<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="research-article"><front><journal-meta><journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id><journal-id journal-id-type="publisher-id">jmir</journal-id><journal-id journal-id-type="index">1</journal-id><journal-title>Journal of Medical Internet Research</journal-title><abbrev-journal-title>J Med Internet Res</abbrev-journal-title><issn pub-type="epub">1438-8871</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v28i1e90654</article-id><article-id pub-id-type="doi">10.2196/90654</article-id><article-categories><subj-group subj-group-type="heading"><subject>Viewpoint</subject></subj-group></article-categories><title-group><article-title>Co-Lifecycle Governance for Learning Medical AI: A Hybrid Convergence Framework for Adaptive Regulatory Oversight</article-title></title-group><contrib-group><contrib contrib-type="author"><name name-style="western"><surname>Lee</surname><given-names>Jae Hyun</given-names></name><degrees>JD, DDS</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Choi</surname><given-names>Boram</given-names></name><degrees>DDS, PhD</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Jeong</surname><given-names>Kwunho</given-names></name><degrees>BS</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Suh</surname><given-names>Sang Won</given-names></name><degrees>MD, PhD</degrees><xref ref-type="aff" rid="aff2">2</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Kim</surname><given-names>Ju Han</given-names></name><degrees>MD, PhD</degrees><xref ref-type="aff" rid="aff3">3</xref></contrib><contrib contrib-type="author" corresp="yes"><name name-style="western"><surname>Son</surname><given-names>Dae-Soon</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff4">4</xref><xref ref-type="aff" rid="aff5">5</xref><xref ref-type="aff" rid="aff6">6</xref></contrib></contrib-group><aff id="aff1"><institution>Global Research Center, JNPMEDI</institution><addr-line>Seoul</addr-line><country>Republic of Korea</country></aff><aff id="aff2"><institution>Department of Physiology, College of Medicine, Hallym University</institution><addr-line>Chuncheon</addr-line><addr-line>Gangwon-do</addr-line><country>Republic of Korea</country></aff><aff id="aff3"><institution>Division of Biomedical Informatics, Seoul National University Biomedical Informatics (SNUBI), College of Medicine, Seoul National University</institution><addr-line>Seoul</addr-line><country>Republic of Korea</country></aff><aff id="aff4"><institution>Major in Bio-Healthcare Convergence, College of Natural Sciences, Hallym University</institution><addr-line>1 Hallymdaehak-gil</addr-line><addr-line>Chuncheon</addr-line><addr-line>Gangwon-do</addr-line><country>Republic of Korea</country></aff><aff id="aff5"><institution>Division of Big Data and Artificial Intelligence, Institute of New Frontier Research, College of Medicine, Hallym University</institution><addr-line>Chuncheon</addr-line><addr-line>Gangwon-do</addr-line><country>Republic of Korea</country></aff><aff id="aff6"><institution>Hallym AI-BioHealth R&#x0026;BD Center, Research Institute of Medical-Bio Convergence, Hallym University</institution><addr-line>Chuncheon</addr-line><addr-line>Gangwon-do</addr-line><country>Republic of Korea</country></aff><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Coristine</surname><given-names>Andrew</given-names></name></contrib></contrib-group><contrib-group><contrib contrib-type="reviewer"><name name-style="western"><surname>Omachonu</surname><given-names>Rebecca</given-names></name></contrib><contrib contrib-type="reviewer"><name name-style="western"><surname>Adachi</surname><given-names>Takeya</given-names></name></contrib></contrib-group><author-notes><corresp>Correspondence to Dae-Soon Son, PhD, Major in Bio-Healthcare Convergence, College of Natural Sciences, Hallym University, 1 Hallymdaehak-gil, Chuncheon, Gangwon-do, 24252, Republic of Korea, 82 332482037; <email>biostat@hallym.ac.kr</email></corresp></author-notes><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>19</day><month>5</month><year>2026</year></pub-date><volume>28</volume><elocation-id>e90654</elocation-id><history><date date-type="received"><day>31</day><month>12</month><year>2025</year></date><date date-type="rev-recd"><day>23</day><month>04</month><year>2026</year></date><date date-type="accepted"><day>23</day><month>04</month><year>2026</year></date></history><copyright-statement>&#x00A9; Jae Hyun Lee, Boram Choi, Kwunho Jeong, Sang Won Suh, Ju Han Kim, Dae-Soon Son. Originally published in the Journal of Medical Internet Research (<ext-link ext-link-type="uri" xlink:href="https://www.jmir.org">https://www.jmir.org</ext-link>), 19.5.2026. </copyright-statement><copyright-year>2026</copyright-year><license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (<ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link>), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research (ISSN 1438-8871), is properly cited. The complete bibliographic information, a link to the original publication on <ext-link ext-link-type="uri" xlink:href="https://www.jmir.org/">https://www.jmir.org/</ext-link>, as well as this copyright and license information must be included.</p></license><self-uri xlink:type="simple" xlink:href="https://www.jmir.org/2026/1/e90654"/><abstract><p>Artificial intelligence (AI) in health care is increasingly defined not by static algorithms but by adaptive intelligence&#x2014;systems that evolve over time through interactions with data, clinicians, and clinical environments. This adaptive capacity creates a structural mismatch with regulatory frameworks built for technologies whose behavior remains static. As AI models drift, recalibrate, or degrade in real-world contexts, they dissolve the linear boundaries between design, deployment, and clinical interpretation. These temporal, epistemic, and organizational frictions expose responsibility gaps that cannot be resolved through incremental modifications to legacy oversight structures. Regulators across major jurisdictions are beginning to respond to these challenges, though with differing orientations. The United States advances mechanisms for predictable adaptation, including Predetermined Change Control Plans, real-world evidence frameworks, and life cycle&#x2013;oriented quality management reforms. The European Union emphasizes precautionary, rights-based governance through the European Union Artificial Intelligence Act (AI Act) and modernized liability rules. South Korea, operating within a hyperconnected digital health ecosystem, has introduced the Digital Medical Products Act (DMPA), one of the world&#x2019;s first comprehensive statutory frameworks for learning medical AI. Despite philosophical differences, these regulatory trajectories converge on a shared insight: learning AI systems cannot be governed by static rules or episodic evaluation. This viewpoint proposes Co-Lifecycle Governance as a conceptual framework to synchronize regulatory oversight with adaptive intelligence. Rather than treating oversight as a discrete event, Co-Lifecycle Governance frames regulation as a continuous, synchronized process grounded in 4 pillars: continuous validation, agile change management, proactive performance surveillance, and distributed accountability. Each pillar functions as a structural antidote to the responsibility frictions that arise when AI systems evolve faster than expectations surrounding them. Together, these pillars provide a governance grammar capable of supporting safe, iterative model improvement while maintaining system-level trust. Drawing from the strengths of US predictability, European Union accountability, and Korean scalability, this paper outlines a hybrid convergence pathway that synthesizes predictability, accountability, and operational feasibility. Learning AI will not wait for governance to catch up; oversight must evolve in lockstep with adaptive intelligence. Co-Lifecycle Governance offers a foundation for regulatory systems that not only regulate learning AI but also learn with it&#x2014;at the speed at which adaptive intelligence actually changes.