Where AI/ML medical software meets safety classification
Medical device software already carries a formal safety classification under IEC 62304 — Class A (no injury possible), B (non-serious injury possible), or C (death or serious injury possible) — that determines how rigorously it must be developed, documented, and maintained. AI/ML-based Software as a Medical Device adds a specific wrinkle regulators have been actively building guidance for since the early 2020s: these models can change after approval through retraining, so the FDA and international partners built Good Machine Learning Practice (GMLP) and Predetermined Change Control Plans (PCCPs) to govern that.
What AIC maps, and against what
AIC maps AI/ML-based medical software and clinical decision-support tools against the IEC 62304 safety-classification discipline and the emerging GMLP/PCCP framework for how such software is allowed to change over time. This applies to organisations building or deploying AI-assisted diagnostic, monitoring, or clinical decision-support software — not to clinical practice itself, and not as a substitute for FDA, MHRA, or other regulatory clearance.
The established concept, and its AI equivalent
| Established | AI equivalent | What it means here |
|---|---|---|
| IEC 62304 safety classification (A/B/C) | AI/ML software safety classification | The same severity-of-harm classification applied to the AI component's role in the device or software. |
| Design history / lifecycle documentation | GMLP data & training documentation | Training data representativeness, held-out validation, and algorithm limitations documented as part of the software lifecycle record. |
| Change control | Predetermined Change Control Plan (PCCP) | Anticipated model updates are pre-specified and bounded, rather than each retraining requiring a fresh, unplanned review. |
| Post-market surveillance | Ongoing model performance monitoring | The model's real-world performance is tracked after deployment, not assumed to hold indefinitely from validation-time results. |
| Labelling & disclosure | ML-use disclosure | End users are told the device incorporates machine learning and, where relevant, that a PCCP governs how it may change. |
The safety measures a subject demonstrates
Documented safety classification
The AI component's role has been classified for severity of potential harm, consistent with IEC 62304 discipline.
GMLP-aligned development record
Training data, validation approach, and known limitations are documented, not just the model's headline performance.
A defined change-control plan
How the model is allowed to change post-deployment is pre-specified and bounded, not open-ended.
Post-deployment monitoring
Real-world performance is tracked on an ongoing basis, with a path to act if it degrades.
Clear ML-use disclosure
Clinicians and patients are told, plainly, that machine learning is part of the software they're relying on.
Where this mapping has limits
The PCCP framework was only finalised in December 2024 and is still maturing through 2025–2026 — practice and regulatory expectations are evolving faster than in the more settled parts of IEC 62304. This mapping is US-FDA-centric by default; the EU (MDR/IVDR), UK, and other regulators apply related but distinct requirements, and AIC's assessment does not substitute for any regulator's clearance process. Most importantly, none of this replaces clinical judgement — it maps the software governance around an AI tool, not the clinical decision a practitioner makes using it.
Reviewed 2026-09-01.