Hashlogics
Answers

When does my software become a regulated medical device?

The test isn't how clever your software is. It's whether the clinician using it has time to check its reasoning.

Answered in short

6 things that decide this

  1. 01Section 520(o) of the FD&C Act keeps five kinds of software out of the device definition. Clinical decision support is the fifth, and it's the one people argue about.
  2. 02You lose that exclusion at once if your software reads a medical image, a signal from an in vitro diagnostic device, or a pattern from a signal acquisition system.
  3. 03Most builds miss one condition: the health professional must be able to check the basis of the advice on their own. It can't be built so they lean mainly on it.
  4. 04FDA says software meant for a critical, time-sensitive task fails that condition, because the clinician is unlikely to have time to check the basis.
  5. 05If your software advises patients or carers, rather than health professionals, it's a device.
  6. 06FDA replaced its clinical decision support guidance in January 2026, and the current version is dated 29 January 2026.
Why teams get this wrong

The carve-out is narrower than it reads

Founders read section 520(o)(1)(E) and see a way out. Support the clinician, don't replace their judgement, and you sit outside the device rules. That reading is too hopeful.

The statute opens with an "unless". Does your software read a medical image? A signal from a Blueprint device? A pattern from a signal system? If so, the exclusion doesn't apply. Your imaging tool or waveform reader is out before anything else gets weighed.

For everything else, three conditions have to hold together. The last one decides most cases: your clinician must check the basis of the advice on their own. You can't design it so they lean mainly on it.

Verified against the statute and current guidance

What pushes software across the line

Checked 11 August 2026 against 21 USC 360j(o) and FDA's Clinical Decision Support Software guidance dated 29 January 2026.

Design choiceEffect on the carve-outWhy
Reads an image or a device waveformCarve-out unavailableThe statutory "unless" clause excludes it up front
Used in a time-critical decisionFDA does not consider Criterion 4 metThe clinician is unlikely to have time to review the basis
Outputs a specific directiveFails Criterion 3It provides a specific preventive, diagnostic or treatment output
Shows options with the reasoning and sourcesSupports the carve-outThe clinician can review the basis independently
Speaks to a patient or caregiverIt is a deviceThe carve-out applies to healthcare professionals
Schedules, bills or handles lab workflowExcluded separately520(o)(1)(A) covers administrative support
The part nobody expects

FDA writes about automation bias by name

FDA's current guidance names two things it weighs here: how automated your software is, and how time-critical the decision is.

It then defines automation bias as the habit of over-trusting a suggestion from an automated system. That produces both errors of action and errors of omission. When action is urgent, bias rises, because there's no time to weigh other information.

This is a design instruction hiding in a regulatory document. Show your reasoning, name your sources, describe how you built and tested the model. That's what makes independent review real rather than nominal.

  • 01Criterion 4 also expects a plain-language account of how you built and tested the algorithm, including where you used AI or machine learning and how well your data matched real patients.
  • 02Your class decides the route. Most non-exempt Class I and II devices go through 510(k). Class III needs premarket approval.
Working through the device questionLive
  1. Image or signal?If yes, the carve-out is gone.
  2. Who reads it?Patient or caregiver means device.
  3. Directive or options?A specific directive fails Criterion 3.
  4. How urgent?Time-critical fails Criterion 4.
  5. Can they check it?Basis, sources, validation, shown.
  6. Document the answerWritten down before you ship.

The fourth station catches builds that pass everything else. A tool designed for a fast decision is, by FDA's reasoning, one the clinician cannot properly check.

Questions, answered
01Does keeping a human in the loop keep us out of device territory?+

Only where that person can really check the reasoning. FDA's condition is about the clinician being able to review the basis on their own, not about somebody clicking approve. A reviewer with no time and no visible reasoning is exactly the automation-bias case the guidance describes.

02We only rank or triage. Is ranking a directive?+

Judge a ranking by what it replaces. Options with the evidence behind each, for a clinician who then decides, work differently from one output telling them what to do. TrialTriage ranks eligible oncology trials from de-identified data. A nurse reviews and finalises every result before it reaches anyone.

03What if the software is only used inside one hospital?+

Your device definition turns on intended use, not how widely you ship. A single-site tool can still meet it. Scale changes your commercial exposure, not your classification, so settle the classification first and let it shape the design.

04How many AI-enabled devices has FDA authorised?+

FDA keeps a public list of AI-enabled medical devices, updated as of 16 June 2026, but it publishes no headline total. Counting unique submission numbers in that table on 11 August 2026 gives you 1,524, with the most recent entry dated 30 March 2026. FDA notes the list doesn't cover every such device.

By Abdul Basit, CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter