Healthcare software: TGA clarifies when AI will be regulated as a medical device
Digital health innovators who use artificial intelligence (AI) must navigate a range of regulatory risks under Australia's medical device regime. To help them do so, the TGA has recently published guidance that clarifies when and how existing regulations do apply – and when they don't.
The TGA has also foreshadowed increased scrutiny in this space, software as a medical device (SaMD) being identified as one of 12 priority focus areas for the TGA's compliance and enforcement activities in 2026 and 2027. Market players who don't meet their obligations can therefore expect to face serious (and expensive) consequences if they fail to get it right.
A foundational question: what is the technology intended to do?
Software that is, or uses, artificial intelligence (AI) is not defined in the therapeutic goods legislation, but it will be regulated as a medical device including where it is intended for the purposes of "diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease" in humans.
The applicable regulations are technology-agnostic: the analysis does not turn on how an AI feature or tool works (nor on what hardware it works with), but on what the technology is intended to do.
Critically, a product's intended purpose is ascertained by reference to its technical documentation, labelling, instructions for use, or any relevant marketing materials. This means that clinical claims in marketing material could potentially cause your product to be captured as a medical device, even if that was not the actual product designer's original intention.
Software captured by the regime will include a range of AI technologies, including potentially those which incorporate machine learning, Large Language Models (LLMs), generative AI, natural language processing, computer vision and robotics. There has been a rapid proliferation of new AI technologies in the healthcare sector; however, there remains no separate regulatory regime for AI. This is why the TGA has published its timely guidance, to clarify how the existing framework applies.
The TGA has clarified its views about the boundaries
The TGA's recently published guidance includes specific guidance about "digital therapeutics" – a subset of SaMD, which the TGA describes as being evidence-based software products that deliver medical interventions intended to prevent, manage or treat a disease, disorder or injury. Such digital therapeutics are, in the TGA's view, regulated medical devices. In contrast, software intended for a range of lower-risk uses (like general health and wellness apps) will likely be excluded types of software.
To improve transparency about what is and is not regulated, in 2025, the TGA first published a list of AI-enabled medical devices currently included in the Australian Register of Therapeutic Goods (ARTG). These examples illustrate how the regulatory framework applies in practice. The TGA has also highlighted that highlights that chatbots, LLMs, and clinical decision support tools that provide or monitor treatment, or provide diagnostic or treatment recommendations, can fall within the purview of medical device regulation where their intended purpose is clinical. Even tools presented as “general information” (for example, symptom checkers or wellness phone applications) may be regulated where the intended purpose, as evidenced by documentation and marketing, is to support clinical decision-making or provide diagnostic or treatment recommendations.
You may need to apply for ARTG inclusion if your software or app is captured
To be legally supplied in Australia, medical devices (including software and apps) must be included in the ARTG, unless an exclusion or exemption applies.
Both the manufacturer (the entity that designs and builds the software) and the sponsor (the entity that imports or supplies it in Australia) have obligations under the Australian regulatory framework. The manufacturer is responsible for ensuring that the device is designed and produced in accordance with the "Essential Principles" and applying appropriate conformity assessment procedures and the sponsor must certify that these requirements have been complied with and that it holds evidence or a written agreement to obtain that evidence, in accordance with the law. The sponsor takes on the primary responsibility for liaison with the TGA about any matters relating to compliance, including in relation to pharmacovigilance.
Where a developer of AI-enabled software both designs and supplies a product in Australia, that entity may be considered to be both the manufacturer and the sponsor, and must discharge the prescribed obligations of each role.
Digital health innovators assessing their regulatory risk should consider:
whether the product meets the medical device definition under section 41BD of the Act, or alternatively, whether a relevant exclusion or exemption applies; and
the correct risk classification, because classification drives the depth of evidence required, the conformity assessment pathway and time-to-market.
Other regulatory requirements will depend on risk-based classifications. Software-based medical devices in Australia can be classified from Class I to Class III, depending on clinical significance and potential harm, with higher classifications attracting more extensive regulatory requirements.
Proving your AI is safe and effective
The TGA expects manufacturers to hold robust, transparent evidence of safety and performance for AI-enabled devices, in line with the "Essential Principles", and requires manufacturers to maintain documentation of the AI model’s intended purpose, algorithm and model design, training and validation processes, data quality and provenance, risk management, and clinical validation.
