Why FDA Approval Is Not AI Governance
Edward Meyman, Founder & CEO, FERZ, Inc.
January 2026
Recent discussions around AI in healthcare regulation have rightly raised concerns about whether current approval processes provide real safety guarantees. A growing body of research argues that many AI-enabled medical products enter clinical use with limited transparency, inconsistent post-market oversight, and insufficient protection against model drift, bias, and unintended harm.
A recent paper in PLOS Digital Health — "The Illusion of Safety: A Report to the FDA on AI Healthcare Product Approvals" (Abulibdeh, Celi, Sejdić, 2025) — documents these concerns rigorously. The authors call for stronger monitoring, more disclosure, mandatory bias evaluations, and community engagement in AI regulation.
These recommendations are sound. But they also reveal a deeper problem that is still being missed.
The core issue is not that AI systems lack monitoring. It is that monitoring is being mistaken for governance.
Observation is not control
Most regulatory approaches to AI today focus on observation:
- performance metrics
- audit logs
- bias reports
- post-market surveillance
- transparency disclosures
These tools tell us what happened or what tends to happen. They are valuable, but they do not answer the question that matters most once something goes wrong:
Was this specific AI-mediated action permitted under binding constraints at the moment it occurred?
That is a fundamentally different question — and one that monitoring alone cannot answer.
Governance happens before action, not after harm
In high-stakes domains like healthcare, compliance cannot be reconstructed retroactively. You cannot authorize a medical decision after it has already affected a patient. You cannot statistically "correct" a categorical violation of policy, law, or clinical protocol after the fact. And you cannot rely on ethical intent or historical averages when the outcome of a single decision matters.
True governance is therefore pre-execution, not retrospective.
It requires that legal, clinical, ethical, and operational constraints are resolved prior to execution, not reconstructed afterward. Anything less is supervision, not control.
The limits of post-market fixes
Calls for stronger post-market surveillance, continuous evaluation, and adaptive regulation are understandable responses to the dynamic nature of modern AI systems. But they are not sufficient on their own.
Adaptive systems that learn over time inevitably drift. Monitoring can detect that drift, but detection does not equal prevention. Once a system is deployed, the question is no longer whether it performs well on average, but whether each action complies with binding rules in real time.
Without that capability, regulatory confidence remains provisional — dependent on trust, documentation, and interpretation rather than proof.
Fairness and safety are control problems, not reporting problems
Bias, inequity, and unsafe behavior are often framed as measurement challenges: something to detect, report, and mitigate statistically. But in regulated environments, fairness and safety must be enforceable properties, not aspirational ones.
If a system is allowed to act first and justify later, then fairness exists only as an after-action narrative. Real accountability requires mechanisms that can prevent disallowed actions from occurring in the first place.
The missing layer in AI regulation
What is absent from most AI governance discussions is a clear distinction between:
- visibility into system behavior, and
- authorization of system actions.
Governance begins only when an AI system can demonstrate that a specific action was permitted under defined constraints at the moment it was taken — and when that determination can be independently verified.
Until that distinction is addressed, no amount of monitoring, transparency, or ethical guidance will fully close the gap between regulatory approval and real-world safety.
Moving forward
AI will continue to play an expanding role in healthcare. That progress should not be slowed — but it must be grounded in mechanisms that make compliance provable, not presumed.
Approval is not governance. Logs are not proof. And safety cannot depend on after-the-fact explanations.
If AI is to be trusted in high-stakes decisions, governance must be enforced where it belongs: before the action, not after the harm.
FERZ researches and develops deterministic AI governance infrastructure for regulated environments.
