Radiology Partners, the largest radiology practice in the United States, has filed a citizen petition with the FDA asking the agency to state clearly when a vision-language model (VLM) used to analyze medical images becomes a medical device subject to premarket authorization. The petition was submitted on August 12 by Mosaic Clinical Technologies, the group’s technology services division, and it goes straight at the most uncomfortable question in the market right now: an entire class of AI models is being sold for diagnostic use without anyone being certain which rules apply to it.
What is actually being asked
The core request is interpretive, not prohibitive. Mike Peresie, president of Mosaic Clinical Technologies, wrote to the FDA that “as these technologies are increasingly commercialized and deployed in clinical settings, differing interpretations have emerged regarding the application of existing FDA medical device requirements, creating uncertainty for developers, healthcare organizations, clinicians and patients.”

The sharpest technical question in the filing is the one that matters most to technology buyers: is a model marketed with the expectation that it will later be fine-tuned on institution-specific data already, in itself, a medical device requiring clearance or approval? Both answers currently have defenders. If the answer is yes, a large share of the foundation models being distributed to hospitals are out of compliance. If it is no, there is now a legitimate path to deliver diagnostic capability without premarket review — simply hand the final training step to the customer.
Notably, Radiology Partners is not asking for a brake on innovation. The filing calls diagnostic imaging VLMs an “important and promising” advance in medicine, and closes by asking only for consistency: “Clarity on standards will ultimately accelerate both the development and adoption of safe and trusted clinical diagnostic technologies.”
Why foundation models break the current regulatory model
The FDA framework for imaging AI was built around one premise: software with a narrow indication for use, validated in a defined population, for a defined task. Detect a pulmonary nodule on chest CT. Flag intracranial hemorrhage. Measure ejection fraction. Each authorization ties performance to a task and a context — and that is what makes it possible to demand sensitivity, specificity and subgroup performance.
Foundation models break that premise by design. They are trained at scale to solve a variety of downstream tasks, many of which do not even exist at training time. There is no single indication for use, no single target population and often no fixed decision threshold at all — the output is free text. The filing names the practical consequence: there is no established standard for validating the performance and quality of these models.
The risks listed are specific rather than rhetorical. “The absence of regulatory oversight and standardization significantly increases the risk that they may be trained on biased or unrepresentative datasets and that they lack transparency, explainability, and basic cybersecurity controls,” Peresie wrote. “All these risks have the potential to cause tangible patient harm.” He adds a point that rarely enters the technical debate: several developers contractually disclaim responsibility for model reliability or legal compliance, offering few or no warranties about performance or fitness for the diagnostic uses the models are marketed for.
Who ends up holding the risk: the radiologist
This is where the petition stops being a legal matter and becomes a workflow problem. If the vendor guarantees nothing and the FDA authorized no indication, who answers for the decision to use the model on this case, on this patient? The filing answers bluntly: downstream users — read radiologists — bear “substantial responsibility” for determining whether a model is appropriate for its intended use. Models introduced without premarket review may simply never have demonstrated the baseline safety and effectiveness an authorization would require.
That risk transfer is not theoretical. We have already covered how radiologist expertise is what stops a language model’s error when it suggests something wrong — which is reassuring and alarming at once, because it means the final safety barrier is human and documented in no validation process anywhere. Practices building AI governance now should treat three of the petition’s asks as procurement requirements: validation criteria, continuous performance monitoring, and a vendor quality management system.
The contrast with what is already regulated
The inconsistency is obvious when you compare it with the rest of the ecosystem. Narrow detection tools go through 510(k), get an explicit indication for use and, when they deliver demonstrable value, can even earn dedicated payment — as happened with the Medicare add-on payment for CT triage AI. On the other side, a generalist model able to describe any finding on any exam can circulate as a “research tool” or “assistant,” with no indication, no validated population and no monitoring obligation.
There is also precedent for professional bodies filling the vacuum while the regulator decides: the ACR guidance on AI-generated report summaries came out of exactly that logic — steer usage while the formal rule does not exist. Petitions like Mosaic’s try to shorten that gap.
What changes in practice, and what to expect
A citizen petition is a formal instrument under US regulation: the FDA must respond, and the response can be a grant, a denial, or a tentative decision while the agency studies the issue. None of those outcomes is fast. In practice the market should go through another full commercial cycle without resolution — which means the decision keeps landing at the level of the individual radiology practice.
For imaging leaders outside the US, the message applies immediately and does not depend on the FDA. Software as a medical device has its own rules in most jurisdictions, and the question Mosaic is putting to the FDA — who validates, on what data, under which indication — is exactly the question that belongs in every procurement process. Three minimum questions for any vendor: what is the declared indication for use; in which population was performance measured and with which metrics; and who takes contractual responsibility if the model fails in production. If the answer to any of them is a disclaimer, the risk has not disappeared — it has only changed owner. Vendors that instead pursue formal clearance, as in the DeepHealth breast ultrasound AI authorization, are answering those questions before the customer has to ask.




