A year after Washington buried third-party evaluation, it came back as a state programme — on 10/5 Utah turned its AI sandbox into a healthcare pillar and named six independent evaluators, one of them CHAI, whose assurance labs collapsed in 2025 after HHS deputy secretary O'Neill and FDA commissioner Makary called it a self-licking ice cream cone and Kennedy called it a cartel; the same week FDA put AI-enabled device lifecycle management and PCCPs on its FY2027 A-list (11 finals, 3 drafts, comments close 11/30) and the UK accepted all 44 recommendations on 10/6, shifting oversight from pre-market review to post-deployment monitoring — while the one place AI already denies care at scale, CMS WISeR, gave up 5,944 non-affirmations and an 83-day wait only because EFF sued
Three jurisdictions moved in the same direction this week, and none of them moved on the question of approval. They moved on the question of who is watching afterwards. On 6 October the UK government accepted all 44 recommendations of the National Commission into the Regulation of AI in Healthcare, explicitly swapping one-off pre-market assessment for continuous lifecycle monitoring (The Pharmaceutical Journal). On 1 October the FDA's CDRH published its FY2027 guidance agenda with AI-enabled device lifecycle management and PCCPs on the top-priority A-list (FDA). On 5 October Utah simply outsourced the watching, naming six independent evaluators at once (Fox 13). The control group landed in the same week: the only American programme where AI already shapes coverage decisions at scale, CMS's WISeR model, surrendered 5,944 non-affirmations in its first three months and one 83-day wait — and only because the Electronic Frontier Foundation sued for the records (24/7 Wall St.). Oversight is moving downstream, and downstream currently has no mandatory disclosure.
01 — Top Stories
Utah turns its AI sandbox into a healthcare pillar, names six third-party evaluators, and clears clinical pilots for prescription renewals, acne and pelvic-floor therapy
On 5 October Utah's Department of Commerce added a healthcare pillar to its existing Pro-Human AI Initiative and designated six independent third-party evaluators: Vega Health, Clarion AI Partners, the Coalition for Health AI (CHAI), Glacis Technologies, Empathic Health and Stanford's Clinical Excellence Research Center. The clinical pilots cleared alongside them are Nolla Health's AI-supported telehealth for mild-to-moderate acne (with dermatologist oversight and escalation protocols), Expect Fitness's remote pelvic-health physical therapy for pregnancy and postpartum care, August AI's renewals of non-controlled chronic-condition prescriptions (roughly 148 drugs at the start), and master agreement frameworks with Intermountain Health and University of Utah Health covering data privacy and AI governance (Fox 13, 2026-10-05). The legal instrument is a regulatory mitigation agreement granting temporary relief from specific state rules, administered by the Office of Artificial Intelligence Policy — the first state AI office in the country, created in 2023 (Deseret News, 2026-10-05).
This is the first time an American government has named a specific set of independent organisations and given them a formal mandate to verify vendor claims on the state's behalf. Vega Health CEO Mark Sendak put the function plainly: "Third party evaluation of AI is important so that users of the technology don't have to rely solely on vendor performance claims" (Business Wire, 2026-10-05). Commerce director Margaret Woolley Busse framed the upside as "better access, lower costs, greater clinician capacity" — then added the floor: "I do know that we always want to have a human involved somewhere."
STAT flags a design gap with no answer yet: Nolla Health's AI judgements are currently reviewed and signed off by a licensed clinician, but the startup "may eventually be allowed to prescribe drugs without this review" (STAT, 2026-10-05 — paywalled; written from the publicly visible headline and deck only). Nor does the public material say who pays each evaluator or whether their reports will be published in full; it says only that findings are "shared with the state and applicants".
