O Software Que Muda Depois de Aprovado — e o Vão Entre o CFM e a ANVISA Que Ninguém Nomeou
Em 26 de agosto de 2026 entra em vigor a resolução do CFM que obriga o médico brasileiro a usar apenas sistemas de inteligência artificial com certificação regulatória pertinente — e a responder pelo que eles fizerem ao longo de todo o ciclo de vida, inclusive depois de cada retreinamento. O problema é que a norma sanitária brasileira que emite essa certificação ainda trata software como se fosse um produto que nunca muda. A revisão que corrigiria isso está na fila da ANVISA desde 2024 e continua “em andamento”. Este artigo mostra onde exatamente está o vão, o que ele significa no plantão, e por que a consulta pública que a FDA abriu há quatro dias é a melhor chance que um médico brasileiro tem de influenciar o desenho da regra antes que ela chegue pronta.
📅 Publicado em 22 de agosto de 2026
Navegue pelo Artigo
De um prazo que vence nesta semana ao problema regulatório que vai definir a próxima década da IA clínica
- 1. Por Que Isso Importa Para Quem Está na Ponta
- 2. O Que Aconteceu Neste Mês — Dois Movimentos, Um Só Problema
- 3. As Datas e os Números, Sem Filtro
- 4. A Armadilha: o CFM Já Cobra o Que a ANVISA Ainda Não Verifica
- 5. O Que a FDA Propôs — e Por Que Soa Familiar a Quem Forma Residente
- 6. A Solução Como Ato Clínico
- 7. A Linha do Tempo
- 8. O Que Fazer na Segunda-Feira
- 9. Considerações Finais
- 10. Referências
Para quem não é da área — o essencial em 60 segundos
Este artigo funciona em duas camadas: uma para quem trabalha com saúde ou tecnologia, outra que exige apenas curiosidade. Toda ideia central aparece duas vezes — uma com exemplo de hospital, outra com exemplo do dia a dia.
Software como dispositivo médico é um programa de computador que, sozinho, faz o trabalho de um equipamento de saúde: interpreta um exame, calcula um risco, sugere uma conduta. Ele não é um aparelho que se pega na mão, mas é regulado como se fosse — precisa de autorização da vigilância sanitária antes de ser vendido, do mesmo jeito que um marca-passo ou um respirador.
Modelo que aprende (ou “adaptativo”) é o programa que continua mudando depois de instalado, porque vai sendo reajustado com dados novos. No hospital: um sistema que prevê piora clínica e é reajustado a cada seis meses com os casos daquele hospital. No dia a dia: o aplicativo de trânsito que muda a rota sugerida conforme aprende o comportamento do trânsito — a versão que você usa hoje não decide igual à de dois anos atrás, embora o nome e o ícone sejam os mesmos.
Por que isso quebra a regra atual: aprovar um remédio é aprovar uma fórmula fixa. O comprimido de hoje é quimicamente igual ao de daqui a cinco anos. Já um programa que aprende é mais parecido com um funcionário recém-contratado: você avalia na entrevista, ele passa, e depois ele continua estudando — e mudando. A licença sanitária de hoje é uma fotografia do dia da contratação. A pergunta que ninguém respondeu ainda é quem confere o que esse funcionário virou no terceiro ano.
Os três atores deste texto: o CFM (Conselho Federal de Medicina) regula a conduta do médico. A ANVISA regula o produto que o médico usa. A FDA é a agência norte-americana equivalente à ANVISA, e o que ela decide costuma virar referência mundial — inclusive aqui.
Por Que Isso Importa Para Quem Está na Ponta
Nesta quarta-feira, 26 de agosto de 2026, termina o prazo de adaptação da Resolução CFM nº 2.454/2026. A partir dessa data, ela não é mais uma norma anunciada: é uma norma exigível, fiscalizada pelos Conselhos Regionais.
Dois dos seus dispositivos merecem ser lidos com atenção por qualquer médico que use qualquer ferramenta de IA — e hoje isso inclui praticamente todo mundo. O artigo 3º, inciso III, assegura ao médico o direito de recusar sistemas que não tenham “validação científica adequada” ou “certificação regulatória pertinente”. O artigo 4º, inciso IV, transforma isso em dever: utilizar apenas sistemas que atendam às normas regulatórias vigentes no território nacional.
Lido rápido, parece protocolo burocrático. Lido devagar, é outra coisa: a resolução transfere ao médico a obrigação de verificar a regularidade sanitária da ferramenta que ele usa. E aqui começa o problema deste artigo — porque a regularidade que existe hoje no Brasil responde a uma pergunta diferente da que a resolução faz.
O Que Aconteceu Neste Mês — Dois Movimentos, Um Só Problema
Movimento 1 — a FDA abriu uma consulta pública sobre IA generativa em dispositivos médicos
Em 18 de agosto de 2026 — há quatro dias — o Centro de Excelência em Saúde Digital da FDA publicou um documento de discussão intitulado Considerations for the Regulation of Generative AI-Enabled Medical Devices e abriu o docket FDA-2026-N-7874 no portal Regulations.gov, com prazo de comentários até 19 de outubro de 2026.
O documento é explícito quanto ao que não é: não é norma, não é minuta de norma, não comunica expectativa regulatória. É um pedido de opinião, deliberadamente feito antes de a agência ter decidido qualquer coisa. Na apresentação oficial, a diretora do centro de dispositivos, Michelle Tarver, descreve o processo como um que pode “servir de modelo potencial para reguladores ao redor do mundo”.
Três elementos do conteúdo importam para nós: uma proposta de estrutura de risco em dois eixos; uma proposta de avaliação pré-mercado baseada em aferição de competência; e uma proposta de monitoramento pós-mercado proporcional ao risco — ou seja, vigiar o produto depois que ele já está em uso, com intensidade proporcional ao dano que ele pode causar. O documento também discute explicitamente modelos de fundação e sistemas de IA agêntica.
Movimento 2 — a ANVISA tem a revisão da norma de software na fila, e ela não anda
A Agenda Regulatória 2026-2027 da ANVISA, aprovada pela Diretoria Colegiada, lista 162 temas prioritários. Entre os de dispositivos médicos, o tema 5 é a “Revisão da regularização de software como dispositivo médico (SaMD) — Revisão da RDC nº 657/2022”.
Vale ler a justificativa oficial, porque ela é direta: “O marco regulatório atual (RDC 657/2022) referente a Softwares como Dispositivos Médicos apesar de publicado recentemente deve ser atualizado, de forma a acompanhar a evolução de um mercado que cresce e se expande de forma muito rápida. Itens referentes à inteligência artificial e à aprendizagem de máquinas devem ser incorporados à RDC, além da harmonização com as regulamentações e práticas internacionais.”
A própria ANVISA, portanto, reconhece por escrito que a norma vigente não contempla inteligência artificial nem aprendizado de máquina. Não é interpretação minha nem crítica de fora: está no documento da agência.
