Persistence Analytics Group
What they argued
Pre-specified material-change triggers and revalidation for third-party dependencies; evidence for action-taking systems scales with both axes; authorization of specific actions.
Themes it raises
Across the five cross-cutting questions
High-consequence work: Not stated
The comment as filed
Persistence Analytics Group LLC (PAG) appreciates the opportunity to provide feedback on FDA’s discussion paper concerning generative AI-enabled medical devices.
PAG is an independent infrastructure and decision-risk analytics firm focused on a recurring question: before a consequential decision relies on a representation, what evidence establishes that the underlying assumption remains sufficiently supported, and what change should require revalidation?
FDA’s discussion paper raises precisely this issue for GenAI-enabled medical devices.
GenAI-enabled devices may produce open-ended and variable outputs, rely on third-party foundation models, change through prompts, retrieval strategies, guardrails, orchestration logic, software updates, or model evolution, and in some cases autonomously take multi-step actions. FDA correctly recognizes that these characteristics make point-in-time premarket evaluation insufficient by itself for some devices.
PAG recommends that FDA distinguish clearly between initial authorization and continued reliance.
A device that satisfies an evidentiary threshold at authorization may later experience a material change in its model, deployment environment, data distribution, intended workflow, third-party dependency, or observed performance. Continued reliance should therefore depend on evidence that the assumptions supporting the original authorization remain valid.
PAG suggests a simple lifecycle structure:
Representation > Evidence > Dependency > Reliance > Decision Gate > Revalidation
For higher-risk GenAI-enabled devices, FDA could require sponsors to identify in advance:
1. material assumptions supporting safe and effective use;
2. evidence supporting those assumptions;
3. critical third-party dependencies;
4. defined performance and safety thresholds;
5. responsibility for monitoring each dependency;
6. material-change triggers requiring reassessment; and
7. required action if a trigger is reached.
This is especially important for devices incorporating third-party foundation models. FDA notes that changes to an underlying model may occur outside the manufacturer’s direct control and may affect safety or effectiveness. A manufacturer therefore needs a defined evidentiary standard for determining whether continued reliance remains justified.
PAG also supports FDA’s consideration of independent third parties in benchmarking, clinical confirmation, adjudication, and standards development.
Independence could be particularly valuable where the sponsor develops or selects its own benchmarks, where the underlying foundation model is supplied by another company, or where postmarket evidence determines whether a device may continue operating without additional review.
For agentic AI-enabled devices, PAG recommends an additional distinction:
Identity is not authentication. Authentication is not authority. Authority is not necessarily safe reliance.
Where an AI-enabled device can autonomously initiate a clinical action, order, prescription, escalation, or other consequential step, evaluation should ask not only whether the system performed technically as designed but whether it was authorized to take that specific action, within its intended scope, under the conditions then present.
FDA’s proposed risk framework appropriately considers both the independence of device activity and the consequences of relying on an incorrect output. For action-taking systems, the strength of evidence required for continued reliance should increase with both dimensions.
PAG also supports periodic re-benchmarking, performance-degradation monitoring, defined reassessment triggers, and postmarket monitoring.
PAG recommends that FDA formalize the underlying principle:
Premarket authorization establishes an initial reliance boundary. It should not establish permanent reliance where the assumptions, dependencies, or behavior of the system materially change.
A durable regulatory framework should answer not only whether a GenAI-enabled device is safe and effective when first reviewed, but also:
What evidence permits continued reliance, and what change requires the evidence to be tested again?
Respectfully submitted,
Persistence Analytics Group LLC
National Security & Infrastructure Risk Analytics
Infrastructure Assumption Verification | Decision Assurance