How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Healthcare AI Compliance

    Off-Label Use of Clinical AI and Its Compliance Risks

    Off-label use of clinical AI occurs when a diagnostic algorithm, clinical decision support tool, or other AI-enabled Software as a Medical Device is applied outside the specific indication, patient population, or clinical context described in its FDA clearance or vendor-authorized labeling. Because clinicians can legally use cleared devices off-label under practice-of-medicine principles, this use is rarely restricted by FDA directly. The resulting compliance exposure falls to the health system, and depends on internal governance, permissioning, and audit logging to detect when AI outputs are relied upon beyond their validated scope.

    What Constitutes Off-Label Use of Clinical AI

    Off-label use applies when an AI-enabled SaMD is ordered, invoked, or relied upon outside the indication, population, or clinical context in its FDA clearance or vendor-authorized labeling. The model may still produce an output for inputs outside that scope. Clearance defines authorized intended use; technical capability alone does not expand it.

    Under practice-of-medicine principles, licensed clinicians may use legally marketed devices outside labeled indications. FDA focuses manufacturer promotion of unapproved uses, not clinician use itself. Organizational exposure therefore comes from quality, malpractice, and governance obligations rather than direct FDA enforcement against the health system for off-label clinical use.

    How Off-Label Use Develops Inside Clinical Workflows

    Off-label use of clinical AI rarely results from a single deliberate decision. It typically emerges from the gap between what a model is technically capable of producing and what its clearance actually authorizes.

    1. Capability exceeds cleared scope

      A diagnostic algorithm cleared for a specific imaging modality, patient age range, or disease stage may still return an output for any input it receives, whether or not that input falls within the cleared population. Once the tool is embedded in an EHR workflow, nothing in the underlying integration necessarily prevents a clinician from ordering it, or the system from routing a case to it, outside that population.

    2. Model updates shift practical behavior

      This gap widens as models are updated. FDA’s Predetermined Change Control Plan guidance, finalized in December 2024, allows manufacturers to pre-specify categories of future model modifications without a new marketing submission, provided the changes stay within the currently authorized intended use. Health systems that do not maintain their own version-to-indication mapping have no way to confirm that a model update did not shift the tool’s practical behavior relative to what clinicians assume it still does.

    3. Missing inference-level context

      Combined with the absence of inference-level logging that captures clinical context and indication at the time of use, many organizations cannot reconstruct after the fact whether an AI-assisted decision stayed within labeled scope.

    Where Off-Label Clinical AI Risk Originates

    Four structural factors explain why off-label exposure accumulates even when individual clinicians act in good faith.

    Labeled vs. off-label use

    FDA clearance defines a specific indication and population; use outside that scope is off-label.

    Regulatory basis

    SaMD framework, PCCP guidance, and the Cures Act CDS exemption set the boundaries of authorized intended use.

    Governance gap

    IT access controls govern system access, not whether a specific AI invocation matches its cleared indication.

    Runtime controls

    Permission scoping and audit logging at the point of tool invocation are needed to detect and prevent drift.

    Regulatory Guidance Shaping Compliance Expectations

    Several frameworks define when clinical AI is a regulated device, what its intended use covers, and how post-market changes may proceed.

    FDA off-label device principles

    FDA guidance on off-label use of marketed devices permits licensed practitioners to use a legally marketed device outside its labeled indication as part of medical practice. FDA restricts manufacturer promotion of unapproved uses, not clinician use itself. No specific mechanism for tracking off-label clinical AI use by health systems appears in current FDA guidance. FDA maintains a public list of AI-enabled devices with their cleared indications, but confirming that actual use matches that indication is the deploying organization’s responsibility.

    Predetermined Change Control Plans

    A PCCP lets manufacturers pre-specify certain future model changes without a new FDA submission, provided those changes stay within the currently authorized intended use. If a health system does not map model versions to indications internally, a permitted update can still shift practical model behavior, increasing the risk of unintentional off-label reliance.

    Clinical decision support and the Cures Act

    Not all clinical decision support tools are regulated as medical devices. Under the 21st Century Cures Act, some CDS software functions are excluded from FDA device regulation if they meet specific criteria, including allowing clinicians to independently review the basis for a recommendation. Tools that do not meet these criteria are regulated as devices with a defined intended use, making off-label use a relevant risk for that subset.

    Compliance posture depends less on blocking clinician judgment and more on knowing, at runtime, which tool ran, under which clearance, for which patient context, and under which model version.

    Governance Controls Health Systems Should Require

    Closing off-label exposure requires controls that tie each AI invocation to cleared indication and retain enough context for later review.

    • Map each deployed AI tool call to its specific FDA-cleared indication and intended-use population before workflow integration.
    • Restrict AI tool invocation through permission scoping tied to approved clinical context, such as specialty, patient cohort, or order type.
    • Capture indication-relevant metadata, including patient context, ordering clinician, and model version, in audit logs at the time of each AI-assisted decision.
    • Align AI governance committees with current FDA labeling documentation to detect drift between observed usage and approved indications.
    • Validate vendor PCCP-defined change boundaries against the currently authorized intended use before deploying any model update.

    Vendor and Platform Diligence Questions

    Use the following questions when evaluating clinical AI vendors and integration platforms for off-label risk management.

    • Does the vendor provide documented, current FDA clearance or authorization scope, including classification, indications, and intended use population, for each AI tool?
    • Can the platform support runtime permissioning that restricts AI tool invocation to clinical contexts matching its cleared indication?
    • What audit logging is available to reconstruct the clinical context of any AI-assisted decision and confirm it stayed within the labeled indication?
    • How does the vendor manage model updates under a Predetermined Change Control Plan, and how are changes communicated to prevent inadvertent off-label drift?
    • Does the vendor’s documentation meet ONC HTI-1 source-attribute requirements for predictive decision support interventions?

    Frequently Asked Questions

    Is off-label use of clinical AI illegal?

    Not inherently. FDA guidance on off-label use of marketed devices permits licensed practitioners to use a legally marketed device outside its labeled indication as part of medical practice. FDA restricts manufacturer promotion of unapproved uses, not clinician use itself. Organizational exposure comes from quality, malpractice, and governance obligations rather than direct FDA enforcement against the health system.

    Does the FDA track off-label use of AI-enabled devices?

    No specific mechanism for tracking off-label clinical AI use by health systems appears in current FDA guidance. FDA maintains a public list of AI-enabled devices with their cleared indications, but confirming that actual use matches that indication is the deploying organization’s responsibility, not something FDA monitors in real time.

    How does a Predetermined Change Control Plan affect off-label risk?

    A PCCP lets manufacturers pre-specify certain future model changes without a new FDA submission, provided those changes stay within the currently authorized intended use. If a health system does not map model versions to indications internally, a permitted update can still shift practical model behavior, increasing the risk of unintentional off-label reliance.

    Are all clinical decision support tools regulated as medical devices?

    No. Under the 21st Century Cures Act, some CDS software functions are excluded from FDA device regulation if they meet specific criteria, including allowing clinicians to independently review the basis for a recommendation. Tools that do not meet these criteria are regulated as devices with a defined intended use, making off-label use a relevant risk for that subset.

    Assess Off-Label Exposure in Your Clinical AI Deployments

    Understanding where AI tool use may fall outside its cleared indication starts with visibility into how each tool is invoked and by whom. Runtime governance controls can help compliance and IT teams close that visibility gap.

    Explore Runtime Governance