Compliance & Regulation

Meeting FDA cybersecurity guidance for AI-enabled device software

The FDA's January 2025 AI-Enabled Device guidance identifies seven AI-specific cyber threats. Only one of them, model evasion, lives at runtime on the device. The other six attack the pipeline: training data, model registries, evaluation logic, and deployment.

7 FDA-named AI threats. Only 1 lives at runtime.Data poisoningPIPELINEModel inversionPIPELINEData leakagePIPELINEOverfittingPIPELINEModel biasPIPELINEPerformance driftPIPELINEModel evasionRUNTIME
Six of the seven FDA-named AI threats attack the pipeline, not the deployed model.

Most testing programs today only cover the deployed model. That means they are addressing one-seventh of what the FDA is explicitly asking about. Data poisoning, model inversion and stealing, data leakage, overfitting, model bias, and performance drift all sit upstream of the running model.

Test everything that touches the model

Our approach expands the digital twin to include the full AI pipeline as an associated system, then structures testing to cover the whole lifecycle. Runtime testing stays focused and purpose-built. Every test case maps back to a specific FDA-identified threat, executed against real pipeline components, producing defensible evidence for premarket and postmarket.

This is not "test the model." It is "test everything that touches the model."
← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Proof Over Probability

The AI testing newsletter.

One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about the FDA AI-enabled device guidance.

What AI cybersecurity threats does the FDA identify for AI-enabled devices?

The FDA's January 2025 AI-Enabled Device guidance names seven AI-specific cyber threats: data poisoning, model inversion and stealing, data leakage, overfitting, model bias, performance drift, and model evasion. Only model evasion lives at runtime on the device. The other six attack the pipeline that produces the model.

Is testing the deployed model enough to meet the FDA AI guidance?

No. A program scoped to the deployed model covers one of the seven threats the FDA names, model evasion. The other six sit upstream in training data, model registries, evaluation logic and deployment, which means runtime-only testing addresses roughly one seventh of what the guidance asks about.

What counts as the AI pipeline for a medical device?

The AI pipeline is everything that touches the model before it runs: training data, model registries, evaluation logic and deployment. Treating that pipeline as an associated system inside the device model is what lets testing cover the whole lifecycle instead of stopping at the version that ships.

How do you produce defensible evidence for AI-specific threats?

Map every test case back to a specific FDA-identified threat and execute it against real pipeline components. That mapping is what turns test activity into evidence a reviewer can follow for premarket and postmarket, because each result points at the named threat it answers.

Does the AI guidance replace runtime security testing?

No. Runtime testing stays in scope and stays focused, because model evasion is a runtime threat. The guidance widens the scope rather than shifting it. The instruction is not to test the model. It is to test everything that touches the model.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationFind the 1%Remediation OptimizationELTON TestLink™SBOM, VEX & ReportingCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Legacy Testing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo