← All 95 filings

Daniel B. Fagbuyi, MD (Practicing Emergency Physician; Founder, Orzyn)

CliniciansClinicianFiled September 11, 20261,716 words · 1 attachmentFDA-2026-N-7874-0089
“It should be required as a verifiable, tamper-evident record that a real, present, uncoerced human authorized each consequential action at the moment it was taken.”

What they argued

RecovryAI’s one-line reading of the filing.

M1 from his governing-principle section: agentic devices are acceptable but for the narrow set of actions consequential and irreversible enough to warrant it, no agent should complete the action without verifiable authorization by an accountable human, and the system should fail safe in its absence. M2 from his risk-assessment recommendation: acceptance criteria should scale so that the more consequential and less reversible the autonomous action, the stronger the required evidence of contemporaneous human authorization. autonomy_high is direct on that basis - the agent may plan and propose but may not complete a consequential or irreversible action on its own; no level is stated for low-consequence functions. He asks for premarket demonstration and postmarket retention of authorization records but never addresses trading premarket evidence for postmarket monitoring, competency benchmarks, or change control, so M3-M5 are N. He cites no FDA question numbers. He files in his capacity as a physician and former federal advisor while disclosing a commercial interest as founder of a company selling human-accountability technology for AI.

Themes it raises

6 of the 21 themes in the docket, each with the passage we counted, verbatim.
What makes a function high riskFDA Q1, Q2, Q5
“I recommend the risk framework distinguish agentic devices by the reversibility and consequence of the actions the agent can take autonomously, not only by clinical indication or model type.”
Watching the device after it shipsFDA Q19, Q20
“If each consequential agentic action carries a tamper-evident record of its human authorization (or of its absence), then adverse-event investigation, root-cause analysis, and pattern detection across a fleet of deployed agents become tractable.”
Devices that plan and take actionsFDA Q26
“An agent that drafts a note for clinician signature is a different risk object from one that can place an order or alter a record.”
Whether human oversight is real oversightFDA Q3, Q4, Q14, Q20, Q21, Q26
“Present frameworks name human oversight everywhere and give device makers no way to demonstrate it.”
Records that let investigators reconstruct an eventFDA Q19, Q21, Q24, Q26
“Without such records, postmarket monitoring of agentic behavior is largely reconstructive guesswork.”
Privacy and protection of patient dataNot asked by the FDA
“This is achievable without collecting or storing biometric identifiers; presence and authorization can be evidenced without building a biometric database that itself becomes a privacy liability and a security target.”

Across the five cross-cutting questions

RecovryAI’s reading of the whole filing. Silence is never counted as opposition.
Patient-facing autonomyShould FDA permit patient-facing AI to act with meaningful autonomy within a defined scope?
Supports with conditions
Proportionate evidenceShould evidence requirements scale with clinical risk rather than a uniform high bar?
Supports
Postmarket relianceCan strong postmarket monitoring justify accepting more premarket uncertainty?
No position stated
Competency evaluationCan a device be evaluated on competency benchmarks and clinical confirmation against clinicians?
No position stated
Change controlCan devices on third-party foundation models be maintained under pre-specified change control?
No position stated
Autonomy acceptedThe highest level this filing accepts
Low-consequence work: Not stated
High-consequence work: Directs
Machine-assisted draft, pending human review. The source text and highlighted passages appear below. Read the filing on regulations.gov ↗

The comment as filed

Comment submitted on regulations.gov. Passages we counted are highlighted.

Disclosure: I am a practicing emergency physician and a former federal advisor — Special Medical Advisor to the FDA Commissioner (Office of Pediatric Therapeutics; Office of Counterterrorism and Emerging Threats) and a former appointee to the U.S. National Biodefense Science Board. I am also the founder of a company working on human-accountability technology for AI, and I disclose that commercial interest plainly. This comment is offered at the level of regulatory principle. A fuller version is attached.

Central recommendation: For agentic AI-enabled medical devices, "human oversight" should not be accepted as a design claim. It should be required as a verifiable, tamper-evident record that a real, present, uncoerced human authorized each consequential action at the moment it was taken. The discussion paper asks the right question — how to reflect the "reduced opportunity for human review" when an agent plans and executes multi-step tasks. The answer is to make human oversight provable.