Assurance labs died once at federal level — called a "self-licking ice cream cone" and a "cartel", abandoned by Microsoft and Amazon — and have come back as a state procurement
CHAI's national AI assurance-lab concept began with a JAMA article in late 2023, was relaunched as a nonprofit with HHS backing in March 2024, drew a combined $1.25 million pledge from Duke, Mayo Clinic, Stanford and Johns Hopkins, and attracted more than 32 companies interested in taking part. Republican lawmakers attacked the FDA's involvement in June 2024; HHS officials left the board in July. Through the first half of 2025 the labs collapsed and were rebranded as "assurance resource providers". In October 2025 HHS deputy secretary Jim O'Neill and FDA commissioner Marty Makary published a scathing op-ed calling CHAI a "self-licking ice cream cone" and a "virtual and unethical syndicate"; Kennedy called it a "cartel". Microsoft and Amazon dropped their memberships late in 2025 (Fierce Healthcare, 2026-02-19). The trade newsletter Second Opinion argues Utah has now resurrected the model — with CHAI itself among the six names (Second Opinion, 2026-10-04).
The technical reason CHAI failed is precisely the reason three jurisdictions turned this week. Fierce attributes the collapse to health systems discovering they needed post-deployment monitoring rather than pre-procurement testing — and to AI governance costs that already run into millions a year at a well-resourced hospital for a handful of models, making the model impossible to scale. One-off pre-market validation does not pay for itself. Federal guidance, the UK commission and the Utah sandbox have now all bet on the same answer: continuous monitoring. They differ only on who pays and who does it.
"Resurrection" is Second Opinion's framing, not Utah's: the state has never called its six evaluators assurance labs. And CHAI's present scale — roughly 1,000 individuals contributing to workgroups — is not the 2024 organisation.
FDA's device centre publishes its FY2027 guidance agenda: AI-enabled device lifecycle management and PCCPs on the A-list, a draft on generative-AI conversational devices for mental disorders, comments close 30 November
On 1 October CDRH published its list of guidances it intends to issue in FY2027: 11 finals and 3 drafts (FDA CDRH, 2026-10-01). The top-priority A-list finals cover marketing submissions and lifecycle management for AI-enabled devices (including user-interface considerations), predetermined change control plans — a holdover from the FY2026 list — and robotically assisted surgical devices, alongside NIOSH respirators, menstrual product performance testing, quality management systems and the conformity assessment accreditation scheme. The A-list draft sets evidentiary recommendations for generative-AI conversational devices for mental disorders. The B and C lists carry small-business user fees, software function policy, post-market cybersecurity management, predicate selection, thermal effects, and risk assessment for generative-AI devices (RAPS, 2026-10-02). Comments close 30 November 2026 under docket FDA-2012-N-1021.
A standalone A-list draft on generative-AI conversational devices for mental disorders is the first sign that the FDA intends to pull therapy chatbots into the device evidence framework — exactly the territory California's SB 903 tried to govern by state law and the governor vetoed. On the other side, the PCCP final slipping from FY2026 to FY2027 is the most honest line in the document: that guidance determines whether an AI device can update its model without a fresh submission, so a year's delay is another year of the whole industry's iteration cadence held in place.
This is a list of intentions, not issued guidance: the A-list is what CDRH intends to publish if it can, the B-list what it will publish if resources allow, and none of it carries a binding deadline. Citeline's headline gets it right — the agenda prioritises AI and surgical robots, but delivery is the test. One FY2026 item, in vitro diagnostics validation, quietly failed to carry forward (MedTech Dive, 2026-10-02).
On 6 October the UK government accepted all 44 recommendations of its National Commission on AI regulation in healthcare, moving device oversight from one-off pre-market assessment to continuous lifecycle monitoring; the MHRA picks its first AI Airlock phase-three cohort next month
The National Commission into the Regulation of AI in Healthcare reported on 10 September 2026; the government responded on Tuesday 6 October, accepting all 44 recommendations (The Pharmaceutical Journal, 2026-10-06). The commitments include a "world-leading agile approach to AI device regulation", clarifying how responsibility is allocated between manufacturers and providers, a shared baseline of AI literacy embedded in existing professional education, monitoring AI throughout its use in practice, stronger patient involvement in decisions, and clear routes to redress when something goes wrong. On timing: the first firms for phase three of the MHRA's AI Airlock sandbox — this round focused on post-deployment monitoring — are selected next month; draft guidance in December covers devices that evolve after deployment; a 2027 consultation will address how to classify them; fuller detail follows in spring 2027 (City A.M., 2026-10-06). About two-thirds of the commission's respondents said existing frameworks restrict innovation.
Accepting all of them is unusual in a UK government response, and industry read it straight: the BioIndustry Association's Martin Turner said the MHRA's approach "absolutely makes the UK a leading testbed for innovation", and the Association of British HealthTech Industries' Steve Lee called it a "positive direction of travel for Healthtech companies". Health innovation minister James Frith kept a foot on each pedal — patients should benefit from AI faster, but "innovation must never come at the expense of patient safety". Worth noting who framed it on the commission's side: deputy chair Henrietta Hughes, England's patient safety commissioner, called full implementation "an important step towards ensuring that innovation and patient safety go hand in hand".
Accepting recommendations is not legislating: none of the 44 took effect on 6 October, the earliest concrete step is December's draft guidance, and classification waits for a 2027 consultation. The published coverage gives no figure for how many AI devices the NHS currently runs, and says nothing about who bears the cost of continuous monitoring — the very cost that sank CHAI in the United States.
CMS's AI prior-authorisation model non-affirmed 5,944 requests in three months and left one case waiting 83 days — figures that exist only because the EFF filed a FOIA request, was stonewalled, and sued for the thousand pages
The WISeR (Wasteful and Inappropriate Service Reduction) model went live on 1 January 2026 in Arizona, New Jersey, Ohio, Oklahoma, Texas and Washington, applying AI-assisted prior authorisation to 13 services judged low-value or vulnerable to misuse, across roughly 6.4 million Original Medicare beneficiaries, and is scheduled to run to 2031. The Electronic Frontier Foundation filed a FOIA request on 29 January; CMS missed both the expedited and the standard deadline; the EFF sued on 24 March and obtained about 1,000 pages. Those records show two vendors denied or "non-affirmed" 5,944 prior-authorisation requests in the first three months; one request took 83 days end to end, including steps outside the vendor's control; vendors have three calendar days to decide once a request reaches them; and they can earn up to 20% of the savings from the care avoided. Washington's vendor, Virtix Health, initially rejected more requests than it approved and was placed on a corrective action plan for delays, reportedly ending 14 August (24/7 Wall St., 2026-10-01).
Set this beside the three stories above and the contrast resolves. Utah, the FDA and the UK are designing disclosure and monitoring regimes for AI that assists clinical judgement. AI that participates in coverage denials is already live, across six states and 6.4 million people, with vendors paid up to a fifth of the savings from care not delivered — and with no routine disclosure at all. The numbers required a lawsuit. Congress has tried both routes: on 16 July the Senate rejected a disapproval resolution from Wyden, Cantwell, Blumenthal and Gillibrand 46–50 on party lines (Fierce Healthcare, updated 2026-07-16); on 24 July two physician members, Herb Conaway (D-NJ) and Gregory Murphy (R-NC), introduced the Protecting Patients from Automated Denials Act, which would require a qualified physician to review and sign off every AI-assisted denial and attest that it reflects independent medical judgement rather than an AI output, and would let HHS audit algorithms and overturn rates. The AMA endorsed it (Rep. Conaway's office, 2026-07-24).
The 5,944 is the combined count of denials and non-affirmations, not final refusals to pay: WISeR decisions can be appealed and the records carry no overturn rate. The 83 days is one case end to end, not an average, and the reporting is explicit that it includes steps outside the vendor's control. These figures come from CMS records obtained by the EFF; this report works from 24/7 Wall St.'s account of them, not the thousand pages themselves.
California closes the book: AB 1979, SB 503 and AB 1609 signed, but SB 903 — which would have barred AI from being advertised as "therapy", passed unanimously in the Senate and 71–4 in the Assembly — was vetoed as going "too far"
Governor Newsom signed three healthcare AI bills (Healthcare IT News, 2026-10-01). AB 1979, sponsored by the California Nurses Association, extends medical confidentiality law to patient health information reached through chatbots and confines clinical decision support AI to an advisory role, exempting documentation and communications that require no professional judgement. SB 503 requires developers and deployers to identify known or foreseeable bias risks in clinical decision support systems, make reasonable efforts to mitigate them, and requires providers to monitor on an ongoing basis. AB 1609 bars large enterprises from presenting customer-service chatbots as human, exempting hospital and facility communications tied to the provision, coordination, management, payment or operation of care. Assembly member Mia Bonta's framing: "Technology should not replace human decision-making in healthcare." AB 2575 and SB 903 were vetoed.
This paper's 30 September edition left SB 903 open as the bill sitting on the governor's desk on its signing deadline. The answer is a veto. SB 903 would have barred companies from advertising chatbots as "therapy", restricted AI to administrative and supplementary support, required clear disclosure and consent before AI recorded a therapy session, and prohibited AI from interacting independently with clients or making therapeutic decisions. Its author, San Diego senator Steve Padilla, was blunt: "The Governor's veto message claims the protections for patients and clinicians in this bill go too far, but Governor Newsom knows all too well the dangers chatbots pose to vulnerable Californians, and despite that knowledge, has allowed unlicensed algorithms to act as therapists" (California Senate District 18, 2026-10-01). The gap it leaves is exactly the one the FDA has just put a draft guidance against on its FY2027 A-list: state law steps back, the federal device framework prepares to step in.
None of the coverage located gives effective dates for the three signed bills; California statutes commonly take effect the following 1 January, but this report has not read the enrolled texts and does not state that as fact. The author's press release dates the SB 903 veto only to September, without a day.
No fresh EU move this week, but this is the timetable device makers now plan against: Article 50 transparency has applied since 2 August, while embedded high-risk systems (Annex I, which covers medical devices) slip to 2 August 2028
The EU institutions reached a provisional political agreement to amend the AI Act on 6 May 2026, confirmed by member states on 13 May. Stand-alone high-risk systems (Annex III) move from 2 August 2026 to 2 December 2027; high-risk systems embedded in regulated products (Annex I, which is where medical devices sit) move from 2 August 2027 to 2 August 2028. The agreement also empowers the Commission to limit specific AI Act requirements where sectoral legislation such as the MDR or IVDR already imposes equivalent obligations, and narrows the "safety component" definition so that non-safety assistance features are excluded unless their failure would endanger health and safety (Gibson Dunn, 2026-05-27). But 2 August 2026 did not vanish: the Article 50 transparency obligations took effect on schedule and are in force now (regulation-ai.eu).
The EU belongs in this edition as the contrast case. While the United States and the UK move the weight of oversight to post-deployment monitoring — driven by state procurement and a national commission's recommendations — the EU has gone the other way: push the high-risk obligations back two years, and let the MDR and IVDR absorb part of the AI Act through the equivalent-obligations mechanism. For a manufacturer selling into all three markets, the practical reading is that the binding constraint through 2026–27 is not Brussels. It is your own post-deployment monitoring and incident reporting.
This item is background, not this week's news: the regulatory news in the window came from the US and the UK, and the EU published nothing new, so the May agreement and the Article 50 date are supplied here for timetable context and flagged as such per this paper's convention. The dates are taken from law-firm and tracker summaries rather than checked line by line against the Official Journal.
02 — Product Analysis
MHRA AI Airlock(phase 3)
National regulatory sandbox · Medicines and Healthcare products Regulatory Agency (UK)
Function and position. The AI Airlock is a sandbox the MHRA runs itself, letting manufacturers test how an AI device can meet existing requirements with the regulator in the room. Phase three is open for applications and explicitly themed on post-deployment monitoring, with the first firms chosen next month. The government's 6 October response ties it to December's draft guidance on devices that evolve after deployment and a 2027 consultation on classifying them (City A.M., 2026-10-06).
- Strength : the regulator is in the room, so what the sandbox learns feeds straight back into guidance — which is where December's draft comes from. Industry reads it that way too: the BioIndustry Association says it "absolutely makes the UK a leading testbed for innovation" (City A.M.).
- Concern : it is a controlled experiment, not a deployment. This week's public material gives no cohort size, no budget, and no count of products that have reached market through the Airlock. Without that number there is no way to tell a pathway from a shop window.
Utah OAIP Regulatory Sandbox(healthcare pillar)
State regulatory mitigation agreements plus outsourced evaluation · Utah Department of Commerce (USA)
Function and position. Utah created the first state AI policy office in the country in 2023. The mechanism is a case-by-case regulatory mitigation agreement: temporary relief from named state rules in exchange for supervised real clinical deployment. The 5 October upgrade does two things — adds a healthcare pillar with five approved applicants, and for the first time names six third-party evaluators to validate vendor claims, benchmark against real patient data, audit the accuracy of AI decisions, and report findings to the state and the applicant (Fox 13, 2026-10-05).
- Strength : it runs on real patients, and the health systems have put their names to it. Intermountain Health CEO Rob Allen: "That's what the sandbox allows, a very structured approach to assure before we deploy those tools that they will work effectively and keep patients safe" (Deseret News). You cannot monitor post-deployment without a deployment.
- Concern : the public material does not say who pays the evaluators or whether their reports will be published, and STAT reports that Nolla Health "may eventually be allowed to prescribe drugs without" a licensed clinician's review (STAT, paywalled). If the endpoint of the relief is removing the human signature, third-party evaluation becomes the only brake left in the system — and it currently has no statutory guarantee of independence.
03 — Companies & Competition
| Company | Recent state & numbers | Position & moat |
|---|---|---|
| Vega Health AI lifecycle management platform (Durham, NC) |
Selected on 5 October as a third-party evaluator for Utah's AI sandbox, covering pre-deployment performance testing, benchmarking against real patient data, validating vendor claims, auditing decision accuracy and reporting to the state. Co-founder and CEO Mark Sendak came out of the Duke Institute for Health Innovation (Business Wire, 2026-10-05; Healthcare IT News). Funding undisclosed. | The moat is academic methodology plus the first state endorsement. The weakness is that neither scale nor funding is disclosed, and its customers — health systems — are also the buyers of the products it audits, which is not a clean structure. |
| Coalition for Health AI (CHAI) Nonprofit standards body |
Its 2024 national assurance-lab plan drew a $1.25m pledge from Duke, Mayo, Stanford and Johns Hopkins and interest from 32-plus companies. The concept collapsed in 2025; in October HHS deputy secretary O'Neill and FDA commissioner Makary attacked it in print, Kennedy called it a "cartel", and Microsoft and Amazon left by year-end. Roughly 1,000 individuals now contribute to workgroups (Fierce Healthcare, 2026-02-19). On 5 October it became one of Utah's six evaluators (Fox 13). | Going from would-be standard setter to one of six suppliers is a severe demotion in position — and the only living route: an organisation rejected federally buying legitimacy through a state procurement. The moat is convening power and the workgroup network; the weakness is that the quasi-regulatory role it was accused of playing is now, literally, a government-appointed checking function. |
| Nolla Health AI dermatology telehealth |
Utah pilot: AI assessment and prescribing for mild-to-moderate acne under dermatologist oversight with escalation protocols. It has raised $4.5m, investors including General Catalyst, and aspires to direct AI treatment across a range of conditions (STAT, 2026-10-05, paywalled). | The moat is the regulatory position itself: first place inside a framework that explicitly contemplates relaxing human review over time, which incumbent tele-dermatology players such as Hims & Hers or Curology cannot buy. The weakness sits in the same place: that position is tied to one state and is revocable. |
| August AI Chronic-condition prescription renewals |
Utah pilot: AI-supported renewals of existing non-controlled medications for chronic conditions, roughly 148 drugs at the start (Fox 13, 2026-10-05). | It is competing for the layer underneath the renewal workflow EHR vendors (Epic, Oracle Health) already own — a layer that today is a physician clicking once. Its differentiation can only be regulatory position and liability-bearing; the technology is not a moat. |
| Virtix Health CMS WISeR prior-authorisation vendor (Washington) |
WISeR's Washington contractor. It initially rejected more requests than it approved and was put on a corrective action plan for delays, reportedly ending 14 August. The model lets vendors take up to 20% of the savings from avoided care, with three calendar days to decide (24/7 Wall St., 2026-10-01). | The moat is a government contract and the risk is entirely political: the Senate's 46–50 on 16 July kept the model alive, but if the Conaway–Murphy bill passes, requiring a physician signature on every AI-assisted denial would eat the economics of the savings-share model outright. |
| Intermountain Health / University of Utah Health Utah's two large health systems |
Each signed a master agreement framework covering data privacy and AI governance, onto which future departmental pilots can hang. U of U Health chief innovation officer Jim Hotaling: "The goal is not to take the human out of the loop… make the human a better human." Medical board member Bill Hamilton stressed the working group's three anchors — "physician-led oversight, phased safety review, patient disclosures" (Fox 13, 2026-10-05). | These are the real gatekeepers. The sandbox grants relief from state rules, but the patients, the data and the clinicians all sit inside the health system. A startup gets a ticket; the hospital decides whether it ever runs. |
Today's competitive structure is a new job opening: the checker. In 2024 that role was a national standard pushed by large health systems and cloud incumbents, and it died of cost and politics. In October 2026 it reappeared in a different shape — a state naming six organisations case by case, with no statutory independence and no published fee schedule. For AI device makers, what has to be prepared from here is not only the submission file but the answers to three questions with no settled answer: who audits you, on whose patient data, and whether the result is published.
