Reframing risk management for AI-enabled medical devices: A dual-layer risk governance framework
Pujitha GourabathiniBackground
AI-enabled medical devices introduce dynamic, data-dependent risks that challenge traditional safety-risk management frameworks. While ISO 14971, AAMI CR34971, and the EU Artificial Intelligence Act each address elements of device safety and algorithmic governance, they remain fragmented when applied. This review examines conceptual and operational gaps in current approaches and proposes an integrated governance model for AI-specific safety-risk management.
Methods
A structured narrative review was conducted using PubMed, IEEE Xplore, Google Scholar, and regulatory repositories. Eligibility criteria focused on addressing AI-specific safety-risk management, regulatory obligations, or risk-analysis methodologies. A total of 19 academic studies and regulatory sources met inclusion criteria. Data were charted using JBI, AACODS, and normative appraisal categories, and synthesized to identify cross-cutting themes and gaps.
Results
The review identified persistent challenges in linking AI-specific hazards to safety-risk evaluation, determining adequacy of risk controls, integrating algorithmic-risk obligations with ISO 14971 processes, and operationalizing lifecycle monitoring under the EU AI Act. Existing frameworks address components of AI risk but lack a unified operational pathway.
Conclusions
An integrated governance model is proposed to align AI-specific risk identification with established medical-device safety frameworks. This synthesis provides regulators, manufacturers, and professionals with a clearer, more actionable approach to managing AI-related safety risks.