In the span of a few years, artificial intelligence has moved from the margins of medicine to the center of clinical decision-making in nearly every American hospital — yet the federal government is now proposing to dismantle the only standardized transparency rules that gave institutions a common language for understanding what these tools are and how they behave. The proposed HTI-5 rule, emerging from a broader deregulatory impulse, would remove source-attribute disclosures and risk management requirements at the precise moment when hallucination rates in clinical AI remain measurable in the
FDA's Clinical AI Rollback Leaves Hospitals Without Transparency Standards
Clinical AI may fail quietly, over months, as populations shift
Why does it matter whether hospitals have a standardized disclosure form for AI tools? Can't they just ask the vendor what they need to know?
Because hospitals don't have the expertise to know what to ask, and vendors have no incentive to volunteer information that might make their product look risky. A standardized form creates a common language—it forces everyone to disclose the same things in the same way, so a procurement officer can actually compare two different tools.
But the FDA already clears these devices. Isn't that enough?
The FDA clears them once, at the beginning. It doesn't monitor what happens after they're deployed. A tool that works perfectly in a trial with one population might start making mistakes when it's used on a different population. The transparency requirement forced developers to publish an update schedule—to say when they'd check for that kind of drift. Without it, nobody's watching.
The government says this is about reducing paperwork burden. Is that not a real concern?
It's real, but it's being applied to the wrong problem. The paperwork burden isn't on clinicians—they don't see these disclosures. It's on developers. And the cost of compliance is tiny compared to the cost of deploying an AI tool that starts hallucinating in ways nobody catches.
What happens to the hospitals now?
They have to build their own audit process for every tool they buy. That's expensive and inconsistent. Some hospitals will do it well. Others won't have the resources. And the fastest-growing category of AI—generative tools—isn't even regulated by the FDA, so there's no floor at all.
Is there a middle ground?
Yes. Keep the disclosure requirement but make it machine-readable and continuous. Let hospital committees check in on the tool's performance over time, not just once at purchase. That puts the burden on the developer, where it belongs, and gives hospitals a way to actually oversee what they're using.
Der Puls
- Over 1,450 AI medical devices have been authorized for clinical use, yet fewer than 2% were tested in randomized trials and language models used in care settings generate false information at rates as high as 20%.
- The proposed HTI-5 rule would strip away the 31 standardized source-attribute disclosures and lifecycle risk management requirements that formed the only federal analog to an AI model-card mandate.
- Regulators have misread the purpose of these rules — they were never bedside paperwork for clinicians, but procurement tools for hospital administrators trying to compare, audit, and govern the algorithms entering their workflows.
- Two regulatory gaps are widening simultaneously: the FDA lacks robust post-market surveillance for cleared devices, and the fastest-growing category of clinical AI — generative tools — falls entirely outside FDA jurisdiction.
- A viable alternative exists: making source attributes machine-readable, versioned, and API-accessible would transform disclosure from a one-time event into continuous infrastructure for oversight across hospitals, payers, and accreditors.
- Without intervention, the rollback leaves a post-market accountability void precisely when clinical AI is most embedded, most opaque, and most capable of failing slowly and silently as patient populations shift.
In the span of a few years, artificial intelligence has moved from the margins of medicine to the center of clinical decision-making in nearly every American hospital — yet the federal government is now proposing to dismantle the only standardized transparency rules that gave institutions a common language for understanding what these tools are and how they behave. The proposed HTI-5 rule, emerging from a broader deregulatory impulse, would remove source-attribute disclosures and risk management requirements at the precise moment when hallucination rates in clinical AI remain measurable in the double digits and post-market accountability remains largely unbuilt. What is being framed as a reduction in burden is, in the longer view, a transfer of risk — from developers who control the models to hospitals, patients, and the quiet spaces where algorithmic drift goes unnoticed.
By the end of 2025, the FDA had cleared more than 1,450 AI-enabled medical devices, with 295 authorized in that year alone. Two-thirds of American clinicians now use AI in daily practice, and the systems they rely on reach 96 percent of U.S. hospitals. Yet fewer than 2 percent of those cleared devices were backed by randomized clinical trials, and large language models deployed in clinical settings hallucinate — producing plausible but false outputs — at rates between 8 and 20 percent. Into this landscape, the Department of Health and Human Services introduced HTI-5 in January 2026, a proposed rule that would eliminate the only federal transparency requirements governing how these tools are built and maintained.
Those requirements, finalized in late 2023, obligated developers of AI tools in certified electronic health records to disclose 31 standardized source attributes — covering training data, fairness testing, performance metrics, and maintenance schedules — and to conduct structured intervention risk management across each tool's lifecycle. Modest as they were, these provisions represented the closest the United States had come to a model-card mandate: a standardized label that hospital procurement officers and compliance teams could use to compare vendors and meet their own governance obligations. HTI-5 would remove all of it, citing lack of demonstrated clinical utility and alignment with the administration's deregulatory agenda.
The justification misreads the rules' purpose. The source-attribute regime was never designed for clinicians at the bedside; it was designed for institutional buyers. Removing it does not reduce burden — it relocates it, forcing every hospital to construct its own diligence process for every algorithm in every workflow, without a common floor.