04 — Taiwan Angle
(1) Taiwan already took the PCCP step the FDA keeps postponing. On 25 September 2024 the TFDA issued guidance on predetermined change control plans for AI/ML medical device software under announcement FDA器字第1131607731號, publishing it alongside the existing AI/ML SaMD registration technical guidance on the smart medical device information and matching platform (TFDA announcement). Against an FDA that has just pushed its PCCP final from FY2026 to FY2027 (RAPS, 2026-10-02), Taiwan is ahead on paper on the question of whether a model can be updated without a fresh submission. The real gap is elsewhere.
(2) That three-month window is now. Taiwan's AI Basic Act passed its third reading on 23 December 2025, naming the National Science and Technology Council as central competent authority and setting seven principles — sustainable development and welfare, human autonomy, privacy, information security, transparency and explainability, fairness and non-discrimination, and accountability — with high-risk applications required to carry clear warnings (The News Lens). On 6 August 2026 Lee Chien-chang, director of the Ministry of Health and Welfare's Department of Information Management, said draft implementing rules for healthcare would come within three months, defining "what you must do so as not to harm these seven principles, and what counts as harming them". He also noted that the Department of Medical Affairs' May 2026 guidance on generative AI in healthcare institutions is advisory only, with no legal force, whereas the implementing rules will bind (CNA, 2026-08-06). Counting from 6 August, that window lands in November — the same stretch as the FDA's 30 November comment deadline and the MHRA's December draft on devices that evolve after deployment.
(3) The middle layer is empty in Taiwan. What Utah added this week is not a rule but an institutional position: between what the vendor says and what the regulator registers, a set of government-named independent evaluators benchmarking on real patient data. Taiwan has the two ends — TFDA registration before market, each hospital's own implementation review after — and nothing institutionalised in between. If the MOHW's implementing rules only address how healthcare institutions should use AI, then who measures post-deployment drift, on whose data, and reports it to whom, stays inside each hospital's IT department. That is precisely the arrangement that killed CHAI in the United States: carried hospital by hospital, it costs millions a year at a single well-resourced system (Fierce Healthcare, 2026-02-19).
(4) WISeR is a warning about the payer side, not the clinical side. Taiwan's National Health Insurance has no public programme of automated AI claim review, but the lesson is worth filing early: the hard part is not algorithm quality, it is disclosure — the American figure of 5,944 only surfaced through litigation (24/7 Wall St., 2026-10-01). Any design that puts AI into a review workflow should write the disclosure rule at the same time as the algorithm, not after someone sues.
05 — Further Reading
-
Inside CHAI's failed assurance labs — Fierce Healthcare (2026-02-19)
The single most explanatory piece behind today's edition. It walks a national validation scheme from proposal to collapse over three years, and the technical reason it collapsed — health systems wanted post-deployment monitoring, not pre-procurement testing — is exactly why the FDA, the MHRA and Utah all turned in the same direction.
-
CDRH Proposed Guidances for Fiscal Year 2027 — FDA (2026-10-01)
The primary document, and worth reading the A, B and C lists in order yourself. What sits on the B list — post-market cybersecurity, risk assessment for generative-AI devices — says more about what CDRH thinks its staffing can carry than the A list does. Comments close 30 November.
-
Assurance labs are back — Second Opinion (2026-10-04)
A short piece that caught the historical arc a day before Utah's formal announcement. Its framing — a state reviving the model Washington buried — is the spine of this edition, and worth reading against the official release.
