I have had type 1 diabetes for more than 30 years, which I manage using a glucose monitor connected to an insulin pump. About every five years, I would get upgraded pumps and sensors that were approved by the Food and Drug Administration and covered by my insurance. Still, my glucose control slowly deteriorated.
One day, my physician encouraged me to explore new, open-source software that better manages the sensor and pump system. This new code — written by people who were dissatisfied with the existing, FDA-regulated app — is a revelation. It fine-tunes my insulin delivery in a manner no FDA-approved systems could. I am now meeting guidelines that had previously eluded me, and I’m feeling great. All of this is free and runs on my iPhone.
But I am also a health economist, and I know using this software is a gamble. This technology has been developed outside FDA’s oversight. The agency generally regulates medical software as a device, which helps ensure it works as intended and is free from dangerous bugs. But that also makes the process expensive and slow. The FDA reviewers are like Ethel and Lucy at the candy factory, outmatched by the speed of the product line. The pace of software updates is now so rapid that it is turning regulators into impediments to innovation.
I recently asked a colleague, Lowell Schiller, a former head of policy at the FDA, what could be done. He noted that the FDA has made substantial efforts to modernize its frameworks. For example, it has exempted certain lower-risk applications and developed programs to expand the scope of software updates that do not require new regulatory review.
But there are limits to what the agency can do while operating under a 50-year-old statute that was designed for traditional devices, not modern software development.
The FDA needs help from Congress. One approach would build on a pilot program, launched during the first Trump administration, that aimed to streamline or even eliminate software reviews by pre-certifying software developers’ processes. Do they have the right controls in place and follow good development practices, with appropriate quality systems and performance monitoring? An arbiter at the agency could review these questions and certify the process, giving the developer latitude within that approved framework. Safety would come first, but such a regulatory pathway would allow software innovation to be more accessible, and to reach the market more quickly.
But the software pre-certification pilot program could not be fully implemented within the FDA’s existing statutory authorities. Congress has an opportunity to make the program feasible: Next year, it will be tasked with reauthorizing the FDA’s next five-year user fee cycle, which could be a great opportunity to modernize the device framework for software and generative AI.
The FDA is currently negotiating with industry groups to set performance goals in exchange for fees that fund approximately half of the agency’s human medical product budget. The agreements submitted to Congress for debate next January could contain statutory reforms that would enable more effective review of medical software — including open-source software.
If no action is taken, it will be no surprise that patients like me will increasingly turn to homegrown codes. This bifurcated software environment is unfair not only to patients but also to medical device manufacturers, who are subject to regulations and review timelines that prevent them from innovating at the same pace and scale.
We have reached the point where it is no longer possible to ask the FDA to keep pace with software development by doing the same reviews faster, or with more people. In a world of machine learning and generative AI, the FDA needs the tools to adapt so that it can do more within the scope of a single review or assessment, and to apply more effective oversight on the post-market side.
For me and others like me, regulatory change would be welcome. Without it, we are reduced to scouring the corners of the internet for the best solutions. For those with diabetes, that often means going open source and assuming some unknown risks. That’s not where our regulatory system should be pushing patients.
Dana Goldman is founding director of the USC Schaeffer Institute for Public Policy and Government Service.
