The central awkwardness of regulating medical AI has always been that the thing being approved does not hold still. A model cleared on 2024 data drifts against a 2026 population, a new scanner, a changed referral pattern. Traditional device review assumes a fixed artifact. Learning systems are not fixed artifacts.

A draft framework circulated this week proposes a compromise: sponsors may update a cleared model within a pre-declared envelope — bounded architecture, bounded training data provenance, bounded indication — without a new submission, provided they instrument the deployment and report performance on a fixed cadence. Step outside the envelope and you are back in the queue.

The obligation that has drawn the most industry attention is rollback. Under the draft, a sponsor must be able to revert any deployed site to a previously validated version within a defined window, and must demonstrate that capability during review. Several vendors we contacted acknowledged privately that their release infrastructure does not currently support this for on-premise customers.

Comment closes in the autumn. The consensus among the health system counsels we spoke with is that the framework is directionally right and operationally expensive, which is roughly where most useful regulation starts.