Why was additional guidance needed now?
AI-based medical devices differ from conventional, “non-AI” devices in ways that existing risk management
approaches did not always fully capture. Drawing on an earlier AAMI-BSI report, the document identifies three
characteristics that distinguish MLMDs from traditional devices: the ability to process large volumes of data and
improve results within the intended use of the device; the level of autonomy, which can include generating
treatment options and selecting the best one with reduced human involvement; and explainability, the inherent
opacity of complex algorithms, which makes it difficult to interpret how a specific conclusion was reached, even
for well-trained clinicians and other healthcare personnel.
Scope, and what the document does not cover
ISO/TS 24971-2:2026 is intended to be used together with ISO 14971 and the ISO/TR 24971 technical report.
Importantly, the guidance does not apply to MLMD employing large language models (LLM) or generative AI,
a clear scope limitation that manufacturers should keep in mind when planning their compliance documentation.
Instead, the document focuses on risks related to:
- management of training and test data,
- feature extraction,
- unwanted bias in the algorithm,
- information security,
- the process of training the ML model via an ML algorithm,
- valuation and testing of the trained model.
How does “risk” under ISO 14971 differ from definitions used in general AI documents?
This distinction can easily be missed by teams importing terminology directly from general-purpose AI
standards. ISO/IEC 22989 and ISO/IEC 23894 define risk as the effect of uncertainty on objectives, a definition
useful for organizational or business risk management, and consistent with ISO 31000. The healthcare sector,
however, uses a different definition: under ISO 14971:2019, risk is the combination of the probability of
occurrence of harm and the severity of that harm. The new technical specification makes clear that it is this
second definition that applies when assessing MLMDs, regardless of the terminology used in broader AI
standards.
Model lifecycle and “continuous learning”
The document notes that models may require retraining after a period of use, and that some models learn
continuously from patient data, modifying their parameters accordingly. ISO/TS 24971-2:2026 consistently uses
the term “continuous(ly) learning,” rather than “adaptive,” which appears in other documents, it may be worth
aligning internal procedures with this terminology to avoid inconsistencies during audits.
Links to other documents
The specification references IMDRF documents N67 and N88, along with guidance from FDA, Health Canada,
and MHRA on MLMDs, and for cybersecurity and systems security topics, IEC 80001-1 and IEC/TR 80002-1.
The AAMI TIR34971 report also provided valuable input during development. The document was prepared by
Technical Committee ISO/TC 210 in collaboration with IEC/TC 62 (Subcommittee SC 62A) and
CEN/CLC/JTC 3, ensuring alignment with the European regulatory approach to medical devices.
Conclusion
For manufacturers developing diagnostic solutions, clinical decision-support software, or other machine learning-based functionalities, the publication of ISO/TS 24971-2:2026 is a signal to review AI risk management processes, software lifecycle documentation, data validation strategies, and post-market surveillance plans. It is also worth checking the consistency of these processes with the AI Act, MDR, and IVDR requirements, especially since the explicit exclusion of LLMs and generative AI from the document’s scope means manufacturers in that category must still rely on more general guidance.
Link to the document: