By the end of 2025, the FDA’s public list identified 1,451 AI-enabled medical devices authorised for marketing in the United States, including 295 authorised during that year.1 Three quarters are in radiology. Most of the remainder are concentrated in cardiology, haematology, pathology, ophthalmology and a growing number of surgical specialties. Few regulated sectors reveal so starkly the distance between regulatory authorisation and the allocation of civil liability.
This is the sixth article in a series examining AI liability across industrial sectors. The previous five covered vessels, energy grids, aviation, mining and agriculture. In healthcare, the end user is a patient. The patient does not select the device, cannot interrogate the algorithm and has no contractual relationship with the developer. The liability questions are accordingly different from those arising in autonomous shipping, grid management or mine automation: who owes a duty of care to a person who never chose to interact with the system at all?
Clinical AI and the Product Liability Question
In May 2025, the US District Court for the Middle District of Florida declined to dismiss product-liability claims against Character Technologies.2 At the pleading stage, the court was not prepared to hold that the Character.AI service and its outputs fell outside Florida product-liability law as a matter of law. It also rejected the defendants’ attempt to obtain dismissal on First Amendment grounds. The decision did not finally classify the chatbot as a product, but it prevented the developer from defeating that classification at the outset. The case settled in January 2026, leaving the pleading-stage order on the public record but the classification question unresolved.
Garcia concerned a consumer chatbot, not a clinical device. It does, however, show that courts may be unwilling to exclude software-based AI systems categorically from product-liability doctrine. Clinical AI presents a stronger but legally distinct case, where the software is incorporated into a device already regulated by the FDA as a medical device.
Surgical robotics illustrates the interaction between product liability and clinical negligence. Claims involving the da Vinci system have alleged both defects in robotic instruments and failures in surgical technique, training or postoperative care.3 The systems in widespread clinical use remain surgeon-controlled rather than independently autonomous, making fault allocation highly fact-sensitive.
That interaction tests the factual assumptions underlying the learned-intermediary doctrine. Under the traditional formulation, a medical-device manufacturer discharges its duty to warn by providing adequate information to the prescribing or operating clinician. The clinician, as a learned intermediary, interprets that information and exercises independent professional judgement before the product reaches the patient. The doctrine assumes that the clinician stands between the manufacturer and the patient as a filter of risk.
Clinical AI does not displace the learned-intermediary doctrine merely because it performs a defined task as accurately as a clinician. The doctrine concerns whether the manufacturer adequately warned the clinician and whether the clinician could exercise informed, independent judgement. That factual predicate weakens where a model’s limitations are undisclosed, where its output is not reasonably interpretable, where its recommendations reach the patient without meaningful clinical review, or where the decision to adopt and configure the system was made institutionally rather than by the treating clinician. The doctrine has not been formally displaced in any US jurisdiction. Its application will depend on whether the clinician performed a meaningful intermediary function, and the more autonomous the clinical output, the harder that factual case becomes.
Regulation: Authorisation Without Liability Rules
The FDA’s approach to AI-enabled medical devices rests on three instruments. The first is the Predetermined Change Control Plan, finalised in August 2025, which permits a manufacturer to obtain authorisation for specified future modifications to an AI device, together with the methods by which those modifications will be developed, validated and implemented.4 The PCCP responds to the problem that some machine learning models are designed to be modified after deployment. A device cleared against a defined dataset and performance profile may subsequently be modified, retrained or updated in ways that alter its diagnostic behaviour. Without a mechanism for pre-authorised modification, such a modification might otherwise require a new marketing submission, depending on its nature and effect.
The second instrument is the Clinical Decision Support guidance, finalised on 29 January 2026.5 Section 520(o)(1)(E) of the Federal Food, Drug, and Cosmetic Act excludes certain professional clinical-decision-support functions from the statutory definition of a device where all four statutory criteria are met. Among them, the software must enable the healthcare professional independently to review the basis for its recommendations rather than rely primarily on the software in making a diagnosis or treatment decision. The January 2026 guidance clarifies the boundary between software that meets those criteria and software that does not.
The third is enforcement. In February 2025, the FDA issued a warning letter to Exer Labs, treating its AI-based exercise analysis tool as an adulterated and misbranded device marketed without the required premarket authorisation.6 The action confirms that the FDA applies its existing medical-device requirements to AI-enabled products without creating a separate regulatory category.
