Cassiana Souza Meyer
Themes it raises
FDA questions it names
Q1 · The two-axis risk frameworkQ2 · The spectrum of device activityQ6 · Care escalation functionsQ21 · Clinicians, institutions and societiesQ22 · Re-benchmarking after a modificationQ23 · PCCPs for GenAI devicesQ24 · Third-party foundation model changesQ25 · Foundation Model Master Files
The comment as filed
Docket No. FDA-2026-N-7874 - Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback
Submitted by Cassiana Souza Meyer, MD, occupational medicine physician (CRM 109.930/SP, Brazil). I have no financial interest in any medical device and am not submitting on behalf of any organization. I am a physician who reads statutes, not a lawyer.
The full comment is attached (Attachment 1). It responds to Questions 1, 21 and 25, and touches Questions 6, 22, 23 and 24. Every provision relied on is quoted verbatim in its Appendix, with its official source.
Summary. In the regimes I examined that govern the use of artificial intelligence in health coverage decisions - guidance issued by the Centers for Medicare & Medicaid Services for Medicare Advantage, and seven state instruments - the duty falls on the regulated entity that uses the tool; none imposes an obligation on the developer of the underlying model. This bears on Question 25’s request for alternative mechanisms: in these regimes, the regulator reaches the model supplier, if at all, only through the regulated entity. The attached comment describes three mechanisms consistent with that record, and one way the record shows such a mechanism can fail: when the legal requirement can be discharged without performing it.
A three-question test for any accountability assignment, offered for drafting, including of CDRH’s own text:
1. Is the bearer named in the operative sentence?
2. Does any satisfaction clause act on proof, or on the duty?
3. Is the trigger neutral to the direction of the outcome?
A role that fails any one of these can be assigned in text and still leave no one answerable in practice.
Attachment
Comment
Docket No. FDA-2026-N-7874 — Considerations for the Regulation of Generative AI-Enabled
Medical Devices: Discussion Paper and Request for Feedback (August 2026)
Submitted by Cassiana Souza Meyer, MD — occupational medicine physician (CRM
109.930/SP, Brazil), Health AI Observatory (healthaiobservatory.org).
Summary. In the regimes I examined that govern the use of artificial intelligence in health
coverage decisions — guidance issued by the Centers for Medicare & Medicaid Services for
Medicare Advantage, and seven state instruments — the duty falls on the regulated entity that uses
the tool; none imposes an obligation on the developer of the underlying model. This bears on
Question 25's request for alternative mechanisms: in these regimes, the regulator reaches the
model supplier, if at all, only through the regulated entity. Section 5 describes three mechanisms
consistent with that record, and one way the record shows such a mechanism can fail. The
comment also addresses Questions 1 and 21, where state law shows that HCP supervision can
mean different things in different deployment settings. Section 7 reduces the record to a threequestion test that can be applied to any text assigning a postmarket role, including CDRH's own.
Every provision relied on is quoted verbatim in the Appendix, with its official source.
I maintain an independent regulatory observatory that tracks how binding instruments allocate
legal responsibility when artificial intelligence participates in clinical care. I have no financial
interest in any medical device and am not submitting on behalf of any organization. I am a
physician who reads statutes, not a lawyer; every claim below is tied to the provision it comes
from, so any reader can check it against the source.
1. Scope
This comment responds to Questions 1, 21 and 25, and touches Questions 22, 23 and 24 within
the answer to 25 and Question 6 within the answer to 21.
The evidence is domestic law on automated decisions about health coverage. CDRH lists "payers"
among the ecosystem participants in Section VI.B. Coverage is a setting in which U.S. regulators
have already decided, in binding text, who answers when software participates in a decision about
a patient: CMS for Medicare Advantage, and at least seven states for commercial coverage. The
record is instructive, including where it fails.
2. Question 1 — a device's position on the activity axis is a legal property, not a technical
one
Question 1 asks whether the two-axis framework captures the relevant dimensions, and invites
additional ones — naming reversibility, downstream safeguards, time pressure and traceability.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 1 of 12
I would add a dimension adjacent to "availability of downstream safeguards", but distinct from it:
not whether a safeguard exists, but whether the legal requirement for it can be discharged
without performing it.
The activity axis separates functions that take action under healthcare professional (HCP)
supervision from functions that act fully autonomously. Two states have legislated what the
supervised position means, and they produce opposite results for the same device.