E há o dado que quase ninguém extrai desse mesmo documento. A referência de origem do tema é “AR 24-25 — Tema 11.8”. Ou seja: essa revisão já constava da Agenda Regulatória anterior, do biênio 2024-2025, e migrou para a atual sem ter sido concluída. A situação registrada segue sendo “Em andamento”, com a Análise de Impacto Regulatório ainda por realizar.
Um exemplo concreto: o funcionário que continuou estudando
Versão hospital: um sistema de alerta precoce é registrado na ANVISA em 2024, tendo demonstrado desempenho adequado no conjunto de dados de validação daquele momento. Em 2026, o fornecedor reajusta o modelo com dados novos — a sensibilidade sobe em adultos e cai em lactentes, um subgrupo pequeno demais para aparecer na média. O número que o registro sanitário atesta continua sendo o de 2024. O produto mudou; o documento que o autoriza, não.
Versão dia a dia: é como contratar um motorista, avaliar a direção dele no teste de admissão e arquivar a avaliação. Três anos depois ele continua com o mesmo crachá — mas dirige diferente, porque aprendeu atalhos, adquiriu vícios e mudou de hábitos. O crachá não mente sobre o passado. Ele apenas não diz nada sobre o presente.
E é exatamente o presente que a Resolução CFM 2.454 cobra do médico, a partir de 26 de agosto.
As Datas e os Números, Sem Filtro
A tabela abaixo separa o que já é norma exigível do que ainda é intenção declarada. Essa separação é o conteúdo principal deste artigo — mais importante que qualquer data isolada.
| Data | Ato | Órgão | Situação jurídica | Leitura |
|---|---|---|---|---|
| 24/03/2022 | RDC nº 657 — regularização de software como dispositivo médico | ANVISA | Vigente | → não cobre IA nem aprendizado de máquina |
| 2024–2025 | Revisão da RDC 657 entra na Agenda Regulatória como tema 11.8 | ANVISA | Não concluída | ↓ migrou sem conclusão |
| Ago/2025 | Guia final sobre Plano Predeterminado de Controle de Mudanças (PCCP) | FDA | Guia final | ↑ mecanismo já operante nos EUA |
| 11/02/2026 | Resolução CFM nº 2.454 — normatiza IA na medicina | CFM | Publicada 27/02/2026 | ↑ retificada em 05/03/2026 |
| 26/08/2026 | Fim dos 180 dias — resolução passa a ser exigível | CFM | Exigível | ⚠ esta semana |
| 18/08/2026 | Documento de discussão sobre IA generativa · docket FDA-2026-N-7874 | FDA | Consulta aberta | → não é norma |
| 19/10/2026 | Prazo final para enviar comentários à FDA | FDA | Aberto a qualquer pessoa | ↑ janela de influência |
| 2026–2027 | Revisão da RDC 657 · tema 5 dos dispositivos médicos | ANVISA | Em andamento · AIR pendente | → sem data de consulta pública definida |
💡 O que é PCCP, sem sopa de letrinhas
PCCP significa Predetermined Change Control Plan — Plano Predeterminado de Controle de Mudanças. É a resposta que os Estados Unidos deram ao problema do funcionário que continua estudando.
A ideia é simples e elegante: em vez de aprovar apenas o software como ele está hoje, o fabricante apresenta junto um plano do que ele pretende mudar, como vai testar cada mudança e qual desempenho mínimo precisa ser mantido. Se o regulador aprova o plano, as atualizações previstas nele podem ser feitas sem uma nova submissão a cada vez. O que sai do plano continua exigindo autorização nova.
Analogia do dia a dia: é a diferença entre pedir permissão para cada reforma da casa e ter uma planta aprovada que já prevê onde uma parede pode ser derrubada, com quais materiais e sob qual laudo. A liberdade é maior — mas ela é declarada antes, e não justificada depois.
O mecanismo foi criado por lei nos Estados Unidos em 2022 e ganhou guia final da FDA em agosto de 2025. O Brasil não tem equivalente.
⚠ A ressalva metodológica — o que eu afirmo e o que eu não afirmo
Várias análises publicadas no Brasil afirmam que a revisão da RDC 657 vai incorporar o conceito de PCCP. Eu li o documento oficial da ANVISA e ele não diz isso. O texto da agência fala em incorporar “itens referentes à inteligência artificial e à aprendizagem de máquinas” e em “harmonização com as regulamentações e práticas internacionais” — o que torna o PCCP uma hipótese razoável, já que ele é hoje a principal prática internacional para esse problema. Mas é hipótese de mercado, não texto normativo.
Faço essa distinção porque ela é o próprio método do artigo: a diferença entre o que uma agência escreveu e o que o setor espera que ela escreva não é detalhe de forma. É a diferença entre planejar com base em um fato e planejar com base em uma expectativa.
A Armadilha: o CFM Já Cobra o Que a ANVISA Ainda Não Verifica
Aqui está o achado que eu não vi ninguém escrever, e que só aparece quando se leem os dois documentos lado a lado, na íntegra.
A Resolução CFM 2.454 regula explicitamente a IA que muda. Não por acaso, não nas entrelinhas — de forma literal, em três pontos distintos:
No Anexo I, item IV, ao definir “ciclo de vida”, a resolução inclui expressamente “o treinamento, o retreinamento, os testes, a validação, a implantação, o monitoramento, as eventuais modificações ou adaptações de um sistema de IA”.
No artigo 9º, §1º, determina que a verificação de compatibilidade ética “deverá ocorrer em todas as fases do ciclo de vida — incluindo o design, o desenvolvimento, a fase de testes, a implantação, as atualizações e eventuais retreinamentos“.
No Anexo II, §1º, vai além e cria uma regra que quase ninguém comentou: uma solução classificada como de baixo risco deve ser revista periodicamente, e se “com o tempo ou mudanças” ela passar a apresentar impactos mais graves, sua reclassificação para médio ou alto risco deverá ser avaliada e procedida. É risco dinâmico, não etiqueta permanente.
Ou seja: o conselho profissional brasileiro tratou o problema do software que aprende com precisão notável — e, em alguns aspectos, antes da própria FDA fechar posição.
⚠ O vão, nomeado
O artigo 4º, inciso IV da resolução obriga o médico a utilizar apenas sistemas que atendam “às normas éticas, técnicas, legais e regulatórias vigentes no território nacional”. O artigo 3º, inciso III dá a ele o direito de recusar o que não tiver “certificação regulatória pertinente”.
Mas a norma sanitária que emite essa certificação no Brasil — a RDC 657/2022 — não contempla inteligência artificial nem aprendizado de máquina. Quem afirma isso é a própria ANVISA, na justificativa do tema 5 da sua Agenda Regulatória.
Isso produz uma situação concreta e desconfortável: um sistema de IA pode estar regularizado na ANVISA, e essa regularização não dizer nada sobre o comportamento atual do modelo depois de retreinado. O médico cumpre o artigo 4º ao verificar o registro. E ainda assim não sabe — porque a norma não pergunta — se o produto que ele está usando hoje é o mesmo que foi avaliado.