The rollback also arrives as two other gaps widen. The FDA's post-market surveillance for cleared AI devices remains preliminary, and the source-attribute disclosures had been quietly filling part of that void by requiring published validation and update schedules. Simultaneously, the fastest-growing category of clinical AI — generative tools built on foundation models — frequently falls outside FDA jurisdiction entirely. The transparency framework had been deliberately drafted to cover both regulated and non-device tools; eliminating it leaves that entire category in a regulatory blind spot.
A more defensible path would preserve the source attributes and evolve them into continuous monitoring infrastructure: machine-readable, versioned, and accessible through standard APIs so that hospitals, payers, and accreditors could verify them in real time. The nine core disclosure categories align directly with NIST's AI risk management framework and with the post-deployment questions the FDA itself is beginning to ask. Treating AI governance as ongoing infrastructure — rather than a one-time clearance event — would place compliance costs on the developers who control the models and give the broader health system a shared substrate for oversight. Three years of deployment have made one thing clear: clinical AI does not always fail at the moment of authorization. It can fail quietly, over months, as populations shift and models drift.
By the end of 2025, the FDA had cleared more than 1,450 artificial intelligence-enabled medical devices. In that same year alone, 295 new AI tools received authorization. Two-thirds of American clinicians now incorporate AI into their daily work. Yet the federal government is preparing to weaken the only transparency rules that govern how these tools are built, tested, and maintained inside the hospital systems that serve 96 percent of U.S. hospitals.
The numbers tell a story of rapid deployment without adequate safeguards. Fewer than 2 percent of those 1,450 cleared devices were supported by randomized clinical trials—the gold standard for medical evidence. Studies of large language models used to support clinical decisions show hallucination rates between 8 and 20 percent, meaning the systems generate plausible-sounding but false information at measurable rates. Against this backdrop, the Department of Health and Human Services released a proposed rule in January 2026 called HTI-5, which would eliminate the transparency requirements that were meant to keep pace with deployment.
Those requirements, finalized in late 2023, were modest but meaningful. They obligated developers of AI tools in certified electronic health records to disclose 31 standardized source attributes—categories describing how each tool was built, what data trained it, how it was tested for fairness, what its performance metrics were, and how it would be maintained over time. Developers also had to conduct intervention risk management, a structured process for identifying and mitigating potential harms across the tool's entire lifecycle. Together, these provisions represented the closest the United States had come to a model-card mandate, the kind of standardized "nutrition label" that would tell hospital administrators what they were buying.
HTI-5 would remove all of it. The agency justifies the rollback by arguing that the transparency requirements lack demonstrated clinical utility and that they conflict with the White House's broader push to deregulate AI. Some industry observers see relief in the change—fewer barriers to development and deployment. But the rollback rests on a fundamental misreading of what those transparency rules were designed to do. Regulators treated them as paperwork burdens imposed on clinicians at the bedside. In reality, the source-attribute regime was built for institutional buyers: hospital procurement officers, compliance leads, and quality committees who needed a standardized floor to compare vendors, audit deployed models, and meet their own governance obligations. Removing that floor does not eliminate burden; it shifts it onto the hospital, which must now construct its own diligence process for every algorithm in every workflow.
This shift arrives at a moment when two other regulatory gaps are widening. First, the FDA's own oversight, though broad in scope, was never designed to monitor how AI tools perform after they enter the market. A 2025 analysis of cleared devices found that most of the public evidence manufacturers file to obtain FDA clearance lacks basic details on study design, sample sizes, and whether the research included diverse populations. The FDA has acknowledged this gap and begun asking questions about real-world performance measurement and model drift—the phenomenon where an AI tool's accuracy degrades as patient populations change. But that work remains preliminary. In the interim, the source-attribute disclosure regime forced developers to publish validation and update schedules, filling part of the post-market accountability void. Removing it leaves that void exposed.
Second, much of the clinical AI now entering hospital workflows is not regulated by the FDA at all. Internally developed models, non-device clinical decision support tools, and generative AI assistants frequently fall outside the agency's jurisdiction. The transparency criterion was deliberately drafted to cover both FDA-regulated software and non-device predictive tools supplied through certified health IT systems. Eliminating that umbrella means that the fastest-growing category of clinical AI—generative tools built on foundation models—operates in a regulatory blind spot at the exact moment when hallucination rates remain measurable in the double digits.
A more defensible path would preserve the source-attribute disclosures and reframe them as one layer of continuous monitoring. The nine disclosure categories that were codified—purpose, development inputs, fairness process, external validation, performance measures, ongoing maintenance, update schedule, cautioned out-of-scope use, and intervention details—align cleanly with the AI risk management framework published by the National Institute of Standards and Technology and with the post-deployment surveillance questions the FDA itself is now asking. Rather than retiring the model card, regulators could require that those attributes be machine-readable, versioned, and exposed through a standard application programming interface. Hospital governance committees, payers, and accreditors could then verify them continuously. That approach treats AI governance as infrastructure rather than as a one-time disclosure event. It places the marginal cost of compliance on the developer who controls the model, and it gives the rest of the health care system a common substrate for oversight. It also acknowledges what three years of deployment have demonstrated: clinical AI may not fail at the moment of regulatory clearance, but it may fail quietly, over months, as populations shift and models drift.
Bemerkenswerte Zitate
Removing that floor does not relieve a burden; it shifts the burden onto the buyer, who now must construct bespoke diligence processes for every algorithm in every workflow.— Analysis in The Regulatory Review
Clinical AI may not fail at the moment of regulatory clearance, but it may fail quietly, over months, as populations shift and models drift.— Analysis in The Regulatory Review