Colorado requires the supervision to attach to a person. Colo. Ins. Reg. 10-1-1, 3 CCR 702-10, §
5.A.5 (health benefit plans added effective October 15, 2025):
"Health benefit plan insurers shall ensure that a provider acting on behalf of the insurer
is ultimately responsible for the decisions made when [the system is] used to inform
decisions to modify, or deny requests … for authorization…"
Alabama requires the human decision and then permits it to be attested. Ala. Act 2026-589 (SB
63), § 1(b)(3):
"a determination to deny, delay, or modify … shall always be made by a licensed
physician or other health care professional who is competent to evaluate any
recommendation or conclusion of artificial intelligence…"
And § 1(c)(4):
"The requirements under subsection (b) and this subsection shall be satisfied by an
attestation by an authorized representative of the health benefit plan provider based on
reasonable reliance upon internal policies, procedures, and third-party vendors".
The human-decision requirement sits in subsection (b). By the act's own terms it is satisfied by a
signature resting on reliance on vendors.
The same device, deployed in both states, occupies different positions on CDRH's activity
axis — and nothing about the device has changed. In one, a named clinician carries final
responsibility. In the other, the supervision requirement is dischargeable on paper.
Where a risk framework treats HCP supervision as mitigating, the assumption is doing work the
device cannot guarantee. I would suggest the framework note that the supervised position depends
on whether the supervision requirement is enforceable in the deployment setting, which is
observable in the governing law rather than in the device.
Of the candidate dimensions the paper names, I would also keep time pressure visible as an
explicit modifier rather than folding it into consequence. An action-directing output reaching a
clinician who must act before a second source can be consulted is not the same function as the
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 2 of 12
same output reaching a clinician with time to read the trace. It compounds the point above:
supervision that is legally required but must be exercised in seconds may be supervision in name
only.
3. Question 21 — two domestic models already answer it, by opposite routes
Question 21 asks how to structure roles without diffusing manufacturer accountability. Two states
have answered in enforceable instruments, differently.
Texas prohibits. Tex. Ins. Code § 4201.156(a):
"A utilization review agent may not use an automated decision system to make, wholly or
partly, an adverse determination".
Colorado allocates, in the provision quoted above, and keeps the duty on the regulated entity.
Section 5.B of the same regulation: where an insurer uses third-party vendors, "the insurer
remains responsible for ensuring all requirements in Section 5.A. are met". Section 9 provides for
civil penalties, cease and desist orders, and suspension or revocation of license.
Prohibition and allocation have different lifespans. A prohibition on automated adverse
determinations becomes harder to hold as performance improves. Allocation is indifferent to how
capable the tool becomes: it names who answers. For a postmarket framework expected to outlast
several generations of models, the second is the more durable design.
What undoes allocation is the discharge clause, and Alabama is the worked example. The
same act that requires a clinician to decide also defines the requirement as satisfied by attestation.
Nothing in Section 1 states that the provider remains responsible; the words "responsible",
"remains responsible" and "ultimately responsible" do not appear in the section.
This is not ordinary evidentiary flexibility: it operates on the requirements themselves, and the
verb is "shall", not "may". Comparable provisions elsewhere are narrower: the NAIC Model
Bulletin (adopted December 4, 2023) says insurers "may demonstrate their compliance … through
alternative means" while requiring that third-party systems "will meet the legal standards imposed
on the Insurer itself"; Colorado provides that insurers "may satisfy requests for documentation
and information" through vendors, immediately after "remains responsible". Both act on proof.
Alabama acts on the duty.
The transferable lesson is narrow: assigning a role and defining how that role is discharged are
separate choices, and the second determines whether the first survives.
Applied to the stakeholders Question 21 names, the test is whether a role is written as an input
the manufacturer must be able to receive and act on, or as a duty that can be satisfied in place of
the manufacturer's own. The first adds signal; the second diffuses accountability.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 3 of 12
Clinicians are placed to report failures that appear only in use: an output that is fluent, locally
plausible and wrong. In my own field, occupational medicine, fitness-for-work and return-towork determinations are one such setting, where the harm is both clinical and economic. The
paper already casts clinicians this way, as "[q]ualified, independent clinician adjudicators" in
sample-based review. A clinician report is a postmarket signal, not a transfer of accountability.