</p></abstract><kwd-group><kwd>medical artificial intelligence</kwd><kwd>medical AI</kwd><kwd>adaptive artificial intelligence</kwd><kwd>adaptive AI</kwd><kwd>learning health systems</kwd><kwd>Co-Lifecycle Governance</kwd><kwd>regulatory science</kwd><kwd>United States Food and Drug Administration Predetermined Change Control Plan</kwd><kwd>European Union AI Act</kwd><kwd>Digital Medical Products Act</kwd><kwd>hybrid governance</kwd></kwd-group></article-meta></front><body><sec id="s1" sec-type="intro"><title>Introduction</title><p>Medical artificial intelligence (AI) is no longer a fixed device; it is a learning system whose behavior shifts as its data, context, and interactions change. Traditional medical technologies move through segmented and predictable phases, whereas learning AI operates through continuous feedback loops. Evidence from explainability research, clinical deployment challenges, unintended consequences, big data fragility, ethical risks, calibration drift, adversarial vulnerabilities, and explainability limitations demonstrates that learning systems do not maintain a single fixed &#x201C;performance state&#x201D; [<xref ref-type="bibr" rid="ref1">1</xref>-<xref ref-type="bibr" rid="ref8">8</xref>].</p><p>Throughout this viewpoint, we use &#x201C;learning medical AI&#x201D; as an umbrella term for AI-enabled medical software whose behavior can change after deployment through planned updates, recalibration, or context-dependent drift. This does not imply autonomous real-time online learning at the bedside, which is neither assumed nor advocated in this framework. In many medical domains, definitive outcome labels are delayed (&#x201C;ground truth lag&#x201D;), which makes life cycle governance dependent on staged reassessment rather than continuous real-time outcome learning. Accordingly, throughout this viewpoint, we use &#x201C;continuous&#x201D; strictly in a life cycle sense&#x2014;ongoing, repeated, and trigger-based&#x2014;rather than as uninterrupted real-time outcome learning.</p><p>This paper begins from a consequential insight: the life cycle of a medical product and the learning cycle of an AI system are structurally distinct yet increasingly intertwined. Embedding AI into clinical environments reshapes its behavior in ways that static regulatory snapshots cannot adequately represent. As a result, foundational governance questions arise: Who is responsible when models drift? How should updates be reviewed? Which evidence should guide continuous performance assessment?</p><p>Regulators worldwide are experimenting with different answers. The United States is developing structured pathways for predictable adaptation, such as Predetermined Change Control Plans (PCCPs) [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>]. The European Union (EU) emphasizes precautionary accountability through the AI Act and accompanying liability reforms [<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. Korea has enacted the DMPA, establishing a statutory foundation for adaptive oversight within a highly digitized health care ecosystem [<xref ref-type="bibr" rid="ref14">14</xref>].</p><p>Taken together, these regulatory responses point to a shared structural realization: learning medical AI cannot be effectively governed through static rules or episodic review. While each jurisdiction approaches the problem from a distinct regulatory philosophy&#x2014;adaptive flexibility in the United States, precautionary accountability in the EU, and infrastructural hybridization in Korea&#x2014;all 3 are converging on the need for oversight systems that remain responsive to ongoing model evolution. These systems share the same problem statement, but they operationalize it through different regulatory logics. This convergence, coupled with persistent divergence in implementation, creates the conditions for a governance framework that can integrate adaptability, accountability, and operational feasibility within a single life cycle&#x2013;aware structure.</p><p>This viewpoint proposes Co-Lifecycle Governance, a framework that integrates regulatory, organizational, and technical responsibilities to synchronize oversight with adaptive intelligence. Rather than replicating any single jurisdictional model, Co-Lifecycle Governance articulates a life cycle&#x2013;aware structure capable of operationalizing the core requirements embedded across PCCP-based update governance, risk-based AI regulation, and statutory digital medical product oversight.</p></sec><sec id="s2"><title>Regulatory DNA of Learning AI: Divergent Philosophies and Converging Pressures</title><p>Regulatory systems designed for fixed-performance technologies were never built to follow AI that continues to change itself after approval. What distinguishes learning AI is not only its evolving performance but also the mechanisms through which that evolution emerges&#x2014;data drift, contextual adaptation, workflow coupling, and distributed system interactions. These dynamics force regulators to articulate what kinds of change should be permitted, anticipated, monitored, or constrained. The result has been the crystallization of 3 regulatory archetypes, each representing a deeper institutional philosophy about uncertainty, risk, and technological evolution. Although they often appear as regional policy variations, they are better understood as expressions of distinct regulatory &#x201C;genotypes&#x201D;: different ways of encoding how a governance system adapts to the presence of learning systems.</p><p>In this context, &#x201C;regulatory DNA&#x201D;&#x2014;previously articulated in comparative form between the United States and the EU [<xref ref-type="bibr" rid="ref15">15</xref>]&#x2014;does not refer to a normative ideal or a shared philosophical blueprint. Rather, it describes the structural response patterns that different regulatory systems have activated in reaction to the same underlying pressure: the inability of fixed, static regulatory models to govern learning systems that continue to change after deployment. While the United States, the EU, and Korea exhibit divergent regulatory forms, they are responding to a common constraint&#x2014;the need to govern AI across its life cycle rather than at a single point in time.</p></sec><sec id="s3"><title>United States: Predictable Adaptation Through Structured Flexibility</title><p>The United States has taken the clearest steps toward treating model evolution not as a postmarket anomaly but as a governable life cycle property. The United States Food and Drug Administration (FDA)&#x2019;s introduction of PCCPs [<xref ref-type="bibr" rid="ref9">9</xref>] represents a foundational shift in regulatory logic: manufacturers may prespecify which aspects of a model will change, how they will change, and what validation evidence will be required before updates are deployed. This preauthorization mechanism acknowledges that learning systems cannot be frozen at the moment of approval. Instead, it reframes updates as predictable events within a predefined envelope of acceptable change.</p><p>This philosophy has roots in the FDA&#x2019;s long-standing Total Product Life Cycle approach, which emphasizes that the safety of software-based products is shaped not only by design but also by postmarket performance and the manufacturer&#x2019;s quality processes. The modernization of the Quality Management System Regulation [<xref ref-type="bibr" rid="ref11">11</xref>] reinforces this orientation by embedding continuous monitoring, process discipline, and organizational accountability into regulatory expectations. Together with the International Medical Device Regulators Forum&#x2019;s foundational software as a medical device (SaMD) frameworks (definitions, risk categorization, and clinical evaluation) [<xref ref-type="bibr" rid="ref16">16</xref>-<xref ref-type="bibr" rid="ref18">18</xref>], these instruments operationalize a life cycle&#x2013;thinking mindset in which regulators oversee systems in motion, not artifacts at rest.</p><p>Importantly, the US governance approach also relies on real-world evidence (RWE) to monitor performance and validate changes [<xref ref-type="bibr" rid="ref10">10</xref>]. RWE offers regulators a dynamic evidentiary substrate for detecting drift, inequities, or clinically significant shifts that may not appear during premarket testing. This integration of real-world learning into regulatory oversight represents a pragmatic recognition: learning AI is safer when regulators explicitly permit controlled evolution rather than forcing manufacturers to choose between compliance and improvement.</p><p>Still, the US approach carries trade-offs. Its emphasis on developer responsibility and on organizational quality systems places substantial trust in manufacturers to monitor themselves. Moreover, while PCCPs offer clarity about planned updates, they provide less formal structure for unplanned evolution arising from distributional drift or environmental coupling&#x2014;precisely the kinds of changes most likely to generate risk. Nevertheless, as an archetype, the US model contributes a vital regulatory virtue: predictable adaptation, which aligns closely with the Co-Lifecycle Governance pillar of agile change management.</p></sec><sec id="s4"><title>EU: Precautionary Governance Anchored in Accountability</title><p>The EU approaches learning AI through a fundamentally different regulatory lens. Where the United States structures change, the EU seeks to control risk and ensure rights. The AI Act [<xref ref-type="bibr" rid="ref12">12</xref>] is built on a precautionary logic: high-risk AI systems&#x2014;especially those used in medical contexts&#x2014;must undergo extensive ex ante conformity assessment, maintain comprehensive technical documentation, demonstrate risk mitigation measures, and preserve human oversight throughout their life cycle. The premise is not that AI will necessarily evolve safely, but that institutions must be able to reconstruct and audit system behavior at every stage.</p><p>This approach reflects a long-standing European regulatory tradition: documentation as governance. By requiring detailed data provenance records, model design dossiers, transparency reports, and continuous postmarket monitoring plans, the AI Act constructs an auditable trail that can reveal how a model changes, how those changes were validated, and how they may contribute to harm. In this sense, the EU does not primarily regulate learning as a dynamic engineering process; rather, it regulates the evidence environment needed to hold systems accountable.</p><p>The updated Product Liability Directive (PLD) [<xref ref-type="bibr" rid="ref13">13</xref>] further reinforces this architecture by expanding liability to software-driven harms and update-related failures. Under the new PLD, manufacturers may face strict liability if insufficient documentation prevents courts from determining how a failure occurred. This makes transparency not only a compliance requirement but also a legal survival mechanism. If a model&#x2019;s learning trajectory is not well documented, its developer becomes more&#x2014;not less&#x2014;exposed.</p><p>Yet the EU approach has its own trade-offs. Its strong ex ante compliance burden can slow down adaptation, creating tension for AI systems that rely on frequent updates to remain safe or clinically relevant. The AI Act permits modifications, but the pathways for high-risk systems remain comparatively rigid, requiring additional documentation and potential reassessment. At scale, this may create a mismatch between the speed of learning and the velocity of regulatory processes.</p><p>Still, the EU model contributes a distinct regulatory strength that no other jurisdiction provides as strongly: rights-based accountability. It articulates a governance stance in which AI evolution is allowed only when it remains transparent, contestable, and traceable. In Co-Lifecycle Governance terms, the EU strengthens the pillar of distributed accountability, ensuring that oversight does not simply trust manufacturers but constrains them through enforceable obligations.</p></sec><sec id="s5"><title>Korea: Hybridization in a Hyperconnected Ecosystem</title><p>South Korea offers a regulatory trajectory shaped not only by policy choice but also by structural conditions that make fixed, static oversight particularly difficult to sustain. As one of the world&#x2019;s most digitally connected health care environments&#x2014;with near-universal electronic health record adoption, integrated claims databases, nationwide broadband infrastructure, and high digital literacy&#x2014;Korea operates in a setting where AI-enabled medical products are likely to evolve rapidly once deployed. In such an environment, regulatory frameworks that rely solely on premarket authorization or episodic review are inherently mismatched to real-world use. The DMPA [<xref ref-type="bibr" rid="ref14">14</xref>,<xref ref-type="bibr" rid="ref19">19</xref>] emerges from this context as one of the first statutory frameworks explicitly designed to govern digital medical technologies, including adaptive AI, across their operational life cycle.</p><p>In this sense, the DMPA does not simply borrow from US or European regulatory traditions; it reflects a convergence driven by necessity. Korea&#x2019;s regulatory environment faced simultaneous pressures: the need to accommodate iterative software updates without stalling clinical innovation, and the need to ensure traceability, documentation, and enforceability in a highly data-intensive health system. Elements commonly associated with US governance&#x2014;such as acceptance of planned postmarket modification and structured update pathways&#x2014;are reflected in the Ministry of Food and Drug Safety (MFDS) guidance emphasizing proportionality and predefined validation of changes [<xref ref-type="bibr" rid="ref20">20</xref>]. At the same time, the DMPA incorporates features characteristic of European regulation, including explicit documentation requirements and auditable risk management structures, which are essential in a system where large-scale data integration amplifies both benefit and harm.</p><p>Korea&#x2019;s broader Digital Health Innovation Strategy [<xref ref-type="bibr" rid="ref21">21</xref>] further reinforces this hybridization by embedding AI governance within national health care modernization. Institutional coherence across the MFDS, the Health Insurance Review and Assessment Service, the National Institute of Medical Device Safety Information, and clinical providers creates conditions under which postmarket oversight can be coordinated at scale. Importantly, this infrastructural strength should not be interpreted as implying continuous raw-data access for private developers to retrain models. Rather, Korea&#x2019;s centralized claims and safety-monitoring systems primarily enable mediated, privacy-preserving surveillance and audit mechanisms. Under such an approach, population-level data can support regulator- or institution-led monitoring, signal detection, and periodic revalidation without necessitating unrestricted data transfer to manufacturers. In this sense, the infrastructure strengthens the learning cycle of oversight and recalibration. It does not imply autonomous, developer-driven continuous model updating. At the same time, centralized oversight architectures introduce their own governance trade-offs, including heightened privacy sensitivity, potential centralization risks, and institutional dependency. These constraints should be recognized as part of the design conditions for scalable life cycle governance, not as automatic advantages. The boundary between medical AI and broader health care AI is particularly salient in Korea&#x2019;s fast-moving digital ecosystem. Tools that begin as wellness, administrative, or population-health software (eg, lifestyle coaching, symptom checkers, appointment triage, or operational risk stratification) may become &#x201C;medical&#x201D; AI once their intended use shifts toward diagnosis, treatment selection, or clinical risk management. For learning systems, this boundary can evolve over time as workflow integration deepens, creating &#x201C;category drift,&#x201D; which challenges static regulatory categorization and reinforces the need for life cycle&#x2013;aware governance.</p><p>A practical Korean example of boundary management can be seen in the MFDS&#x2019;s 2020 approval of Samsung Electronics&#x2019; blood pressure measurement mobile app as a SaMD [<xref ref-type="bibr" rid="ref22">22</xref>]. Rather than treating the broader mobile platform as a medical device in its entirety, the MFDS attached device oversight to the specific software function and its intended use: once the app claimed noninvasive measurement and display of blood pressure and pulse, it became subject to medical device performance standards and approval [<xref ref-type="bibr" rid="ref22">22</xref>]. Although this case is not itself a postdeployment learning event, it demonstrates the operative Korean rule that regulatory status follows function and intended use rather than the digital platform label alone. For adaptive AI, the same logic implies that category drift can occur when iterative updates or deeper workflow integration transform a health-management tool into clinically actionable measurement, triage, or treatment-support software.</p><p>These structural conditions directly shape how the 4 pillars of Co-Lifecycle Governance are operationalized in Korea. Surveillance and agile change management are most visibly enabled by Korea&#x2019;s infrastructure, but the remaining pillars are equally implicated. Continuous validation becomes practicable because performance can be reassessed using real-world population data rather than isolated device-level follow-up studies. Distributed accountability is reinforced by the ability to trace responsibility across developers, deploying institutions, and regulators through unified data and documentation pathways. Rather than emphasizing a single pillar, Korea&#x2019;s contribution lies in demonstrating how continuous validation, change management, surveillance, and accountability can operate simultaneously within one statutory and infrastructural ecosystem.</p><p>The DMPA is still evolving, and implementation challenges remain. Yet Korea&#x2019;s approach illustrates a form of operational feasibility that neither US flexibility nor European accountability alone can guarantee. Where the US model excels at structuring change and the EU model excels at enforcing responsibility, Korea shows how life cycle&#x2013;aware governance can be instantiated at scale. In this respect, Korea&#x2019;s experience is not merely nationally specific but offers a transferable reference for health systems seeking to align regulatory oversight with the realities of learning AI in data-rich environments.</p></sec><sec id="s6"><title>Convergence</title><p>Despite philosophical divergence, the regulatory genotypes expressed in the US, EU, and Korean frameworks converge on a shared structural recognition: learning AI cannot be governed through fixed rules designed for static technologies. Whether through adaptation envelopes, rights-based documentation regimes, or infrastructural hybridization, each jurisdiction is articulating mechanisms for continuous oversight, proportional risk management, and distributed responsibility. Beyond national regulation, international bodies have similarly emphasized the need for continuous governance, responsible data stewardship, and life cycle&#x2013;aware oversight in digital health and AI systems [<xref ref-type="bibr" rid="ref23">23</xref>,<xref ref-type="bibr" rid="ref24">24</xref>]. These 3 regulatory archetypes are summarized in <xref ref-type="table" rid="table1">Table 1</xref>.</p><table-wrap id="t1" position="float"><label>Table 1.</label><caption><p>Comparative regulatory DNA of the United States, European Union, and Korea.</p></caption><table id="table1" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom"/><td align="left" valign="bottom">United States</td><td align="left" valign="bottom">European Union</td><td align="left" valign="bottom">Korea</td></tr></thead><tbody><tr><td align="left" valign="top">Philosophy</td><td align="left" valign="top">Predictable adaptation</td><td align="left" valign="top">Precautionary accountability</td><td align="left" valign="top">Hybrid operationalization</td></tr><tr><td align="left" valign="top">Key regulatory instruments</td><td align="left" valign="top">PCCP<sup><xref ref-type="table-fn" rid="table1fn1">a</xref></sup>, RWE<sup><xref ref-type="table-fn" rid="table1fn2">b</xref></sup>, and QMSR<sup><xref ref-type="table-fn" rid="table1fn3">c</xref></sup></td><td align="left" valign="top">AI Act<sup><xref ref-type="table-fn" rid="table1fn4">d</xref></sup> and PLD<sup><xref ref-type="table-fn" rid="table1fn5">e</xref></sup></td><td align="left" valign="top">DMPA<sup><xref ref-type="table-fn" rid="table1fn6">f</xref></sup></td></tr><tr><td align="left" valign="top">Oversight mode</td><td align="left" valign="top">Preauthorized change</td><td align="left" valign="top">High-risk controls</td><td align="left" valign="top">Mixed adaptive pathways</td></tr><tr><td align="left" valign="top">Liability</td><td align="left" valign="top">Tort<sup><xref ref-type="table-fn" rid="table1fn7">g</xref></sup> + regulatory</td><td align="left" valign="top">Strict liability</td><td align="left" valign="top">Hybrid evolving</td></tr><tr><td align="left" valign="top">Strength</td><td align="left" valign="top">Predictability</td><td align="left" valign="top">Accountability</td><td align="left" valign="top">Scalability</td></tr></tbody></table><table-wrap-foot><fn id="table1fn1"><p><sup>a</sup>PCCP: Predetermined Change Control Plan.</p></fn><fn id="table1fn2"><p><sup>b</sup>RWE: real-world evidence.</p></fn><fn id="table1fn3"><p><sup>c</sup>QMSR: Quality Management System Regulation.</p></fn><fn id="table1fn4"><p><sup>d</sup>AI Act: European Union Artificial Intelligence Act.</p></fn><fn id="table1fn5"><p><sup>e</sup>PLD: Product Liability Directive.</p></fn><fn id="table1fn6"><p><sup>f</sup>DMPA: Digital Medical Products Act.</p></fn><fn id="table1fn7"><p><sup>g</sup>Tort refers to civil liability for wrongful acts or omissions, including negligence or product-related harm, outside contractual obligations.</p></fn></table-wrap-foot></table-wrap></sec><sec id="s7"><title>The Erosion of Linear Responsibility: Structural Frictions in Learning AI</title><p>As AI systems evolve during real-world use, responsibility across developers, clinicians, institutions, and regulators becomes unstable. Drift, opacity, and adversarial vulnerabilities erode the linear chain linking design to deployment [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref4">4</xref>-<xref ref-type="bibr" rid="ref8">8</xref>]. Responsibility gaps arise from three structural frictions:</p><list list-type="order"><list-item><p>A temporal friction, in which performance changes after approval in ways not reflected in initial validation [<xref ref-type="bibr" rid="ref6">6</xref>]</p></list-item><list-item><p>An epistemic friction, in which failures become invisible to clinicians due to opacity and design constraints [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref8">8</xref>]</p></list-item><list-item><p>An organizational friction, driven by distributed control across developers, vendors, institutions, and regulators [<xref ref-type="bibr" rid="ref25">25</xref>-<xref ref-type="bibr" rid="ref28">28</xref>]</p></list-item></list><p>These frictions produce responsibility gaps and &#x201C;accountability overload,&#x201D; in which responsibility is simultaneously diluted across multiple actors and disproportionately concentrated on those least able to influence system behavior. Learning AI thus destabilizes legacy responsibility doctrines that rely on static role allocation and linear chains of control. Addressing this breakdown requires a governance structure capable of tracking responsibility across time, reallocating obligations as systems evolve, and maintaining traceability between technological change and regulatory accountability. The resulting life cycle responsibility matrix is summarized in <xref ref-type="table" rid="table2">Table 2</xref>.</p><table-wrap id="t2" position="float"><label>Table 2.</label><caption><p>Responsibility matrix across the life cycle of learning artificial intelligence systems.</p></caption><table id="table2" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom"/><td align="left" valign="bottom">Developer</td><td align="left" valign="bottom">Institution</td><td align="left" valign="bottom">Clinician</td><td align="left" valign="bottom">Regulator</td></tr></thead><tbody><tr><td align="left" valign="top">Design</td><td align="left" valign="top">Architecture</td><td align="left" valign="top">&#x2014;<sup><xref ref-type="table-fn" rid="table2fn1">a</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">Standards</td></tr><tr><td align="left" valign="top">Deployment</td><td align="left" valign="top">Documentation</td><td align="left" valign="top">Integration quality</td><td align="left" valign="top">Correct use</td><td align="left" valign="top">Authorization</td></tr><tr><td align="left" valign="top">Real-world learning</td><td align="left" valign="top">Patch cycles</td><td align="left" valign="top">Monitoring</td><td align="left" valign="top">Interpretation</td><td align="left" valign="top">Surveillance</td></tr><tr><td align="left" valign="top">Failure</td><td align="left" valign="top">Root cause</td><td align="left" valign="top">Incident detection</td><td align="left" valign="top">Reporting</td><td align="left" valign="top">Enforcement</td></tr><tr><td align="left" valign="top">Update</td><td align="left" valign="top">Validation</td><td align="left" valign="top">Rollout oversight</td><td align="left" valign="top">Communication</td><td align="left" valign="top">PCCP<sup><xref ref-type="table-fn" rid="table2fn2">b</xref></sup> and DMPA<sup><xref ref-type="table-fn" rid="table2fn3">c</xref></sup> rules</td></tr></tbody></table><table-wrap-foot><fn id="table2fn1"><p><sup>a</sup>No primary responsibility is assigned to that actor at the corresponding life cycle stage.</p></fn><fn id="table2fn2"><p><sup>b</sup>PCCP: Predetermined Change Control Plan.</p></fn><fn id="table2fn3"><p><sup>c</sup>DMPA: Digital Medical Products Act.</p></fn></table-wrap-foot></table-wrap><p>These structural frictions point to a deeper limitation of existing governance approaches. Learning medical AI systems do not merely introduce new risks; they alter the temporal and organizational conditions under which responsibility is exercised. Addressing these challenges therefore requires a governance framework that treats technological change as a core design feature rather than an exception to be managed after deployment. The central task is not only to allocate responsibility when failures occur but also to synchronize regulatory oversight with the ongoing evolution of learning systems.</p></sec><sec id="s8"><title>Co-Lifecycle Governance: 4 Pillars for Learning Systems</title><p>Co-Lifecycle Governance operationalizes the coevolutionary relationship between learning medical AI and regulatory oversight through 4 interdependent pillars. Rather than functioning as isolated controls, these pillars work together to ensure that adaptation remains both governable and accountable across the product life cycle, as illustrated in <xref ref-type="fig" rid="figure1">Figure 1</xref>.</p><fig position="float" id="figure1"><label>Figure 1.</label><caption><p>Co-Lifecycle Governance framework for learning medical artificial intelligence (AI). This figure illustrates the parallel and interconnected evolution of medical AI systems and regulatory oversight across the product life cycle.