Abstract
Artificial intelligence (AI) is entering medicine through diagnostic, administrative, and patient-facing applications, yet governance remains fragmented across medical product regulation, hospital oversight, privacy, civil-rights law, research ethics, and consumer protection. The March 2026 White House National Policy Framework for Artificial Intelligence is a set of nonbinding legislative recommendations to Congress that clarifies the current administration’s proposed direction for AI policy as pro-deployment, pro-infrastructure, and reliant on sector-specific oversight rather than a new central regulator. In international context, this approach differs from the European Union’s more horizontal, risk-based model and from ethics frameworks emphasizing consent, transparency, independent oversight, and protection of vulnerable populations. For medicine, the US framework may accelerate the development and uptake of AI tools by expanding data access, reducing infrastructure barriers, and supporting adoption, but it leaves unresolved a specific governance gap for clinically consequential tools that fall outside traditional Food and Drug Administration-regulated pathways. Addressing that gap will require stronger clinical governance, institutional accountability, transparency, consumer-protection mechanisms, and international interoperability. Medical AI is expanding faster than the governance systems that regulate clinical risk, transparency, and accountability. Here, we examine how the new US AI framework may accelerate adoption while leaving clinically consequential tools outside traditional regulatory pathways.
Subject terms: Health care, Public health
Artificial intelligence (AI) is entering medicine through multiple channels at once: diagnostic software, clinical decision support, administrative tools, ambient documentation, patient-facing applications, and general-purpose generative systems used for health questions. As a result, AI in medicine is no longer governed by a single agency or statute. It sits at the intersection of medical product regulation, hospital oversight, civil-rights law, privacy, research ethics, and consumer protection. To make these governance issues more concrete, this Comment focuses on three illustrative categories of medical AI: FDA-regulated diagnostic software, health-system tools used within clinical workflows, such as ambient documentation and triage or risk-prediction systems, and patient-facing generative AI tools used outside traditional care settings. The central argument of this Comment is that the new US framework may accelerate adoption across these categories, but it does not by itself resolve the governance gap for clinically consequential tools that fall outside traditional Food and Drug Administration-regulated pathways.
The White House’s March 2026 National Policy Framework for Artificial Intelligence is therefore important for medicine, even though it is not health-specific1. However, it is not law, regulation, or executive action; rather, it is a set of nonbinding legislative recommendations to Congress. It is therefore best read as clarifying the current administration’s legislative priorities for AI rather than establishing a settled US AI policy. For medicine, this still matters because proposals regarding infrastructure, datasets, liability, regulatory architecture, and federal preemption could shape which tools are built, how quickly they are deployed, and under what conditions they enter clinical care if enacted2.
The proposed US federal direction is distinctive when viewed internationally. Unlike the EU AI Act, which is a binding law with phased implementation, the White House framework outlines a prospective US legislative agenda rather than an operational governance regime. In the European Union, the Artificial Intelligence Act provides a horizontal, risk-based framework, but for medical software, it operates alongside, rather than instead of, the Medical Device Regulation and In Vitro Diagnostic Medical Devices Regulation; recent European Commission guidance emphasizes that these regimes apply simultaneously and complementarily to qualifying medical AI systems3. Beyond product regulation, medical AI in the European Union also operates within the General Data Protection Regulation, which governs personal-data processing, and the European Health Data Space, which establishes requirements for access to, sharing of, and secondary use of electronic health data.
The US regulatory landscape is also more complex than a simple US–EU comparison might suggest. Existing US oversight of medical AI is already distributed across multiple institutions: the Food and Drug Administration for device software and lifecycle oversight4,5; the Office of the National Coordinator for Health Information Technology for transparency requirements governing predictive decision support in certified health information technology6; the Office for Civil Rights for HIPAA enforcement and nondiscrimination obligations under Section 1557 as applied to artificial intelligence, clinical algorithms, and predictive analytics7; the Federal Trade Commission for deceptive or inadequately substantiated health-related claims; the Centers for Medicare & Medicaid Services through payment and delivery structures that shape clinical adoption; and local hospital governance, state law, and professional standards8. The more precise contrast, therefore, is not between governance and non-governance, but between a more codified horizontal European legal architecture and a more distributed US system in which governance is spread across product regulation, health information technology regulation, civil-rights enforcement, consumer protection, payer influence, and institutional oversight.
However, this comparison should also be qualified by the European Union’s own implementation difficulties. The Digital Omnibus on AI was formally adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. It delayed application of the AI Act’s high-risk requirements to December 2, 2027, for high-risk systems classified under Article 6(2) and Annex III, and to August 2, 2028, for high-risk AI embedded in products under Article 6(1) and Annex I, reflecting implementation challenges related to standards, common specifications, alternative guidance, and national competent-authority capacity9.
Other international efforts have emphasized human rights, transparency, and adaptive governance2. The revised Declaration of Helsinki adds a further normative frame2,10. Although written for medical research involving human participants, it highlights principles that are highly relevant to AI in medicine: informed consent, independent oversight, scientific validity, risk-benefit assessment, protection of vulnerable populations, and accountability for harms2.
These differences reflect distinct theories of governance, but also different institutional architectures. The European Union relies on a codified horizontal framework layered onto sector-specific legislation, whereas the proposed US direction emphasizes innovation, infrastructure, and distributed oversight. The White House document is therefore best understood as an enabling national strategy rather than a comprehensive safety statute for medical AI.
That strategy has real strengths; it targets practical constraints on AI scale-up in the United States. The framework supports regulatory sandboxes, broader access to federal datasets in AI-ready formats, streamlined permitting for AI infrastructure, and adoption incentives1. In health care, where technical capacity is unevenly distributed, and resource gaps between large academic centers and smaller systems remain substantial, these policies could have important downstream effects11,12.
Its reliance on existing sector-specific oversight also has logic. In medicine, AI is already being addressed through institutions with relevant domain expertise13,14. The Food and Drug Administration has increasingly framed oversight of AI-enabled medical products through a total product life cycle approach, emphasizing evaluation before use, management of modifications, and monitoring after deployment14. In the United States, this sector-specific landscape also extends beyond the Food and Drug Administration to include the Office of the National Coordinator for Health Information Technology transparency requirements for predictive decision support interventions in certified health information technology6, as well as the Federal Trade Commission oversight of deceptive AI and health-related consumer claims15. FDA’s January 2026 Clinical Decision Support Software guidance illustrates how case-specific these regulatory boundaries remain5, while its 2025 draft guidance on AI-enabled device software functions reinforces lifecycle-based risk management4. To make these governance issues more concrete, this Comment focuses on 3 illustrative categories of medical AI: FDA-regulated diagnostic software, health-system tools used within clinical workflows, such as ambient documentation and triage or risk-prediction systems, and patient-facing generative AI tools used outside traditional care settings. Existing patient-safety, quality-improvement, and oversight structures can be used to evaluate local fit, identify errors, and respond to harm from AI tools introduced into care pathways8.
A more useful way to understand this governance problem is not to treat medical AI as a single regulatory object. As Table 1 shows, clinically relevant tools differ in regulatory status, user group, clinical consequence, governance body, evidence requirements, and post-deployment monitoring needs. Oversight should therefore be matched to a tool’s function and risk rather than to the label “AI” alone2,13. Other clinically consequential tools, including workflow-embedded systems, such as ambient documentation or triage and risk-prediction models, and patient-facing generative AI used outside traditional care settings16, often rely more heavily on local institutional oversight or consumer-protection mechanisms than on classic device regulation.
Table 1.
