AI regulatory compliance is the program around a model: which law applies, what risk class it sits in, what you have to document, and who is accountable. It is not the FDA device pathway. It is not a PYCAD product.
If you meant FDA class → 510(k) / PMA / De Novo → FDA medical device approval process. If you meant QMS / ISO 13485 → medical device quality management system. If you meant why a model flagged a pixel → explainable AI in healthcare. If you meant HIPAA transfer → HIPAA-compliant data transfer.
PYCAD builds custom web DICOM viewers and medical-imaging models. It is not a regulatory agent, a HIPAA platform, or a compliance shop. Imaging software that is a medical device still has to walk the FDA tree. That walk is the other article.
Compliance is not ethics
Ethics is a voluntary bar (fairness statements, model cards, an internal review board). Compliance is whatever a statute or a regulator can enforce. You can fail ethics and still be legal. You can pass an ethics slide and still be illegal. Build the file the law asked for; do not treat a values page as the file.
Three recurring duties sit under almost every AI rule, whatever the jurisdiction calls them:
- Transparency. Can a user tell they are talking to a system, and can you explain what it does well enough for a regulator.
- Data protection. Lawful basis, minimization, retention, cross-border. In the US for health data that is often HIPAA; it is not the only statute.
- Bias and human oversight. High-stakes outputs (credit, hiring, a clinical flag) need a person who can override, and a test that the model does not systematically fail a group you can name.
EU AI Act: four risk bins
Regulation (EU) 2024/1689 is the one horizontal AI law that actually shipped. It bins systems by risk. The bin picks the duty. Healthcare diagnostic and triage models usually land in high-risk when they are a safety component of a medical device or are used for that purpose — they do not get a free pass because they are “assistive.”
| Bin | Examples | What you actually do |
|---|---|---|
| Unacceptable | Social scoring, some real-time biometric ID in public, untargeted facial scrapes | Do not ship. Banned. |
| High-risk | Medical-device safety component; employment; credit; some law-enforcement and critical-infrastructure uses | Risk file, data-governance, logging, human oversight, conformity assessment, CE-style marking for the AI duties. On top of MDR if it is also a device. |
| Limited / transparency | Chatbots, some deepfakes, emotion-recognition notices | Tell the person they are dealing with a system. Label synthetic content. |
| Minimal | Spam filter, inventory forecast | Almost nothing extra. Do not pretend this bin covers a CT worklist model. |
Article 99 sets the fines: up to €35 million or 7% of worldwide annual turnover (whichever is higher) for prohibited practices; 3% / €15 million for other operator failures; 1.5% / €7.5 million for supplying wrong information. Those are the Act’s numbers, not a market-deck “up to.” Extraterritorial: if you put the system on the Union market or the output is used there, the Act can reach you outside the EU.
A medical-device AI is not done when the AI Act file is done. Class, 510(k)/PMA/De Novo, and the EU MDR technical file are the device pathway.
United States: no single AI statute
There is no federal AI Act analogue. What you have instead:
- NIST AI Risk Management Framework (AI 100-1, January 2023). Voluntary. Map / measure / manage / govern. Useful as the spine of an internal program. It is not a clearance.
- Existing sector law. HIPAA for PHI. FDA if the software is a device (SaMD). FTC for unfair/deceptive. Sector rules in finance, employment, housing. The NIST page is the framework; the FDA page is still the device page.
- State privacy. CCPA/CPRA in California and the growing state-privacy set. They are about personal data, not “is this a high-risk model.” They still bite a training set that holds California residents.
- Blueprint for an AI Bill of Rights (White House OSTP, 2022). A policy document. Not a statute. Do not cite it as a license.
White & Case’s AI Watch tracker is a decent public map of the moving pieces. It is a law-firm tracker, not a regulator.
Asia-Pacific: named statutes, not a bloc
APAC is not one regime. Three names that actually exist:
- India — Digital Personal Data Protection Act, 2023. Consent / legitimate-use, significant-data-fiduciary duties. Section 33 can fine up to ₹250 crore per breach. It is a data law. It is not an AI Act.
- China — PIPL (2021) plus the algorithm-recommendation and deep-synthesis rules. Localization and algorithm-filing duties for systems that operate in China. Cross-border transfer is its own gate.
- Singapore — Model AI Governance Framework. Voluntary. Widely copied as a checklist. Not a fine schedule.
Data-localization and consent rules change how you store a training set. They do not replace a device file.
What a compliance program actually is
The “12-month roadmap” posts invent durations. The work is shorter to name:
| Piece | Job | What it is not |
|---|---|---|
| Inventory | Every model, intended use, data in, output, where it runs, who can override. | Not a slogan slide. If it is not on the list it will not be in the file. |
| Risk class | Map each model onto the EU bins / FDA device-or-not / HIPAA-or-not. | Not “we are assistive so we are low-risk.” |
| Controls | Human oversight, logging, access, de-id, change control when the weights move. | Not a one-time pentest. |
| File | Intended use, data-governance, test set, known failure modes, instructions for use. | Not an ethics PDF in a drawer. |
An “AI ethics committee” is useful if it can stop a launch. A title without a veto is decoration. Continuous monitoring is the same job as post-market surveillance once the thing is a device — do not invent a second PMS article here.
What this page is not
- Not the FDA 510(k) / PMA / De Novo tree. That is 7568. 698 left this URL on purpose.
- Not a PYCAD HIPAA platform, “AI compliance suite,” or regulatory retainer.
- Not a market-size or “60% of European companies” slide. Dropped.
- Not a YouTube embed or a form-analytics blogroll. Dropped.
If the work is a viewer or a model that has to live inside someone else’s compliance file, that is the imaging piece. Case studies.