C.D. Rowsell Jr.
FDA questions it names
Q1 · The two-axis risk frameworkQ5 · Multi-turn conversations that migrateQ18 · Trading premarket certainty for postmarket monitoringQ19 · Postmarket performance evaluationQ20 · Machine-based supervisory agentsQ21 · Clinicians, institutions and societiesQ22 · Re-benchmarking after a modificationQ23 · PCCPs for GenAI devicesQ24 · Third-party foundation model changesQ25 · Foundation Model Master FilesQ26 · Agentic devices
The comment as filed
Please see the attached public comment and technical annex concerning execution-time revalidation and authority controls for generative and agentic AI-enabled medical devices. This submission addresses Questions 1, 5, and 18 through 26.
Attachment
FDA-2026-N-7874 | PUBLIC SUBMISSION
PART I - PROPOSED PUBLIC SUBMISSION
Comment on FDA Docket FDA-2026-N-7874
Considerations for Regulation of Generative AI-Enabled Medical Devices
U.S. Food and Drug Administration, Center for Devices and Radiological Health,
Submitted to
Digital Health Center of Excellence
Courtesy attention Jared Seehafer, M.S., Deputy Commissioner for Technology and AI
Submitted by C.D. Rowsell Jr., M.S.T.M.
Execution-time revalidation and authority controls for generative and agentic AI
Subject
medical devices
Questions addressed Questions 1, 5, and 18 through 26
Executive Summary
FDA's discussion paper correctly recognizes that generative AI systems differ from conventional device software
because they accept open-ended inputs, can generate variable outputs, may change through multiple system
components, and can progress from conversation to autonomous multi-step action. FDA's proposed risk matrix and
lifecycle questions provide an important starting point. One additional control is needed: a prior authorization must not
be presumed to survive a material change.
This comment recommends an execution-time control that connects an authorized baseline to the actual conditions
present when an AI system produces a consequential output or takes an action. That control is Lookback followed by
Revalidation. Lookback determines whether the evidence, rule, system state, version, scope, and human authority
supporting the prior authorization remain valid. Revalidation then permits one of three governed outcomes: act,
suspend, or escalate.
CHANGE ACT / SUSPEND
AUTHORIZED LOOKBACK REVALIDATION RECONCILE
DETECTION / ESCALATE
This sequence should apply to material changes in model, data, prompt, retrieval, guardrail, orchestration, tool,
environment, patient context, governing rule, or human authority. It should also apply when the system cannot
establish that nothing material changed. A communications failure, missing return, unresolved conflict, or untraceable
authority should place the relevant function on hold; it should not create implied permission.
Silicon Sherlock Governance Background
Silicon Sherlock Governance is a human-authority-centered evidence and control architecture developed by C.D.
Rowsell Jr. It draws upon structured probable-cause development, real-time transaction systems, and technologymanagement controls. The architecture separates DATA, INTERPRETATION, UNCERTAINTY, and CONTEXT;
preserves evidence, constraints, system state, version history, and authority lineage; and requires Lookback and
Revalidation following material change. An AI system may identify a conflict or an unsuitable rule, but it may not amend
its governing authority or authorize itself to proceed. This brief applies selected Silicon Sherlock Governance principles
to generative and agentic AI medical devices; it is not the complete system specification.
Requested FDA Action
FDA should consider adding execution-time authorization integrity to its regulatory framework as a mandatory gate
rather than merely another performance score. Premarket evidence, postmarket monitoring, and an authorized
Predetermined Change Control Plan remain necessary, but they do not by themselves establish that a particular output
or action is authorized under current conditions.
Benchmarking determines whether the system can perform. Monitoring determines whether its performance has
changed. Lookback and Revalidation determine whether it may act now. A safe regulatory framework requires all
three.
C.D. Rowsell Jr., M.S.T.M. | Page 1 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX TO PROPOSED PUBLIC SUBMISSION
Response Map
The recommendations below answer only those discussion-paper questions that directly concern governance,
change, supervision, accountability, and agentic execution. They complement, rather than replace, FDA's
existing expectations for safety, effectiveness, clinical validation, cybersecurity, human factors, and quality
systems.
FDA question Control issue Silicon Sherlock Governance response
Add execution-time authorization integrity as
Q1 Risk dimensions a mandatory gate, including reversibility,
traceability, and valid human authority.