A practical integration and classification for distinguishing categories of medical AI by governance needs
| Category of medical AI | Representative examples | Typical regulatory status | Typical clinical risk | Primary user group | Main governance body or mechanism | Minimum evidence requirement before deployment | Priority post-deployment monitoring needs | Main unresolved governance gap |
|---|---|---|---|---|---|---|---|---|
| FDA-regulated diagnostic or therapeutic decision software | AI-enabled image interpretation, ECG or arrhythmia detection, software that directly informs diagnosis or treatment selection | Often, within FDA device or software-as-a-medical-device pathways, in Europe often overlaps with AI Act high-risk obligations plus MDR/IVDR requirements | Moderate to high, because outputs can directly affect diagnosis, treatment, or escalation decisions | Clinicians | FDA, manufacturer quality systems, and local health system implementation oversight | Analytic validity, clinical validity, external validation in intended-use populations, subgroup performance, human factors, documentation of intended use and update pathways | Performance drift, subgroup degradation, adverse events, override patterns, site-specific failures, effects of model or software updates | How to manage adaptive updates, local generalizability, and real-world performance after deployment |
| Workflow-embedded clinician-facing AI | Ambient documentation, note drafting, inbox summarization and chart review assistance | Often outside classic FDA device regulation, when framed as administrative or documentation support, governed mainly through health-system policy, vendor contracts, privacy and IT oversight | Low to moderate direct risk but potentially substantial indirect risk, because errors may propagate into records, communication, orders, or follow-up | Clinicians and clinical staff | Health systems, EHR governance, privacy/compliance offices, quality and safety programs | Local pilot testing, usability assessment, documentation fidelity, error and omission review, workflow impact evaluation | Hallucination or omission rates, correction frequency, downstream documentation errors, privacy incidents, clinician overreliance, workflow disruption | Clinically meaningful effects despite sitting outside traditional device pathways |
| Triage, risk-prediction, and resource-allocation AI inside care delivery | ED triage tools, risk scores used for escalation or referral, care-management prioritization, discharge or follow-up prioritization | Mixed status; some may be regulated, but many operate mainly under institutional oversight, civil-rights obligations, payer rules, and quality governance | Moderate to high, because tools can alter prioritization, access, escalation, and resource distribution | Clinicians, care managers, administrators | Health systems, quality and patient-safety programs, civil-rights and compliance oversight; FDA in selected cases | Local validation in the target population and workflow, calibration assessment, subgroup performance, threshold justification, demonstration of clinical utility | Calibration drift, subgroup inequities, changes in referral or escalation patterns, override rates, access disparities, unintended workflow effects | Tools can reshape access and care pathways without fitting neatly into diagnostic-device categories |
| Patient-facing generative AI and consumer health AI | Symptom-checking chatbots, medication question-answering tools, care-navigation assistants, wellness or retail-health AI | Highly heterogeneous; often outside traditional clinical oversight and sometimes outside FDA pathways unless specific medical claims are made; may instead rely on FTC, privacy, and consumer-protection mechanisms | Variable but potentially high, because tools may delay care, give false reassurance, escalate anxiety, or provide biased recommendations | Patients and caregivers | FTC and consumer-protection authorities, developers, platforms, app marketplaces; FDA in selected cases | Accuracy and safety testing for common scenarios, clear disclosure of limitations, escalation rules, readability, evaluation across demographic groups, provenance and source disclosure | Harmful advice reports, escalation failures, misinformation patterns, user complaints, uneven performance across populations, commercial steering or bias | The largest gap between clinical consequence and formal medical oversight |
| Hybrid or general-purpose AI repurposed for clinical use | General LLMs are used ad hoc for diagnosis support, letter drafting, patient messaging, or medication explanation | Often not originally developed or cleared for a specific clinical use; governance depends on local policy, user behavior, and context of deployment | Variable and context-dependent, ranging from low-risk drafting support to high-risk decision influence | Clinicians, staff, and sometimes patients | Local institutional governance, professional standards, procurement controls, privacy/security oversight | Restriction to defined use cases, user training, disclosure of non-authoritative outputs, and local testing in intended workflows | Off-label use expansion, hidden decision influence, data leakage, hallucinations, overreliance, scope creep beyond approved workflows | General-purpose tools can become clinically consequential without entering a formal medical-AI pathway |
AI artificial intelligence, FDA Food and Drug Administration, ECG electrocardiogram, MDR Medical Device Regulation, IVDR In Vitro Diagnostic Regulation, ED emergency department, FTC Federal Trade Commission, LLM large language model.
Four implications follow:
First, regulatory boundaries remain uneven. Many tools that influence care do not fit neatly within classic device categories2,13. FDA’s January 2026 CDS guidance shows that oversight may depend on the intended user, time-criticality, transparency of inputs, and whether clinicians can independently review the basis of a recommendation. It also indicates that some software functions providing only one clinically appropriate recommendation may be subject to enforcement discretion rather than active device requirements5. For example, FDA’s Example 31 treats a mammography follow-up recommendation tool as a device, not because the output is inherently impermissible, but because the clinician is not given enough information about the relevant inputs, dataset composition, generalizability, and recommendation basis to independently review the software’s reasoning.
Second, the framework does not specify evidence thresholds, when local validation is required, how subgroup performance should be assessed, or what findings should trigger post-deployment review, retraining, rollback, or withdrawal. These are operational as well as policy questions because they determine whether oversight is meaningful in practice. Existing reporting frameworks, including TRIPOD-AI17 and SPIRIT-AI18, begin to operationalize some of these expectations by improving the structure of reporting and evaluation for AI-related prediction models and clinical studies, but they do not eliminate the need for clearer standards regarding local validation, subgroup performance, and post-deployment oversight.
Third, authorization is not the endpoint. Models may perform unevenly across populations, alter clinician behavior, or degrade after workflow changes. Continued surveillance and correction are therefore ethical, as well as technical obligations: consent, transparency, fairness, and protection of vulnerable groups are integral to clinically legitimate innovation2,8,13,14.
Fourth, the White House framework does little to close the governance gap for consumer-facing health AI outside traditional clinical and HIPAA-covered settings. This category should be distinguished from AI used in regulated clinical care, where governance can more readily draw on device regulation, hospital oversight, professional standards, and quality and safety infrastructure. FDA’s January 2026 CDS guidance highlights the gap for patient-facing AI. It states that software providing recommendations to patients or caregivers meets the definition of a device, yet also acknowledges that policy examples for non-health care providers CDS will need to be developed further as the category evolves5. Patients increasingly encounter AI through symptom checkers, wellness applications, insurance interactions, retail health platforms, and general-purpose generative systems used for medical questions. For example, patients may increasingly rely on generative AI chatbots for symptom interpretation, care navigation, or medication questions. These uses can be clinically consequential even outside formal care delivery because they may delay care, spread misinformation, provide inappropriate reassurance, escalate anxiety, widen inequities in access or digital literacy19, or steer users toward commercially biased recommendations. Consumer-facing health AI may therefore fall under a different mix of governance tools than clinician-facing medical software, including Food and Drug Administration oversight in selected cases, Federal Trade Commission standards for substantiation of health-related claims and breach-notification requirements for health apps and similar technologies, even when such tools do not clearly fit traditional device pathways15.
What should follow? The United States does not need a single omnibus health AI law to make progress. But it does need a more explicit clinical governance agenda within its broader AI strategy. One priority is to preserve sector-specific expertise while making expectations more operational. For regulated products, the total product life cycle framework should be linked to clearer expectations for external validation, subgroup analysis, modification protocols, and postmarket performance monitoring2,13.
