← All 95 filings

Matthew Collins (Quality and Regulatory Executive)

IndustryConsultantFiled September 15, 20261,317 words · 1 attachmentFDA-2026-N-7874-0099
“I support exploring greater reliance on postmarket monitoring in well-justified cases, but I caution against treating postmarket monitoring as a substitute for premarket rigor rather than a complement to it.”

What they argued

RecovryAI’s one-line reading of the filing.

M3 from his Q18 section: support for exploring the trade, conditioned on monitoring that identifies the specific failure modes benchmarking did not rule out, with named signals, decision thresholds, escalation requirements, accountable owners and criteria for intervention, rollback or suspension - not a general monitoring program. M4 from his closing: the two-axis framework and competency-based approach are directionally sound, conditioned on CDRH making the decision criteria explicit, including what constitutes meaningful human review (competence, source information, time, authority and documented responsibility, with evidence of what the reviewer verified). M5 from Q22-Q25: prompt, retrieval, guardrail and orchestration changes should be stated in guidance to be device changes subject to documented impact assessment, review, approval and verification, and reliance on a Foundation Model MAF must not shift responsibility for detecting and controlling a developer-initiated change. He recommends reversibility be treated as a gating factor in risk placement but states no position on permitting device autonomy and no autonomy level. Type: an individual quality and regulatory executive filing on his own experience rather than for a firm; consultant is the closest fit for a regulatory practitioner.

Themes it raises

7 of the 21 themes in the docket, each with the passage we counted, verbatim.
What makes a function high riskFDA Q1, Q2, Q5
“I would encourage CDRH to treat reversibility of the resulting action as an explicit gating factor in applying the two-axis framework rather than as an optional modifier.”
Trading premarket certainty for postmarket monitoringFDA Q18
“I support exploring greater reliance on postmarket monitoring in well-justified cases, but I caution against treating postmarket monitoring as a substitute for premarket rigor rather than a complement to it.”
Watching the device after it shipsFDA Q19, Q20
“At minimum, the monitoring strategy should identify the failure modes associated with unresolved premarket uncertainty, the signals used to detect them, decision thresholds, escalation requirements, accountable owners, and criteria for intervention, rollback, or suspension.”
Who is accountable when something goes wrongFDA Q21
“a recurring root cause has been an organization treating a vendor relationship as a transfer of responsibility rather than what it actually is: a transfer of work with retained accountability”
Controlling a device that keeps changingFDA Q22, Q23, Q24, Q25
“I recommend that CDRH state directly in future guidance that prompt, retrieval, and orchestration changes meeting this threshold are device changes subject to change control, not implementation details exempt from it.”
Whether human oversight is real oversightFDA Q3, Q4, Q14, Q20, Q21, Q26
“I recommend that CDRH define human review as a risk-mitigating control only when the reviewer has the competence, source information, time, authority, and documented responsibility needed to independently evaluate the output.”
Records that let investigators reconstruct an eventFDA Q19, Q21, Q24, Q26
“Evidence of human review should identify what the reviewer verified, what evidence was considered, and whether the reviewer accepted, modified, escalated, or rejected the output.”

FDA questions it names

Questions this filing names by number.

Q1 · The two-axis risk frameworkQ3 · When an output becomes directiveQ4 · Generalist and specialist usersQ18 · Trading premarket certainty for postmarket monitoringQ21 · Clinicians, institutions and societiesQ22 · Re-benchmarking after a modificationQ23 · PCCPs for GenAI devicesQ24 · Third-party foundation model changesQ25 · Foundation Model Master Files

Across the five cross-cutting questions

RecovryAI’s reading of the whole filing. Silence is never counted as opposition.
Patient-facing autonomyShould FDA permit patient-facing AI to act with meaningful autonomy within a defined scope?
No position stated
Proportionate evidenceShould evidence requirements scale with clinical risk rather than a uniform high bar?
No position stated
Postmarket relianceCan strong postmarket monitoring justify accepting more premarket uncertainty?
Supports with conditions
Competency evaluationCan a device be evaluated on competency benchmarks and clinical confirmation against clinicians?
Supports with conditions
Change controlCan devices on third-party foundation models be maintained under pre-specified change control?
Supports with conditions
Autonomy acceptedThe highest level this filing accepts
Low-consequence work: Not stated
High-consequence work: Not stated
Machine-assisted draft, pending human review. The source text and highlighted passages appear below. Read the filing on regulations.gov ↗

The comment as filed

Comment submitted on regulations.gov. Passages we counted are highlighted.

