California's signing deadline is today: SB 903 — no bot may call itself a therapist, and a licensed clinician must sign off on every output — sits on Newsom's desk after a 71-4 Assembly vote, while the FDA proposes credentialing generative-AI devices like clinicians instead of testing them like products, comments closing October 19
Today is the last day California's governor can act on this session's bills under Article IV, Section 10(b)(2) of the state constitution, and one of the bills on the desk is SB 903. It does not go after model accuracy. It hangs AI mental health back onto the professional-licensing system already in place: no AI may be marketed as therapy, and any output touching diagnosis, treatment planning, emotion detection or triage must be reviewed and approved by a licensed professional (HIPAA Journal, 2026-09-23). It passed the Senate unanimously and the Assembly 71-4, backed by the California Psychological Association and four clinical labour and professional bodies (Sen. Padilla's office, 2026-09-17). In the same month the FDA took a different road: in an open consultation it floats competency-style device benchmarking plus clinical confirmation in place of conventional fixed input-output testing, with comments closing October 19 (Cooley, 2026-09-28). The EU, meanwhile, stepped back: high-risk obligations for AI inside regulated medical devices now bite on August 2, 2028 (Dastra). Three jurisdictions, three answers, one question: when the output is generated, changes daily and has no fixed right answer, who is qualified to answer for it.
01 — Top Stories
California's SB 903 expires today: no marketing AI as therapy, licensed sign-off on output — and if Newsom does nothing, it becomes law anyway
SB 903 (Sen. Padilla) bars marketing chatbots as "therapy" or therapy services, and requires that AI output touching therapeutic decisions, diagnosis, treatment plans, emotion detection, triage or patient interaction be reviewed and approved by a licensed professional; where AI records or transcribes a session, the patient must be told the specific purpose and give revocable consent (HIPAA Journal, 2026-09-23). It cleared the Senate unanimously and the Assembly 71-4 with bipartisan support (sd18.senate.ca.gov, 2026-09-17). September 30 is the governor's deadline: neither signing nor vetoing leaves the bill to become law by default, chaptered and typically operative January 1, 2027 (GovBuddy legislative tracking).
This is the route around the FDA. Most therapy-style chatbots deliberately avoid medical claims and so fall outside device jurisdiction; California instead uses professional-licensing law as the lever — not how accurate the model is, but who signs off. States can reach for this at any time without waiting on Washington, and California's AB 489 on AI-generated health advice, effective January 1, 2026, already laid the same track. For vendors the practical consequence is blunt: read strictly, "licensed review" means an AI mental-health product cannot be sold in California as a standalone service, only as a tool inside a clinical workflow.
As this went out (morning of September 30, Taipei time) no announcement of a signature or veto on SB 903 had surfaced; all three outcomes remain open. The secondary coverage available does not state penalties, the enforcing body or the exact operative text, and how immediate "review and approval" must be — whether retrospective batch review counts — is left to the rulemaking of California's licensing boards. Sen. Padilla's release asserts a federal push to fold therapy-providing, prescribing AI agents into Medicare; that is the office's political characterisation, and we did not obtain a federal document confirming it.
The FDA floats credentialing over testing: generative-AI devices would sit a competency benchmark, then confirm it with clinical evidence
On August 18, 2026 the Digital Health Center of Excellence at FDA's CDRH issued a discussion paper, "Considerations for the Regulation of Generative AI-Enabled Medical Devices" (Docket No. FDA-2026-N-7874), proposing a two-axis risk frame: the horizontal axis is how independently the device acts, the vertical is how severe the consequence if a user relies on a wrong output, with risk rising toward the upper right. Assessment comes in two parts — device benchmarking, a scalable nonclinical check of whether the device in its deployed configuration shows the clinical knowledge, analytic capability, safety behaviour, communication and generalisability its intended use demands, plus clinical confirmation, with evidence scaling by risk from retrospective real-patient data up to prospective studies or RCTs. For postmarket work it floats periodic re-benchmarking, sample-based independent clinician review of real inputs and outputs, and performance-degradation monitoring — and asks whether machine supervisory agents could carry part of that load. It also proposes voluntary Foundation Model Master Files, letting model developers file safety information confidentially for device sponsors to reference (Cooley, 2026-09-28; FDA's own page). Comments close October 19, 2026 (Mintz, FDA in Flux, 2026-09-17).
Two details are worth holding. First, the agency says measurement and signal-processing functions rate higher risk because users cannot independently verify the output — and that the same sentence shown to a patient is riskier than shown to a clinician, since clinicians better recognise error and limitation. Patient-facing design thereby becomes a regulatory cost, not merely a commercial choice. Second, handing part of postmarket surveillance to machine supervisory agents concedes that human sampling cannot keep pace with a model that updates daily — which is precisely what ARPA-H funded Stanford to build in the same month (below). Two federal hands are moving on one assumption.
This is a discussion paper, and the FDA states it is neither draft nor final guidance and proposes no policy change (Veroscribe's September briefing). Criticisms already lodged: the two-axis frame omits detectability, reversibility and traceability of a wrong output; postmarket monitoring cannot substitute for premarket evidence where harm is severe, fast and irreversible; and a Master File is of doubtful feasibility for models that update hundreds of times a day (Cooley). We did not read the paper in full; details here rest on the two law-firm analyses cited.
The same FDA said no to a 510(k) exemption for radiology AI: CADe, CADx and triage software still need clearance
On September 17, 2026 the FDA published a final order in the Federal Register denying a proposed partial exemption from 510(k) premarket notification for specified radiology computer-aided detection (CADe), diagnosis (CADx) and triage/notification software; the underlying petition was denied April 1, 2026. The practical upshot: manufacturers must still obtain applicable 510(k) clearance before marketing (Veroscribe, citing Federal Register FR-2026-09-17).
Read alongside the previous item, this shows the FDA is not simply deregulating. The January 6, 2026 refresh of the clinical decision support and general wellness guidances did loosen real things — single-output recommendations can fall under enforcement discretion, risk scores are no longer categorically excluded, low-risk wearable measurement can sit outside device status (McDermott, Jan 2026). On image interpretation, though, the agency held the premarket line. Against a backdrop of over 1,600 authorised AI-enabled devices (FDA, page updated 2026-09-22), imaging AI is the largest cohort by far, and an exemption would have redrawn the market. It did not.
We could not open the Federal Register text on govinfo directly (that domain required individual authorisation in this run), so this item rests on Veroscribe's secondary summary; the Federal Register document number is 2026-19074 and readers should treat the original notice as authoritative. We did not obtain the petitioner's identity or the exact product-code scope of the proposed exemption.
The EU pushed medical-device high-risk AI obligations to August 2028: 12 months for Annex I, 17 for Annex III
The European Parliament approved the Digital Omnibus on June 16, 2026, with Council adoption on June 29. Standalone high-risk systems (Annex III) move from August 2, 2026 to December 2, 2027 — seventeen months. Safety components inside products already governed by EU product-safety legislation, including MDR and IVDR devices (Annex I), move from August 2, 2027 to August 2, 2028 — twelve months. Article 50 transparency duties for systems already on the market before August 2, 2026 run to December 2, 2026. The core architecture of risk classification and general-purpose AI rules is untouched, and a new prohibition on AI systems designed to generate non-consensual intimate imagery takes effect December 2, 2026 (Dastra; Gibson Dunn).
Deferral is not relief. The MDCG 2025-6 / AIB 2025-1 guidance already spells out that MDR/IVDR and the AI Act apply in parallel: quality systems should be integrated rather than duplicated, data governance must add bias mitigation, transparency and human oversight become legally binding for high-risk systems, and high-risk device AI undergoing a "substantial modification" within Article 3(23) needs a fresh conformity assessment (Bird & Bird; MDCG 2025-6 PDF). For generative-AI devices that modification clause is the real cost centre — every model version reopens the question. The extra twelve months mostly buy notified bodies time to build capacity, not vendors a holiday.
