Scale retesting to the change’s clinical impact · Manage bounded changes under an agreed plan
Requires testing before a changed model reaches patients and retains PCCPs for sponsor-controlled changes; rejects extending plans to unpredictable supplier changes.
Read the source passage
R4. Third-party model changes require hard controls, not extended PCCPs (Questions 22, 23, and 24) Docket No. FDA-2026-N-7874 — Individual comment — Page 4 This follows from S3. If the object of evaluation is the deployed configuration, then any change to that configuration — including a change to the underlying model initiated by the model developer — invalidates the evidence until it is re-established. The paper correctly notes that such changes "may be initiated by the foundation model developer rather than the device manufacturer." In practice the sponsor may not learn that a hosted model has changed until behavior shifts in the field. A Predetermined Change Control Plan is the wrong instrument for changes the sponsor cannot predetermine. I recommend instead that CDRH expect the following as conditions of authorization for any device built on a third-party model: version pinning, so that the device runs against a specified, immutable model version; contractual change notification with a minimum lead time before any version is retired; a prohibition on silent updates reaching patients; and re-benchmarking against the premarket baseline before any new model version is placed into clinical use. Where a developer will not offer version pinning or notification, that fact belongs in the risk assessment, and the sponsor should be expected to justify why the device remains safe without it. PCCPs remain useful for changes the sponsor does control, such as prompt revisions or guardrail updates, and the premarket benchmark is the right baseline against which to evaluate them.Original source ↗