← All 111 filings

Syntheka (Tolu Apena)

IndustryStartupFiled September 22, 20261,301 words · 1 attachmentFDA-2026-N-7874-0112

Themes it raises

4 of the 21 themes in the docket, each with the passage we counted, verbatim.
What makes a function high riskFDA Q1, Q2, Q5
“The consequence axis of the proposed framework needs to account for this category of regulated-but-non-device AI use.”
How this fits rules that already existFDA Q8, Q9, Q16, Q25
“They therefore fall outside the medical device definition. But they operate in GCP-regulated environments where their outputs directly affect the integrity of regulatory submissions.”
Whether human oversight is real oversightFDA Q3, Q4, Q14, Q20, Q21, Q26
“When an AI tool provides a recommendation in this context, the operator's ability to critically evaluate it is not guaranteed by institutional governance frameworks.”
Records that let investigators reconstruct an eventFDA Q19, Q21, Q24, Q26
“If an AI tool generates a recommendation that a coordinator accepts without modification, the AI's role in producing that output may not be captured in the audit trail at all.”

FDA questions it names

Questions this filing names by number.

Q3 · When an output becomes directiveQ7 · The competency-based approachQ14 · Comparators and acceptance criteria

Machine-assisted draft, pending human review. The source text and highlighted passages appear below. Read the filing on regulations.gov ↗

The comment as filed

Comment submitted on regulations.gov. Passages we counted are highlighted.

Please see the attached document for Syntheka’s full comment on Regulation of Generative AI-Enabled Medical Devices.

Attachment

Attachment, text extracted from the filed document. Passages we counted are highlighted.

Tolu Apena, Founder
SYNTHEKA MSc, Applied Clinical Research
St. Cloud State University, Minnesota
Placing Agreements Together

DATE: September 22, 2026
TO: U.S. Food and Drug Administration, Digital Health Center of Excellence
RE: Docket No. FDA-2026-N-7874, Considerations for the Regulation of Generative AI-Enabled
Medical Devices, Discussion Paper and Request for Feedback
FROM: Tolu Apena, Founder, Syntheka | MSc, Applied Clinical Research

Introduction

I submit this comment as a clinical research professional with experience across oncology,
nephrology, and multiple therapeutic areas in Nigeria and the United States, and as the
founder of Syntheka, a platform focused on clinical trial agreement and budget negotiation
infrastructure. My perspective on this discussion paper is grounded in operational experience
at the research site level, where AI tools are beginning to enter regulated workflows occupied
by personnel who have no formal framework for evaluating AI-generated outputs.
I welcome the Digital Health Center of Excellence's initiative to build a regulatory framework
for generative AI-enabled medical devices. This comment responds to Questions 3, 7, and 14
of the discussion paper, which address risk assessment, human oversight, and postmarket
monitoring respectively. I do not address all 26 questions. I address only those where clinical
research site operations provide a perspective that device manufacturers and health systems
are unlikely to bring.

Question 3: Risk Assessment for AI Operating in Regulated Research Settings

The discussion paper proposes a two-axis risk framework: one axis scoring how
independently a function acts, from non-directive information through action-directing
information to autonomous action; the other scoring the consequence of relying on an
incorrect output. This framework is a sound foundation. It has a gap, however, when applied
to AI tools operating in clinical research settings that are regulated under Good Clinical
Practice but not classified as medical devices.
As AI tools enter contract review and budget analysis workflows at research sites, they do not
diagnose patients or direct clinical care. They therefore fall outside the medical device
definition. But they operate in GCP-regulated environments where their outputs directly
affect the integrity of regulatory submissions.
An AI tool that flags a contract clause
incorrectly, or suggests a budget line item that does not reflect fair market value, produces
an error that becomes part of a regulated trial record when a site coordinator acts on it
without independent verification.
The consequence axis of the proposed framework needs to account for this category of
regulated-but-non-device AI use.
The harm is not clinical harm to a patient in real time. It is
regulatory harm: compromised data integrity, incorrect contract terms in a binding
agreement, and audit trail failures in a GCP-regulated submission. These consequences are
serious and they are not currently captured in frameworks designed around clinical care AI.

