India has moved to close a long-standing regulatory gap around AI-powered healthcare software, with the Central Drugs Standard Control Organisation formalising a framework that classifies diagnostic, treatment and monitoring applications as medical devices in their own right. Software performing functions such as disease screening, clinical decision support or patient monitoring will now require regulatory approval and licensing under the Medical Device Rules, 2017, before it can be marketed or deployed in India.
Closing a Regulatory Blind Spot
The guidance builds on a draft document CDSCO first released on October 21, 2025, which, for the first time, comprehensively addressed how existing medical device law applies to software rather than only physical hardware. Until then, India lacked dedicated regulatory guidance for AI-enabled medical software despite its rapid adoption across hospitals, diagnostic centres and digital health platforms, leaving developers and manufacturers to navigate a legally applicable but practically unclear regime.
The framework draws a clear line between two categories: Software in a Medical Device, meaning code embedded in and inseparable from physical hardware such as an insulin pump, and Software as a Medical Device, meaning standalone applications that perform a medical function independently, such as AI-based imaging tools or remote patient-monitoring platforms. Only software that directly influences a medical decision or performs a medical function falls within scope; general wellness apps, fitness trackers and lifestyle software that merely provide health information without shaping clinical decisions remain outside it.
A Four-Tier Risk Ladder
CDSCO has introduced a risk-based classification running from Class A through Class D, mirroring the structure already used for physical medical devices under Indian law and broadly aligning with international frameworks such as the EU’s MDR and the US FDA’s approach to software as a medical device. Class A covers low-risk software, while Class D is reserved for tools tied to life-supporting functions, critical disease diagnosis or high-impact clinical decision-making. Classification depends on the software’s intended use, the severity of the medical condition it addresses, and how significantly its output could affect patient care.
Higher-risk categories, Class C and D, will require full technical dossiers, risk assessments and clinical data submitted to the Central Licensing Authority, with review timelines running 90 to 180 days depending on the class. Developers must also maintain a robust Quality Management System covering the software’s entire lifecycle, spanning design, development, testing, validation, cybersecurity, risk management, post-deployment updates and ongoing maintenance, aligned with international standards such as IEC 62304 for software lifecycle management and ISO 14971 for risk management.
AI Models That Keep Learning Pose a Distinct Challenge
A notable feature of the framework is its treatment of AI and machine-learning tools that continue to update after deployment, unlike traditional static software. Developers of such systems are required to submit an Algorithm Change Protocol detailing how the model may evolve post-launch, alongside standard documentation covering software versioning, intended users, autonomy level and change management, an acknowledgment that AI-driven diagnostic tools do not necessarily behave the same way at the time of approval as they do months or years into real-world use.
Industry bodies, including Nasscom, submitted detailed recommendations during the public consultation period, largely welcoming the move toward regulatory clarity while pushing for streamlined compliance requirements for low-risk software so that smaller developers are not burdened disproportionately relative to the risk their products pose. Legal and healthcare technology analysts have noted that the framework does not so much introduce new regulatory requirements as clarify how existing provisions of the Medical Device Rules apply to software, a distinction that matters for compliance planning even if it does not change the underlying legal obligation software makers already carried.
Why the Timing Matters
India’s digital health market was valued at roughly $14.5 billion in 2024 and is projected to grow nearly sevenfold by 2033, according to industry estimates, a trajectory that has made the absence of software-specific regulatory clarity increasingly untenable as AI tools move from pilot projects into routine clinical use for interpreting X-rays, CT scans and MRIs, and for supporting treatment decisions in hospitals nationwide. Health technology specialists note that the safety of such systems ultimately depends on more than algorithmic accuracy alone, encompassing data quality, cybersecurity, transparency and continuous validation, all areas the new framework attempts to formally institutionalise rather than leave to individual manufacturers’ discretion.
The government has framed the guidelines as supporting rather than constraining innovation, arguing that a transparent, predictable regulatory pathway will ultimately build greater confidence in India’s AI-driven healthcare sector among clinicians, hospitals and patients alike, even as manufacturers adjust to the compliance obligations the new classification system now imposes.