A second priority is to strengthen institutional accountability through a formal AI governance program. This is particularly important for workflow-embedded tools, such as ambient clinical documentation systems and triage or risk-prediction models, which may alter communication, prioritization, or escalation decisions even when they do not fit neatly within traditional device categories. Emerging models include multidisciplinary AI oversight committees and, in more advanced systems, executive-level AI leadership supported by specialized subcommittees for validation, implementation, and monitoring20. Responsibility should include clinical, informatics, quality and safety, legal and compliance, privacy, equity, and operational expertise. The program should cover all AI tools that may influence clinical decisions, patient communication, workflow prioritization, documentation, or access, regardless of whether they are marketed as medical devices. Before deployment, each tool should have minimum documentation describing intended use, target users, data provenance, validation settings, subgroup performance, known limitations, update pathway, and local workflow integration. After deployment, health systems should monitor performance drift, subgroup disparities, override patterns, safety events, user complaints, and workflow disruption, with reevaluation at predefined risk-based intervals and after major model, vendor, or workflow changes. Material performance degradation, clinically important bias, serious safety events, or undocumented system changes should trigger modification, suspension, or withdrawal.
A third priority is to reduce fragmentation in evidence and transparency. Clinicians and patients should not have to infer a tool’s reliability from marketing claims or procurement materials. More standardized disclosure of intended use, validation setting, population, performance, and limitations would improve accountability and adoption. Finally, US leadership should be aligned with international legitimacy21. The United States may choose a different governance architecture from the European Union, but for AI in medicine, divergence cannot mean incompatibility with core expectations for ethics, evidence, and oversight2,13. Systems that are difficult to validate, monitor, or compare across jurisdictions will face trust and adoption barriers regardless of how quickly they are deployed.
The White House framework clarifies the current administration’s legislative priorities for AI, but whether and how they will be enacted remains uncertain. The central question is whether US leadership in AI will be accompanied by governance capable of identifying, monitoring, and correcting clinically consequential tools outside traditional Food and Drug Administration-regulated pathways. Closing this gap will require stronger institutional oversight, clearer evidence and transparency standards, and explicit consumer protections for patient-facing systems. For medical AI, speed and scale are important but insufficient.
Author contributions
A.A.A. contributed to the conception, funding of the study, and writing of the manuscript.
Peer review
Peer review information
Communications Medicine thanks Rabai Bouderhem, Nikolaus Forgó, and Jeffrey David Iqbal for their contribution to the peer review of this work.
Funding
A.A.A. is partly funded by the Institute of Precision Medicine (17UNPG33840017) of the American Heart Association, the RICBAC Foundation, NIH grants 1 R01 HL135335-01, 1 R01 HL161008-01, 1 R21 HL137870-01, 1 R21EB026164-01, and 3R21EB026164-02S1.
Competing interests
The author declares no competing interests.
Footnotes
Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
References
- 1.The White House. National Policy Framework for Artificial Intelligence: Legislative Recommendations. Accessed 20 March 2026 https://www.whitehouse.gov/wp-content/uploads/2026/03/03.20.26-National-Policy-Framework-for-Artificial-Intelligence-Legislative-Recommendations.pdf. This nonbinding framework defines the current US legislative direction for AI as pro- deployment and sector-specific, making it the central policy document for assessing implications for medical AI governance.
- 2.Armoundas, A. A. & Loscalzo, J. Do world-wide policy initiatives for regulating health care related artificial intelligence safeguard the Declaration of Helsinki? EClinicalMedicine92, 103784 10.1016/j.eclinm.2026.103784 (2026). This Viewpoint compares international health AI policy initiatives against Declaration of Helsinki principles and highlights why medical AI governance must include ethics, accountability, equity, and protection of patients in addition to technical regulation. [DOI] [PMC free article] [PubMed] [Google Scholar]
- 3.Aboy, M., Minssen, T. & Vayena, E. Navigating the EU AI Act: implications for regulated digital medical products. NPJ Digit. Med.7, 237 10.1038/s41746-024-01232-3 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 4.United States, Food and Drug Administration. Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations. Draft Guidance for Industry and Food and Drug Administration Staff. Accessed 16 July 2026 https://www.fda.gov/regulatory-information/search-fda-guidance-documents/artificial-intelligence-enabled-device-software-functions-lifecycle-management-and-marketing (2025).
