 2026-01-15. stateline.org
  35. MHRA secures £3.6m to expand AI regulatory sandbox. Digital Health, 2026-04. digitalhealth.net
  36. Advancing AI Regulation in Healthcare: Insights from AI Airlock Phase 2. MHRA MedRegs Blog, 2026-06-09. medregs.blog.gov.uk
  37. MHRA AI Airlock: from pilot sandbox to scaling regulatory pathway for AI medical devices. Fieldfisher, 2026. fieldfisher.com
  38. AI Airlock: the regulatory sandbox for AIaMD. GOV.UK. gov.uk
  39. HeartFlow's CCTA Outpatient Reimbursement Increased by CMS. Cardiac Interventions Today. citoday.com
  40. Optellum's NTAPC. The Imaging Wire, 2022-06-29. theimagingwire.com
  41. 厚生會成立智慧醫療委員會 衛福部擬提 AI 醫療細則草案. 中央社 CNA, 2026-08-06. cna.com.tw
  42. 衛福部頒布「醫療機構應用生成式人工智慧指引」. 理律法律事務所, 2026. leeandli.com
  43. 食品藥物管理署智慧醫療器材專案辦公室成立. 衛生福利部. mohw.gov.tw
  44. 核准應用 AI/ML 技術之醫療器材清單公告. 衛生福利部食品藥物管理署. fda.gov.tw
  45. 智慧醫療器材資訊暨媒合平台. 衛生福利部食品藥物管理署. aimd.fda.gov.tw
  46. AI 醫療創新加速 醫師採用意願與健保給付成落地挑戰. DIGITIMES. digitimes.com.tw
Editor's note: (1) All four STAT News citations from this period (2026-08-24, 2026-08-05, 2026-04-09, 2026-01-06) and the 2025-11-11 piece sit behind STAT+. This report draws only on publicly visible headlines, standfirsts and readable passages; the Rick Abramson quotation comes from a publicly readable portion. (2) The Norton Rose Fulbright analysis of xAI v. Colorado is blocked by robots.txt, so that sequence is assembled from Axios and law-firm client alerts; no court filings were obtained. (3) The covering window is Aug 18–Sep 2, longer than the usual seven days, because the FDA discussion paper (Aug 18) and the two CMS comment deadlines (Aug 31, Sep 14) form one event; a hard seven-day cut would sever the through-line. The EU Omnibus (May), the White House executive order (Dec 11, 2025), the FDA CDS guidance (January) and the MHRA items (April–June) are clearly dated background, not new events. (4) Products named in Table 61 (LiverMultiScan, Optellum Lung Cancer Prediction and others) are taken from secondary summaries by Discoveries in Health Policy and Nixon Law Group; we did not verify each against the Federal Register table itself, and no vendor attribution was written in where a source did not name one. (5) HeartFlow's "just over $1,000" is the Medicare national rate as reported by STAT rather than a company figure, but we could not obtain the corresponding HCPCS code or fee-schedule entry. (6) We could not obtain the number, identity or content of comments actually filed with CMS before the August 31 deadline.