Blog · Enforcement
FDA Warning Letters Against AI Medical Devices — What They Reveal
FDA has issued warning letters to AI device companies for a consistent set of violations. Understanding the patterns tells you what to avoid — and what FDA is watching most closely.
FDA warning letters are public documents. They're also some of the most useful regulatory intelligence available, because they tell you exactly what FDA considers a violation, in specific factual contexts. For AI device companies, the warning letter record reveals a clear pattern of the most common and consequential compliance failures.
This analysis is based on warning letters involving AI-enabled devices issued by CDRH, tracked through AIFDA Intel's enforcement monitor.
The Most Common Violations
1. Marketing Without 510(k) Clearance
The most common warning letter basis for AI device companies is marketing an AI diagnostic tool without obtaining 510(k) clearance. This typically involves software companies that developed AI tools originally as research tools or clinical decision support, then began marketing them with diagnostic claims without going through the clearance process.
FDA's standard is intent-based: if the AI is intended to diagnose, treat, cure, mitigate, or prevent a disease or condition, it's a device and requires clearance. The fact that it runs as software, operates in the cloud, or is used alongside a clinician doesn't change this.
2. Claims Exceeding Cleared Indications
Several warning letters have targeted AI device companies that had obtained 510(k) clearance but were marketing the device for indications beyond what FDA cleared. For AI devices, this often involves:
- Claiming the AI can diagnose conditions beyond its cleared indication
- Marketing to clinical settings (e.g., primary care) different from the validated setting
- Claiming performance metrics not validated in the cleared submission
3. Unauthorized Algorithm Modifications
A growing category of enforcement involves AI devices that were cleared, then had their algorithms updated post-clearance without appropriate regulatory coverage. These modifications — retraining on new data, architecture changes, threshold adjustments — required a new 510(k) or PCCP coverage and didn't have it.
This violation is particularly significant because it's often invisible: the device is cleared, it's being used clinically, and the company believes it's compliant. The enforcement action comes as a surprise. Post-market algorithm governance is now a serious compliance requirement, not an afterthought.
4. MDR Reporting Failures
Companies with cleared AI devices are required to report malfunctions and adverse events through FDA's Medical Device Reporting (MDR) system. Warning letters have been issued for failing to report events where an AI output was involved in a clinical decision that led to harm, or failing to investigate complaints about AI performance systematically.
Which Categories Are Most Scrutinized
Enforcement actions are not evenly distributed. FDA's attention has been concentrated in:
Diagnostic AI with autonomous outputs — devices that provide diagnoses without requiring clinician interpretation receive the highest scrutiny. FDA's concern is that failures in these systems directly affect patient care without a human safety net.
Dermatology and skin lesion AI — this category has seen multiple enforcement actions, likely because of the proliferation of consumer-facing apps making diagnostic claims without clearance.
Mental health and behavioral health AI — an emerging enforcement priority, with FDA taking an increasingly firm position that AI claiming to assess mental health conditions requires clearance.
Radiology AI with expanded claims — cleared radiology AI companies expanding their marketed indications without updated clearances.
What the Enforcement Pattern Tells You
Reading enforcement actions across the AI device landscape, several strategic conclusions emerge:
FDA is more focused on the claim than the technology. A very sophisticated AI used for administrative purposes faces minimal enforcement risk. A simple algorithm marketed with diagnostic language faces substantial risk. The intended use is the central regulatory determination.
Post-market compliance is as important as pre-market strategy. A company that navigates 510(k) successfully and then modifies its algorithm without regulatory coverage has eliminated its compliance status. Post-market algorithm governance needs to be built into product development processes, not treated as a separate regulatory function.
Monitoring your category's enforcement record is valuable intelligence. If FDA is issuing warning letters in your indication, it signals heightened attention — both for your own compliance review and as context for your 510(k) submission strategy.
This analysis is based on publicly available FDA warning letters and enforcement records tracked by AIFDA Intel. Company names have been omitted from specific examples. Always verify against current FDA records and consult a qualified regulatory professional for compliance guidance.