Recommendation: Question 3
FDA should consider a supplementary risk category for AI tools operating in GCPregulated clinical research environments that fall below the medical device
threshold. The consequence axis of the proposed framework should explicitly
address regulatory harm, not only clinical harm, as a consequence class. This
category includes AI tools used in contract review, budget analysis, eligibility
screening, and regulatory document management at research sites.

Question 7: Human Oversight Requirements at the Operator Level

The discussion paper discusses human oversight primarily at the institutional and developer
level. It addresses how developers should design systems with human oversight in mind, and
how institutions should establish governance frameworks. What it does not address is the
operator level: the individual clinical research coordinator, contract manager, or regulatory
affairs specialist who receives an AI-generated recommendation and must decide whether to
act on it.
This gap matters because in clinical research site operations, the operator is frequently the
end point of the oversight chain. Coordinators manage multiple concurrent trials, under time
pressure, with limited AI literacy training, and with direct accountability for the accuracy of
regulatory submissions. When an AI tool provides a recommendation in this context, the
operator's ability to critically evaluate it is not guaranteed by institutional governance
frameworks.
It depends on individual training, available time, and access to verification
resources that are often absent.
The competency-based premarket evaluation approach the paper proposes for clinicians
using GenAI diagnostic tools is the right model. The same logic applies to research site staff
using AI tools in GCP-regulated workflows. If a site coordinator's independent judgment is the
last human check before an AI-assisted output enters a regulatory submission, that
coordinator needs a defined competency standard, not just an institutional policy that a
governance committee approved.

Recommendation: Question 7
FDA's competency-based oversight framework should extend to operator-level
personnel in GCP-regulated settings, not only clinicians using AI diagnostic tools.
For AI tools used in clinical research site operations, sponsors and platform
developers should be required to demonstrate that site-level personnel have access
to defined competency standards for evaluating AI-generated outputs in their
specific workflow context. Institutional AI governance policies do not substitute for
this requirement.

Question 14: Postmarket Monitoring in Research Site Environments

The discussion paper addresses postmarket monitoring primarily in terms of real-world
performance data collected after a device enters the market. In clinical research site settings,
there is an additional postmarket monitoring dimension that warrants specific consideration:
the audit trail.
When an AI tool assists in contract negotiation or budget analysis at a research site, the
output of that process becomes part of the clinical trial record. Under FDA 21 CFR Part 11,
electronic records in regulated clinical research must meet specific requirements for
integrity, authenticity, and auditability. If an AI tool generates a recommendation that a
coordinator accepts without modification, the AI's role in producing that output may not be
captured in the audit trail at all.
The record shows only the final agreed output, not the
process by which it was reached or the AI's contribution to it.
This creates a gap in the postmarket monitoring framework. If an AI tool is consistently
producing outputs that site personnel accept without modification, and this pattern is not
visible in the audit trail, neither the sponsor, the site, nor the FDA has the information needed
to evaluate whether the tool is performing appropriately or whether operator oversight is
functioning as intended.

Recommendation: Question 14
For AI tools operating in GCP-regulated clinical research environments, postmarket
monitoring requirements should include audit trail transparency: a documented
record of AI-generated recommendations, operator review decisions, and the basis
for acceptance or rejection. This requirement should apply regardless of whether
the tool meets the medical device threshold, as it directly supports GCP compliance
and data integrity in regulated submissions.

Conclusion

The FDA's generative AI medical device discussion paper is a necessary and timely
foundation for a regulatory framework that will shape how AI enters healthcare for years to
come. This comment offers a practitioner perspective on three dimensions where the current
framework has gaps specific to clinical research site operations: risk assessment for GCPregulated but non-device AI tools, human oversight at the operator level, and audit trail
requirements in postmarket monitoring.
These are not edge cases. Clinical research sites in the United States are increasingly being
offered AI tools for contract review, budget analysis, and regulatory document management.
The personnel using these tools are operating in regulated environments with direct
accountability for the accuracy of what they submit. A regulatory framework that does not
account for this setting leaves a foreseeable gap that will become visible in the form of GCP
deficiencies, audit findings, and data integrity failures.
I welcome the opportunity to contribute further to this discussion and am available to provide
additional practitioner perspective to the Digital Health Center of Excellence if it would be
useful.

Respectfully submitted,
Tolu Apena
Founder, Syntheka
MSc, Applied Clinical Research
St. Cloud State University | Minnesota, United States

Syntheka | Placing Agreements Together | Minnesota, United States