O CFM cobra vigilância sobre o ciclo de vida. A ANVISA ainda não tem instrumento para verificá-lo. E a responsabilidade final, por definição do artigo 7º, permanece integralmente com o médico.
Traduzindo para o chão do plantão
Você usa um sistema de apoio à decisão que está regularizado. O paciente evolui mal. Numa eventual sindicância, a pergunta do CRM não será “o software tinha registro?” — essa é fácil e você responde. A pergunta será a do artigo 4º, inciso II: você exerceu julgamento crítico sobre a recomendação, avaliando sua coerência com o quadro clínico? E a do inciso III: você se mantinha atualizado quanto às limitações e vieses conhecidos daquele sistema?
Para responder a essa segunda pergunta com honestidade, você precisaria saber quando o modelo foi retreinado pela última vez e o que mudou no desempenho. Hoje, no Brasil, não existe obrigação de que alguém te informe isso. Não porque a informação seja secreta, mas porque nenhuma norma a exige.
Versão dia a dia: é como ser responsabilizado por dirigir um carro cujo sistema de freios foi atualizado pela fábrica sem aviso — e depois te perguntarem por que você não sabia da mudança.
O Que a FDA Propôs — e Por Que Soa Familiar a Quem Forma Residente
O documento da FDA propõe, para avaliação antes da entrada no mercado, um caminho que a própria agência descreve como “baseado no conceito de aferição de competência, inspirado, em alto nível, na forma como médicos são treinados e avaliados”. Ele teria duas etapas: aferição não clínica do dispositivo em provas padronizadas, e confirmação clínica de que o sistema desempenha o que promete antes de chegar ao paciente.
Leia de novo. A proposta é avaliar uma inteligência artificial mais ou menos como se avalia um residente.
Não é metáfora de divulgação — é a arquitetura declarada da proposta. E ela faz um sentido profundo que vale desenrolar: a formação médica também lida com um agente que muda com o tempo. Ninguém avalia um residente uma única vez, no primeiro dia, e arquiva o resultado por seis anos. Avalia-se em etapas, por competências definidas, com reavaliação periódica e possibilidade de intervenção quando o desempenho cai.
É exatamente o desenho que falta para o software que aprende. E é um desenho que a medicina já domina há décadas — só nunca tinha sido pedido a ela que o emprestasse.
💡 Por que a analogia é boa e onde ela quebra
Onde funciona: avaliar por competência resolve o problema da fotografia. Você não certifica um estado, certifica uma capacidade de sustentar desempenho — e reavalia.
Onde quebra: um residente que erra sabe que errou, é confrontado por um preceptor e carrega esse aprendizado para o próximo caso. Um modelo estatístico não tem constrangimento nem memória do erro individual — ele só muda se alguém o retreinar. A competência humana se corrige por dentro; a do modelo, apenas por fora. Isso significa que a vigilância pós-mercado não é um complemento da avaliação inicial: é a parte principal.
Versão dia a dia: a diferença entre um funcionário que percebe sozinho que errou e um que só corrige quando alguém revisa o trabalho dele. Os dois podem ser bons. Mas o segundo exige um revisor permanente — e alguém precisa ser pago para ser esse revisor.
Um exemplo concreto: a consulta está aberta a qualquer pessoa
O texto da FDA é explícito quanto a quem pode se manifestar: fabricantes de dispositivos, médicos, consumidores, pesquisadores, o público e demais interessados. Não é necessário ser cidadão americano nem representar empresa. Basta enviar um comentário no docket FDA-2026-N-7874 até 19 de outubro.
A agência também diz que não é preciso responder a todas as perguntas do documento — cada um responde ao que domina. Um intensivista pediátrico que descreva, com dados de serviço, por que um modelo calibrado em adultos falha em lactentes está contribuindo exatamente com o que a agência pediu: conhecimento clínico específico que quem escreve a norma não tem.
É a diferença entre reclamar da regra depois de pronta e escrever uma linha dela.
A Solução Como Ato Clínico
Enquanto a norma sanitária não fecha o vão, ele não desaparece — ele é apenas absorvido por alguém. E esse alguém, por força do artigo 7º da resolução, é o médico.
Há, porém, uma leitura menos passiva disso. A Resolução CFM 2.454 não apenas cobra: ela também autoriza e organiza a defesa institucional. Três dispositivos são instrumentos concretos, e vale conhecê-los antes de precisar deles.
O artigo 4º, inciso V obriga o registro no prontuário do uso de IA como apoio à decisão. Isso costuma ser lido como burocracia. É proteção: cria o rastro documental que distingue “usou a ferramenta e julgou criticamente” de “seguiu a máquina”.
O artigo 14, parágrafo único exige, nas instituições que adotem sistemas próprios de IA, a criação de uma Comissão de IA e Telemedicina, sob coordenação médica e subordinada à diretoria técnica. Essa comissão é o lugar institucional onde a pergunta “quando esse modelo foi retreinado pela última vez?” passa a ter dono.
E o artigo 7º, §2º estabelece o dever de comunicar às instâncias competentes falhas e riscos relevantes. É o equivalente, para software, do que a notificação de evento adverso é para medicamento — e é o mecanismo pelo qual o problema deixa de ser individual e vira dado.
A Linha do Tempo
2022–2024 · A fase da fotografia
A RDC 657/2022 estabelece a regularização de software como dispositivo médico no Brasil, seguindo o padrão internacional da época: avaliar o produto no momento em que ele é submetido. Funciona bem para software que não muda — e a maior parte não mudava.
2025 · Os Estados Unidos fecham a primeira resposta
A FDA publica o guia final do PCCP em agosto de 2025, criando o mecanismo pelo qual mudanças previstas em um plano aprovado deixam de exigir nova submissão. A pergunta “e quando o modelo mudar?” ganha uma resposta operacional.
Agosto de 2026 · Onde você está agora
O CFM passa a exigir do médico, em 26/08, vigilância sobre todo o ciclo de vida da IA que ele usa. A FDA abre consulta pública sobre IA generativa em 18/08, com prazo até 19/10. A ANVISA mantém a revisão da norma de software “em andamento”, pelo segundo biênio consecutivo. O vão está aberto e a janela de influência, também.
Próximos 12–24 meses · A janela de harmonização
A FDA consolida os comentários e caminha para uma proposta. A ANVISA declara buscar “harmonização com as regulamentações e práticas internacionais” — o que significa, na prática, que o desenho discutido agora nos Estados Unidos tende a chegar aqui já formatado. Quem participou da discussão chega com repertório; quem não participou, recebe pronto.
Depois · A consolidação
Quando a nova RDC sair, a pergunta institucional deixa de ser “esse software tem registro?” e passa a ser “qual o plano de mudança aprovado e qual o desempenho mínimo garantido?”. Serviços que já tiverem instrumentado seus próprios dados de desempenho vão responder. Os demais vão descobrir que não sabem.