Healthcare institutions own the deployment environment — local prompts, retrieval sources,
routing and house rules layered on a device. They can be asked to preserve logs and to notify
the manufacturer of material local configuration changes. Owning the environment is not
owning the device, and an institution should not be asked to re-validate the underlying model.
Professional societies and standards bodies are natural authors of shared competency batteries
and of incident taxonomies that make clinician reports comparable across sites.
4. An asymmetry that Question 6 also reaches
Every state instrument I read regulates the technology on one side of the decision only. Colorado §
5.A.5 reaches decisions to "modify, or deny". Maryland, Washington and Alabama use the same
triad — "deny, delay, or modify". Texas reaches the "adverse determination".
None restricts approval. Washington addresses approval only to permit its automation:
"Algorithms may be used to process and approve prior authorization requests, but may not be used
without human review to deny care based on a determination of medical necessity". A payer may
automate approvals end to end, with no named responsible person and no human review, without
coming within the restrictions of any of these provisions.
Question 6 asks how manufacturers should characterize "both under-escalation and overescalation". The state record is the same observation in another setting: when a rule is written to
catch harm in one direction, the other direction becomes the unregulated path. A system that
approves the inexpensive automatically and routes the expensive to human review produces the
distributional effect these statutes were written to prevent, without triggering any of them.
Where CDRH assigns postmarket roles, I would suggest the trigger be the use of the system in the
decision rather than the direction of its outcome.
5. Questions 25 and 24 — what domestic law shows about reaching upstream
Question 25 notes that "model developers may have limited incentive to disclose safety-relevant
information", and asks: "Are there alternative mechanisms CDRH should consider for obtaining
information about underlying foundation models?" Domestic law on coverage decisions shows
which mechanism has been used so far.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 4 of 12
In each regime examined here, federal and state, the duty for automated coverage decisions falls
on the regulated entity that uses the tool, not on the entity that develops it. CMS took this approach
for Medicare Advantage: an algorithm or software tool "can be used to assist MA plans in making
coverage determinations, but it is the responsibility of the MA organization to ensure that the
algorithm or artificial intelligence complies with all applicable rules for how coverage
determinations by MA organizations are made". The seven state instruments examined —
Washington, California, Texas, Maryland, Indiana, Alabama and Colorado — follow the same
allocation. Their operative provisions name payers, the entities that conduct review on their behalf,
and, in Indiana, the provider that submits the claim; they are silent on the developers of underlying
models.
A distinction matters. In these instruments, the perimeter extends to a third party when that party
performs the regulated function. A vendor that conducts utilization review with an AI tool may
itself be a regulated review agent; the developer of the foundation model beneath that tool does not
conduct review, and none of the instruments examined imposes an obligation on it. The record
does not support treating a model developer as if it were the regulated reviewer.
Where a supplier appears at all, it appears in relation to someone else's duty. California and
Washington use the same formula: each reaches a plan or carrier that uses an artificial intelligence
tool "or that contracts with or otherwise works through an entity that uses" one, and each places
the resulting obligation on the plan or carrier, which "shall ensure all of the following". The NAIC
Model Bulletin asks for contract terms providing audit rights, prefaced by "Where appropriate
and available". Colorado requires insurers to document "the process used for selecting external
resources including third-party vendors that supply" the systems and models it regulates, and
permits documents or information requested by the Division to be provided by third-party vendors
"on behalf of the insurer" — a provision that acts on how compliance is shown, not on who owes
it. Alabama is different: the single occurrence of "third-party vendors" in the act is the discharge
provision quoted above, where reliance on vendors is the basis on which the plan's own duty is
treated as satisfied.
In every regime examined, then, the regulator's line runs to the regulated entity and reaches the
supplier, if at all, through it. That is the mechanism domestic law has used. Alabama shows one
way it can fail: the party that holds the information has no duty to provide it, and the party that
holds the duty may discharge it by attesting to reliance on the first. The record does not show how
the mechanism performs in general. It does not show whether contractual notice of model changes
is honored in practice, how often a silent change to a hosted model goes undetected, or what
follows when a developer refuses audit. And it covers only part of the market: state insurance law
generally does not reach self-funded employer plans, which enrolled 67 percent of covered
workers in 2025 (KFF, Employer Health Benefits Survey 2025).
Mechanisms consistent with this record. The following are offered as options consistent with the
record above, not as conclusions it proves. Each keeps the duty on a party FDA already regulates.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 5 of 12
1. Production on behalf of the obligated party. In the device system, the analog of the insurer is
the manufacturer of the finished device. Information about an underlying model could be
specified among the requirements the manufacturer places on its supplier; the quality
management system regulation already provides that node, since 21 CFR 820.10(a) requires a
quality management system that complies with ISO 13485, which includes purchasing
requirements in Clause 7.4, which the final rule lists as "Purchasing". Such requirements could
cover version identity, a pinned model or endpoint identifier, a changelog, documented refusal
and guardrail behavior, and access to an audit log. Where the information is too sensitive to
travel with every submission, the supplier could produce it directly to the Agency on the
manufacturer's authorization. This is the Colorado § 5.B pattern moved onto a party FDA
already holds.
Alabama marks the boundary of this mechanism. The manufacturer's authorization for a
supplier to produce information should be a way of demonstrating compliance, not a basis on
which the manufacturer's own obligation is treated as satisfied. Written the first way, it follows
Colorado. Written the second way, it reproduces Alabama § 1(c)(4).
2. Evaluation of the assembled device. The paper already states that "the final user-facing device,
as configured and intended to be deployed for real-world use—and not the foundation model
standing alone or other isolated subcomponent—would be evaluated", and Question 22
envisions the manufacturer's premarket competency-based assessment as "a baseline against
which post-deployment modifications could be re-evaluated". That baseline is the technical
half of Question 24: the instrument against which a developer-initiated change is detected and
re-checked. It does not require the model developer to become a device manufacturer.
3. A voluntary Foundation Model Device Master File, on the terms Question 25 drafts. It can
reduce duplicative review, but it does not replace the manufacturer's demonstration that the
finished device remains safe and effective after a change the manufacturer did not initiate, and
the incentive problem the paper identifies remains.
A Predetermined Change Control Plan can describe the manufacturer's detection and re-benchmark
protocol for a class of upstream changes. Question 23 itself recognizes the case where "the nature
or scope of future modifications cannot be fully prespecified"; a change initiated by a third-party
developer is that case. A PCCP can govern the response to such a change; it cannot stand in for
mechanisms 1 and 2.
I do not offer a view on what authority CDRH holds for any of these mechanisms; the paper
expressly reserves that question.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 6 of 12
6. A structural note bearing on monitorability
Maryland's statute, Md. Code Ann., Ins. § 15-10B-05.1, created by Chapter 747 of the 2025 Laws
of Maryland and effective October 1, 2025, moves through three registers in a single section: (B)
names every bound party — carrier, pharmacy benefits manager, private review agent; (C)
replaces the names with a cross-reference — "AN ENTITY SUBJECT TO THIS SECTION
SHALL ENSURE THAT…"; and (D) removes the person entirely — "AN ARTIFICIAL
INTELLIGENCE, ALGORITHM, OR OTHER SOFTWARE TOOL MAY NOT DENY, DELAY
OR MODIFY HEALTH CARE SERVICES".
The subsection that merely delimits scope names everyone, and the most categorical prohibition
in the act is the only sentence with no person in it. A duty whose operative sentence names no
bearer has no one to monitor and no one to report.
To avoid overstating this: designation quality and enforceability are independent properties. In the
instruments I read, the state with the most precise designation is also the one with the discharge
clause. These are two axes, not one ladder.
7. A three-question test for any accountability assignment
The state record reduces to three questions that can be asked of any text assigning a postmarket
role, including CDRH's own:
1. Is the bearer named in the operative sentence? Maryland's most categorical prohibition
names no one (Section 6).
2. Does any satisfaction clause act on proof, or on the duty? Colorado lets vendors supply
documents "on behalf of the insurer"; Alabama treats the requirements as "satisfied by an
attestation" (Section 3).
3. Is the trigger neutral to the direction of the outcome? In the state instruments read,
restrictions attach to one side of the decision; none restricts approval (Section 4).
A role that fails any one of these can be assigned in text and still leave no one answerable in
practice. The test is offered for drafting; it does not measure how a regime performs.