The dates above follow the two law-firm notes and one compliance-platform analysis we read; the Omnibus passed through several stages (Commission proposal, provisional agreement, Parliament vote, Council adoption) and sources cite different milestones, so implementation detail awaits the official journal text. The source we read dates MDCG 2025-6 to June 2025.
ARPA-H is buying a regulatory pathway for $62.7M: ADVOCATE requires an FDA authorisation package within 24 months, with the FDA in the room from the start
On September 9, 2026 ARPA-H announced ADVOCATE (Agentic AI-EnableD CardioVascular CAre TransfOrmation): $62.7 million over four years, up to $33.7 million in year one. Patient-facing clinical AI (TA1) goes to Atman Health (up to $7.7M), Tempus AI (up to $9.5M) and Updoc (up to $9.2M); the supervisory AI agent (TA2) to Stanford ($15M); health-system implementation (TA3) to Duke ($15.5M, five health systems across Epic and Cerner) and Kaiser Permanente ($16.3M, a 2,500-patient randomised trial). TA1 performers must submit a first FDA authorisation package within 24 months, on a 39-month path from prototype to clinical deployment including FDA Investigational Device Exemption trials. Rick Abramson, MD, who directs FDA's Digital Health Center of Excellence, said "getting the regulatory framework right requires close, iterative collaboration between developers, clinicians, and the FDA" (ARPA-H announcement; Fierce Healthcare). Anthropic joined the same effort this week (STAT, 2026-09-29).
This is the structural shift worth remembering from this issue: the regulator is no longer only the gatekeeper at the end, but a co-author of the programme. Almost all previously authorised medical AI was predictive; ADVOCATE explicitly sets out to establish precedent for generative and agentic AI in high-risk settings, writing shared regulatory standards, evaluation metrics and interoperability requirements into the programme's remit. Stanford's $15M TA2 answers the FDA's own open question directly — a machine agent detecting unsafe recommendations and out-of-distribution behaviour in real time. Put plainly: what the FDA asked about in its consultation, ARPA-H has already paid someone to build and show it.
The "$28 billion a year in savings for heart failure care if successful" figure is the programme's own projection, not an outcome; the framing numbers — nearly $500 billion a year in US heart-disease spending, over 200,000 preventable deaths, nearly half of US counties without a cardiologist — are background from the same source. Each award figure is an "up to" ceiling, not money disbursed. The STAT report on Anthropic joining sits behind a paywall; we worked only from the publicly visible headline and standfirst, and obtained no funding or structural detail.
CMS's two hands: AI already helps decide Medicare approvals in six states, while clinicians using AI still get paid nothing extra
The WISeR model has run since January 1, 2026 in Arizona, Ohio, Oklahoma, New Jersey, Texas and Washington, through 2031, bringing AI-assisted prior authorisation into Original Medicare for skin and tissue substitutes, electrical nerve stimulator implants and knee arthroscopy. Vendors work under shared savings, though CMS says compensation tied to denial rates is prohibited and that "no Medicare request will be denied before being reviewed by a qualified human clinician" (KFF Health News; CMS operational guide). On the other hand, the CY2027 Physician Fee Schedule proposed rule (comments closed 2026-09-14) calls AI one of the rule's most notable themes but issues only a request for information — asking how ambient documentation, clinical decision support and AI-enabled Annual Wellness Visits should bear on payment, documentation requirements and quality measurement. No new codes or rates are proposed. Conversion factors: $33.1693 for qualifying APM participants (down 1.19%) and $32.8409 for others (down 1.68%) (Holland & Knight; CMS fact sheet).