See attached file(s): I am submitting this comment as a quality and regulatory executive with 30 years of experience across medical device, pharmaceutical, diagnostic, and combination-product quality systems. My experience includes senior quality leadership during FDA Warning Letter remediation and work within an FDA Consent Decree environment.

I support the direction of this discussion paper. My attached comment addresses the two-axis risk framework, meaningful human review, accountability for third-party foundation models, change control for GenAI-specific modifications, and postmarket monitoring.

My central recommendation is that CDRH make the decision criteria surrounding these controls explicit. In my experience, controls that remain implicit are applied inconsistently and are difficult to defend during an FDA inspection.

Attachment

Attachment, text extracted from the filed document. Passages we counted are highlighted.

Docket No. FDA-2026-N-7874 — Comment of Matthew Collins

Comment on Docket FDA-2026-N-7874: Considerations for the Regulation of Generative AI-Enabled
Medical Devices

Submitted by: Matthew Collins

Capacity: Quality and regulatory executive with 30 years of experience across medical device,
pharmaceutical, diagnostic, and combination-product quality systems, including senior quality
leadership during FDA Warning Letter remediation and experience working within an FDA Consent
Decree environment.

I am submitting this comment as an individual with direct operating experience leading CAPA, complaint
handling, postmarket surveillance, field actions, and quality management systems under FDA oversight,
together with current work developing AI-enabled decision systems for quality and regulatory
operations. I support the direction of this discussion paper and offer the following comments on specific
sections, grounded in what holds up during an FDA inspection versus what appears sound on paper but
fails in execution.

1. On the two-axis risk framework and additional dimensions (Discussion Question 1)

The two-axis framework, the degree and independence of device activity against the consequence of
relying on an incorrect output, correctly identifies the two variables that matter most. I would
encourage CDRH to treat reversibility of the resulting action as an explicit gating factor in applying the
two-axis framework rather than as an optional modifier.

In my experience running field action and CAPA decisions, one of the factors that most influences how
much scrutiny a decision receives, automated or human, is whether the action can be undone before
harm compounds. An AI-generated recommendation that is reviewed and corrected before it reaches a
patient carries fundamentally different risk than one that has already triggered an irreversible clinical
action.

The paper’s agentic AI discussion in Section VII.B implicitly recognizes this by identifying “humanoversight checkpoints before irreversible or high-consequence actions” as a benchmarking
consideration, but reversibility is not elevated to the same visible status as the two primary axes in
Figure 1. I recommend that reversibility be evaluated explicitly before determining a function’s final risk
position, particularly when an output may initiate an irreversible or high-consequence action.

2. On meaningful human review versus nominal human review (Section IV, patient-facing versus HCPfacing discussion; Discussion Questions 3 and 4)

I strongly support the paper’s recognition that a human in the loop does not automatically reduce risk.
In quality systems I have run and remediated, a recurring and dangerous failure mode is not the absence
of human review, but the presence of a signature without genuine evaluation behind it.

A reviewer may sign off on an AI-generated CAPA root cause narrative without independently evaluating
the evidence and reasoning. Similarly, a clinician may accept an AI-generated recommendation because
it is fluent and confidently stated, reflecting the paper’s concern about automation bias in Appendix A,
E.4. In either case, human involvement creates the appearance of oversight without demonstrating that
meaningful review occurred.