O Que Fazer na Segunda-Feira
Se você usa qualquer ferramenta de IA na assistência
- ☐ Faça uma lista honesta do que você já usa. Transcrição de evolução, sumarização de prontuário, apoio a decisão, triagem, leitura de imagem. A resolução se aplica a tudo isso, não só ao que tem cara de dispositivo médico.
- ☐ Para cada item da lista, pergunte ao fornecedor três coisas por escrito: qual a situação regulatória junto à ANVISA; quando o modelo foi retreinado pela última vez; e qual o desempenho medido no subgrupo de pacientes que você atende. A ausência de resposta é, ela própria, uma informação — e um documento.
- ☐ Comece a registrar no prontuário o uso de IA como apoio à decisão. É exigência do artigo 4º, inciso V, a partir de 26 de agosto. E é a sua principal proteção documental.
- ☐ Desconfie de desempenho apresentado como número único. Um valor global esconde subgrupos. Em pediatria isso não é detalhe: a criança pequena costuma ser o subgrupo minoritário que a média engole.
Se você coordena serviço, comissão ou diretoria técnica
- ☐ Verifique se a Comissão de IA e Telemedicina existe. É exigida pelo artigo 14, parágrafo único, para instituições que adotem sistemas próprios de IA. Se não existe, ela é o primeiro item da pauta desta semana, não do próximo semestre.
- ☐ Crie um inventário de sistemas com classificação de risco. Baixo, médio, alto — conforme o Anexo II. E marque a data da próxima revisão de cada um, porque a reclassificação periódica é obrigação, não boa prática opcional.
- ☐ Estabeleça quem responde pela pergunta do retreinamento. Enquanto ninguém tiver esse nome atribuído, a resposta institucional a uma sindicância será o silêncio.
- ☐ Instrumente o desempenho localmente antes de precisar dele. Uma planilha com desfecho previsto versus desfecho observado, atualizada mensalmente, custa quase nada e é o único dado que ninguém pode te fornecer de fora.
Se você quer influenciar a regra, e não só cumpri-la
- ☐ Envie um comentário ao docket FDA-2026-N-7874 até 19 de outubro. É aberto a médicos de qualquer país, não exige resposta a todas as perguntas e não requer representação institucional.
- ☐ Acompanhe o painel de temas prioritários da ANVISA. A agência publicou um painel de monitoramento da Agenda 2026-2027 com a previsão da etapa de consulta pública de cada proposta. É lá que a consulta sobre a RDC 657 será anunciada.
- ☐ Escreva a partir do seu subgrupo. A contribuição mais valiosa que um clínico pode dar a um regulador não é opinião sobre tecnologia — é evidência sobre onde os modelos falham na população que ele atende todo dia.
Entenda a Regra Antes de Ela Chegar Pronta
A metodologia AIMED forma médicos que constroem — não apenas consomem — ferramentas de IA clínica. Leitura crítica de desempenho por subgrupo, instrumentação de dados próprios do serviço, governança de ciclo de vida e a fronteira regulatória entre o que o CFM cobra e o que a ANVISA verifica fazem parte do currículo, porque são a mesma competência vista de ângulos diferentes.
Considerações Finais
A Resolução CFM 2.454 é uma norma melhor do que a discussão pública em torno dela sugere. Ela definiu ciclo de vida incluindo retreinamento, criou reclassificação dinâmica de risco, exigiu comissão institucional com coordenação médica e preservou a autonomia do médico para recusar e para desligar sistemas — inclusive vedando que instituições imponham metas que subordinem a conduta médica. Para uma primeira norma, é ambiciosa e bem construída.
O que ela não podia fazer, porque não é da sua competência, é criar o instrumento sanitário que verifica no produto aquilo que ela cobra do profissional. Esse instrumento é da ANVISA — e está na fila desde 2024.
Não escrevo isso como crítica à agência. Análise de Impacto Regulatório é trabalho lento por desenho, e ser lento é preferível a ser precipitado numa matéria dessas. Escrevo porque o intervalo entre uma norma ética exigível e uma norma sanitária ainda em elaboração não é um vazio: é um lugar onde alguém está de pé. E, a partir de 26 de agosto, esse alguém é o médico assistente.
💡 Connecting the Dots
Todo mundo vai comentar o prazo do CFM nesta semana. Alguns vão comentar a consulta da FDA. Quase ninguém vai notar que os dois documentos, lidos juntos, descrevem o mesmo objeto por metades diferentes — e que o Brasil ficou com a metade mais cara.
O CFM regulou o uso da IA que muda: exigiu vigilância de ciclo de vida, reclassificação periódica e responsabilidade profissional integral. A FDA está discutindo a verificação da IA que muda: como aferir competência antes e como monitorar depois. Uma norma cobra o comportamento; a outra constrói o instrumento. O Brasil tem a que cobra, em vigor nesta quarta-feira, e ainda não tem a que verifica.
A consequência prática é contraintuitiva e vale nomear: no arranjo brasileiro atual, o custo de auditar um modelo que aprende recai sobre quem tem menos acesso ao modelo. O fabricante conhece os pesos, os dados de treino e a data de cada retreino. O médico tem a tela e a responsabilidade. A assimetria de informação é máxima exatamente no ponto em que a responsabilidade jurídica é integral.
Isso desenha uma vantagem competitiva que quase ninguém no meio médico brasileiro está enxergando. O serviço que instrumentar hoje o próprio desempenho — desfecho previsto contra desfecho observado, estratificado por subgrupo, guardado com data — não estará apenas se protegendo. Estará produzindo a única evidência que a nova RDC vai acabar exigindo e que nenhum fornecedor pode entregar em seu lugar: a de como aquele modelo se comporta naquela população. Quando a norma chegar, ela vai pedir esse dado. Quem já o tiver responde; quem não, começa do zero com prazo correndo.
E há uma camada final, que é a mais interessante de todas. A FDA propôs avaliar inteligência artificial pelo método com que se avalia um médico em formação — competência aferida, confirmada na prática e reavaliada ao longo do tempo. Depois de vinte e cinco anos de UTI, a ironia é difícil de ignorar: a medicina passou décadas tentando aprender a medir competência humana com rigor, e o primeiro campo a adotar esse método com seriedade regulatória pode não ser a formação médica — pode ser o software. Se o método é bom o bastante para certificar uma máquina que decide sobre pacientes, a pergunta que fica de pé é por que ainda o aplicamos de forma tão irregular a quem decide de fato.
⚠ O que eu NÃO verifiquei
Não li o texto integral da RDC 657/2022. As afirmações sobre ela neste artigo se limitam ao que consta da justificativa oficial da própria ANVISA na Agenda Regulatória — em especial, que a norma precisa incorporar itens de inteligência artificial e aprendizado de máquina. Não descrevo dispositivos específicos da resolução.