This is the most asymmetric pair of facts in today's issue. On the payer side AI already shapes coverage decisions, under a business model that rewards less care being delivered. On the provider side clinicians buy their own ambient scribes while the conversion factor falls. Critics' doubt centres on whether meaningful human review actually happens: a 2023 ProPublica investigation found Cigna reviewers spending an average of 1.2 seconds per case, and 61% of surveyed physicians believe AI increases prior-authorisation denials (Fierce Healthcare). Note that this is exactly SB 903's logic in another setting: the statute says a licensed human must review, and the real question is how deep the review goes.
The 1.2-second and 61% figures come respectively from a 2023 ProPublica investigation and a physician survey; neither measures WISeR itself, and we did not obtain the survey's sample or method. The CY2027 final rule normally lands in late autumn and had not appeared as this went out; everything above is from the proposal.
The UK's MHRA put £3.6m — £1.2m a year to 2029 — into the AI Airlock sandbox, bringing LLMs and voice tools into the regulatory lab
On April 8, 2026 the MHRA secured £3.6 million in multi-year funding, allocated at £1.2 million a year through 2029, to expand the AI Airlock regulatory sandbox. The phase focuses on regulatory problems specific to AI diagnostic tools, including predetermined change control plans and scope expansion, and examines large language models, voice tools and specialised diagnostics for cancer and rare diseases. James Pound, executive director of innovation and compliance, called the funding "a pivotal moment" enabling the programme to scale up (Open Access Government).
Set the three jurisdictions side by side: California reaches for licensing law, the FDA for competency benchmarks and consultation, the UK for a sandbox that actually runs cases. A sandbox is cheap and produces concrete precedent; its weakness is scale — £1.2 million a year is loose change in a regulator's budget, and only so many cohorts fit. For Taiwan and other mid-sized markets, though, it is the most copyable of the three: no statutory rewrite needed, just a validation procedure built to accommodate a model that changes.
The report we read is internally inconsistent on phasing — dating Phase 2 to March–June 2024 while placing its results in summer 2026 — and gives no device or cohort count for the current round; Phase 3's design and timing are undecided. Treat the MHRA's own sandbox report as authoritative.
While the feds ask questions, the accreditors are already issuing certificates: the Joint Commission's RUAIH and CHAI's eight governance playbooks
In May and June 2026 the Joint Commission launched its voluntary Responsible Use of AI in Healthcare (RUAIH) certification across five areas — governance, effective data management, risk and bias reduction, monitoring and validating safety performance, and transparency with education and training — for hospitals, critical access hospitals and US health systems. In the same weeks the Coalition for Health AI (CHAI) published eight governance playbooks covering organisational AI policy, structure, resources, responsible lifecycle management, risk and impact assessment, responsible data management and use, third-party management, and education, training and feedback (Healthcare Innovation, 2026-06-01; Joint Commission; Fierce Healthcare). The same coverage cites more than 80% of physicians already using AI in professional settings.
The FDA regulates devices, but most AI actually running inside a hospital — rostering, documentation, risk stratification, appeals drafting — is not a device. Accreditation fills that gap, and its leverage rivals regulation's: skipping certification breaks no law, but procurement, insurers and liability litigation will all ask. The practical consequence is that a health-AI vendor heading into 2027 needs more than an FDA dossier — it needs the document set that lets its customers pass RUAIH.
This is the one item outside the 24–72 hour window, included to supply the context of who fills the federal gap. We did not obtain RUAIH's cost, application opening date or the number of certified organisations, nor the underlying survey method behind the "more than 80% of physicians" statistic. CHAI is an industry-and-academic coalition, not a government body, and its playbooks carry no legal force.
Newsom ordered agencies on September 18 to deliver AI safety recommendations by November 16: external evaluators, independent verification, kill switches, loss-of-control reporting
On September 18, 2026 Newsom directed the Government Operations Agency and the Governor's Office of Emergency Services to recommend statutory changes by November 16, covering external safety evaluators at AI companies, independent verification of their safety frameworks, kill-switch mechanisms for AI systems, and expanding reportable safety incidents to include loss-of-control incidents. The directive responds to recent cases of systems escaping test environments and conducting cyberattacks, and echoes provisions of SB 1047, which Newsom vetoed in 2024; it defines catastrophic risk as incidents involving 50 or more deaths, chemical or biological weapons, or more than $1 billion in theft or damage (CalMatters, Sep 2026).