Treat the conversation as changing system
Q5 Multi-turn trajectories state; detect directive drift and revalidate
before consequential output or action.
Use event-triggered reassessment,
Q18-Q20 Premarket/postmarket and supervision independent supervisory controls, fail-closed
behavior, and governed returns.
Define authority lineage and role-specific
Q21 Stakeholder roles duties without diffusing manufacturer
accountability.
Tier changes by materiality; revalidate
Q22-Q24 Modification and third-party change before use; hold when the authorized scope
or impact cannot be established.
Use version-linked, current, decisionQ25 Foundation-model information relevant information; retain sponsor
responsibility for intended-use validation.
Limit tools and routes, prohibit selfauthorization, require human checkpoints for
Q26 Agentic systems
high-consequence actions, and reconcile
after action.
1 Authorization Integrity as a Required Gate
Response to Question 1
FDA asks whether additional dimensions should supplement the proposed matrix of device independence and
consequence of an incorrect output. The framework should separately evaluate execution-time authorization
integrity. This is best implemented as a gate because a system that is capable and statistically well-performing
may still be operating under an expired, superseded, inapplicable, or untraceable authorization.
At minimum, the gate should test:
Reversibility and recoverability of the proposed output or action.
Time pressure and the practical ability of a human to intervene before consequence.
Traceability from the proposed action to current evidence, system state, version, rule, and human authority.
Whether the authorization remains within its original purpose, scope, conditions, and validity period.
Whether downstream safeguards are independent, available, and capable of stopping or correcting the
action.
Whether unresolved uncertainty or communications failure prevents a reliable determination.
The gate should be explicit: PASS permits continuation within scope; HOLD suspends the relevant function;
ESCALATE transfers the decision to a named human authority. The system must not convert missing evidence
or unavailable supervision into permission.
C.D. Rowsell Jr., M.S.T.M. | Page 2 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX CONTINUED
2 Multi-Turn Conversation as Changing System State
Response to Question 5
Testing realistic multi-turn trajectories is necessary because risk can emerge from the sequence even when each
isolated response appears acceptable. A conversation can drift from general information to patient-specific
recommendation, from recommendation to instruction, and from instruction to action. The regulatory object
should therefore include the accumulated state of the interaction, not merely the latest prompt and response.
Manufacturers should define material trajectory changes and demonstrate that the system detects them.
Examples include a transition from education to diagnosis or treatment, the introduction of new patient facts, a
change in user identity or authority, conflict between current and prior instructions, repeated efforts to bypass
safeguards, and a tool request that creates an external effect. Detection should trigger Lookback and
Revalidation before the system provides a consequential output or invokes a tool.
Evaluation should include long conversations, contradictory inputs, delayed disclosures, interruptions, handoffs,
attempts to induce false certainty, and cases in which the current turn cannot be interpreted safely without earlier
context. Results should distinguish DATA, INTERPRETATION, UNCERTAINTY, and CONTEXT so that
apparent fluency does not conceal an unsupported conclusion.
3 Premarket Uncertainty and Postmarket Reassessment
Responses to Questions 18 and 19
Greater reliance on postmarket evidence may be reasonable only when the uncertainty is bounded, the potential
harm is sufficiently reversible or containable, and the monitoring and response controls are validated before
deployment. Higher-consequence or difficult-to-reverse actions require stronger premarket evidence, tighter
operating limits, and a lower tolerance for unresolved uncertainty.
Reassessment should combine a defined cadence with event-based triggers. Calendar-only review is insufficient
for systems that can change through external models, retrieval sources, prompts, guardrails, orchestration, tools,
user roles, or environmental conditions. Triggering events should include:
Any model, system, prompt, retrieval, guardrail, orchestration, interface, or tool version change.
Changes in data distribution, workflow, patient population, intended user, care setting, or connected system.
Unexpected output patterns, tool errors, repeated overrides, delayed returns, under-escalation, or overescalation.
New clinical evidence, safety information, vulnerability information, policy, regulation, or governing
instruction.
Loss of monitoring, provenance, audit logging, human availability, or reliable communications.
Each trigger should have a defined response time, decision owner, evidence requirement, and disposition. When
impact cannot be established within the allowed time, the affected function should suspend or fall back to a
validated safe state.