Não li o PDF completo do documento de discussão da FDA (8,8 MB). As descrições da estrutura de risco em dois eixos, da avaliação por competência e do monitoramento pós-mercado vêm do resumo oficial da agência na página do documento e no comunicado à imprensa de 18/08/2026 — ambos fontes primárias, mas resumos.
Não confirmei se a revisão da RDC 657 incorporará PCCP. Como registrado na seção 3, isso é expectativa de setor, não texto oficial.
Não verifiquei quantos sistemas de IA estão hoje regularizados na ANVISA nem sob qual enquadramento. Seria o próximo dado a levantar, e ele mudaria a dimensão prática do problema descrito aqui.
Referências
- Conselho Federal de Medicina. Resolução CFM nº 2.454, de 11 de fevereiro de 2026 — Normatiza o uso da inteligência artificial na medicina. DOU 2026 fev 27; Ed. 39, Seção 1, p. 158. Retificação: DOU 2026 mar 5; Ed. 43, Seção 1, p. 91. (Art. 3º III; Art. 4º II, III, IV, V; Art. 7º; Art. 9º §1º; Art. 14 parágrafo único; Art. 23; Anexo I item IV; Anexo II §1º; Anexo III item VI) Disponível em: https://sistemas.cfm.org.br/normas/arquivos/resolucoes/BR/2026/2454_2026.pdf
- U.S. Food and Drug Administration. FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices. Comunicado à imprensa, 18 ago 2026. (docket FDA-2026-N-7874; prazo 19 out 2026) Disponível em: https://www.fda.gov/news-events/press-announcements/fda-seeks-public-feedback-inform-regulatory-approach-generative-ai-enabled-medical-devices
- U.S. Food and Drug Administration, Digital Health Center of Excellence. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback. CDRH, 18 ago 2026. Disponível em: https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request
- U.S. Food and Drug Administration. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. Guia final, ago 2025. Docket FDA-2022-D-2628. Disponível em: https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence
- Agência Nacional de Vigilância Sanitária. Agenda Regulatória 2026-2027 — Lista preliminar detalhada de temas: Produtos para a Saúde. Tema 5: Revisão da regularização de software como dispositivo médico (SaMD) — Revisão da RDC nº 657/2022. Origem: AR 24-25, tema 11.8. Situação: em andamento. Disponível em: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao/agenda-regulatoria/agenda-2026-2027/arquivos/lista_preliminar/produtos_para_saude_lista_preliminar_detalhada.pdf
- Agência Nacional de Vigilância Sanitária. Agenda Regulatória 2026-2027. Composta atualmente por 162 temas regulatórios. Disponível em: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao/agenda-regulatoria/2026-2027
- Agência Nacional de Vigilância Sanitária. Resolução da Diretoria Colegiada RDC nº 657, de 24 de março de 2022 — Dispõe sobre a regularização de software como dispositivo médico (SaMD). Disponível em: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao
Textos integrais das referências 1, 2, 3 e 5 consultados diretamente nas fontes oficiais em 22 de agosto de 2026. A referência 4 foi verificada na página oficial do guia no portal da FDA. A referência 7 é citada apenas quanto a número, data e objeto, conforme declarado na seção “O que eu NÃO verifiquei”.
The Software That Changes After Approval — and the Gap Between CFM and ANVISA That No One Has Named
On August 26, 2026, Brazil’s Federal Council of Medicine resolution comes into force, requiring physicians to use only AI systems holding appropriate regulatory certification — and to answer for what those systems do across their entire lifecycle, including after every retraining. The problem is that the Brazilian health-surveillance rule that issues that certification still treats software as a product that never changes. The revision that would fix this has been queued at ANVISA since 2024 and remains “in progress”. This article shows exactly where the gap sits, what it means at the bedside, and why the public consultation the FDA opened four days ago is the best chance a Brazilian physician has to shape the rule before it arrives fully written.
📅 Published on August 22, 2026
Navigate the Article
From a deadline falling this week to the regulatory problem that will define the next decade of clinical AI
- 1. Why This Matters at the Front Line
- 2. What Happened This Month — Two Moves, One Problem
- 3. The Dates and Numbers, Unfiltered
- 4. The Trap: CFM Already Requires What ANVISA Cannot Yet Verify
- 5. What the FDA Proposed — and Why It Sounds Familiar to Anyone Who Trains Residents
- 6. The Solution as a Clinical Act
- 7. The Timeline
- 8. What to Do on Monday
- 9. Closing Remarks
- 10. References
For readers outside the field — the essentials in 60 seconds
This article works on two levels: one for people who work in health or technology, another that requires nothing but curiosity. Every core idea appears twice — once with a hospital example, once with an everyday one.
Software as a medical device is a computer program that, on its own, does the work of a piece of medical equipment: it reads a scan, calculates a risk, suggests a course of action. You cannot hold it in your hand, but it is regulated as if you could — it needs health-authority clearance before it can be sold, just like a pacemaker or a ventilator.
A learning (or “adaptive”) model is a program that keeps changing after installation, because it is retuned with new data. In the hospital: a system that predicts clinical deterioration and is retuned every six months with that hospital’s own cases. In everyday life: the navigation app that changes the route it suggests as it learns traffic patterns — the version you use today does not decide the same way it did two years ago, even though the name and the icon are identical.
Why this breaks the current rule: approving a drug means approving a fixed formula. Today’s tablet is chemically identical to the one five years from now. A learning program is closer to a newly hired employee: you assess them at the interview, they pass, and then they keep studying — and changing. Today’s clearance is a photograph taken on the day of hiring. The question nobody has answered yet is who checks what that employee has become by year three.
The three actors in this text: CFM (Federal Council of Medicine) regulates physician conduct in Brazil. ANVISA regulates the product the physician uses. The FDA is the U.S. agency equivalent to ANVISA, and what it decides tends to become a global reference — including here.
Why This Matters at the Front Line
This Wednesday, August 26, 2026, the adaptation period for CFM Resolution No. 2,454/2026 ends. From that date it is no longer an announced rule: it is an enforceable one, supervised by the Regional Councils of Medicine.
Two of its provisions deserve careful reading by any physician using any AI tool — which today means almost everyone. Article 3, item III grants physicians the right to refuse systems lacking “adequate scientific validation” or “appropriate regulatory certification”. Article 4, item IV turns that into a duty: to use only systems that comply with the regulatory rules in force in national territory.
Read quickly, it looks like paperwork. Read slowly, it is something else: the resolution transfers to the physician the obligation to verify the regulatory standing of the tool being used. And that is where this article’s problem begins — because the standing that exists in Brazil today answers a different question from the one the resolution asks.
What Happened This Month — Two Moves, One Problem
Move 1 — the FDA opened a public consultation on generative AI in medical devices
On August 18, 2026 — four days ago — the FDA’s Digital Health Center of Excellence published a discussion paper titled Considerations for the Regulation of Generative AI-Enabled Medical Devices and opened docket FDA-2026-N-7874 on Regulations.gov, with comments due by October 19, 2026.
