What stands out in the FDA's draft guidance is the timing. Sponsors have to show how they assessed a model's fitness for its specific use before they used it, and that record is hard to produce after the fact without it reading like a reconstruction. The exposure sits in the quiet tools, the risk-based monitoring and data quality flagging that teams adopted fast because they felt like helpers rather than decision makers. In the governance committees I've run, those were exactly the tools nobody had inventoried. With an April warning letter already citing AI misuse, can you list every model that touched your submission data?
The Clinical Trial Vanguard reports that FDA's risk-based AI guidance shifts the validation burden to sponsors. I'd argue that burden was always theirs, and the guidance just removes the illusion that a regulator or a vendor would carry it. Risk-based sounds lighter until you realize someone has to decide what counts as high risk and then defend that call later. In every governance committee I've sat on, that classification step is where programs stall. Sponsors who already run evals and keep a clean model inventory will barely notice. The ones relying on vendor assurances are about to learn what they actually own. Who signs your risk tiering today?
PwC's survey says business and tech leaders can't agree on who owns AI risk, and honestly that matches a lot of governance committees I've sat in. The disagreement usually isn't about philosophy. Risk gets assigned to whoever owns the model, when the real exposure lives in the business process the model changes. Tech can own whether the system works as designed. Only the business can own whether it should be doing that job at all. Most pilots I've watched stall before production stalled right here, because nobody wanted to sign the risk acceptance. So who in your organization actually signs?
The line from OpenAI that stuck with me is Mark Chen admitting monitors weren't on during training because "it wasn't industry practice." The hacks into Hugging Face and Australia's health system came from experimental models under testing, the stage everyone treats as a sandbox. I've sat on enough governance committees to know enterprises make the same assumption about pilots. Controls get deferred until production, as if a test environment can't touch anything real. OpenAI now treats training as not secure, and your AI pilots probably deserve the same assumption. When did your governance program last look at what's running before launch?