Skip to content
AI in Healthcare

Article

The FDA's PCCP guidance in 2026 — what actually changed for AI/ML-enabled devices

The Predetermined Change Control Plan is the FDA's answer to the update problem for AI/ML devices. Two years in, here is what the guidance means in practice and where it still falls short.

By AI in Healthcare Editorial Updated
  • FDA
  • PCCP
  • regulation
  • AI/ML
  • SaMD
  • 510k
  • clinical-ai

Ask a room of AI/ML device manufacturers what they were most anxious about in 2021, and a plurality would have named the same problem: the update problem. FDA authorization was scoped to the specific version of the device that got cleared. Any “significant change” to the algorithm — retraining on new data, adjusting the model architecture, changing the intended-use population — required a new submission. That was tenable when the “device” was a mechanical valve. It was untenable when the “device” was a machine-learning model that the manufacturer wanted to keep improving.

The FDA’s response, developed over five years and finalized in December 2024, is the Predetermined Change Control Plan (PCCP) — a framework that lets a device manufacturer commit, up front, to a defined set of post-market modifications and execute those changes without a new 510(k) submission, as long as the changes fit inside the PCCP envelope.

Two years in, the guidance has been refined again — the FDA’s 2026 PCCP guidance update sharpened several points that manufacturers, health systems, and payers had been asking about. This piece walks through what actually changed, what it means in practice for anyone building or buying an AI-enabled device, and where the framework still has open edges.

What a PCCP actually is

A PCCP is a device-specific document that a manufacturer submits alongside its premarket submission. It has three defined components:

  1. Description of Modifications. What changes the manufacturer intends to make to the device after clearance. This is not “we might update the model sometime” — it is a specific enumeration: which model architectures, which training-data expansions, which performance-characteristic changes, which intended-use tweaks.
  2. Modification Protocol. How the manufacturer will implement and validate each type of change. This includes acceptance criteria, statistical methods, test-set specifications, and clinical-workflow validation where appropriate.
  3. Impact Assessment. How the manufacturer has evaluated the benefits and risks of each modification type, and how the “risk envelope” of the device will be maintained across the modification lifecycle.

Once accepted, the manufacturer can execute PCCP-scoped modifications, document them, and continue marketing the device under the original authorization — subject to Quality System Regulation obligations and ongoing post-market surveillance. Modifications outside the PCCP envelope still require a new submission.

What the 2026 update changed

The 2026 refresh clarified four points that had been recurring pain points in the first year of PCCP-covered clearances:

  • Data drift and distribution shift. The 2026 guidance is more explicit that “retraining on new data drawn from the same distribution as the original training set” is a distinct modification from “retraining to address a documented distribution shift in the deployment population.” The former can fit inside a routine PCCP protocol; the latter requires more careful specification of how the manufacturer detected the shift, what the new target distribution is, and how the performance-maintenance case will be made.
  • Population expansion. Expanding the intended-use population — from adult to pediatric, from a single scanner manufacturer to a broader set, from one care setting to another — was ambiguous under the 2024 guidance. The 2026 update walks through explicit examples of when population expansion can fit inside a PCCP protocol and when it must be its own submission.
  • Foundation-model-based devices. The rise of clinical LLMs — many of them built on general-purpose foundation models updated on an aggressive cadence by the foundation-model vendor — created a novel PCCP question: what happens when the underlying foundation model gets updated by a third party? The 2026 guidance treats this as a change to the device that must be evaluated under the PCCP protocol, which effectively requires manufacturers to freeze the foundation-model version or to include the foundation-model-update pathway in their protocol.
  • Cybersecurity and update-delivery. The 2026 update integrates the FDA’s newer cybersecurity guidance, requiring manufacturers to describe the update-delivery mechanism (over-the-air, at-service, next-scanner-visit) and the vulnerability-management posture across the PCCP lifecycle.

Sources cited

What this means for manufacturers

The practical effect of the 2026 update is that a well-constructed PCCP has become a durable competitive asset — not just a compliance artifact. Manufacturers that invest in a rigorous PCCP up front spend less time on downstream submissions and can move faster on documented in-envelope updates. Manufacturers that submit thin, boilerplate PCCPs find themselves back in the pre-2024 world: every meaningful update becomes a new submission.

Three practical implications:

  1. Invest in the Modification Protocol. The Modification Protocol section is where the FDA reviewers spend the most time and where PCCPs live or die. A protocol that specifies real acceptance criteria, real statistical methods, and a real plan for handling failed validations gets accepted; a protocol that reads like an abstract wish list gets negotiated for months.
  2. Version-lock foundation models where possible. If your device sits on a general-purpose foundation model, treat the foundation-model version as a controlled device parameter. Anticipate the foundation-model vendor’s update cadence in your PCCP or freeze the version.
  3. Plan for post-market surveillance. A PCCP-covered device is signing up for more, not less, post-market data. Build the surveillance instrumentation into the product; do not treat it as an afterthought.

What this means for health systems

For hospital and health-system procurement teams, the PCCP is now something to actively evaluate during due diligence. Questions worth asking every AI-enabled-device vendor:

  • What is the PCCP scope? Read the description-of-modifications section. Does it match the roadmap the vendor is pitching?
  • How are in-envelope updates communicated to us? Some vendors push updates silently under the PCCP; others notify customers. If your governance program (see the health-system AI governance topic) requires review of any model change, you need contractual notice.
  • What is out of PCCP scope? Anything the vendor might do that requires a new submission is a potential future workflow disruption. Ask.
  • What is the surveillance plan? How is the vendor monitoring performance in production? What triggers a pull? Is there a shared dashboard?

What this means for patients and clinicians

For clinicians, the PCCP framework is mostly invisible — as it should be. A well-functioning PCCP means that the model the FDA cleared and the model your radiology suite (or ambient scribe, or LLM copilot) is running on Monday morning are the same model, or a version whose changes have been validated against the same performance envelope. That is a substantial upgrade over the pre-2024 status quo, in which many deployed models drifted quietly from the version that was cleared.

For patients, the effect is similarly indirect but real: post-market surveillance is now part of the regulatory expectation, and the FDA’s post-market authority to require model rollbacks or label updates is more legible.

Where the framework still has open edges

Two things the 2026 update did not resolve:

  • Multi-manufacturer foundation-model chains. When a general-purpose foundation model is fine-tuned by a healthcare-AI vendor, deployed inside a hospital’s on-premises stack, and further customized by the hospital’s own team, whose PCCP governs the chain? The 2026 update treats the device manufacturer as the responsible party, but the operational reality is more distributed.
  • Cross-border operations. Manufacturers selling in the U.S., EU (under the AI Act and MDR), and Asia face materially different post-market change frameworks. The FDA’s PCCP is the most permissive of the major regimes; harmonization is a slow-moving conversation.