-
Government accepts all 44 recommendations from regulation of AI in healthcare report — The Pharmaceutical Journal (2026-10-06)
An itemised account of the response. The point is not the acceptance but one commitment inside it: clarifying how responsibility is allocated between manufacturers and providers — the question every continuous-monitoring regime eventually hits and the one least often written into law.
-
His back injection entered Original Medicare's new AI review — 24/7 Wall St. (2026-10-01)
It follows one patient's single request through to the whole tranche of records the EFF's lawsuit pried loose, and shows what the public has to spend to see basic figures from a government AI programme with no statutory disclosure. Watch the incentive clause: up to 20% of savings.
06 — References
- CDRH Proposed Guidances for Fiscal Year 2027 (FY 2027). U.S. Food and Drug Administration, 2026-10-01. fda.gov
- FDA's device center releases guidance agenda for FY 2027. Regulatory Affairs Professionals Society (RAPS), 2026-10-02. raps.org
- FDA to prioritize guidance on AI, surgical robots next year. MedTech Dive, 2026-10-02. medtechdive.com
- STAT Health Tech: FDA spells out 2027 AI guidance plans. STAT News, 2026-10-06. statnews.com
- Utah launches health care AI push with new clinical pilots, outside evaluators. Fox 13 Salt Lake City, 2026-10-05. fox13now.com
- Utah announces partnership with major healthcare providers to create artificial intelligence clinical pilot programs. Deseret News, 2026-10-05. deseret.com
- Utah expands health AI sandbox, picks third-party auditors. STAT News, 2026-10-05 (paywalled). statnews.com
- Vega Health Selected As Third-Party Evaluator for Utah's AI Sandbox. Business Wire, 2026-10-05. financialcontent.com
- New startup Vega Health seeks to help health systems succeed with AI. Healthcare IT News. healthcareitnews.com
- Assurance labs are back. Second Opinion, 2026-10-04. secondopinion.media
- Inside CHAI's failed assurance labs. Fierce Healthcare, 2026-02-19. fiercehealthcare.com
- Government accepts all 44 recommendations from regulation of AI in healthcare report. The Pharmaceutical Journal, 2026-10-06. pharmaceutical-journal.com
- UK AI health rules could give firms 'competitive edge' as ministers back overhaul. City A.M., 2026-10-06. cityam.com
- His Back Injection Entered Original Medicare's New AI Review. It Took a Lawsuit to Reveal 5,944 Denials and an 83-Day Wait. 24/7 Wall St., 2026-10-01. 247wallst.com
- Senate strikes down Dems' move to overturn CMS' WISeR AI prior auth pilot. Fierce Healthcare, updated 2026-07-16. fiercehealthcare.com
- Conaway and Murphy Introduce Bill to Protect Patients from AI-Assisted Insurance Denials. Office of Rep. Herb Conaway, 2026-07-24. conaway.house.gov
- California Gov. Newsom signs 3 bills to govern healthcare AI. Healthcare IT News, 2026-10-01. healthcareitnews.com
- Governor Newsom Allows Dangerous Chatbots to Provide Therapy. California State Senate, District 18 (Sen. Steve Padilla), 2026-10-01. sd18.senate.ca.gov
- California Finalizes Next Wave of State AI and Privacy Regulation. WilmerHale, 2026-10-02. wilmerhale.com
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes. Gibson Dunn, 2026-05-27. gibsondunn.com
- AI Act: 2028 for Devices, Article 50 Applies Now. Specculo. specculo.com
- EU AI Act Article 50: In Force Since 2 August 2026. regulation-ai.eu. regulation-ai.eu
- 公告「應用人工智慧/機器學習技術之醫療器材軟體預定變更控制計畫(PCCP)申請要點暨撰寫說明指引」. 衛生福利部食品藥物管理署, 2024-09-25(FDA器字第1131607731號). fda.gov.tw
- 厚生會成立智慧醫療委員會 衛福部擬提AI醫療細則草案. 中央社, 2026-08-06. cna.com.tw
- 《人工智慧基本法》三讀通過:主管機關、風險控管、勞權保障?重點條文一次看. The News Lens 關鍵評論網. thenewslens.com