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e90654_fig01.png"/></fig><p>The first pillar, continuous validation, addresses temporal instability introduced by learning systems. Because performance and calibration may shift as data distributions and clinical workflows evolve, validation cannot remain confined to premarket evaluation. However, &#x201C;continuous&#x201D; validation is not synonymous with real-time outcome learning. In settings with delayed end points (eg, oncology or chronic disease), validation must operate across time horizons: (1) short-horizon monitoring of input drift, uncertainty, and process indicators; (2) intermediate validation using proxy outcomes, chart-review audits, or surrogate markers; and (3) longer-horizon confirmation once definitive outcomes mature. This staged structure allows governance to respond to drift early while preserving scientific rigor when ground truth is lagged [<xref ref-type="bibr" rid="ref2">2</xref>,<xref ref-type="bibr" rid="ref4">4</xref>,<xref ref-type="bibr" rid="ref6">6</xref>]. Continuous validation reframes regulatory assurance as an ongoing life cycle obligation, not a one-time premarket certification event. Such life cycle&#x2013;based oversight inevitably entails financial, technical, and organizational burdens, which must be proportionately allocated across developers, institutions, and regulators. In practice, these burdens may be addressed through structured cost-sharing mechanisms. For example, multi-institutional data-sharing consortia can distribute validation costs across participating sites, while subscription-based service models may incorporate ongoing surveillance and validation as part of software maintenance. In some settings, public infrastructure may support baseline monitoring functions, reducing the burden on individual institutions.</p><p>The second pillar, agile change management, structures how updates are proposed, validated, authorized, communicated, and rolled out. Mechanisms such as PCCPs and risk-proportionate pathways under the DMPA exemplify how model evolution can be made transparent, reviewable, and predictable [<xref ref-type="bibr" rid="ref9">9</xref>,<xref ref-type="bibr" rid="ref14">14</xref>]. Importantly, agility must be paired with version governance to avoid inequities across care environments. Co-Lifecycle Governance therefore treats version transparency (who is running which model, with what validated performance), minimum performance floors, and update dissemination policies as ethical and operational requirements rather than mere engineering choices.</p><p>The third pillar, proactive performance surveillance, responds to the epistemic opacity of learning AI by providing early warning signals. Surveillance is primarily passive and signal-oriented: it continuously tracks aggregate and subgroup performance proxies (eg, drift metrics, calibration signals, alert rates, and incident reports) to identify anomalies that warrant investigation [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref8">8</xref>]. By design, surveillance does not &#x201C;reprove&#x201D; effectiveness; it detects deviations and triggers targeted validation when thresholds are crossed. This operational distinction clarifies why surveillance and validation can share data infrastructures yet remain functionally nonredundant.</p><p>Finally, distributed accountability aligns obligations with actual control across developers, deploying institutions, clinicians, and regulators. Here, &#x201C;distributed&#x201D; refers to operational responsibility (who monitors, investigates, communicates, and executes mitigations), not the dilution of legal liability. In strict liability regimes, financial liability may remain concentrated on manufacturers, but operational accountability must still be traceable across the sociotechnical system. Co-Lifecycle Governance therefore emphasizes traceability: a chain of custody for model versions, validation evidence, deployment context, and corrective actions, which supports both clinical trust and legal enforceability [<xref ref-type="bibr" rid="ref25">25</xref>-<xref ref-type="bibr" rid="ref28">28</xref>]. This distinction preserves compatibility with strict liability regimes, where enforceability depends on clear forensic attribution. This structure also remains compatible with the learned intermediary doctrine, under which clinicians retain final decision-making authority in patient care.</p><p>For this structure to remain clinically viable, explainability must function as a deployment and update authorization requirement rather than an optional design feature. Initial deployment and any material recalibration or postmarket update must be conditioned on evidence that the system provides interpretable outputs, uncertainty signals, and traceable decision pathways sufficient for clinicians to understand the basis, confidence, and limits of model recommendations within the relevant workflow. Continuous validation must reassess these explainability properties after substantial model or interface changes, and performance surveillance should treat systematic clinician confusion, abnormal override patterns, or unexplained subgroup performance shifts as safety signals. Where these conditions cannot be met, the system should not be deployed or should be restricted to narrower use contexts, because clinician authority would otherwise be reduced to nominal endorsement rather than meaningful mediation. In this sense, explainability is not merely desirable; it is a governance gate that preserves both clinical trust and the practical viability of the learned intermediary doctrine.</p><p>Taken together, these 4 pillars provide coordinated answers to the structural frictions identified earlier: continuous validation mitigates temporal drift, performance surveillance addresses epistemic opacity, and distributed accountability&#x2014;working in concert with agile change management&#x2014;resolves organizational fragmentation. In combination, they form a life cycle&#x2013;aware governance architecture capable of synchronizing technological evolution with regulatory expectations.</p><p>A robust life cycle governance framework must also specify an exit strategy. When surveillance and validation indicate persistent, nonmitigable risk, governance should support staged controls: conditional suspension (use restricted to defined contexts), rollback to a prior validated version, and decommissioning or recall when risks cannot be acceptably reduced. We position this &#x201C;safe exit&#x201D; protocol as a necessary complement to update pathways, ensuring that life cycle governance is not biased toward improvement alone.</p><p>However, executing rollback or decommissioning in clinical environments is not frictionless. Technical dependencies between AI systems and electronic health record infrastructures may complicate rapid reversion to prior versions. Abrupt changes in system behavior may also disrupt clinical workflows and introduce new safety risks, particularly if clinicians have adapted to the updated system. These constraints highlight the need for preplanned and institutionally integrated exit strategies. <xref ref-type="table" rid="table3">Table 3</xref> maps the 4 pillars of Co-Lifecycle Governance to representative regulatory anchors in the United States, EU, and Korea.</p><table-wrap id="t3" position="float"><label>Table 3.</label><caption><p>Mapping the 4 pillars of Co-Lifecycle Governance to regulatory anchors.