Sustwinability LLC
The comment as filed
See attached file(s)
Attachment
Comment to FDA — Docket FDA-2026-N-7874
Considerations for the Regulation of Generative AI-Enabled Medical Devices:
Discussion Paper and Request for Feedback (CDRH Digital Health Center of Excellence,
18 August 2026)
Submitted by: Ajay Batra, Sustwinability LLC (Kaelox) · ajaybatra@kaelox.ai [Submit on
Regulations.gov, docket FDA-2026-N-7874, by 19 October 2026.]
PUBLIC DISCLOSURE — read discipline. Principle level only. Everything here is
either covered by a filed patent application, already public on our site, or generic
policy. The cross-node supply-chain composition mechanism referenced in §4 is
now the subject of a filed provisional application and is described here only at the
principle level; no analyser internals (thresholds, grounding ontology, design-ofexperiments) are disclosed. Short counsel read before submission because it is
public.
Who is commenting
Sustwinability LLC builds Kaelox — AI-Powered Determinism Infrastructure for Safe
AI. Kaelox is not a model and not a device. It is the layer underneath AI that makes a
probabilistic system safe to use where a regulator is watching: the model advises, a
deterministic engine decides against fixed limits, and a qualified person signs. The
approach is the subject of filed patent applications.
We are early-stage (MVP alpha) and make no product claim here. We comment because the
web learned to carry money only after a shared, verifiable trust layer was placed under it
— and regulated AI now needs the same thing: a common, verifiable way to show that
an AI stayed within its bounds. That idea bears directly on the two questions the
discussion paper puts at its center — how to score risk, and how to evaluate a device
before and after market — and on multi-jurisdiction operation and site-to-site handover.
1 · The core idea — marrying the probabilistic and the deterministic
Generative AI is powerful because it is probabilistic, and unusable in a regulated decision
because it is probabilistic. The resolution is not to make the model trustworthy — it is to
take the model out of the decision while keeping its insight:
Determinism → AI → Determinism. Deterministic, computed context goes in.
The model reads and proposes. A deterministic engine verifies every proposal
against fixed limits and decides. Nothing the model emits can reach a recorded
value.
The consequence for regulation is the important part: the validated object is not the
model — it is the evidence chain. What you validate is the constrained, version-locked
configuration around the model and the deterministic verification that follows it, recorded
as an independently verifiable chain binding manufacturing or clinical telemetry, the AI
proposal, the deterministic decision, and the human authorization. The model can change,
drift, or be replaced; the evidence chain — and its guarantees — do not.
Two properties make this checkable rather than merely asserted:
• Human-in-the-loop as an enforced interlock, not advice — no consequential action
proceeds without a qualified person’s signature, and that signature is part of the
record.
• Determinism — the same inputs reproduce the same result, so any entry can be
verified rather than trusted.
2 · On the paper’s two-axis risk framework
The discussion paper proposes scoring a generative function on two axes: how
independently it acts — from non-directive information, through action-directing
information, to supervised and then fully autonomous action — and the consequence of
relying on an incorrect output. We support a two-axis, risk-proportionate approach and
offer one structural observation that we believe strengthens it.
Position on the independence axis can be a property of the architecture, not a claim
about the model. Where a deterministic verifier sits between the generative component
and any consequential output, and an authorizing outcome is unreachable on the modelinfluenced path, the generative function is confined — by construction — to producing
information, not to directing or taking action. A qualified person and a deterministic
engine, not the model, convert that information into any action that occurs. We suggest the
framework can invite an applicant to demonstrate that a function cannot structurally
reach a higher point on the independence axis — a testable property — rather than
resting the score on assurances about model behaviour. Two devices using an identically
capable model may sit at very different points on that axis depending on whether a
deterministic interlock makes autonomous action reachable. Scoring the architecture, not
the model’s ceiling, keeps the axis meaningful as models grow more capable.
The consequence axis is unaffected by this: severity of harm from an incorrect output
remains a clinical judgment. What determinism changes is the likelihood that the AI reaches
that output at all, and — crucially — the ability to prove after the fact which point on the
independence axis actually governed a given decision.
3 · On premarket evaluation — validate the constraint, not the model
The paper models premarket evaluation on how a clinician is credentialed. The metaphor is
apt, and it points to a precise conclusion: credential the decider. In this architecture the
decider is the deterministic gate plus the signing qualified person — not the generative
model. So the object that should be evaluated and version-locked premarket is the
constrained configuration that bounds the model and the deterministic verification that
follows it; the model sits outside the credentialed boundary precisely because nothing it
emits is binding. This makes premarket evidence proportionate to a structural property
that can be tested once, rather than to a model whose behaviour must be re-argued each
time it changes.
4 · On postmarket monitoring — require verifiable records, not just records
An adjacent regime is instructive: the EU battery passport mandated a digital record but
“does not foresee detailed verification for most data, leaving potential gaps for inaccurate
or fraudulent data.” A self-reported, unverified record is the weak link. We encourage the
Agency to consider requiring that a postmarket AI record be independently verifiable —
a third party can confirm, without the manufacturer’s cooperation and without special
tooling, that an output stayed within its authorised envelope, that the record is unaltered
(tamper-evidence that propagates — altering one entry invalidates every later entry), and
that the result reproduces. An auditor should verify an AI decision the way a browser
verifies a certificate: automatically, offline, without trusting the party that produced it.
We further encourage the Agency to look at the whole lifecycle and every handover, not
a single point in time. A device, its data, and its AI cross sites, suppliers, and jurisdictions.
We suggest the unit of postmarket evidence be a sealed, verifiable envelope that travels
with the article — carrying, at each handover, an independently checkable record that the
AI stayed within the envelope authorised for that step and was evaluated against the rules
of the jurisdiction it is entering. Where changes occur under a Predetermined Change
Control Plan, each change should be recorded as such an envelope, verifiably within its
authorised bounds, rather than attested in prose.
This directly addresses three problems the discussion paper raises together: postmarket
monitoring (the record is verifiable end to end), change control (each change is a
checkable envelope), and multi-jurisdiction operation — because an on-premise, zeroegress design that evaluates against the destination jurisdiction’s rules removes the crossborder data-transfer and privacy problem rather than merely satisfying it, while still
producing a record any regulator can verify. Local medical-device and SaMD law, datasafety, and privacy obligations are then met by where the computation happens (on the
manufacturer’s own hardware) rather than by moving data to be checked.
5 · The single recommendation — a common basis of trust
The highest-leverage step, in our view, is a common, verifiable attestation approach for
constrained AI — a shared way to demonstrate “the model was kept within bounds, and
here is the proof anyone can check,” analogous to the shared certificate standard that let
the web establish trust. Open transparency standards for exactly this now exist (for
example the IETF SCITT architecture, RFC 9943, and COSE Receipts, RFC 9942), which lets
an attestation be verified across parties and borders without exposing proprietary data. We
would be glad to contribute to such a discussion, and we believe it is the durable answer to
governing AI that changes.
We appreciate the opportunity to comment and would welcome further engagement with
the Digital Health Center of Excellence. We are responding in part; we do not address all of
the paper’s discussion questions.
Ajay Batra · Sustwinability LLC · Kaelox — AI-Powered Determinism Infrastructure for Safe AI
· patent pending · MVP Alpha