8. Limits of this evidence
This is a purposive sample, not a census. No jurisdiction has been exhaustively surveyed, and the
instruments are limited to those that expressly address artificial intelligence in health care. Each
provision quoted was read in an official source; access dates are on file. A manifest of the
provisions quoted, with the SHA-256 hash of each file they were read from, is deposited at Zenodo
(https://doi.org/10.5281/zenodo.22959381). Washington's section is served in two versions, the
second effective January 1, 2027; the provisions relied on, § 48.43.830(3)(a) and (3)(b), are byteidentical in both. Where an instrument designates a party by function rather than by name, the
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 7 of 12
mapping to an actor category is my reading and is identified as such in the underlying records. The
NAIC Model Bulletin and Colorado Regulation 10-1-1 were read in full but are not part of the
coded corpus; they, and the CMS guidance, are cited here as documents, not as data points. State
insurance law is an analogy to device regulation, not a substitute for it; I offer it because it is a
domestic setting where these allocation questions have already been decided in binding text. The
mechanisms in Section 5 are proposals by analogy: the record shows how these regimes allocate
the duty, not how the mechanisms would perform in device regulation.
What this comment adds to the record is narrow: the verbatim text, checked against official
sources, of how domestic regimes have allocated this duty to date, three mechanisms consistent
with it, and a test for drafting the roles that carry it. It is offered so that the allocation questions in
Questions 24 and 25 can be considered with that text in view.
I am grateful for the opportunity to comment.
Cassiana Souza Meyer, MD
Occupational Medicine · CRM 109.930/SP · Brazil
ORCID: 0009-0002-6628-5435
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 8 of 12
Appendix — Provisions quoted, verbatim
Each entry gives the provision, the text as it appears in the official source, and the date the source
was accessed. Ellipses mark omissions; bracketed words are mine.
A1. Centers for Medicare & Medicaid Services — HPMS Memo, Frequently Asked Questions
related to Coverage Criteria and Utilization Management Requirements in CMS Final Rule
(CMS-4201-F), February 6, 2024, Question 2. cms.gov. Accessed 23 September 2026.
"Do the new rules on clinical coverage criteria for basic Medicare benefits mean that MA
organizations cannot use algorithms or artificial intelligence to make coverage decisions?"
"An algorithm or software tool can be used to assist MA plans in making coverage
determinations, but it is the responsibility of the MA organization to ensure that the
algorithm or artificial intelligence complies with all applicable rules for how coverage
determinations by MA organizations are made".
"Because publicly posted coverage criteria are static and unchanging, artificial intelligence
cannot be used to shift the coverage criteria over time".
A2. Texas — Tex. Ins. Code § 4201.156(a). capitol.texas.gov, SB 815, enrolled text (HTML).
Accessed 16 September 2026; retained 23 September 2026.
"A utilization review agent may not use an automated decision system to make, wholly or
partly, an adverse determination".
A3. Colorado — Colo. Ins. Reg. 10-1-1, 3 CCR 702-10, § 5.A.5. coloradosos.gov/CCR.
Accessed 17 September 2026.
"Health benefit plan insurers shall ensure that a provider acting on behalf of the insurer is
ultimately responsible for the decisions made when ECDIS, or algorithms or predictive
models that use ECDIS, are used to inform decisions to modify, or deny requests by a
covered person or a covered person's provider for authorization prior to, or concurrent with,
the provision of health care services to a covered person".
A4. Colorado — Colo. Ins. Reg. 10-1-1, § 5.B. Same source.
"If an insurer uses third-party vendors … the insurer remains responsible for ensuring all
requirements in Section 5.A. are met … The insurer must establish and document a process
for the selection and oversight of all external resources and third-party vendors … Insurers
may satisfy requests … by third-party vendors providing the requested documents or
information directly to the Division on behalf of the insurer"
A5. Colorado — Colo. Ins. Reg. 10-1-1, § 5.A.13. Same source.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 9 of 12
"13. Documented description of the process used for selecting external resources including
third-party vendors that supply ECDIS, algorithms, and/or predictive models that use
ECDIS including the intended use of the ECDIS, algorithm(s), and/or predictive model(s)".
A6. Alabama — Ala. Act 2026-589 (SB 63), § 1(b)(3) and § 1(c)(4).
alison.legislature.state.al.us, enrolled text. Accessed 17 September 2026. Act number and
approval (April 16, 2026) confirmed against the Secretary of State's act image, accessed 23
September 2026.
§ 1(b)(3): "a determination to deny, delay, or modify … shall always be made by a licensed
physician or other health care professional who is competent to evaluate any
recommendation or conclusion of artificial intelligence…"
§ 1(c)(4): "The requirements under subsection (b) and this subsection shall be satisfied by
an attestation by an authorized representative of the health benefit plan provider based on
reasonable reliance upon internal policies, procedures, and third-party vendors".