</p></caption><table id="table3" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Pillar</td><td align="left" valign="bottom">United States</td><td align="left" valign="bottom">European Union</td><td align="left" valign="bottom">Korea</td></tr></thead><tbody><tr><td align="left" valign="top">Continuous validation</td><td align="left" valign="top">RWE<sup><xref ref-type="table-fn" rid="table3fn1">a</xref></sup> and QMSR<sup><xref ref-type="table-fn" rid="table3fn2">b</xref></sup></td><td align="left" valign="top">AI Act<sup><xref ref-type="table-fn" rid="table3fn3">c</xref></sup> documentation</td><td align="left" valign="top">DMPA<sup><xref ref-type="table-fn" rid="table3fn4">d</xref></sup> performance tracking</td></tr><tr><td align="left" valign="top">Agile change management</td><td align="left" valign="top">PCCP<sup><xref ref-type="table-fn" rid="table3fn5">e</xref></sup></td><td align="left" valign="top">Change subject to conformity assessment and recertification triggers</td><td align="left" valign="top">Adaptive update pathways</td></tr><tr><td align="left" valign="top">Surveillance</td><td align="left" valign="top">RWE</td><td align="left" valign="top">Mandatory monitoring</td><td align="left" valign="top">National-scale infrastructure</td></tr><tr><td align="left" valign="top">Accountability</td><td align="left" valign="top">Shared</td><td align="left" valign="top">Strict liability</td><td align="left" valign="top">Hybrid</td></tr></tbody></table><table-wrap-foot><fn id="table3fn1"><p><sup>a</sup>RWE: real-world evidence.</p></fn><fn id="table3fn2"><p><sup>b</sup>QMSR: Quality Management System Regulation.</p></fn><fn id="table3fn3"><p><sup>c</sup>AI Act: European Union Artificial Intelligence Act.</p></fn><fn id="table3fn4"><p><sup>d</sup>DMPA: Digital Medical Products Act.</p></fn><fn id="table3fn5"><p><sup>e</sup>PCCP: Predetermined Change Control Plan.</p></fn></table-wrap-foot></table-wrap><p>Because continuous validation and performance surveillance both rely on postmarket data streams, <xref ref-type="table" rid="table4">Table 4</xref> clarifies their distinct operational roles.</p><table-wrap id="t4" position="float"><label>Table 4.</label><caption><p>Operational comparison between continuous validation and performance surveillance.</p></caption><table id="table4" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Dimension</td><td align="left" valign="bottom">Continuous validation (pillar 1)</td><td align="left" valign="bottom">Surveillance (pillar 3)</td></tr></thead><tbody><tr><td align="left" valign="top">Primary purpose</td><td align="left" valign="top">Confirm or update performance claims</td><td align="left" valign="top">Detect early warning signals</td></tr><tr><td align="left" valign="top">Mode</td><td align="left" valign="top">Active, hypothesis-driven testing</td><td align="left" valign="top">Passive, continuous monitoring</td></tr><tr><td align="left" valign="top">Evidence standard</td><td align="left" valign="top">Higher (reference standards and audits)</td><td align="left" valign="top">Preliminary (proxies and alerts)</td></tr><tr><td align="left" valign="top">Typical data</td><td align="left" valign="top">Curated labeled sets, chart review, surrogate outcomes, and matured end points</td><td align="left" valign="top">Drift metrics, calibration signals, alert rates, incident reports, and subgroup signals</td></tr><tr><td align="left" valign="top">Trigger</td><td align="left" valign="top">Scheduled revalidation or triggered by surveillance</td><td align="left" valign="top">Always on and triggers validation when thresholds are crossed</td></tr><tr><td align="left" valign="top">Output</td><td align="left" valign="top">Revalidation report, updated performance claims, and recalibration decision</td><td align="left" valign="top">Alerts/flags, monitoring reports, and escalation tickets</td></tr><tr><td align="left" valign="top">Decision action</td><td align="left" valign="top">Approve recalibration or update or safe exit</td><td align="left" valign="top">Escalate to validation and change control</td></tr></tbody></table></table-wrap></sec><sec id="s9"><title>Illustrative Clinical Scenario</title><p>To illustrate how the proposed framework operates in practice, consider a sepsis prediction algorithm deployed in an intensive care unit.</p><p>Over time, clinicians begin to observe fewer alerts for high-risk patients, potentially increasing the risk of delayed intervention in deteriorating patients. Concurrently, performance surveillance systems detect a decline in calibration across specific patient subgroups (pillar 3), triggering an institutional alert.</p><p>This signal initiates targeted validation (pillar 1), in which recent patient data and chart review audits are used to assess whether the observed drift reflects true performance degradation. Upon confirmation, the developer implements a recalibration update under a prespecified change management plan (pillar 2), with updated performance metrics communicated to clinicians prior to deployment.</p><p>Throughout this process, version tracking and audit logs ensure traceability of decisions and responsibility allocation (pillar 4). If recalibration fails to restore acceptable performance, the system may enter a staged exit pathway, including conditional suspension or rollback.</p></sec><sec id="s10"><title>Hybrid Convergence: Synthesizing Predictability, Accountability, and Scale</title><p>As previously analyzed in comparative context [<xref ref-type="bibr" rid="ref15">15</xref>], the United States contributes predictable adaptation through PCCPs, RWE, and life cycle&#x2013;oriented quality systems [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref16">16</xref>-<xref ref-type="bibr" rid="ref18">18</xref>]. The EU contributes enforceable accountability through risk-based governance and liability reform under the AI Act and PLD [<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. Korea contributes scalable operationalization through statutory digital medical product frameworks and nationally coordinated digital health infrastructure [<xref ref-type="bibr" rid="ref14">14</xref>,<xref ref-type="bibr" rid="ref19">19</xref>-<xref ref-type="bibr" rid="ref21">21</xref>].</p><p>Rather than proposing a single harmonized regulatory procedure, the hybrid convergence should be understood as a governance grammar&#x2014;a set of life cycle concepts and operational primitives that can be instantiated within different legal traditions. In practice, manufacturers operate under one primary jurisdiction at a time, while global developers may translate shared governance artifacts (eg, version traceability records, validation documentation, and monitoring plans) into jurisdiction-specific compliance packages. <xref ref-type="fig" rid="figure2">Figure 2</xref> illustrates this convergence pathway: distinct regulatory logics feed into a shared life cycle&#x2013;oriented governance architecture without requiring legal harmonization.