Pre-emption adds a further layer. For devices that have received premarket approval under section 515 of the FD&C Act, the Supreme Court’s decision in Riegel v Medtronic, 552 U.S. 312 (2008), established express pre-emption of state-law claims that impose requirements different from or additional to the federal ones.7 Most AI-enabled medical devices on the FDA’s list have been cleared under the 510(k) pathway, where pre-emption is narrower. Whether and how pre-emption applies to AI-specific tort claims, particularly where the alleged defect lies in training-data selection or algorithmic design rather than device manufacture, is untested.
The European Union has taken a different path. The interaction between the Medical Devices Regulation and the AI Act remained uncertain until June 2025, when the Medical Device Coordination Group and the AI Board published MDCG 2025-6, a frequently asked questions document on the application of both instruments to AI-enabled medical devices.8 It confirms that medical-device and AI Act obligations may apply cumulatively. An AI system that is itself a medical device, or a safety component of one, will fall within Article 6(1) of the AI Act where the product is covered by Annex I harmonisation legislation and requires third-party conformity assessment.
Two subsequent developments altered the trajectory. Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026, postponed the application of the relevant high-risk AI obligations for Annex I product systems until 2 August 2028. In October 2025, the European Commission withdrew the proposed AI Liability Directive, which would, in defined circumstances, have introduced disclosure obligations and a rebuttable presumption concerning the causal link between specified fault and an AI system’s output or failure to produce an output.9 The withdrawal removed the only pending EU instrument directed specifically at evidential and fault-based civil-liability problems created by AI. Member States retain their domestic product-liability and fault-based regimes.
The UK Medicines and Healthcare products Regulatory Agency published guidance on digital mental health technologies as Software as a Medical Device in February 2025 and proposed international reliance pathways in July 2025, under which the MHRA could accept regulatory decisions from trusted overseas authorities as part of its own assessment process.10 In August 2025, the MHRA joined the FDA and Health Canada in publishing joint principles on predetermined change control plans. The UK has pursued a guidance-led approach. Its civil-liability position remains grounded in existing product-liability, negligence and clinical-malpractice rules rather than an AI-specific statutory regime.
Algorithmic Bias and the Standard of Care
In January 2025, the FDA published draft guidance on pulse oximetry devices, responding to a body of evidence that optical sensors perform less accurately on patients with darker skin pigmentation.11 Inaccurate oxygen saturation readings in darker-skinned patients have been linked to delayed recognition of hypoxia. The draft guidance recommends performance studies that include a broader range of skin pigmentation and more rigorous methods for evaluating differential performance.
Pulse oximetry is a hardware problem with a software dimension. The bias originates in the optical sensor’s calibration. Downstream clinical systems may then reproduce or amplify the measurement error if they treat the sensor output as reliable or were not validated adequately across affected populations. A comparable problem appears in dermatology AI systems trained predominantly on images of lighter skin, which are less accurate at identifying conditions on darker skin.12 The training-data disparity is well documented. A model trained on an unrepresentative dataset is liable to reproduce those gaps in clinical performance. The liability question is whether a manufacturer that deploys a diagnostic AI system with a known training-data limitation has met the standard of care expected of a reasonable manufacturer in its position.
Radiology also presents scale risk. Three quarters of the AI-enabled devices on the FDA’s list are in radiology. A defect in a widely deployed chest X-ray algorithm may affect more patients and clinical pathways than a defect in a specialised planning tool. The relevant exposure therefore depends not simply on the number of authorised products, but on deployment, interoperability and reliance across institutions.
California has moved ahead of federal law on two fronts. SB 1120, effective from January 2025, requires that utilisation review and medical-necessity determinations involving AI be made by appropriately qualified healthcare professionals; the statute prevents AI from supplanting the clinician’s decision-making in coverage determinations.13 AB 3030, also effective from 2025, requires that when generative AI generates specified written or verbal communications concerning patient clinical information, the provider must include a disclaimer and instructions for contacting a human provider, subject to exceptions for communications reviewed and approved by a licensed healthcare provider.14 Neither statute expressly creates a standalone private cause of action in the provisions discussed here. Both address the patient-facing consequences of clinical AI deployment.