The problem. Traditional software produces an output a clinician accepts or rejects; the human is a gate. Agentic systems collapse that gate — the device retrieves data, calls tools, drafts and places orders, and updates the record faster than any clinician can review each step, sometimes with no natural review point. "A human is in the loop" becomes an assertion no one can test. The consequential actions — a medication order, a triage disposition, a documentation entry that drives care and billing — are exactly where an unreviewed error, or an action taken when no human authorized it, causes direct patient harm. A device that cannot demonstrate human authorization cannot be evaluated against any human-oversight requirement; the requirement becomes decorative.

Identity is not authorization. Knowing who the user is does not establish that the user authorized this specific act. Evaluation should ask for proof of authorization at the action, not proof of identity at login — and this can be done without collecting or storing a biometric identifier, which would create its own privacy liability and security target. "Add more biometrics" builds the honeypot that data-minimization counsels against and still does not prove a specific act was authorized. The check should also be resistant to spoofing, so a deepfake or an AI agent cannot stand in for the human.

Recommendations:

Risk assessment — distinguish agentic devices by the reversibility and consequence of the actions the agent can take autonomously, not only by indication or model type. The more consequential and less reversible the action, the stronger the required evidence of contemporaneous human authorization.
Premarket — require a demonstration that the device produces a verifiable, tamper-evident authorization record for each class of consequential action: who authorized it, and were they present and acting freely.
Postmarket — require retention and auditability of that authorization evidence, proportionate to consequence. Without it, surveillance of agentic behavior is reconstructive guesswork.

As a governing principle, we already govern catastrophic, irreversible capability with positive human control — unforgeable authorization and, for the gravest actions, agreement by more than one accountable person. Translated to clinical agents: for the narrow set of actions consequential and irreversible enough to warrant it, no agent should complete the action without verifiable authorization by an accountable human, and the system should fail safe in its absence. Treat verifiable human authorization at the point of the consequential action as an operational control that manufacturers can be asked to demonstrate — a concrete form of human oversight, not just lip service or a statement on a page.

Thank you for the opportunity to comment.

Daniel B. Fagbuyi, MD — Practicing Emergency Physician; former Special Medical Advisor to the FDA Commissioner (Office of Pediatric Therapeutics; Office of Counterterrorism and Emerging Threats); former appointee, U.S. National Biodefense Science Board. LinkedIn: linkedin.com/in/drdandocdanmd

Attachment

Attachment, text extracted from the filed document. Passages we counted are highlighted.

Public Comment — Docket FDA-2026-N-7874
Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper
and Request for Feedback

Submitted to: Division of Dockets Management, U.S. Food and Drug Administration, via
Regulations.gov (Docket No. FDA-2026-N-7874)

Submitted by: Daniel B. Fagbuyi, MD — Practicing Emergency Physician; Founder, Orzyn

Date: September 2026

Disclosure of interest: I am the founder of Orzyn, a company developing human-accountability
infrastructure for AI-mediated actions, and I have a commercial interest in the subject matter of
this comment. I submit it in my capacity as a physician and former federal advisor. I previously
served as a Special Medical Advisor to the FDA Commissioner, Office of Pediatric Therapeutics,
and to the Office of Counterterrorism and Emerging Threats, and I am a former federal
appointee to the U.S. National Biodefense Science Board. The recommendations below are
framed at the level of regulatory principle and are offered to strengthen the framework, not to
advantage any product, including my own.

Summary

I commend CDRH and the Digital Health Center of Excellence for asking, directly, how to reflect
the reduced opportunity for human review in acceptance criteria for agentic AI systems — those
that plan and execute multi-step tasks and use external tools. That is the most important
question in the paper, and this comment addresses it. My central recommendation: for agentic
GenAI-enabled devices, “human oversight” should not be accepted as a design claim. It should
be required as a verifiable, tamper-evident record that a real, present, uncoerced human
authorized each consequential action at the moment it was taken. The regulatory question for
an autonomous clinical agent is no longer only whether the output is accurate. It is whether an
accountable human authorized this specific consequential act — and whether that can be
proven afterward. Present frameworks name human oversight everywhere and give device
makers no way to demonstrate it.
That gap is where patient harm, and unassignable liability, will
concentrate.