A7. Maryland — Md. Code Ann., Ins. § 15-10B-05.1(C) and (D). mgaleg.maryland.gov,
Chapter 747 of 2025. Accessed 17 September 2026.
(C): "AN ENTITY SUBJECT TO THIS SECTION SHALL ENSURE THAT…" (D): "AN
ARTIFICIAL INTELLIGENCE, ALGORITHM, OR OTHER SOFTWARE TOOL MAY
NOT DENY, DELAY OR MODIFY HEALTH CARE SERVICES".
A8. Indiana — Ind. Code § 27-1-52-9(a) and (b); § 27-1-52-6(4). House Enrolled Act 1271
(2026), Public Law 88. iga.in.gov. Accessed 23 September 2026.
§ 9(a): "An insurer may not use an automated: (1) process; (2) system; or (3) tool, including
artificial intelligence; as the sole basis to downcode a claim based on medical necessity
without the review of the covered individual's medical record by an employee or contractor
of the insurer".
§ 9(b): "A provider may not use an automated: (1) process; (2) system; or (3) tool, including
artificial intelligence; to submit a health benefits claim without the review of a provider or
other person involved in the development of the claim for submission".
§ 6(4), defining "insurer": "A third party contractor of an entity described in subdivision (1),
(2), or (3)".
A9. California — Cal. Health & Safety Code § 1367.01(k)(1), as amended by Stats. 2024, Ch.
879, Sec. 1 (SB 1120), effective January 1, 2025. leginfo.legislature.ca.gov. Accessed 17
September 2026.
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 10 of 12
"(k) (1) A health care service plan, including a specialized health care service plan that uses
an artificial intelligence, algorithm, or other software tool for the purpose of utilization
review or utilization management functions, based in whole or in part on medical necessity,
or that contracts with or otherwise works through an entity that uses an artificial
intelligence, algorithm, or other software tool for the purpose of utilization review or
utilization management functions, based in whole or in part on medical necessity, shall
comply with this section and shall ensure all of the following:"
A10. Washington — Wash. Rev. Code § 48.43.830(3)(a) and (3)(b). app.leg.wa.gov. Accessed
16 September 2026; rechecked 18 September 2026. The official page serves two versions, the
second effective January 1, 2027; subsections (3)(a) and (3)(b) are byte-identical in both.
(3)(a): "Only a licensed physician or a licensed health professional working within their
scope of practice may deny a prior authorization request based on medical necessity. The
licensed physician or licensed health professional shall evaluate the specific clinical issues
involved in the health care services requested by the requesting provider by reviewing and
considering the requesting provider's recommendation, the enrollee's medical or other
clinical history, as applicable, and individual clinical circumstances. Artificial intelligence
shall not be the sole means used to deny, delay, or modify health care services. Algorithms
may be used to process and approve prior authorization requests, but may not be used
without human review to deny care based on a determination of medical necessity".
(3)(b): "A carrier that uses artificial intelligence for the purpose of prior authorization or
prior authorization functions, based in whole or in part on medical necessity, or that
contracts with or otherwise works through an entity that uses artificial intelligence for the
purpose of prior authorization or prior authorization functions, based in whole or in part on
medical necessity, shall ensure all of the following: … (vi) The policies and procedures for
using artificial intelligence are open to audit by the office of the insurance commissioner
under chapter 48.37 RCW; …"
A11. NAIC — Model Bulletin: Use of Artificial Intelligence Systems by Insurers (adopted
December 4, 2023), Sections 3 and 4. content.naic.org. Accessed 17 September 2026.
"Where appropriate and available" "may demonstrate their compliance … through
alternative means" "will meet the legal standards imposed on the Insurer itself"
A12. FDA — 21 CFR 820.10(a), Quality Management System Regulation (effective February 2,
2026). ecfr.gov. Accessed 23 September 2026.
"Document a quality management system that complies with the applicable requirements of
ISO 13485 (incorporated by reference, see § 820.7) and other applicable requirements of
this part"
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 11 of 12
Final rule, Medical Devices; Quality System Regulation Amendments, 89 Fed. Reg. 7496
(February 2, 2024). govinfo.gov. Accessed 23 September 2026.
"(iii) Purchasing. Clause 7.4. and its subclauses of ISO 13485;"
Cassiana Souza Meyer · Comment on Docket No. FDA-2026-N-7874 · page 12 of 12