Drug Discovery and the AI-Generated Molecule
In June 2025, Insilico Medicine published Phase IIa results for rentosertib, a drug candidate identified and optimised using its AI platform, in Nature Medicine.15 The molecule moved from target identification to Phase IIa data in under four years. In March 2026, Eli Lilly entered a partnership with Insilico valued at up to $2.75 billion on a contingent-milestone basis.16
The FDA’s January 2025 draft guidance on AI in pharmaceutical development addresses the use of AI-generated information to support regulatory submissions and decisions.17 Early-stage drug discovery falls outside its scope. A drug candidate generated by an AI system is subject to the same premarket approval requirements as one identified through conventional screening. The core approval requirements do not change merely because AI contributed to target or molecule identification.
Patent law in most jurisdictions requires a human inventor. The US Patent and Trademark Office and the UK Intellectual Property Office have both confirmed that an AI system cannot be named as an inventor on a patent application.18 Where an AI system identifies a novel molecular structure, the question is whether a natural person conceived the claimed invention. Under the USPTO’s revised November 2025 guidance, conception remains the touchstone: the human inventor must possess a definite and permanent idea of the complete and operative invention. How that standard applies where an AI system generated the structure remains fact-sensitive. The inventorship issue may affect patent validity, exclusivity and therefore asset value. Liability for clinical performance follows a different path through product-liability, regulatory and professional-negligence rules; it does not turn on who identified the molecule.
The FDA applies its existing Current Good Manufacturing Practice requirements to AI use in pharmaceutical operations. A manufacturer that uses machine learning to optimise a production parameter is subject to the same validation, documentation and deviation-reporting obligations as a manufacturer that uses a conventional control system.
Strategic Outlook
Product-liability claims may reach AI-enabled systems, although Garcia leaves the classification question unresolved and the applicable rules remain state-specific. Medical negligence claims may examine clinicians’ reliance on AI and institutions’ selection, configuration and supervision of the systems they deploy. Regulatory enforcement imposes compliance obligations that define the floor of acceptable conduct, while differential performance and state-level disclosure requirements create additional sources of regulatory and litigation exposure.
Additional liability questions remain. Automation bias, where clinicians defer to algorithmic recommendations against their own clinical judgement, creates a distinct professional-liability exposure. Hospital liability for institutional procurement and configuration decisions is largely untested. Data-protection and cybersecurity obligations introduce further layers of potential non-compliance. Contractual allocation of AI-related risk among developers, distributors and deploying institutions remains at an early stage.
The regulatory divergence among the United States, European Union and United Kingdom is significant. The FDA has the most detailed device-specific authorisation process but no federal AI liability statute. The EU has built the most extensive classification system but has withdrawn its liability directive and postponed the application of its high risk obligations. The UK has proposed international reliance pathways but its civil liability position remains grounded in existing law. A manufacturer deploying a clinical AI system across all three markets faces distinct regulatory regimes and no single cross-jurisdictional standard for algorithmic transparency, bias validation or post-market surveillance.
The revised Product Liability Directive expressly includes software within the concept of a product and introduces disclosure rules and rebuttable presumptions intended to relieve some of the evidential burden created by technically complex products.19 Member States must transpose it by 9 December 2026, and the new regime applies to products placed on the market or put into service thereafter. It mitigates, but does not eliminate, the difficulty of proving defect and causation where model operation, training data and technical documentation remain largely within the producer’s control.
By the end of 2025, the FDA had identified 1,451 AI-enabled devices authorised for marketing. The civil liability rules governing their use in clinical practice have not kept pace. The hardest claims will emerge in the distance between regulatory authorisation and responsibility for clinical use.
Notes
1. US Food and Drug Administration, “Artificial Intelligence and Machine Learning (AI/ML)-Enabled Medical Devices” (updated December 2025). The FDA maintains a public list of devices authorised for marketing that include AI/ML components. The agency notes that the list is not intended to be comprehensive. The figures cited (1,451 total, 295 in 2025, approximately 76% in radiology) are derived from the December 2025 version of the list.
