Voluntary files alone are insufficient
Supports the master-file concept but argues that rapidly changing hosted models make a static file insufficient. The filing’s measurements are claims by its author, not independently replicated findings.
Read the source passage
The question as posed CDRH asks whether voluntary Foundation Model Master Files would be practical for foundation model developers to provide and to keep current, and what content they might include. It asks what would make such a program sufficiently useful for premarket review, given that participation would be voluntary and that model developers may have limited incentive to disclose safety-relevant information. And it asks whether there are alternative mechanisms CDRH should consider for obtaining information about underlying foundation models. Summary of position We support the master file concept and we do not think it can carry the weight the question hopes for. Our comment has four parts, and the first is a measurement rather than an opinion. • The binding constraint is currency, not candour. The question anticipates that developers may be unwilling to disclose. We measured something more basic: on one ordinary workday, the model answering a widely used hosted assistant was exchanged 153 times in fourteen hours — a median of 41 seconds at a time. A document cannot be kept current against a quantity that changes every few minutes. A fully cooperative, entirely honest developer filing in good faith would produce a master file that was stale before it was read. • A second, unrelated provider showed the same class of behavior on the same machine on the same day, in a different rhythm. This is a property of hosted delivery, not the practice of one company, and a master file program has to be designed for it rather than around it. • The most important field in any master file is the one most likely to be omitted: where the model executes. "The model runs on the device" and "the device reaches a model" are different regulatory Docket FDA-2026-N-7874 · The Christman AI Project and Robotics Division Page 1 situations with different evidence behind them. We measured a model registered inside a local runtime, reachable at the loopback address of our own machine, that was in fact answering from a datacenter. • There is an alternative mechanism and it does not require the developer's participation at all. A record produced on the user's side of the connection can establish which model answered and where it ran, timestamped, append-only, with no credentials and no cooperation. We have published such an instrument under a permissive license rather than proposing one. We also recommend a second mechanism that puts the burden on the device rather than on a registry. 1. What we measured, and why it decides the question On 2026-09-08 an observation tool running on a single desktop workstation kept an append-only ledger of which models were answering on that machine. The figures below are computed directly from that file. All times are UTC. 1.1 The first hosted assistant Across fourteen hours and sixteen minutes — 04:59:30 to 19:15:39 — the ledger recorded 307 model-layer events: 154 substitutions and 153 displacements. These resolve into 153 complete cycles in which the assistant's named live model was displaced by a chat model operating from a remote datacenter and then reinstated. That is 10.7 substitutions per hour. The substituted model held the session for a median of 41 seconds, with the middle half of cycles between 33 seconds and 1 minute 6 seconds, and a full range of 25 seconds to 4 minutes 9 seconds. 141 of the 153 cycles lasted under two minutes. In total the substituted model held the session for 139.9 minutes — 16.3 percent of the observed day. The interval between cycles was not stable in the same way: a median of 1 minute 48 seconds, ranging from 8 seconds to 49 minutes 13 seconds. A narrow inner duration inside a highly variable outer one is the signature of a triggered process rather than a schedule. Nothing in the assistant's interface disclosed any of this. The operator states he did not open that assistant at any point during the window. That is his account, recorded as such and not independently verified by the instrument. 1.2 The second hosted assistant A second hosted assistant from an unrelated provider was resident on the same machine across nearly the same window. It produced 24 model-layer events and 10 complete cycles in a quite different shape: one unbroken hold of 7 hours 8 minutes, from 05:04:17 to 12:12:01, followed by nine cycles compressed into a 34-minute burst with a median hold of 2 minutes 29 seconds. After the burst the ledger records three further substitutions with no closing displacement before the window ended. Two providers, one machine, one day, the same class of undisclosed substitution at two different tempos. We name neither, because the behavior is the finding and naming a company converts a technical result into a dispute about a company. 1.3 What did not do this Docket FDA-2026-N-7874 · The Christman AI Project and Robotics Division Page 2 Five other named systems appear in the same ledger over the same window — editors, a local model runtime, an agent extension, a mOriginal source ↗