Page 1 of 3
Docket No. FDA-2026-N-7874 — Comment of Matthew Collins

I recommend that CDRH define human review as a risk-mitigating control only when the reviewer has
the competence, source information, time, authority, and documented responsibility needed to
independently evaluate the output.
Evidence of human review should identify what the reviewer
verified, what evidence was considered, and whether the reviewer accepted, modified, escalated, or
rejected the output.
A signature alone does not demonstrate that meaningful review occurred.

3. On accountability and third-party foundation models (Sections VI.B and VII.A; Discussion Questions
21 and 25)

I specifically support the paper’s position that manufacturer accountability must not be diffused across
the ecosystem of clinicians, institutions, and third-party model developers. I also offer a caution based
on operating experience.

Across quality system failures I have investigated or remediated involving an outsourced component,
whether a contract manufacturer, supplier-provided subassembly, or software vendor, a recurring root
cause has been an organization treating a vendor relationship as a transfer of responsibility rather than
what it actually is: a transfer of work with retained accountability
.

A voluntary Foundation Model Device Master File could provide a useful mechanism for informationsharing. However, CDRH should extend its statement of sponsor responsibility explicitly across the total
product lifecycle, particularly when a foundation model developer initiates a postmarket change.
Reliance on a Foundation Model MAF should not shift responsibility for detecting, assessing, and
controlling the effect of that change. A device manufacturer’s quality system must be designed and
operated on the assumption that the manufacturer owns the outcome regardless of which layer of the
technology stack originated the failure.

4. On change control for GenAI systems (Section VI.C; Discussion Questions 22 through 24)

I support the paper’s recognition that changes to a GenAI-enabled device can originate from sources
beyond a traditional software update, including prompt changes, retrieval strategy changes, guardrail
changes, orchestration logic changes, and passive model evolution. Based on direct quality system
experience, these changes should be governed with the same risk-based discipline applied to other
safety-relevant software and device changes, not treated as configuration adjustments outside the
quality management system.

A prompt that materially influences what a GenAI-enabled device tells a clinician or patient can function
as an executable instruction governing device behavior. When a prompt, retrieval strategy, guardrail, or
orchestration change can affect device output, intended-use boundaries, or risk controls, it should be
treated as controlled configuration subject to documented impact assessment, review, approval, and
verification.

I recommend that CDRH state directly in future guidance that prompt, retrieval, and orchestration
changes meeting this threshold are device changes subject to change control, not implementation
details exempt from it.
Treating them as categorically exempt would create the kind of undocumented
and unassessed change that CAPA investigations repeatedly identify at the root of unexpected field
performance.

Page 2 of 3
Docket No. FDA-2026-N-7874 — Comment of Matthew Collins

5. On postmarket monitoring and reduced premarket certainty (Section VI.A; Discussion Question 18)

I support exploring greater reliance on postmarket monitoring in well-justified cases, but I caution
against treating postmarket monitoring as a substitute for premarket rigor rather than a complement to
it.
In my experience, organizations that rely on postmarket detection because premarket evidence was
incomplete may not detect problems until signals have accumulated or harm has already occurred.

Whatever conditions CDRH ultimately establishes for accepting greater premarket uncertainty should
require, at minimum, a credible mechanism for detecting the specific failure modes that benchmarking
did not rule out, not a general monitoring program applied uniformly regardless of the premarket
evidence gaps associated with the device.

At minimum, the monitoring strategy should identify the failure modes associated with unresolved
premarket uncertainty, the signals used to detect them, decision thresholds, escalation requirements,
accountable owners, and criteria for intervention, rollback, or suspension.

Closing

I appreciate CDRH’s transparency in developing this framework publicly and its acknowledgment of the
limits of traditional software validation for generative AI. The two-axis framework and competencybased evaluation approach are directionally sound.

My central recommendation is that CDRH make the decision criteria surrounding these controls explicit.
Future guidance should clearly define when additional risk factors must be considered, what constitutes
meaningful human review, how accountability is retained across third-party relationships, which noncode changes require change control, and what evidence demonstrates effective postmarket
monitoring. In my experience, controls that remain implicit are applied inconsistently and are difficult to
defend during an FDA inspection.

Thank you for the opportunity to comment.

Page 3 of 3