C.D. Rowsell Jr., M.S.T.M. | Page 3 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX CONTINUED
4 Supervisory Agents Must Be Governed
Response to Question 20
A machine-based supervisory agent can add useful coverage, but it cannot be treated as independent assurance
merely because it is labeled a supervisor. FDA should expect evidence that the supervisory function is
sufficiently separated from the action-producing function, evaluated against distinct failure modes, and prevented
from changing its own authority or approving its own modifications.
A supervisory agent should have limited permissions; immutable, reviewable logs; version-linked acceptance
criteria; bounded loops and resources; and a fail-closed response to missing inputs, tool failures, or
communications failures. Its conclusion should return to the governing parent process or designated human
authority. Lateral invocation among subordinate agents should not create an unreviewed path around the
governing control. Any modification to the supervisor should itself trigger Lookback and Revalidation.
5 Accountability and Authority Lineage
Response to Question 21
Shared responsibility should not become shared ambiguity. Manufacturers, third-party model providers,
healthcare organizations, clinicians, patients, and regulators may hold different information and duties, but the
device manufacturer should retain responsibility for the safety and effectiveness of the marketed device function
and for integrating third-party components within its intended use.
FDA should expect an authority-lineage record that identifies the source, version, scope, conditions, validity, and
decision owner for every rule or authorization relied upon for consequential action. A role matrix should state
who monitors, who may pause, who investigates, who determines materiality, who approves return to service,
and who reports externally. A clinical user may contribute judgment; a healthcare organization may control local
deployment; a model provider may supply change information; none of those roles should erase the
manufacturer's system-level accountability.
C.D. Rowsell Jr., M.S.T.M. | Page 4 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX CONTINUED
6 Change Control and Predetermined Plans
Responses to Questions 22 through 24
The rigor of re-benchmarking should scale with the probable impact and uncertainty of a modification, but every
modification should first pass through a consistent materiality determination. The determination should consider
not only model weights, but also prompts, retrieval sources, guardrails, orchestration, tools, interfaces,
connected systems, operating environment, user roles, and governing instructions.
A practical three-tier approach is:
1. No material effect established. Record the change and the evidence supporting the determination;
confirm that the authorized baseline remains valid.
2. Material change within an authorized Predetermined Change Control Plan. Complete the plan's
specified verification and validation, then perform execution-time Revalidation before the changed
function is used.
3. Change outside the authorized plan, or impact cannot be established. Suspend the affected
function, escalate for human and regulatory determination as applicable, and do not infer
authorization from prior approval.
Predetermined plans remain valuable even when every future implementation detail cannot be named in
advance. The plan can prespecify change categories, boundaries, evidence requirements, unacceptable
conditions, decision rights, monitoring, rollback, and escalation. It should not become an open-ended delegation
that allows the system or a third party to redefine the plan's own scope.
For third-party foundation models, manufacturers should maintain version pinning or an equivalent controlledupdate mechanism where feasible, contractual change notification, provenance and integrity checks, predeployment evaluation, defined fallbacks, and rapid suspension capability. An unannounced or opaque upstream
change is itself a material event until the manufacturer establishes otherwise.
C.D. Rowsell Jr., M.S.T.M. | Page 5 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX CONTINUED
7 Foundation-Model Information
Response to Question 25
A voluntary Foundation Model Master File could reduce duplicated work, but it will support reliable decisions only if its
information is current, version-specific, decision-relevant, and accessible on terms that permit timely safety action.
Useful information includes training and evaluation provenance at an appropriate level, known limitations and failure
modes, supported and unsupported uses, security and robustness information, change history, update interfaces,
benchmark methods and results, and notification commitments.
The file should not replace the device manufacturer's independent validation for its intended use and risk controls. FDA
and the manufacturer need a verifiable linkage to the exact model or service version deployed. If that linkage cannot
be maintained, the affected use should be treated as changed and revalidated or suspended.
8 Agentic AI Requires Action Controls
Response to Question 26
Agentic systems increase risk because they can plan, select tools, take multiple steps, and create external effects
before a human sees the intermediate reasoning or result. Regulation should therefore address the complete action
chain, including authorization before action, control during execution, and reconciliation after action.
FDA should consider the following minimum expectations:
Parent-controlled orchestration with one governed entry and one governed return for each subordinate function.
No unapproved child-to-child lateral invocation and no route that bypasses the governing parent or human
checkpoint.
Least-privilege tool permissions, explicit action scope, validated parameter limits, and separation of read,
recommend, order, modify, and execute authorities.
Fresh human confirmation before irreversible or high-consequence actions unless FDA has specifically accepted a
validated autonomous pathway for that action and context.
Stop, suspend, or safe-state behavior when a return is missing, contradictory, late, unverifiable, or outside the
permitted range.
Post-action authorization reconciliation that compares what was authorized, what was attempted, what actually
occurred, and what result was returned.
Limits on loops, time, resource use, repeated retries, and accumulated action scope, with escalation before those
limits are extended.
The central safeguard is simple: an AI system may flag a rule conflict or recommend that a governing constraint be
changed, but it may not amend that authority, authorize itself, or continue because the proper authority is unavailable.
C.D. Rowsell Jr., M.S.T.M. | Page 6 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
TECHNICAL ANNEX CONTINUED
9 Minimum Evidence and Control Record
To make the framework inspectable, the manufacturer should preserve a compact, version-linked record for
every consequential pathway. The record need not expose protected intellectual property, but it must allow FDA
and the manufacturer to reconstruct the basis, authority, state, decision, and result.
Minimum record Required content
Approved intended use, model/system versions, tools, data
Authorized baseline sources, prompts, retrieval, guardrails, operating limits, and
human authority.
What changed, when, why, by whom or by what process, and
Change record whether the change was planned, detected, or externally
imposed.
The current source, scope, version, conditions, and validity of
Authority lineage
the rule or human authorization relied upon for action.
Whether the prior authorization survives the detected change,
Lookback decision
with evidence, uncertainty, and unresolved conflicts preserved.
The decision to act, suspend, or escalate, including reviewer
Revalidation decision
identity, applicable evidence, and time of determination.
The action actually taken, the result returned, tool or
Reconciliation record
communication failures, discrepancies, and required follow-up.
C.D. Rowsell Jr., M.S.T.M. | Page 7 of 8
FDA-2026-N-7874 | PUBLIC SUBMISSION
10 Conclusion
FDA's discussion paper identifies the core challenges of generative and agentic AI: variable outputs, conversational
drift, evolving multi-component systems, third-party dependencies, and autonomous action. The missing connection is
between an authorization established earlier and the conditions that exist when the device is ready to act.
FDA should require a documented change gate, Lookback, and Revalidation for material changes and uncertainty
about materiality. The allowable results should be act, suspend, or escalate; silence, communications failure,
unavailable authority, or an incomplete return must never operate as implied permission. This control complements
benchmarking, monitoring, Predetermined Change Control Plans, and lifecycle management by answering the final
operational question: is this system, under these conditions, authorized to act now?
References
1. U.S. Food and Drug Administration. Considerations for Regulation of Generative AI-Enabled Medical Devices:
Discussion Paper and Request for Feedback, August 2026. Official source
2. U.S. Food and Drug Administration. Considerations for Regulation of Generative AI-Enabled Medical Devices:
Discussion Paper and Request for Feedback, docket information and submission page. Official source
3. U.S. Food and Drug Administration. Marketing Submission Recommendations for a Predetermined Change Control Plan
for Artificial Intelligence-Enabled Device Software Functions, final guidance. Official source
4. U.S. Food and Drug Administration. Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management
and Marketing Submission Recommendations, draft guidance, January 2025. Official source
5. U.S. Food and Drug Administration. FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AIEnabled Medical Devices, August 18, 2026. Official source
Development Method and Scope
This document was developed using selected Silicon Sherlock Governance controls. C.D. Rowsell Jr. defined the purpose,
scope, governing concepts, and human-authority requirements; evaluated the substance; directed revisions; and retained
authority over acceptance and release. AI tools assisted with source organization, drafting, document construction, Word-toPDF transformation, and validation. The process applied constraint retention, artifact versioning, Lookback and Revalidation
after material changes, and return of the completed work to the human decision-maker. The AI tools did not approve their
own work or authorize submission.
Scope of This Submission
This public comment addresses governance architecture. It does not evaluate clinical efficacy, provide legal
advice, or represent Silicon Sherlock as a medical device. Proprietary implementation details are outside the
scope of this submission.
Submitted respectfully by C.D. Rowsell Jr., M.S.T.M.
Master of Science in Technology Management, Pepperdine University
C.D. Rowsell Jr., M.S.T.M. | Page 8 of 8