- 5.United States, Food and Drug Administration. Clinical Decision Support Software. Guidance for Industry and Food and Drug Administration Staff. Accessed 16 July 2026 https://www.fda.gov/media/109618/download (2026).
- 6.ONC. Office of the National Coordinator for Health Information Technology. HTI-1 Final Rule. Accessed 16 July 2026 https://healthit.gov/regulations/hti-rules/hti-1-final-rule/.
- 7.Department of Health and Human Services. Office for Civil Rights. Nondiscrimination in 297 Health Programs and Activities; Final Rule. Federal Register. Vol. 89, 37522–37824. Accessed 27 August 2026 https://www.govinfo.gov/content/pkg/FR-2024-05-06/pdf/2024-08711.pdf (2024).
- 8.Fleisher, L. A. & Economou-Zavlanos, N. J. Artificial intelligence can be regulated using current patient safety procedures and infrastructure in hospitals. JAMA Health Forum5, e241369 10.1001/jamahealthforum.2024.1369 (2024). [DOI] [PubMed] [Google Scholar]
- 9.European Parliament and Council of the European Union. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal of the European Union. L 2026/1744. Accessed 27 August 2026 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744 (2026).
- 10.World Medical Association. World Medical Association Declaration of Helsinki: ethical principles for medical research involving human participants. JAMA333, 71–74 10.1001/jama.2024.21972 (2025). [DOI] [PubMed] [Google Scholar]
- 11.Bazoukis, G. et al. Impact of social determinants of health on cardiovascular disease. J. Am. Heart Assoc.14, e039031 10.1161/JAHA.124.039031 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 12.Pearson, T. A. et al. The science of precision prevention: research opportunities and clinical applications to reduce cardiovascular health disparities. JACC Adv. 3, 100759 (2024). [DOI] [PMC free article] [PubMed]
- 13.Armoundas, A. A. & Singh, J. P. Total product lifecycle regulatory considerations and recommendations for generative AI-enabled medical devices. Eur. Heart J. Digit. Health7, ztag019 10.1093/ehjdh/ztag019 (2026). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 14.Warraich, H. J., Tazbaz, T. & Califf, R. M. FDA perspective on the regulation of artificial intelligence in health care and biomedicine. JAMA333, 241–247 10.1001/jama.2024.21451 (2025). [DOI] [PubMed] [Google Scholar]
- 15.Federal-Trade-Commission. Health Products Compliance Guidance. Accessed 16 July 2026 https://www.ftc.gov/business-guidance/resources/health-products-compliance-guidance.
- 16.Armoundas, A. A. & Loscalzo, J. Patient agency and large language models in worldwide encoding of equity. NPJ Digit. Med.8, 258 10.1038/s41746-025-01598-y (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 17.Cohen, J. F. & Bossuyt, P. M. M. TRIPOD+AI: an updated reporting guideline for clinical prediction models. BMJ385, q824 10.1136/bmj.q824 (2024). [DOI] [PubMed] [Google Scholar]
- 18.Cruz Rivera, S. et al. Guidelines for clinical trial protocols for interventions involving artificial intelligence: the SPIRIT-AI extension. Nat Med.26, 1351–1363 10.1038/s41591-020-1037-7 (2020). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 19.Narayan, S. M. et al. Access to digital health technologies: personalized framework and global perspectives. Nat. Rev. Cardiol.23, 9–22 10.1038/s41569-025-01184-5 (2026). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 20.Hussein, R. et al. Advancing healthcare AI governance through a comprehensive maturity model based on systematic review. NPJ Digit. Med.9 10.1038/s41746-026-02418-7 (2026). [DOI] [PMC free article] [PubMed]
- 21.Bazoukis, G. et al. The inclusion of augmented intelligence in medicine: a framework for successful implementation. Cell Rep. Med.3, 100485 10.1016/j.xcrm.2021.100485 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
