TL;DR: Midjourney's full-body ultrasonic scanner claims to scan in 60 seconds without radiation or magnetic fields. It is not calling itself a medical device, deliberately. That framing avoids FDA clearance now but limits what it can legally do clinically. The moment any AI tool makes diagnostic claims, it becomes a SaMD and must clear FDA's regulatory gate. Here is what that gate actually requires.
On June 18, 2026, Midjourney, best known for AI image generation, announced its first hardware product: a Full Body Ultrasonic Computational Tomography scanner. The device uses a ring containing half a million ultrasonic transducers to build a complete body image in roughly 60 seconds, without radiation, contrast agents, or the magnetic fields that make MRI scanners noisy, expensive, and inaccessible to patients with metal implants.
The claims were striking. Midjourney said its scanner is 60x faster and 10x cheaper than MRI. The company described plans for a Midjourney Spa in San Francisco, a 25,000-square-foot wellness center where people could get a scan alongside hot tubs, saunas, and cold plunges, with the goal of deploying more than 50,000 scanners worldwide by 2031.
What Midjourney did not claim was equally instructive: it is not positioning this as a medical diagnostic tool. The device currently produces "detailed body composition maps", descriptions of structural content like muscle mass, fat distribution, bone volume, and organ size. Not diagnoses. That distinction is not a modest hedge. It is a regulatory strategy, and understanding why tells you everything about the compliance gate that every AI tool touching patient data eventually has to clear.
What Midjourney is actually selling, and why
A body composition map is a factual description of physical structure. It tells you how much muscle is in a region, where fat is distributed, what organ volumes look like. It does not tell you whether you have cancer, whether a lesion is malignant, whether a finding warrants biopsy or immediate surgical consultation.
That distinction matters to the FDA because it determines whether the device is a medical device at all.
Under the Federal Food, Drug, and Cosmetic Act, a medical device is any instrument, apparatus, machine, or software intended to diagnose, cure, treat, mitigate, or prevent disease in humans. The key word is "intended." FDA looks at what the device is marketed to do, what claims the manufacturer makes, and how it is actually used, not just what the label says.
A device that measures body composition and displays structural data occupies a gray area similar to a general wellness product. A device that analyzes the same data and outputs "probable malignancy in left lung lobe" or "findings consistent with early-stage renal cell carcinoma" is clearly a medical device, specifically, Software as a Medical Device (SaMD), and requires premarket clearance or approval before it can be sold for that purpose in the United States.
Midjourney knows this. The company stated it intends to pursue FDA clearance to enable diagnostic use over time. It is starting with wellness use cases to get devices in the field, build a user base, and accumulate the real-world performance data that FDA will require in any future clearance submission. This is a legitimate and common market entry strategy. It is also a reminder that the wellness-to-medical pathway is not a loophole, it is a waiting room.
The FDA SaMD framework your team needs to understand
By early 2026, the FDA had authorized more than 1,350 AI-enabled devices, roughly double the count from 2022, reflecting the rapid expansion of AI into diagnostic imaging, monitoring, and clinical decision support. Each of those authorizations went through the same basic regulatory framework.
FDA classifies medical devices into three risk tiers:
Class I, General controls. Low-risk devices. Most do not require premarket review. AI-assisted wellness tools, general health monitoring software without diagnostic claims, and informational displays typically fall here.
Class II, Special controls + 510(k) clearance. Moderate-risk devices. The 510(k) pathway requires demonstrating substantial equivalence to a legally marketed predicate device. Most AI diagnostic tools in radiology, cardiology, and pathology that reach the market go through 510(k). The submission must include performance data, validation testing, and a description of the AI algorithm's training and intended use.
Class III, PMA approval. High-risk devices. Premarket Approval requires clinical trial data demonstrating safety and effectiveness. This applies to devices that are life-sustaining, life-supporting, or implanted, or AI systems where no predicate exists and the risk level warrants the highest scrutiny.
For AI/ML-based SaMD specifically, FDA has layered additional requirements on top of the standard device framework:
Good Machine Learning Practices (GMLP). FDA's October 2021 guidance (updated under the December 2024 AI/ML Action Plan) describes best practices for data management, model training and testing, transparency, and human factors evaluation. GMLP is not a checklist, it is a performance standard FDA uses to evaluate whether an AI developer exercised appropriate rigor.
Predetermined Change Control Plans (PCCP). Because AI models can be retrained or updated after clearance, FDA requires developers to specify in advance what types of changes will be made to the model and what validation testing will confirm those changes remain safe and effective. Without a PCCP, each significant algorithm update potentially requires a new 510(k) submission.
Total Product Lifecycle (TPLC) approach. FDA expects continuous monitoring of real-world AI performance after clearance, not just pre-market validation. Post-market surveillance requirements apply, and developers must have mechanisms to detect, investigate, and report performance problems.
Quality Management System Regulation (QMSR). The new QMSR took effect February 2, 2026, aligning FDA requirements with ISO 13485:2016. Medical device manufacturers, including SaMD developers, must maintain quality management systems that document design controls, risk management, and post-market activities.
Why vendor labels do not determine regulatory status
The Midjourney announcement landed in a context where AI vendors routinely use language choices to position their products below the FDA's regulatory threshold. Terms like "clinical decision support," "analytics platform," "population health tool," and "care coordination software" are sometimes used to describe products that, in practice, influence individual clinical decisions about diagnosis or treatment.
FDA addressed this ambiguity directly in the January 6, 2026 updated guidance on Clinical Decision Support (CDS) software. The guidance clarifies the criteria for Non-Device CDS under Section 520(o)(1)(E) of the FDCA, the four-factor test that determines whether CDS software is exempt from medical device regulation:
- The software does not acquire, process, or analyze medical images, signals, patterns, or other complex inputs.
- The software displays, analyzes, or prints medical information that is generally understood by healthcare professionals.
- The software supports or provides recommendations to healthcare professionals about prevention, diagnosis, or treatment of a disease, and enables the healthcare professional to independently review the basis for the recommendation.
- The software is not intended to replace clinical judgment.
The January 2026 guidance added an important carve-out: FDA will exercise enforcement discretion for CDS tools that provide a singular output where only one recommendation is clinically appropriate, as long as the other criteria are met. But it reinforced the core principle: a tool that analyzes medical images, chest X-rays, CT scans, MRI slices, pathology slides, is not CDS exempt. It is a medical device.
This matters for every clinical AI tool your organization uses, not just for novel scanners. If your vendor describes its AI as "informational" while your clinical staff use it to make or defer diagnostic decisions, you may be deploying an uncleared medical device without realizing it.
What this means for your healthcare AI governance policy
The Midjourney scanner is a clean case study because the regulatory choices are visible. Most healthcare AI deployments are less transparent about where they sit relative to FDA's threshold. A governance policy for clinical AI should address this directly.
Require FDA clearance status for any AI tool used in clinical workflows. Ask every vendor whether its product has received FDA 510(k) clearance, De Novo authorization, or PMA approval, and for what specific intended use. A vendor that has not gone through FDA review is either below the regulatory threshold or has not yet pursued clearance. Both answers require follow-up.
Map intended use against actual use. A product cleared for "administrative scheduling support" that clinical staff are using to flag high-risk patients for intervention is being used outside its cleared indication. That gap creates liability for your organization.
Review PCCP status for AI tools you already use. If a vendor updated its AI model after clearance and does not have an approved PCCP, those updates may not have been validated to FDA's standard. Ask your vendors what their post-clearance update process looks like and how changes are documented.
Include AI medical device compliance in vendor due diligence. Your AI vendor due diligence process should include a clinical AI section that covers FDA clearance status, intended use boundaries, GMLP compliance, and post-market surveillance practices.
The Midjourney spa model, scan in a wellness context, pursue diagnostic clearance later, will play out across dozens of AI health companies over the next several years. Each one is making a calculated bet about when to enter the FDA regulatory process. Your job is not to track their timelines. Your job is to know whether the tools your clinical teams are using today have already cleared the gate.
The broader governance lesson
Midjourney's scanner announcement drew attention because of the company's brand recognition and the scale of its ambitions. But the underlying dynamic, an AI product making performance claims that stop just short of the FDA threshold, is not unusual in healthcare AI.
The Pentagon's disclosure that it used Grok AI to assist targeting in Operation Epic Fury prompted Sen. Gillibrand to introduce mandatory human approval requirements for high-consequence AI decisions in military contexts. The same governance logic applies in clinical settings: designation, approval gates, audit trails, incident reporting. Healthcare has had this framework through FDA longer than any other regulated industry.
What FDA's SaMD framework and the Gillibrand bill share is a recognition that AI systems operating in high-stakes domains need governance infrastructure that goes beyond usage policies. Pre-market validation. Defined human review requirements. Change control. Post-deployment monitoring. Incident reporting within defined timeframes.
The companies that build this infrastructure now, before regulatory pressure forces it, are the ones that will be able to expand into regulated clinical use when their products are ready. The ones that do not will face the same clearance process under enforcement scrutiny rather than proactive planning.
Related Reading
- HIPAA and AI vendor BAA requirements 2026
- FDA AI medical device SaMD compliance guide 2026
- Clinical AI decision support: FDA January 2026 guidance explained
- AI medical malpractice 2026: who is liable when diagnostic AI gets it wrong
- AI governance for healthcare startups: HIPAA, FDA, and vendor risk
- Pentagon Grok AI and human oversight: what Gillibrand's bill means for your policy
