Nathan Sabich
What they argued
Q1 only: proposes four-axis model adding human-oversight and traceability axes; no position on permitting autonomy.
Themes it raises
FDA questions it names
Q1 · The two-axis risk framework
Coded positions
Across the five cross-cutting questions
High-consequence work: Not stated
The comment as filed
FDA Question 1: To start, the two-axis framework is a sound starting point but is insufficient for GenAI. It omits three dimensions that are critical for real-world assessment: (a) traceability of the output to source data, (b) the availability and effectiveness of downstream human oversight, and (c) the temporal context of deployment (real-time clinical decision vs. asynchronous review). A GenAI function that generates a patient-facing summary with no clinician intermediary poses fundamentally different risk than one that produces a draft note for clinician review, even if both occupy the same position on the two-axis grid.
An Architecture to Address This: I have created an architecture that explicitly structures risk mitigation through multiple dimensions beyond device activity and consequence. The HITL Validation Points across the lifecycle define distinct human oversight checkpoints, each with named roles and defined responsibilities. I utilize a transparency and labeling framework that requires documentation of intended use, intended user, known limitations, subgroup performance, model characteristics, output interpretation guidance, and update/version information. I created a multi-gate quality checkpoint system that provides progressive risk assessment at design, data integrity, model metrics, model acceptance, business review, and final live deployment, each with designated KOL reviewers.
Recommendation to FDA: Expand the framework to a four-axis model: (1) device activity (current Axis 1), (2) consequence of incorrect output (current Axis 2), (3) degree of human oversight available at the point of output delivery (ranging from fully autonomous to mandatory clinician review), and (4) traceability of output to verifiable source data (ranging from fully traceable to opaque/generative). This four-axis model would better capture the actual risk surface of GenAI-enabled devices and align with IMDRF’s lifecycle management framework, which emphasizes human oversight as distinct a governance dimension