The document is explicit about what it is not: not a rule, not a draft rule, not a communication of regulatory expectations. It is a request for input, deliberately made before the agency has decided anything. In the official announcement, the director of the device center, Michelle Tarver, describes the process as one that may “serve as a potential model for regulators around the world”.
Three elements of its content matter here: a proposed two-axis risk framework; a proposed premarket evaluation built on competency assessment; and a proposed risk-proportionate postmarket monitoring — that is, watching the product after it is already in use, with intensity proportional to the harm it could cause. The paper also explicitly discusses foundation models and agentic AI systems.
Move 2 — ANVISA has the software rule revision queued, and it is not moving
ANVISA’s 2026-2027 Regulatory Agenda, approved by its Collegiate Board, lists 162 priority themes. Among the medical-device items, theme 5 is the “Revision of the regularization of software as a medical device (SaMD) — Revision of RDC No. 657/2022”.
The official justification is worth quoting, because it is blunt: “The current regulatory framework (RDC 657/2022) for Software as a Medical Device, despite being recently published, must be updated to keep pace with a market that grows and expands very rapidly. Items concerning artificial intelligence and machine learning must be incorporated into the RDC, in addition to harmonization with international regulations and practices.”
ANVISA itself therefore acknowledges, in writing, that the rule in force does not cover artificial intelligence or machine learning. This is not my reading nor outside criticism: it is in the agency’s own document.
And there is a data point almost no one extracts from that same document. The theme’s origin reference is “AR 24-25 — Theme 11.8”. In other words: this revision was already on the previous Regulatory Agenda, for the 2024-2025 biennium, and migrated to the current one without being completed. Its recorded status remains “In progress”, with the Regulatory Impact Assessment still pending.
A concrete example: the employee who kept studying
Hospital version: an early-warning system is registered with ANVISA in 2024, having demonstrated adequate performance on the validation dataset available at that time. In 2026, the vendor retunes the model with new data — sensitivity rises in adults and falls in infants, a subgroup too small to show up in the average. The figure that the clearance attests to is still the 2024 one. The product changed; the document authorizing it did not.
Everyday version: it is like hiring a driver, assessing their driving at the admission test, and filing the assessment away. Three years later they still carry the same badge — but they drive differently, because they have learned shortcuts, picked up habits and changed their routines. The badge does not lie about the past. It simply says nothing about the present.
And the present is exactly what CFM Resolution 2,454 demands of the physician, starting August 26.
The Dates and Numbers, Unfiltered
The table below separates what is already an enforceable rule from what is still a declared intention. That separation is the main content of this article — more important than any single date.
| Date | Instrument | Body | Legal status | Reading |
|---|---|---|---|---|
| 03/24/2022 | RDC No. 657 — regularization of software as a medical device | ANVISA | In force | → does not cover AI or machine learning |
| 2024–2025 | RDC 657 revision enters the Regulatory Agenda as theme 11.8 | ANVISA | Not completed | ↓ migrated unfinished |
| Aug/2025 | Final guidance on Predetermined Change Control Plan (PCCP) | FDA | Final guidance | ↑ mechanism already operating in the U.S. |
| 02/11/2026 | CFM Resolution No. 2,454 — regulates AI in medicine | CFM | Published 02/27/2026 | ↑ corrected 03/05/2026 |
| 08/26/2026 | End of the 180-day period — resolution becomes enforceable | CFM | Enforceable | ⚠ this week |
| 08/18/2026 | Generative AI discussion paper · docket FDA-2026-N-7874 | FDA | Consultation open | → not a rule |
| 10/19/2026 | Deadline to submit comments to the FDA | FDA | Open to anyone | ↑ window of influence |
| 2026–2027 | RDC 657 revision · theme 5 of medical devices | ANVISA | In progress · RIA pending | → no consultation date set |
💡 What a PCCP is, without the alphabet soup
PCCP stands for Predetermined Change Control Plan. It is the answer the United States gave to the problem of the employee who keeps studying.
The idea is simple and elegant: instead of approving only the software as it stands today, the manufacturer also submits a plan of what it intends to change, how each change will be tested, and what minimum performance must be maintained. If the regulator authorizes the plan, the updates it covers can be made without a new submission each time. Anything outside the plan still requires fresh authorization.
Everyday analogy: it is the difference between asking permission for every home renovation and holding an approved blueprint that already specifies which wall may come down, with which materials and under what inspection. The freedom is greater — but it is declared in advance, not justified afterwards.
The mechanism was created by U.S. law in 2022 and received final FDA guidance in August 2025. Brazil has no equivalent.
⚠ The methodological caveat — what I claim and what I do not
Several analyses published in Brazil state that the RDC 657 revision will incorporate the PCCP concept. I read ANVISA’s official document and it does not say that. The agency’s text speaks of incorporating “items concerning artificial intelligence and machine learning” and of “harmonization with international regulations and practices” — which makes PCCP a reasonable hypothesis, since it is currently the leading international practice for this problem. But it is a market expectation, not regulatory text.
I draw this distinction because it is the article’s own method: the difference between what an agency wrote and what the sector expects it to write is not a matter of form. It is the difference between planning on a fact and planning on an expectation.
The Trap: CFM Already Requires What ANVISA Cannot Yet Verify
Here is the finding I have not seen written anywhere, and which only emerges when both documents are read side by side, in full.
CFM Resolution 2,454 explicitly regulates AI that changes. Not incidentally, not between the lines — literally, in three distinct places:
In Annex I, item IV, defining “lifecycle”, the resolution expressly includes “training, retraining, testing, validation, deployment, monitoring, and any modifications or adaptations of an AI system”.
In Article 9, §1, it determines that ethical compatibility verification “must occur at every phase of the lifecycle — including design, development, the testing phase, deployment, updates and any retraining“.
In Annex II, §1, it goes further and creates a rule almost nobody has commented on: a solution classified as low risk must be periodically reviewed, and if “over time or through changes” it comes to present more serious impacts, its reclassification to medium or high risk must be assessed and carried out. Risk is dynamic, not a permanent label.
In other words: the Brazilian professional council addressed the learning-software problem with notable precision — and, in some respects, before the FDA itself settled its position.
⚠ The gap, named
Article 4, item IV of the resolution requires physicians to use only systems complying with “the ethical, technical, legal and regulatory rules in force in national territory”. Article 3, item III gives them the right to refuse anything lacking “appropriate regulatory certification”.
But the health-surveillance rule that issues that certification in Brazil — RDC 657/2022 — does not cover artificial intelligence or machine learning. That statement comes from ANVISA itself, in the justification for theme 5 of its Regulatory Agenda.
This produces a concrete and uncomfortable situation: an AI system may hold valid ANVISA clearance, and that clearance may say nothing about the model’s current behaviour after retraining. The physician complies with Article 4 by checking the registration. And still does not know — because the rule does not ask — whether the product in use today is the one that was evaluated.
CFM demands lifecycle vigilance. ANVISA has no instrument yet to verify it. And final responsibility, by definition of Article 7, remains entirely with the physician.
Translating to the bedside
You use a decision-support system that holds valid clearance. The patient deteriorates. In an eventual professional inquiry, the council’s question will not be “did the software have clearance?” — that one is easy and you can answer it. The question will be the one in Article 4, item II: did you exercise critical judgement over the recommendation, assessing its coherence with the clinical picture? And item III: were you keeping up to date with that system’s known limitations and biases?
To answer that second question honestly, you would need to know when the model was last retrained and what changed in its performance. Today, in Brazil, no one is obliged to tell you that. Not because the information is secret, but because no rule requires it.
Everyday version: it is like being held responsible for driving a car whose braking software was updated by the manufacturer without notice — and then being asked why you did not know about the change.
What the FDA Proposed — and Why It Sounds Familiar to Anyone Who Trains Residents
For premarket evaluation, the FDA paper proposes a path the agency itself describes as “built on the concept of competency assessment, inspired at a high level by how physicians are trained and evaluated”. It would have two stages: non-clinical benchmarking of the device against standardized tests, and clinical confirmation that the system performs as intended before reaching patients.
Read that again. The proposal is to assess an artificial intelligence roughly the way one assesses a resident.
This is not a communications metaphor — it is the declared architecture of the proposal. And it makes a deep kind of sense worth unpacking: medical training also deals with an agent that changes over time. Nobody assesses a resident once, on day one, and files the result away for six years. Assessment happens in stages, against defined competencies, with periodic re-evaluation and the option to intervene when performance drops.
That is exactly the design missing for learning software. And it is a design medicine has commanded for decades — it had simply never been asked to lend it out.
💡 Why the analogy works and where it breaks
Where it works: competency-based assessment solves the photograph problem. You are not certifying a state, you are certifying a capacity to sustain performance — and you re-assess.
Where it breaks: a resident who errs knows they erred, is confronted by an attending, and carries that learning into the next case. A statistical model feels no discomfort and holds no memory of the individual error — it changes only if someone retrains it. Human competency self-corrects from within; a model’s is corrected only from outside. Which means postmarket surveillance is not a complement to the initial assessment: it is the main part.
Everyday version: the difference between an employee who notices their own mistake and one who only corrects it when someone reviews their work. Both can be good. But the second requires a permanent reviewer — and someone has to be paid to be that reviewer.
A concrete example: the consultation is open to anyone
The FDA text is explicit about who may respond: device manufacturers, clinicians, consumers, researchers, the public and other interested parties. You need not be a U.S. citizen nor represent a company. It is enough to file a comment on docket FDA-2026-N-7874 by October 19.
The agency also states that respondents need not answer every question in the paper — each person addresses what they know. A pediatric intensivist who describes, with service-level data, why a model calibrated on adults fails in infants is contributing precisely what the agency asked for: specific clinical knowledge that whoever writes the rule does not have.
It is the difference between complaining about a rule once it is written and writing one of its lines.
The Solution as a Clinical Act
While the health-surveillance rule does not close the gap, the gap does not vanish — it is simply absorbed by someone. And that someone, by force of Article 7 of the resolution, is the physician.
There is, however, a less passive reading. CFM Resolution 2,454 does not only demand: it also authorizes and organizes institutional defence. Three provisions are concrete instruments, and they are worth knowing before you need them.
Article 4, item V requires recording the use of AI as decision support in the patient chart. This is usually read as bureaucracy. It is protection: it creates the documentary trail that distinguishes “used the tool and judged critically” from “followed the machine”.
Article 14, sole paragraph requires institutions that adopt their own AI systems to create an AI and Telemedicine Committee, under medical coordination and reporting to the technical directorate. That committee is the institutional place where the question “when was this model last retrained?” finally acquires an owner.
And Article 7, §2 establishes the duty to report relevant failures and risks to the competent bodies. For software, it is the equivalent of adverse-event reporting for drugs — and it is the mechanism by which a problem stops being individual and becomes data.
The Timeline
2022–2024 · The photograph phase
RDC 657/2022 establishes the regularization of software as a medical device in Brazil, following the international standard of its time: evaluate the product at the moment it is submitted. It works well for software that does not change — and most of it did not.
2025 · The United States closes the first answer
The FDA publishes its final PCCP guidance in August 2025, creating the mechanism by which changes foreseen in an approved plan no longer require a new submission. The question “and when the model changes?” gains an operational answer.
August 2026 · Where you are now
On August 26, CFM begins requiring physicians to exercise vigilance over the full lifecycle of the AI they use. On August 18, the FDA opened a public consultation on generative AI, running to October 19. ANVISA keeps the software-rule revision “in progress”, for a second consecutive biennium. The gap is open, and so is the window of influence.
Next 12–24 months · The harmonization window
The FDA consolidates comments and moves toward a proposal. ANVISA states that it seeks “harmonization with international regulations and practices” — which means, in practice, that the design being discussed in the United States now will tend to arrive here already formatted. Those who took part in the discussion arrive with fluency; those who did not, receive it finished.
Afterwards · Consolidation
When the new RDC is issued, the institutional question stops being “does this software have clearance?” and becomes “what is the approved change plan and what minimum performance is guaranteed?”. Services that have already instrumented their own performance data will answer. The rest will discover they do not know.
What to Do on Monday
If you use any AI tool in patient care
- ☐ Make an honest list of what you already use. Note transcription, chart summarization, decision support, triage, image reading. The resolution applies to all of it, not only to what looks like a medical device.
- ☐ For each item, ask the vendor three things in writing: its regulatory standing with ANVISA; when the model was last retrained; and the measured performance in the patient subgroup you treat. A non-answer is itself information — and a document.
- ☐ Start recording AI use as decision support in the chart. It is required by Article 4, item V, from August 26. And it is your main documentary protection.
- ☐ Distrust performance presented as a single number. A global figure hides subgroups. In pediatrics this is no detail: the small child is usually the minority subgroup the average swallows.
If you lead a service, committee or technical directorate
- ☐ Check whether the AI and Telemedicine Committee exists. It is required by Article 14, sole paragraph, for institutions adopting their own AI systems. If it does not exist, it is this week’s first agenda item, not next semester’s.
- ☐ Build an inventory of systems with risk classification. Low, medium, high — per Annex II. And record each one’s next review date, because periodic reclassification is an obligation, not an optional good practice.
- ☐ Assign who owns the retraining question. Until that name exists, the institutional answer to an inquiry will be silence.
- ☐ Instrument performance locally before you need it. A spreadsheet of predicted versus observed outcome, updated monthly, costs almost nothing and is the one dataset nobody can supply you from outside.
If you want to shape the rule, not merely comply with it
- ☐ File a comment on docket FDA-2026-N-7874 by October 19. It is open to physicians of any country, does not require answering every question, and does not require institutional representation.
- ☐ Follow ANVISA’s priority-themes dashboard. The agency published a monitoring panel for the 2026-2027 Agenda with the expected public-consultation stage for each proposal. That is where the RDC 657 consultation will be announced.
- ☐ Write from your own subgroup. The most valuable contribution a clinician can make to a regulator is not an opinion about technology — it is evidence about where models fail in the population they see every day.
Understand the Rule Before It Arrives Fully Written
The AIMED methodology trains physicians who build — not merely consume — clinical AI tools. Critical reading of subgroup performance, instrumentation of a service’s own data, lifecycle governance and the regulatory boundary between what CFM demands and what ANVISA verifies are all part of the curriculum, because they are the same competency seen from different angles.
Closing Remarks
CFM Resolution 2,454 is a better rule than the public discussion around it suggests. It defined lifecycle to include retraining, created dynamic risk reclassification, required an institutional committee under medical coordination, and preserved the physician’s autonomy to refuse and to switch off systems — including by barring institutions from imposing targets that subordinate clinical conduct. For a first rule, it is ambitious and well built.
What it could not do, because it falls outside its remit, is create the health-surveillance instrument that verifies in the product what it demands of the professional. That instrument belongs to ANVISA — and it has been queued since 2024.
I do not write this as criticism of the agency. Regulatory Impact Assessment is slow work by design, and slow is preferable to hasty on a matter like this. I write it because the interval between an enforceable ethical rule and a health rule still under construction is not a void: it is a place where someone is standing. And from August 26, that someone is the attending physician.
💡 Connecting the Dots
Everyone will comment on the CFM deadline this week. Some will comment on the FDA consultation. Almost no one will notice that the two documents, read together, describe the same object in different halves — and that Brazil ended up with the more expensive half.
CFM regulated the use of AI that changes: it required lifecycle vigilance, periodic reclassification and full professional responsibility. The FDA is debating the verification of AI that changes: how to assess competency beforehand and how to monitor afterwards. One rule demands the behaviour; the other builds the instrument. Brazil has the one that demands, in force this Wednesday, and does not yet have the one that verifies.
The practical consequence is counterintuitive and worth naming: under the current Brazilian arrangement, the cost of auditing a learning model falls on whoever has the least access to the model. The manufacturer knows the weights, the training data and the date of every retrain. The physician has the screen and the liability. Information asymmetry is at its maximum precisely where legal responsibility is total.
That draws a competitive advantage almost no one in Brazilian medicine is seeing. The service that instruments its own performance today — predicted versus observed outcome, stratified by subgroup, stored with dates — will not merely be protecting itself. It will be producing the one piece of evidence the new RDC will eventually demand and that no vendor can supply on its behalf: how that model behaves in that population. When the rule arrives, it will ask for that data. Those who already hold it will answer; those who do not will start from zero with the clock running.
And there is a final layer, the most interesting of all. The FDA proposed assessing artificial intelligence by the method used to assess a doctor in training — competency measured, confirmed in practice and re-evaluated over time. After twenty-five years in intensive care, the irony is hard to ignore: medicine spent decades trying to learn how to measure human competency rigorously, and the first field to adopt that method with regulatory seriousness may not be medical education — it may be software. If the method is good enough to certify a machine that decides about patients, the question left standing is why we still apply it so unevenly to those who actually decide.
⚠ What I did NOT verify
I did not read the full text of RDC 657/2022. Statements about it in this article are limited to what appears in ANVISA’s own official justification in the Regulatory Agenda — specifically, that the rule needs to incorporate artificial intelligence and machine learning items. I describe no specific provisions of the resolution.
I did not read the complete PDF of the FDA discussion paper (8.8 MB). The descriptions of the two-axis risk framework, competency-based assessment and postmarket monitoring come from the agency’s official summary on the document page and from the August 18, 2026 press release — both primary sources, but summaries.
I did not confirm that the RDC 657 revision will incorporate PCCP. As recorded in section 3, this is a sector expectation, not official text.
I did not verify how many AI systems currently hold ANVISA clearance nor under which classification. That would be the next data point to gather, and it would change the practical scale of the problem described here.
References
- Conselho Federal de Medicina. Resolution CFM No. 2,454 of February 11, 2026 — Regulating the use of artificial intelligence in medicine. Official Gazette of Brazil, February 27, 2026; Ed. 39, Section 1, p. 158. Correction: Official Gazette, March 5, 2026; Ed. 43, Section 1, p. 91. (Art. 3 III; Art. 4 II, III, IV, V; Art. 7; Art. 9 §1; Art. 14 sole paragraph; Art. 23; Annex I item IV; Annex II §1; Annex III item VI) Available at: https://sistemas.cfm.org.br/normas/arquivos/resolucoes/BR/2026/2454_2026.pdf
- U.S. Food and Drug Administration. FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices. Press release, August 18, 2026. (docket FDA-2026-N-7874; deadline October 19, 2026) Available at: https://www.fda.gov/news-events/press-announcements/fda-seeks-public-feedback-inform-regulatory-approach-generative-ai-enabled-medical-devices
- U.S. Food and Drug Administration, Digital Health Center of Excellence. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback. CDRH, August 18, 2026. Available at: https://www.fda.gov/medical-devices/digital-health-center-excellence/considerations-regulation-generative-ai-enabled-medical-devices-discussion-paper-and-request
- U.S. Food and Drug Administration. Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. Final guidance, August 2025. Docket FDA-2022-D-2628. Available at: https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence
- Agência Nacional de Vigilância Sanitária. Regulatory Agenda 2026-2027 — Detailed preliminary list of themes: Health Products. Theme 5: Revision of the regularization of software as a medical device (SaMD) — Revision of RDC No. 657/2022. Origin: AR 24-25, theme 11.8. Status: in progress. Available at: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao/agenda-regulatoria/agenda-2026-2027/arquivos/lista_preliminar/produtos_para_saude_lista_preliminar_detalhada.pdf
- Agência Nacional de Vigilância Sanitária. Regulatory Agenda 2026-2027. Currently comprising 162 regulatory themes. Available at: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao/agenda-regulatoria/2026-2027
- Agência Nacional de Vigilância Sanitária. Collegiate Board Resolution RDC No. 657 of March 24, 2022 — On the regularization of software as a medical device (SaMD). Available at: https://www.gov.br/anvisa/pt-br/assuntos/regulamentacao
Full texts of references 1, 2, 3 and 5 consulted directly at official sources on August 22, 2026. Reference 4 was verified on the official guidance page of the FDA portal. Reference 7 is cited only as to number, date and subject matter, as declared in the “What I did NOT verify” section.
◆ Novidades
- Memória Inteligente: o que a ciência da aprendizagem realmente sustenta
- Metade do Tempo, Melhor Desempenho — e o Efeito Grande Demais Para Ser Verdade
- Hospital cheio, margem caindo: por que o gargalo não é o diagnóstico