1. The problem the paper correctly identifies

Traditional software and locked AI models produce an output that a clinician reviews and
accepts or rejects; the human is a gate. As the paper recognizes, agentic systems collapse that
gate: the device plans and executes a chain of actions — retrieving data, calling external tools,
drafting and placing orders, updating the record — often faster than any clinician can
meaningfully review each step, and sometimes with no natural review point at all. “A human is
in the loop” becomes an assertion no one can test. This matters clinically because the
consequential actions an agent can now take — a medication order, a triage disposition, a
documentation entry that drives downstream care and billing — are exactly the actions where
an unreviewed error, or an action taken when no human actually authorized it, causes direct
patient harm. It matters for regulation because a device that cannot demonstrate human
authorization cannot be meaningfully evaluated against any human-oversight requirement; the
requirement becomes decorative.

2. Recommendation for risk assessment

I recommend the risk framework distinguish agentic devices by the reversibility and
consequence of the actions the agent can take autonomously, not only by clinical indication or
model type.
An agent that drafts a note for clinician signature is a different risk object from one
that can place an order or alter a record.
Acceptance criteria should scale accordingly: the more
consequential and less reversible the autonomous action, the stronger the required evidence of
contemporaneous human authorization at the point of that action.

3. Recommendation for premarket evaluation

For agentic devices, I recommend CDRH consider requiring, as part of the premarket submission,
a demonstration that the device produces a verifiable, tamper-evident authorization record for
each class of consequential action it can take — evidence that answers who authorized this, and
whether they were actually present and acting freely. This is achievable without collecting or
storing biometric identifiers; presence and authorization can be evidenced without building a
biometric database that itself becomes a privacy liability and a security target.
The reflex
solution — “add more biometrics” — creates exactly the honeypot that data-minimization
principles counsel against, and it does not actually prove authorization of a specific act. The
evaluation should ask for proof of authorization at the action, not proof of identity at login.
Identity is not authorization. Knowing who the user is does not establish that that user
authorized this particular consequential action — and the second is what protects the patient.

4. Recommendation for postmarket monitoring

Authorization records of the kind described above are also the substrate for meaningful
postmarket surveillance. If each consequential agentic action carries a tamper-evident record of
its human authorization (or of its absence), then adverse-event investigation, root-cause
analysis, and pattern detection across a fleet of deployed agents become tractable.
Without
such records, postmarket monitoring of agentic behavior is largely reconstructive guesswork.
I
recommend postmarket expectations for agentic devices include retention and auditability of
authorization evidence proportionate to the consequence of the actions the device performs.

5. A governing principle from adjacent high-consequence fields

The field has already solved a version of this problem for other high-consequence, irreversible
actions. In domains where an erroneous or unauthorized act cannot be undone, we do not rely
on asking the system to behave; we require positive human control — unforgeable
authorization and, for the gravest actions, concurrence by more than one accountable person.
That principle translates directly to autonomous clinical agents: for the narrow set of actions
consequential and irreversible enough to warrant it, no agent should be able to complete the
action without verifiable authorization by an accountable human, and the system should fail
safe in the absence of that authorization. I encourage CDRH to treat verifiable human
authorization at the point of the consequential action as an operational control that
manufacturers can be asked to demonstrate — the concrete form that “human oversight” must
take to be more than a word.

Conclusion

The paper asks the right question about agentic systems and the reduced opportunity for
human review. My recommendation is to answer it by making human oversight provable:
require, proportionate to consequence and irreversibility, a verifiable and tamper-evident
record that a real, present, uncoerced human authorized each consequential action —
evidenced without building a new biometric honeypot. This protects patients, makes the
human-oversight requirement testable in premarket review, and gives postmarket surveillance
something real to examine. I appreciate the Agency’s early engagement and am glad to provide
further detail on any point.

Respectfully submitted,

Daniel B. Fagbuyi, MD
Practicing Emergency Physician
Former Special Medical Advisor to the FDA, Office of Pediatric Therapeutics (OPT), and Office of
Counterterrorism and Emerging Threats (OCET)
Founder, Orzyn
Former Federal Appointee, U.S. National Biodefense Science Board
linkedin.com/in/drdandocdanmd