Filed comment — FDA-2026-N-7874 (GenAI-enabled medical devices)
Status: DRAFT — NOT YET FILED. On filing, this text is replaced verbatim by the as-filed comment, with the filing date and tracking number (if a receipt is elected).
- Docket: FDA-2026-N-7874 — nonrulemaking; comments close 19 October 2026
- Responds to: the discussion paper’s Questions 18, 21, 25, and 26 (of 26)
- This cut (20 Aug 2026): the predecessor file enters as exhibit — three comments from Docket FDA-2024-D-4488 (the AI-DSF draft guidance) are cited by ID and quoted verbatim: the platform that cannot see upstream (0018), the clinician cast as the risk mitigation (0041), and the physicians asking for the § 1557 duty to be moved with nowhere to move it (0021). The abstract versions of the same claims were cut to pay for them.
- Body length: 4,990 characters — form limit 5,000
- Decisions parked to filing day: identity — Individual / Organization / Anonymous, all supported by the form
- Quote fidelity: both verbatim quotes checked against the as-posted attachments, retrieved from the docket 20 August 2026; the § 1557 and survey characterizations are paraphrase, marked as such
- One upgrade held pending evidence: the flat sentence “no foundation-model developer filed in 2024-D-4488” is supportable only after all 51 posted comments are inventoried; 26 remain unseen. If confirmed, it enters; until then the comment claims only what the cited exhibits themselves say.
- Two-surface note: this artifact cites the repository only; no campaign surface is named here, per the project’s standing rule
- Reader profile and the agency’s own register — added 24 Aug (from press coverage of the docket’s launch, ⚠ P, library): the discussion paper belongs to the Digital Health Center of Excellence, directed since February 2026 by Rick Abramson, MD (a radiologist), under CDRH director Michelle Tarver, MD, PhD — the comment’s first readers. The agency’s stated vocabulary for this docket: a “risk-based approach”; “least burdensome principles”; a “nimble regulatory approach”; “timely access to safe and effective medical devices”; a “transparent process” that “safeguards patients and consumers”; Abramson’s triad — “enable beneficial innovation, protect public health and preserve trust”; and Tarver’s “a potential model for regulators around the world.” Filing-day drafting notes — the body sits at the character limit, so any weave is a swap, not an addition: (1) the architecture proposed already IS the register — risk-based (duties scale to the deployed configuration), least-burdensome (no premarket gate anywhere in it; SEC. 3(b) forbids one), timely-access-preserving (nothing in it delays a deployment; it prices the decision) — and saying so in the agency’s own words costs about sixty characters. (2) The closer’s candidate echo: the agency asked for “a potential model”; a model, in statutory form, is what this comment attaches.
Comment text (as currently drafted)
Comment on Docket No. FDA-2026-N-7874, “Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback”
This comment responds to Questions 18, 21, 25, and 26. One suggestion, four applications: these are accountability problems, and the agency owns the instrument — the public-welfare doctrine of United States v. Dotterweich, 320 U.S. 277 (1943), and United States v. Park, 421 U.S. 658 (1975): responsibility attaching to the natural person with practical power to prevent or correct a violation, which delegation does not relieve. The agency’s predecessor file shows the need. In the AI-DSF draft-guidance comments (Docket FDA-2024-D-4488), each link locates responsibility elsewhere: the platform intermediary “may not be able to offer information on model training data when not otherwise disclosed by the model developer” (comment 0018); the radiologists describe the qualified clinician as one who “would intrinsically serve as a device risk mitigation” (0041); the physicians ask HHS to rescind the § 1557 rule placing bias-monitoring duties on providers (0021) — with no upstream address to move the duty to. Downstream cannot see in; the intermediary cannot vouch; the clinician is cast as the safety component. What is missing sits upstream and has a job title.
Q18 (premarket uncertainty traded for postmarket monitoring). The trade is sound only where monitoring is mandatory, time-boxed, and owned: (1) incident definitions prespecified, not discovered in litigation; (2) clocks that run from when a certified monitoring program would have detected the event — not looking starts the clock; (3) records duties making destruction and falsification the offense, never disclosure: a filed nonconformity should be a protected act; (4) a named natural person answerable for the program’s operation. Absent these, uncertainty is not managed but transferred — to patients, and to the clinicians who told the agency in 2024-D-4488 that they do not wish to be the mitigation. Not appropriate: the upper-right of Figure 1 — autonomous action with severe consequences — where postmarket detection is post-harm detection.
Q21 (ecosystem roles without diffusing manufacturer accountability). Diffusion is prevented by non-delegable responsibility: one identified natural person of the manufacturer — an officer with authority to halt the device — signs the monitoring commitments and retains responsibility no delegation, vendor contract, committee, or consortium relieves. Everyone else — clinicians, institutions, societies, standards bodies, supervisory agents — is load-bearing help, never load-bearing responsibility. This is Park operationalized — the element no predecessor-file commenter could supply from where they sit; only a signature above them closes the chain. It costs the ecosystem nothing and preserves the one address enforcement needs.
Q25 (voluntary Foundation Model MAFs; limited disclosure incentives). The paper names the defect — developers “may have limited incentive to disclose safety-relevant information” — and voluntary, confidential, consequence-free filing is the pre-1906 architecture. Two cures. First, attestation by an identified responsible officer of the model developer: a submission to FDA already carries 18 U.S.C. § 1001 exposure, so a signature converts a courtesy into a statement with an owner at no new statutory cost. Second, the alternative mechanism Question 25 requests exists: Cal. Bus. & Prof. Code § 22757.12, N.Y. Gen. Bus. Law § 1421, and Ill. P.A. 104-0538 § 10 impose transparency and safety-framework duties on frontier developers as obligations, not favors. Aligning MAF content (paper, n.24) with those duties lets one document discharge both — obtaining by requirement what voluntariness did not.
Q26 (agentic devices). Make the deployed configuration, not the model, the unit of evaluation — the paper’s Section V.A instinct carried to the agentic case: an evaluation attaches to an identified model version with its tools, memory, retrieval, credentials, and permissions — a device evaluated without tools is evaluated for no configuration granting external access — and granting a new class of tools or permissions — rightward motion on Figure 1’s activity axis — is itself a triggering event for re-benchmarking under element A.1, alongside human-oversight checkpoints before irreversible actions and injection resistance across inputs, retrieved content, and tool outputs (Appendix A’s failure surfaces). The acceptance criterion Question 26 seeks is the configuration manifest: what the agent can reach is what was evaluated, nothing more.
These four answers are one answer. The predecessor file’s safety elements were documents and downstream professionals; the reply is the agency’s oldest: a duty, a record, a clock, and a name.
A public-domain research draft of this architecture in statutory form: github.com/FrontierAIAccountabilityProject/model-act. Reference, not authority.