FDA created more room for certain clinical decision support tools. It did not make the decisions they influence any less consequential.
FDA’s January 2026 clinical decision support guidance made a narrow change with broad practical consequences. The agency opened an enforcement-discretion pathway for some software that delivers a single, clinically appropriate recommendation – an output that previously faced a less forgiving regulatory interpretation.
That does not make the output self-validating. It gives physicians, clinical leaders and health systems more reason to examine what sits behind it. For anyone evaluating AI clinical decision support in 2027, the useful question is no longer simply, “Was this reviewed by FDA?” It is: “What can I see, test and challenge before this changes care?”
Take the Clinical AI Conversation Further at HIMSS27
Connect with physicians, informaticists and health leaders working through these decisions in practice. Get notified when HIMSS27 registration opens.
FDA Changed One Important Part of the Test
A single recommendation no longer leads to one automatic regulatory answer.
To understand the change, start with Criterion 3 of the federal non-device CDS framework. It addresses software that supports or provides recommendations to a healthcare professional about prevention, diagnosis or treatment.
A tool that produced several options could potentially satisfy that criterion. Software delivering only one specific course of action was more likely to be treated as directive – and therefore more likely to fall within FDA’s oversight of medical devices.
The agency’s revised Clinical Decision Support Software guidance did not rewrite the criterion. Instead, FDA clarified that it intends to exercise enforcement discretion for certain tools offering one clinically appropriate recommendation, provided the other relevant conditions are satisfied.
The phrase “clinically appropriate” now carries considerable weight. FDA has not supplied a universal checklist that makes the determination automatic. In practice, appropriateness will depend on the use case, supporting evidence, intended patient population and way the tool is deployed.
Nor does one regulatory label necessarily cover an entire platform. FDA’s accompanying clinical decision support FAQ makes clear that a single product can contain non-device CDS functions alongside functions subject to medical-device requirements.
Three Regulatory Lanes
Non-device CDS
The function satisfies all four statutory criteria, including the clinician’s ability to independently review its basis.
Enforcement discretion
The function may fall within the device definition, but FDA does not intend to enforce certain requirements under the circumstances described in its policy.
Device oversight
The function is subject to the applicable medical-device framework and FDA requirements.Better data signals can help care teams identify rising risk and prioritize outreach sooner.
The product name does not determine the lane. The specific function, intended use and clinical context do.
Patient-facing tools require a separate analysis. The healthcare-professional CDS exclusion does not automatically extend to a patient chatbot, symptom checker or consumer-facing recommendation engine. Some may fall outside device regulation for other reasons, but they should not inherit a clinician-facing tool’s status by association.
FDA Status Is Only the First Question
Regulatory classification and clinical trust answer different questions
Criterion 4 remains central to the non-device CDS analysis: the healthcare professional must be able to independently review the basis for the recommendation rather than rely primarily on the software. That standard should be visible in the interface, not buried in a technical file. A clinician needs enough information to understand the tool’s intended use, the patient data it considered, the evidence supporting the output and the limitations that could make it unreliable in this case.
FDA’s transparency principles for machine-learning-enabled medical devices point in the same direction. Useful disclosure includes how a system was developed, how it performs, where it may fail and how its information fits into the user’s workflow. Transparency also helps clinicians recognize bias, errors and declining performance after deployment.
HIMSS26 put the expectation in plainer clinical terms. The session “Operationalizing Trustworthiness: Strengthening Clinical Decision Support Across the Care Team” described high-stakes clinical AI as needing to be “grounded in trusted evidence, transparent in their outputs, and aligned with clinical workflows.” The order matters. Evidence gives an output its footing. Transparency makes scrutiny possible. Workflow determines whether that scrutiny can happen before a decision is made.
“Grounded in trusted evidence, transparent in their outputs, and aligned with clinical workflows.”
– Operationalizing Trustworthiness, HIMSS26 Session
The Physician Still Has to Make the Call
Meaningful oversight requires time, information and a genuine way to disagree.
FDA guidance classifies software under federal law. It does not settle malpractice standards, allocate contractual responsibility or decide how state law and organizational policy will apply when an AI-supported decision causes harm.
That distinction matters. FDA clearance does not transfer clinical judgment to software, while enforcement discretion should not be mistaken for a finding that a tool is clinically appropriate for every patient.
The American Medical Association’s 2026 AI policies reinforce an assistive model: AI should support physicians, preserve meaningful oversight and remain subject to transparency and accountability.
Oversight, however, cannot exist only on paper. It depends on three practical conditions:
- Time: Can the physician pause long enough to examine the output?
- Information: Is the basis understandable at the point of use?
- Authority: Can the physician reject, modify or escalate the recommendation without being penalized by the workflow?
FDA’s FAQ recognizes the time problem directly. Time-critical decision support generally cannot qualify as non-device CDS when the clinician lacks sufficient opportunity to independently review its basis.
Two Clinical Scenarios
Review is realistically possible
The output arrives early enough to evaluate. Supporting evidence and relevant patient inputs are accessible. The clinician can compare alternatives and record a different decision.
Review exists in name only
The alert arrives moments before action is required. Its rationale is opaque. Overriding it creates friction, while accepting it requires one click.
The same underlying model can create very different conditions for human judgment depending on where and how it enters care.
Reimbursement Is Arriving One Service at a Time
A billing code can help a tool enter care without funding everything required to use it well.
Reimbursement is beginning to catch up with selected AI-enabled services, but the movement is incremental.
One example is the January 2026 transition from temporary CPT codes 0623T-0626T to CPT 75577 in a specific non-invasive coronary-analysis billing context. The relevant CMS Medicare Administrative Contractor article also includes an important warning: use of a code does not guarantee reimbursement. Coverage criteria and documentation requirements still apply.
That is a more useful model for understanding the reimbursement landscape than treating it as a blanket signal that payers now cover clinical AI.
Code, Coverage, and Capacity
Code
Is there a recognized way to report the service?
Coverage
Does the patient’s payer cover it under the applicable criteria?
Capacity
Can the organization support integration, clinician training, documentation, monitoring and follow-up?
A code may improve the business case for adoption. It does not pay automatically for every operational safeguard that responsible use requires.
Five Questions to Ask Before Trusting the Recommendation
A point-of-care check for evidence, fit and an exit path.
Our earlier look at how AI is reshaping clinical decision-making examined the technology’s expanding role in care. The 2026 regulatory change makes the next step more immediate: deciding whether a particular output deserves influence in a particular case.
Avoid evaluating the platform as a single object. Identify what this component does, who it is designed for and whether it informs, prioritizes, predicts or directs a clinical action.
Look for the relevant patient inputs, evidence sources, model limitations and intended-use boundaries. A confidence score alone does not explain the clinical basis.
Review validation populations and subgroup performance where available. A strong aggregate result can conceal weaker performance across age, race, sex, disability, language, geography or care setting.
Independent judgment requires more than agreeing or disagreeing with the screen. Consider competing explanations, missing data and the consequences of a false positive or false negative.
A trustworthy workflow should make disagreement possible. Physicians need a clear route to record their reasoning, report a questionable output and trigger review when performance appears to drift.
Enterprise governance still matters; our broader examination of AI’s benefits and risks in healthcare addresses that organizational layer. At the point of care, these five questions turn policy into a usable clinical habit.
The Better Question to Bring Into 2027
The regulatory label is the starting point. Clinical judgment comes next.
The vocabulary surrounding AI – cleared, non-device, enforcement discretion, human in the loop – can create a false stopping point. None of those phrases answers the question a physician faces when an output conflicts with the chart, the patient or clinical experience.
A better question is more demanding: What would I need to know before I allowed this recommendation to change care?
That is where the 2027 conversation belongs. Physicians should be able to examine the evidence, recognize the limits, challenge the output and remain fully present in the decision.
Final Takeaway
Move from regulatory possibility to responsible practice.
Explore the HIMSS27 experience for physicians and join the people shaping how clinical AI enters care. Pre-register for HIMSS27.