For software that uses AI or machine learning, the TGA requires evidence that is sufficiently transparent to enable evaluation of the product’s safety and performance, including in terms of training and testing processes, data representativeness, risk management (including algorithmic bias and model drift) and clinical evidence. To this end, the TGA has borrowed from the International Medical Device Regulators Forum (IMDRF) guidance on Good Machine Learning Practice for Medical Device Development: Guiding Principles.
In addition, the TGA references a number of recognised international standards across its guidance materials for software-based medical devices, and in practice, sponsors are expected to map their compliance evidence to these standards, including, for example, IEC 62304 (software lifecycle processes), IEC 62366 (usability engineering), ISO 14971 (risk management), ISO 13485 (quality management systems) and IEC 81001-5-1 (cybersecurity).
Compliance risks to watch
Scope creep and agile development
AI products are often developed and updated through agile and iterative methodologies. However, "feature creep" can quickly become "regulatory creep": manufacturers of AI-based SaMD should continuously monitor software updates and new features. Any change that alters the intended purpose of the product may cause that product to meet the definition of “medical device” and trigger the need for regulatory approval before implementation.
For example, if a digital scribe or clinical documentation tool adds functionality to a product that starts suggesting diagnoses or recommending treatment pathways, this may constitute "feature creep", which adds a new intended use and creates a different "kind" of medical device. This may necessitate a TGA-approved variation to the existing ARTG entry, or, if the relevant change is substantial, the creation of a new ARTG inclusion.
Regulatory checkpoints must be baked into the product development cycle, so that any new features that could change the software’s regulatory status are identified early (and in any case, well before the need to apply for inclusion on the ARTG arises).
Off-label use
A manufacturer’s or sponsor’s responsibilities do not end once the product is on the market. The "scope creep" risk above heightens the risk that the software may be supplied or marketed for an unapproved or "off-label" use. ‘Off-label use’, in this context, refers to the use of a medical device for a purpose not included in its intended use as recorded on the ARTG. Off-label use by medical practitioners is not prohibited – the Act does not regulate clinical practice.
However, sponsors and manufacturers have regulatory obligations, and must:
ensure that all advertising and promotional material is consistent with the device’s intended purpose as included in the ARTG. It is an offence (and may attract civil penalties) to advertise a medical device for an unapproved use; and
where a manufacturer becomes aware that its device is being used outside its approved intended purpose, the TGA expects it to take corrective action, which may include either taking steps to prevent further off-label use, or cease supply and progress the appropriate pre-market assessment to reflect the revised intended purpose and ARG status.
Although sponsors are not responsible for regulating clinicians’ decisions to use devices off-label, they must comply with post-market obligations, including monitoring and reporting adverse events arising from both on-label and off-label use, to the extent they become known.
The TGA is not the only regulator paying attention
While the TGA is the primary regulator for medical devices, AI in clinical settings often triggers overlapping regulatory regimes and requirements, and organisations should be aware of the breadth of their potential obligations outside the therapeutic goods framework.
By way of example, the TGA’s guidance on digital scribes explicitly directs developers to consider obligations under privacy, cybersecurity and consumer law regimes. Further, the Australian Commission for Safety and Quality in Health Care, responsible for e-health safety, is developing guidance to support AI safety in clinical settings, working with the Commonwealth Department of Health, Disability and Ageing to ensure that safety and performance requirements for AI-enabled technologies are appropriately calibrated.
Key takeaways
Key takeaways from the TGA’s February 2026 guidance include:
Early and ongoing regulatory scoping is essential: Organisations should not wait until launch to consider their regulatory obligations. Building regulatory checkpoints into the product development cycle is critical, particularly for agile development environments where feature creep poses a real risk. Scoping should address definition, exclusions and classification.
Evidence requirements are substantial: Manufacturers must hold transparent, robust evidence of safety and performance, including documentation of AI model design, training processes, data quality, risk management and clinical validation, in accordance with the Essential Principles.
SaMD is an enforcement priority: The TGA has expressly identified SaMD as a priority focus area for 2026–2027. Coupled with quarterly reviews of enforcement priorities and an increasingly proactive regulatory posture, non-compliance carries heightened risk.
Get in touch