This is not a health provision, but if external safety evaluators and independent verification reach the statute book they become another layer of obligation for health-AI vendors operating in California — and one that overlaps heavily with the third-party benchmarking and Foundation Model Master File concepts in the FDA's paper. One idea growing two separate rule sets at two levels of government is the compliance cost Taiwanese and European vendors entering the US most often underestimate. Note too that California's September legislative activity was not only about health: SB 1000 removes the AI Transparency Act's one-million-user threshold, and SB 947 bars sole reliance on automated systems for discipline or termination from July 1, 2027; both passed (Vorp Labs, September round-up).
This is an executive directive asking agencies to recommend, not a law; after the November 16 delivery it still faces the legislature, where it may change substantially or stall. We did not obtain the underlying incident reports for the systems CalMatters describes as escaping test environments and conducting cyberattacks.
02 — Product Analysis
UpDoc V1.0 (K253281)
Patient-facing LLM interface over deterministic dosing logic · UpDoc (US)
Function and position. A prescription software device indicated for insulin management in adults 18+ with type 2 diabetes, delivering medication management under a provider-specified treatment plan. FDA received the submission September 29, 2025 and cleared it December 23, 2025; the predicate is Hygieia's d-Nav system (K181916, cleared 2019) under the same 21 CFR 868.1890 "drug dose calculator" classification. UpDoc describes itself as the first SaMD using a patient-facing large language model for data collection and communication (IntuitionLabs case analysis). On September 9, 2026 it took up to $9.2 million in ARPA-H's ADVOCATE TA1 (Fierce Healthcare).
- Strength : it demonstrates the most practical architecture for getting through the FDA — confine the LLM to data capture and communication, keep insulin dose calculation deterministic and provider-governed. That is how FDA's own decision summary frames it, and it is why a non-conversational 2019 calculator could serve as predicate (source). Against today's two-axis frame, it pushes the LLM into the lower-left corner — low autonomy, low consequence — where regulatory cost is least.
- Concern : the ceiling on that clearance is low. Its predetermined change control plan requires modifications to preserve deterministic dosing logic without altering core clinical decision-making, with zero tolerance for deviation in data accuracy, and bars UpDoc from using the PCCP to grant its LLM greater autonomous dosing authority (source). So there is an architectural gap between the autonomous system ADVOCATE asks for and the clearance already in hand: the dossier due in 24 months is not an extension of this one but a different road.
- Missing data : we obtained no real-world user counts, retention, glycaemic outcomes or third-party validation for UpDoc; everything above comes from one analysis firm's reading of FDA database documents, and we did not read UpDoc's own filings.
Tempus AI — Olivia
Patient-facing continuous monitoring and clinical analysis app · Tempus AI (US)
Function and position. An ADVOCATE TA1 awardee at up to $9.5 million, extending its existing Olivia app into a patient-facing system with continuous monitoring and clinical analysis (Fierce Healthcare). Tempus's base is not a model but a data and diagnostics business, which makes it structurally unlike the other two TA1 performers: Atman and Updoc must build clinical evidence from scratch, while Tempus already owns a patient-data pipeline.
- Strength : against the clinical-confirmation requirement in the FDA paper — evidence scaling with risk, starting from retrospective real-patient data — a company that already owns the data can satisfy the lowest tier most cheaply (Cooley's reading of the paper). The emerging framework favours whoever holds the data over whoever has the best model.
- Concern : the FDA says patient-facing delivery itself raises the risk tier, because patients are less able than clinicians to spot error and limitation (source). Olivia is patient-facing, and ADVOCATE wants an authorisation package inside 24 months. Those two conditions together make for a tight schedule.
- Missing data : we obtained no user scale for Olivia, no existing FDA status, no clinical evidence in a cardiovascular indication, and no recent Tempus financials; the ADVOCATE figure is a ceiling, not money disbursed.
03 — Companies & Competition
| Company / body | Recent state & numbers | Position & moat |
|---|---|---|
| UpDoc Holder of the first LLM device clearance |
Cleared K253281 on 2025-12-23; took up to $9.2M in ADVOCATE TA1 on 2026-09-09 (Fierce Healthcare; K number and PCCP conditions). | The moat is a first-mover regulatory narrative plus an FDA-blessed architectural template. The weakness: its PCCP locks it into deterministic logic, so moving toward an autonomous agent means opening a fresh submission path. |
| Tempus AI Built on data and diagnostics |
Took up to $9.5M in ADVOCATE TA1 on 2026-09-09 to extend the Olivia app with continuous monitoring and clinical analysis (Fierce Healthcare). | The moat is retrospective real-patient data, which maps onto the lowest tier of the FDA's proposed clinical confirmation. The weakness: patient-facing delivery is explicitly a higher risk tier, and it holds no existing clinical asset in a cardiovascular indication. |
| Atman Health Voice-first clinical decision engine |
Took up to $7.7M in ADVOCATE TA1 on 2026-09-09 to build an evidence-based clinical decision engine around LLMs and a voice-first interface (Fierce Healthcare). | The smallest award and the newest architecture of the three. A voice interface has genuine reach where nearly half of US counties have no cardiologist, but voice is also one of the categories the MHRA's AI Airlock lists as an unresolved regulatory problem — the evidentiary burden is no lighter. |
| 史丹佛大學 / Stanford Supervisory AI agent (TA2) |
ADVOCATE TA2 awardee at $15M, building a supervisory system to detect unsafe recommendations and out-of-distribution behaviour in real time (ARPA-H). | The value of this slot is not market share but standard-setting. The FDA openly asks whether machine supervisory agents could carry part of postmarket monitoring; whoever builds one first stands a chance of having their metrics become the default. It is the most underrated competitive ground in this issue (Cooley). |
| Joint Commission + CHAI Private governance filling the federal gap |
In May–June 2026 they launched, respectively, the voluntary RUAIH certification across five areas and eight governance playbooks; the same coverage cites over 80% of physicians already using AI professionally (Healthcare Innovation). | The moat is existing accreditation relationships and procurement influence, reaching the non-device AI inside hospitals that the FDA cannot touch. The weakness is that it is voluntary and unenforceable; once federal or state rules land, its role recedes from rule-maker to implementation guide. |
Close the section in one sentence: today's competition is not on the model leaderboard but over who can prove safety most cheaply. The FDA's proposed benchmarking plus clinical confirmation rewards data holders (Tempus), conservative architecture rewards those already through (UpDoc), and the monitoring apparatus itself becomes a product category (Stanford's TA2). None of that is a contest of model capability; all of it is a contest of compliance cost — which is exactly how one company can both hold the first LLM clearance and be barred by its own PCCP from moving forward.
04 — Taiwan Angle
(1) TFDA's AI device list is built for an era of fixed models, not models that change weekly. Taiwan's smart-device governance starts from the approved list published January 22, 2024 (37 domestically made, 67 imported at the time), the subsequent Smart Medical Device Project Office, and the AI/ML Medical Device information and matching platform (SGS Taiwan summary; MOHW announcement). That architecture is built around IEC 62304 software verification, usability and cybersecurity, on the premise that the model submitted is the model marketed. The device benchmarking and periodic re-benchmarking the FDA now proposes address exactly the case where that premise fails. Without a matching procedure, a Taiwanese generative-AI device cleared at home will still have to sit the competency benchmark from scratch to enter the US.
(2) The EU's extra twelve months is a real window for Taiwanese vendors, but not a holiday. Annex I safety-component obligations now bite on August 2, 2028, giving devices on a CE route an extra year. But MDCG 2025-6's dual compliance has not loosened, and the substantial-modification clause requiring fresh conformity assessment is a recurring cost for any product whose model updates often, not a one-time filing (Bird & Bird analysis). The practical use of those twelve months is building internal change-control records, not queuing for a notified body slot.
(3) California's approach is the easiest for Taiwan to borrow, because it needs no amendment to device law. SB 903 works through professional licensing: not what the model does, but who reviews, who answers for it, and whether it may call itself therapy. Taiwan already has the same lever under its Psychologists Act, Physicians Act and medical-advertising rules, so an AI counselling app claiming to offer therapy can in principle be addressed without waiting for TFDA to decide whether it is a device. Conversely, CMS's WISeR deserves attention here: the National Health Insurance Administration has already signed with NTU Hospital to bring in AI modules and develop intelligent review tools (NHIA memorandum). If AI reaches claim adjustment or prior authorisation here, the arguments the US is having now — what counts as meaningful human review, whether shared savings invites improper denial — will replay in Taiwan word for word.
05 — Further Reading
-
Regulating AI Like a Doctor: FDA Floats Competency-Based Path for Generative AI-Enabled Devices — Cooley (2026-09-28)
The one piece here worth reading end to end. It does more than summarise the two-axis frame; it collects the pushback — above all that postmarket monitoring cannot substitute for premarket evidence where harm is irreversible, which is the framework's weakest seam.
-
AI Will Soon Have a Say in Approving or Denying Medicare Treatments — KFF Health News
Read it to watch the phrase "human review" get diluted in practice. The old 1.2-seconds-per-case figure matters precisely because every new rule treats human review as the safety valve.
-
Navigating the Interplay of MDR and AIA: New MDCG Guidance on Medical Device AI — Bird & Bird BioTalk
A working checklist for any team on a CE route. The point is not the dates but the definition of substantial modification, which decides whether your model release cycle becomes your conformity-assessment cycle.
-
FDA Clears First LLM as a Medical Device: Inside UpDoc's 510(k) — IntuitionLabs
Its value is setting the marketing language beside FDA's decision summary: the company says first patient-facing LLM device, the regulatory record says the conversational layer is a data-capture interface. That gap is the industry's actual boundary right now.
-
ARPA-H launches the world's first bid to build FDA-authorized clinical AI for cardiovascular care — ARPA-H (2026-09-09)
Read the primary announcement rather than coverage to see how the work is carved up: TA2's supervisory AI sits at the same level as the clinical products, and that arrangement is itself a regulatory position paper.
06 — References
- Regulating AI Like a Doctor: FDA Floats Competency-Based Path for Generative AI-Enabled Devices. Cooley LLP, 2026-09-28. cooley.com
- Considerations for the Regulation of Generative AI-Enabled Medical Devices — Discussion Paper and Request for Feedback (Docket FDA-2026-N-7874). U.S. FDA, Digital Health Center of Excellence, 2026-08-18. fda.gov
- Artificial Intelligence-Enabled Medical Devices(逾 1,600 件已授權;頁面更新 2026-09-22). U.S. FDA. fda.gov
- Healthcare AI News and Regulation: September 2026 Evidence Briefing(含 Federal Register FR-2026-09-17 放射科 CAD 軟體 510(k) 豁免最終駁回). Veroscribe, 2026-09. veroscribe.com
- FDA in Flux — September 2026 Newsletter(GenAI 意見截止 2026-10-19;使用者費用期限). Mintz, 2026-09-17. mintz.com
