TL;DR: FDA's January 2026 CDS guidance revised the Non-Device CDS test to add enforcement discretion for singular-output recommendations. The four-factor framework under Section 520(o)(1)(E) still controls: tools must not analyze complex inputs, must show their reasoning, must support (not replace) clinical judgment, and must not be intended as a replacement for clinical decision-making. Tools that analyze imaging data or generate opaque recommendations remain regulated SaMD.
Clinical AI is now embedded in EHR systems, nursing workflows, pharmacy dispensing, radiology reading rooms, and surgical planning platforms. The breadth of deployment has outrun most healthcare organizations' understanding of which of these tools require FDA clearance and which do not. FDA's January 2026 update to its Clinical Decision Support (CDS) guidance was partly an attempt to clarify that line, with some notable expansions and some firm limits.
The Non-Device CDS exemption and why it matters
The 21st Century Cures Act (2016) amended the Federal Food, Drug, and Cosmetic Act to exclude certain software functions from the medical device definition. Section 520(o)(1)(E) creates the Non-Device CDS category, software that supports healthcare professional (HCP) decision-making but does not, by itself, cross into regulated medical device territory.
Non-Device CDS status matters because it determines which clinical AI tools require FDA premarket clearance and which can be deployed, updated, and marketed without going through the FDA submission process. Getting this wrong in either direction has consequences: treating a device as Non-Device CDS when it does not qualify means deploying an uncleared medical device; treating Non-Device CDS as a regulated device adds regulatory overhead to tools that do not need it.
The four-factor Non-Device CDS test
Under Section 520(o)(1)(E), a software function qualifies as Non-Device CDS if it satisfies all four of the following criteria:
Factor 1: Input type The software must not acquire, process, or analyze medical images, medical signals, or patterns or signals from signal acquisition systems.
This factor eliminates AI tools that analyze chest X-rays, CT scans, MRI images, ECG waveforms, EEG signals, continuous glucose monitor streams, pulse oximetry data, or similar medical signals from the Non-Device CDS category. It does not matter how the AI is described by the vendor or how the output is framed. If the tool analyzes medical images or signals, it is a regulated SaMD.
Tools that analyze structured EHR data, lab values, vital signs recorded in text fields, medication lists, diagnosis codes, are not automatically disqualified by Factor 1, but they often fail factors 3 or 4.
Factor 2: Information type displayed The software must display, analyze, or print medical information that is generally understood by healthcare professionals.
This factor is designed to distinguish tools that present well-understood clinical data from those that extract complex patterns that a clinician could not independently verify. A drug-drug interaction alert citing a known pharmacological interaction is Factor 2-compliant. An AI that outputs a "risk score" derived from hundreds of input variables using an opaque model is not, because the clinician cannot independently assess whether the score is meaningful.
Factor 3: Transparency of reasoning The software must support or provide recommendations to healthcare professionals about prevention, diagnosis, or treatment, and must enable the healthcare professional to independently review the basis for the software's recommendations.
This is the transparency requirement. It is not enough that a physician sees the AI's output, the physician must be able to see and evaluate the reasoning. A drug interaction checker that displays the conflicting medications and the nature of the interaction is Factor 3-compliant. An AI that outputs "recommend immediate cardiac catheterization" without displaying which data drove that recommendation is not.
Factor 4: Not intended to replace clinical judgment The software must not be intended to replace clinical judgment of a healthcare professional.
This factor is evaluated based on intended use, marketing claims, and actual use context. A tool that automates a diagnostic step without requiring physician review may fail Factor 4 even if the vendor labels it "decision support." Autonomous AI systems, those designed to operate without real-time physician oversight, typically fail Factor 4 for most intended uses, though FDA has cleared specific autonomous screening tools (diabetic retinopathy screening in specific settings) through the De Novo pathway.
What changed in the January 2026 guidance
FDA issued the updated CDS guidance on January 6, 2026, replacing the prior version from September 2022. The changes reflected industry feedback and practical experience with the 2022 framework.
Singular output enforcement discretion. The most significant change: FDA stated it will exercise enforcement discretion for CDS tools that provide a singular output where only one recommendation is clinically appropriate. The 2022 guidance had been more restrictive about singular recommendations, which industry argued penalized CDS tools that provide clear, specific guidance in well-understood clinical scenarios (e.g., a drug dosing calculator that outputs a specific dose for a specific patient based on well-established pharmacokinetic formulas). The 2026 guidance allows these tools to maintain Non-Device CDS status as long as the other factors are met.
Drug-drug interaction and dosing calculators. FDA clarified that drug-drug interaction checkers and pharmacokinetic dosing calculators using well-understood clinical data and displaying their full reasoning can qualify as Non-Device CDS. This resolved ambiguity that had affected pharmacy AI tools and clinical pharmacology software.