2. Garcia v Character Technologies, No. 6:24-cv-01903 (M.D. Fla., May 2025). The court declined to dismiss the product-liability claim at the pleading stage, holding that it was not prepared to find as a matter of law that the AI chatbot fell outside Florida product-liability doctrine. It also declined to dismiss on First Amendment grounds. The case settled in January 2026, leaving the pleading-stage order on the public record but the classification question unresolved.
3. Claims involving the da Vinci system have alleged instrument defects, inadequate warnings, insufficient training and failures in postoperative care. See, for example, Pierre v Intuitive Surgical, Inc., No. 18-62553-CIV (S.D. Fla. 2020).
4. US Food and Drug Administration, “Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning-Enabled Device Software Functions” (finalised August 2025).
5. US Food and Drug Administration, “Clinical Decision Support Software: Guidance for Industry and Food and Drug Administration Staff” (29 January 2026).
6. FDA warning letter to Exer Labs Inc (10 February 2025), treating the Exer Scan product as an adulterated and misbranded device marketed without premarket approval, clearance or authorisation.
7. Riegel v Medtronic, Inc., 552 U.S. 312 (2008). The Supreme Court held that the Medical Device Amendments expressly pre-empt state-law claims imposing requirements different from or additional to federal requirements for PMA-approved devices. Pre-emption is narrower for 510(k)-cleared devices: see Medtronic, Inc. v Lohr, 518 U.S. 470 (1996). Parallel claims alleging violation of federal requirements may survive pre-emption.
8. Medical Device Coordination Group and AI Board, MDCG 2025-6, “FAQ on the Interplay Between the Medical Devices Regulation (EU) 2017/745, the In Vitro Diagnostic Medical Devices Regulation (EU) 2017/746 and the Artificial Intelligence Act” (19 June 2025).
9. Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026. The European Commission withdrew the proposed AI Liability Directive in October 2025.
10. UK Medicines and Healthcare products Regulatory Agency, guidance on digital mental health technologies as Software as a Medical Device (February 2025). International reliance pathways proposed July 2025. FDA, Health Canada and MHRA, joint principles on predetermined change control plans for AI/ML-enabled medical devices (August 2025).
11. US Food and Drug Administration, draft guidance on pulse oximetry device performance across skin pigmentation levels (January 2025).
12. R. Daneshjou, K. Vodrahalli, R.A. Novoa et al., “Disparities in Dermatology AI Performance on a Diverse, Curated Clinical Image Set”, Science Advances, vol. 8, no. 32 (2022), eabq6147, DOI: 10.1126/sciadv.abq6147; A.S. Adamson and A. Smith, “Machine Learning and Health Care Disparities in Dermatology”, JAMA Dermatology, vol. 154, no. 11 (2018), pp. 1247–1248, DOI: 10.1001/jamadermatol.2018.2348.
13. California SB 1120 (effective 1 January 2025). The statute requires that utilisation review and medical-necessity determinations involving AI be made by appropriately qualified healthcare professionals.
14. California AB 3030 (effective 2025). The statute applies to specified AI-generated written or verbal communications concerning patient clinical information. Communications reviewed and approved by a licensed or certified healthcare provider are exempted.
15. A. Zhavoronkov et al., “A Generative AI-Discovered TNIK Inhibitor for Idiopathic Pulmonary Fibrosis: A Randomized Phase 2a Trial”, Nature Medicine, vol. 31, no. 8 (2025), pp. 2602–2610, DOI: 10.1038/s41591-025-03743-2. Published online 3 June 2025. Rentosertib was identified and optimised using Insilico’s AI-driven drug discovery platform.
16. Eli Lilly and Insilico Medicine partnership announced March 2026. The stated value of up to $2.75 billion represents a contingent maximum including development and commercial milestones, not the upfront transaction value.
17. US Food and Drug Administration, “Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products” (draft guidance, January 2025).
18. US Patent and Trademark Office, “Revised Inventorship Guidance for AI-Assisted Inventions”, 90 Fed. Reg. 54636 (28 November 2025), rescinding and replacing the guidance published at 89 Fed. Reg. 10043 (13 February 2024). The revised guidance confirms that ordinary principles of human conception apply and that AI systems cannot be inventors. The UK position was confirmed in Thaler v Comptroller-General of Patents [2023] UKSC 49.
19. Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products. Member States must transpose by 9 December 2026.