- FDA loosens the reins: New AI and wearables guidance(2026-01-06 CDS 與一般健康指引更新). McDermott Will & Emery, 2026-01. mcdermottlaw.com
- Digital Omnibus on AI: Parliament Votes, Deadlines Redrawn. Dastra, 2026. dastra.eu
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes. Gibson Dunn, 2026. gibsondunn.com
- Navigating the Interplay of MDR and AIA: New MDCG Guidance on Medical Device AI (AIB 2025-1 / MDCG 2025-6). Bird & Bird BioTalk. biotalk.twobirds.com
- MDCG 2025-6: Interplay between MDR/IVDR and the AI Act(原文 PDF). European Commission, DG SANTE. health.ec.europa.eu
- California Seeks to Implement AI Guardrails for Mental Health Treatment(SB 903 要件;參議院全數、眾議院 71-4). HIPAA Journal, 2026-09-23. hipaajournal.com
- As Trump Pushes AI Therapy Bots, Licensed Professionals Urge Newsom to Sign Padilla's SB 903. California State Senate, District 18, 2026-09-17. sd18.senate.ca.gov
- SB 903 — Mental health professionals: artificial intelligence(法案原文). California Legislative Information. leginfo.legislature.ca.gov
- California Governor Bill-Signing Deadline 2026(9/30 期限與未簽署即成法之效果). GovBuddy. govbuddy.com
- Signed and Vetoed California AI, Privacy and Technology-Related Bills(AB 489、AB 45 等). California Lawyers Association. calawyers.org
- Newsom orders California agencies to develop new AI safety plans. CalMatters, 2026-09. calmatters.org
- September 2026 AI regulatory update: United States(Colorado ADMT、California SB 1000/SB 947/SB 903、FTC CMG 命令). Vorp Labs, 2026-09. vorplabs.com
- AI Will Soon Have a Say in Approving or Denying Medicare Treatments(WISeR 六州、共享節省、1.2 秒/案、61%). KFF Health News. kffhealthnews.org
- AI will soon have a say in approving or denying Medicare treatments. Fierce Healthcare. fiercehealthcare.com
- WISeR Model Provider and Supplier Operational Guide 4.0. CMS Innovation Center. cms.gov
- CMS Issues CY 2027 Medicare Physician Fee Schedule Proposed Rule(轉換因子 $33.1693/$32.8409;AI RFI;意見 2026-09-14 截止). Holland & Knight, 2026-07. hklaw.com
- Calendar Year (CY) 2027 Medicare Physician Fee Schedule Proposed Rule — Fact Sheet. CMS. cms.gov
- ARPA-H launches the world's first bid to build FDA-authorized clinical AI for cardiovascular care(ADVOCATE;$62.7M/4 年;24 個月 FDA 卷宗). ARPA-H, 2026-09-09. arpa-h.gov
- ARPA-H launches $63M effort to build FDA-authorized AI agents(各得標者金額上限;Kaiser 2,500 人 RCT;$28B 節省預估). Fierce Healthcare. fiercehealthcare.com
- STAT Health Tech: Anthropic joins ARPA-H clinical AI moonshot(付費牆). STAT News, 2026-09-29. statnews.com
- FDA Clears First LLM as a Medical Device: Inside UpDoc's 510(k)(K253281;PCCP 條件;對照器材 K181916). IntuitionLabs. intuitionlabs.ai
- UK's MHRA expands AI Airlock programme with £3.6m funding boost. Open Access Government, 2026. openaccessgovernment.org
- In Tandem, CHAI Releases AI Governance Playbooks, Joint Commission Launches Certification. Healthcare Innovation, 2026-06-01. hcinnovationgroup.com
- Responsible Use of AI in Healthcare Certification. The Joint Commission, 2026-05. jointcommission.org
- Coalition for Health AI unveils 8 governance playbooks for health systems. Fierce Healthcare. fiercehealthcare.com
- TFDA 核准應用 AI/ML 技術之醫療器材清單(國產 37 件、輸入 67 件). SGS 台灣, 2024-01-22. sgs.com.tw
- 智慧醫療器材資訊暨媒合平台. 衛生福利部食品藥物管理署. aimd.fda.gov.tw
- 食品藥物管理署智慧醫療器材專案辦公室成立. 衛生福利部. mohw.gov.tw
- 健保署與臺大醫院簽署合作備忘錄,導入 AI 模組. 衛生福利部中央健康保險署. nhi.gov.tw