General wellness clarifications. FDA simultaneously updated its general wellness guidance to clarify the boundary between general wellness products and medical devices, relevant for fitness AI, wearables, and consumer health apps that generate health insights without making specific diagnostic or treatment claims.
Core limits unchanged. FDA did not relax the prohibition on imaging or signal analysis tools claiming Non-Device CDS status, nor did it change the transparency requirement. Tools analyzing radiology images, ECG waveforms, or other complex medical signals remain regulated SaMD regardless of how the output is labeled.
Practical implications: which tools are you running that may be SaMD
Healthcare organizations running AI-powered clinical tools frequently encounter products that sit in ambiguous territory between Non-Device CDS and SaMD. The questions to work through for each tool:
Does it analyze medical images or signals? If yes, it is SaMD. Ask your vendor for the FDA clearance number or De Novo authorization. If they cannot provide one, ask why.
Can a clinician see why the AI made its recommendation? If no, if the output is a score or recommendation without traceable reasoning, the tool likely fails Factor 3. Ask the vendor for the explanation interface, if any exists.
Is a physician required to review and approve the AI output before clinical action is taken? If the AI triggers clinical action autonomously, ordering a test, sending an alert that nursing staff act on without physician review, generating a prescription recommendation that flows directly to a pharmacy, the tool may fail Factor 4.
What does the vendor's labeling say about intended use? Vendor documentation and marketing claims are FDA's starting point for intended use analysis. A vendor that markets a tool for "clinical decision support" while showing a demo where the AI outputs diagnoses without physician review may be making incompatible claims.
Human oversight requirements in clinical AI contexts
The January 2026 CDS guidance reinforced a principle that appears throughout FDA's AI device framework: human oversight in clinical AI is not merely procedural. It requires that humans have the information, time, and authority to exercise genuine judgment.
An AI system that generates recommendations faster than clinicians can review them, presents output in a format that discourages questioning, or creates workflow pressures that make override practically difficult is not providing human oversight in any meaningful sense, even if a human nominally approves each output.
This parallels the concern that Sen. Gillibrand raised about Grok AI's role in Operation Epic Fury: 2,000 target packages reviewed at one per three minutes may satisfy a process requirement without constituting substantive human review. The AI governance lesson from that context is directly applicable to clinical AI: your governance policy should specify what information reviewers receive, how much time review is expected to take, and what constitutes substantive rather than procedural oversight.
For clinical AI specifically:
- Define what a reviewer must evaluate before approving an AI recommendation (not just "acknowledge")
- Set a minimum review time for high-consequence AI recommendations
- Track override rates, a 0% override rate may indicate rubber-stamp review, not excellent AI performance
- Create a feedback mechanism for clinical staff to report cases where the AI output seemed wrong, even if they proceeded anyway
Practical implications for healthcare technology teams
The January 2026 guidance has three downstream effects that healthcare technology and compliance teams need to address before deploying or renewing contracts with clinical AI vendors.
Singular-output CDS under enforcement discretion is not a permanent status. FDA's enforcement discretion is an interim posture, not a regulatory exemption. Tools that fall into the singular-output CDS category should be tracked in an internal register with a notation that their regulatory status may change when FDA finalizes a subsequent guidance update or initiates enforcement. If a tool shifts from enforcement discretion to requiring clearance, you need to know which tools in your environment that affects.
The four-factor Non-Device CDS analysis applies to every AI tool in your clinical workflow. The January 2026 guidance applies to all CDS software, not just new products. If your organization deployed clinical AI tools before 2026, apply the four-factor analysis retroactively: who the user is, what the basis of recommendation is, whether the logic is transparent, and whether clinical review is the intended pathway. Tools that fail this analysis but have been treated as Non-Device CDS are a compliance exposure.
Document your Non-Device CDS determinations. For each tool you determine is Non-Device CDS, write down the four-factor analysis and date it. If FDA or a plaintiff's attorney later questions whether you understood what regulatory framework applied, contemporaneous documentation is your evidence. A vendor's claim that their product is "not a medical device" is not a substitute for your own analysis.
For teams that need to run the four-factor analysis across a clinical AI portfolio, the AI regulatory readiness scorecard provides a structured framework for documenting these determinations at scale.
One practical note on the vendor-side documentation burden: FDA's January 2026 guidance places responsibility for Non-Device CDS determinations on the developer or deployer, not on a third-party auditor. If your vendor tells you their product is Non-Device CDS, ask them for their four-factor analysis in writing and file it. If they cannot provide it, or if their analysis does not engage with the four factors specifically, that is a signal to perform your own analysis before relying on the product in a clinical workflow.
Related Reading
- Midjourney's scanner: what FDA SaMD clearance actually requires
- HIPAA and AI vendor BAA requirements 2026
- FDA AI medical device SaMD compliance guide 2026
- AI medical malpractice 2026: who is liable when diagnostic AI gets it wrong
- AI governance for healthcare startups: HIPAA, FDA, and vendor risk
- AI governance checklist 2026