</p><p>This framing addresses the apparent friction between rapid iteration and precautionary compliance. US-style preauthorized change pathways enable structured model updates, whereas the EU high-risk regime emphasizes conformity assessment, documentation, and recertification triggers. Co-Lifecycle Governance does not claim to eliminate these compliance burdens. Instead, it renders them governable by (1) classifying changes according to risk and regulatory impact, (2) prespecifying validation evidence proportional to each change category, and (3) maintaining audit-ready documentation that preserves traceability across updates. In this sense, agile change management can operate within precautionary systems as a discipline for anticipating and controlling recertification thresholds rather than as a mechanism for unconstrained speed.</p><p>The focus on the United States, EU, and Korea reflects their representation of 3 archetypal regulatory logics&#x2014;predictable adaptation, precautionary accountability, and infrastructural scalability&#x2014;rather than an exhaustive global survey.</p><fig position="float" id="figure2"><label>Figure 2.</label><caption><p>Convergence of archetypal regulatory logics into a hybrid life cycle governance architecture. This schematic figure shows how the United States (predictability), the European Union (EU; accountability), and Korea (scalability) converge toward a shared hybrid life cycle governance architecture.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e90654_fig02.png"/></fig><p>Other jurisdictions, including Japan&#x2019;s postapproval change management approaches, Singapore&#x2019;s life cycle guidance for software medical devices, and China&#x2019;s classification principles for AI-based medical software, demonstrate parallel movement toward life cycle&#x2013;aware governance. China has also issued classification and technical review guidance for AI-based medical software, emphasizing risk-based categorization and performance evaluation requirements tied to intended use and clinical function. Japan has explored controlled postapproval update pathways, while Singapore emphasizes life cycle monitoring and quality system&#x2013;based regulatory flexibility. These examples reinforce the broader claim of structural convergence while preserving regional divergence in implementation.</p><p>Finally, scalability is not synonymous with simplicity. National infrastructures that enable coordinated surveillance also introduce governance prerequisites and risks, including robust data governance, privacy safeguards, institutional capacity for monitoring, and clear legal pathways for corrective action. Co-Lifecycle Governance treats these as design constraints to be explicitly managed rather than as automatic advantages. Therefore, the hybrid convergence represents not a unified regime but a convergent architecture through which diverse regulatory systems can align life cycle oversight with adaptive intelligence.</p><p>In the context of unplanned postmarket drift, regulatory approaches also diverge. In the United States, such events are primarily addressed through manufacturer-led monitoring within quality management systems, with less formalized pathways for unplanned changes outside PCCP-defined updates. In contrast, the Korean framework enables more centralized signal detection through national-scale infrastructure, supporting coordinated revalidation and corrective action. This distinction reflects a broader difference between distributed monitoring and infrastructure-enabled oversight.</p></sec><sec id="s11" sec-type="conclusions"><title>Conclusions</title><p>Learning AI exposes foundational limits of legacy governance structures. Evidence of drift, opacity, and adversarial vulnerability demonstrates why static oversight cannot ensure safety in dynamic environments [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref4">4</xref>-<xref ref-type="bibr" rid="ref8">8</xref>]. Co-Lifecycle Governance reframes oversight as a synchronized, adaptive process grounded in 4 structural pillars [<xref ref-type="bibr" rid="ref2">2</xref>-<xref ref-type="bibr" rid="ref8">8</xref>,<xref ref-type="bibr" rid="ref25">25</xref>-<xref ref-type="bibr" rid="ref28">28</xref>]. These pillars provide a shared language for distributing responsibility and coordinating obligations across the life cycle.</p><p>Internationally, predictable adaptation (United States) [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>], enforceable accountability (EU) [<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>], and operational scalability (Korea) [<xref ref-type="bibr" rid="ref14">14</xref>,<xref ref-type="bibr" rid="ref19">19</xref>-<xref ref-type="bibr" rid="ref21">21</xref>] represent complementary strengths. No single philosophy suffices in isolation. A durable hybrid governance pathway must synthesize these approaches while maintaining public trust.</p><p>The pace of adaptive AI development increasingly challenges the capacity of static governance models to respond. Co-Lifecycle Governance offers a foundation for regulatory systems capable of learning and adapting with the technologies they oversee.</p></sec></body><back><ack><p>The authors used generative AI tools (Google&#x2019;s Gemini 3 Flash and OpenAI&#x2019;s ChatGPT [GPT-4&#x2013;class model]) solely for literature discovery, organizing background notes, and linguistic editing. All content and final interpretations remain the sole responsibility of the authors.</p></ack><notes><sec><title>Funding</title><p>This research was supported by the Regional Innovation System &#x0026; Education (RISE) Glocal University 30 Project program through the Gangwon RISE Center, funded by the Ministry of Education (MOE) and the Gangwon State (GS), Republic of Korea (2025-RISE-10-009).</p></sec></notes><fn-group><fn fn-type="conflict"><p>JHL is the chief of staff at JNPMEDI. KJ is the founder and chief executive officer of JNPMEDI and holds a financial interest in the company. JNPMEDI provides clinical trial data management and related services. The authors emphasize that this viewpoint does not evaluate, endorse, or promote any specific product or service. All other authors declare no other conflicts of interest.</p></fn></fn-group><glossary><title>Abbreviations</title><def-list><def-item><term id="abb1">AI</term><def><p>artificial intelligence</p></def></def-item><def-item><term id="abb2">AI Act</term><def><p>European Union Artificial Intelligence Act</p></def></def-item><def-item><term id="abb3">DMPA</term><def><p>Digital Medical Products Act</p></def></def-item><def-item><term id="abb4">EU</term><def><p>European Union</p></def></def-item><def-item><term id="abb5">FDA</term><def><p>United States Food and Drug Administration</p></def></def-item><def-item><term id="abb6">MFDS</term><def><p>Ministry of Food and Drug Safety</p></def></def-item><def-item><term id="abb7">PCCP</term><def><p>Predetermined Change Control Plan</p></def></def-item><def-item><term id="abb8">PLD</term><def><p>Product Liability Directive</p></def></def-item><def-item><term id="abb9">RWE</term><def><p>real-world evidence</p></def></def-item><def-item><term id="abb10">SaMD</term><def><p>software as a medical device</p></def></def-item></def-list></glossary><ref-list><title>References</title><ref id="ref1"><label>1</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Ribeiro</surname><given-names>MT</given-names> </name><name name-style="western"><surname>Singh</surname><given-names>S</given-names> </name><name name-style="western"><surname>Guestrin</surname><given-names>C</given-names> </name></person-group><article-title>&#x201C;Why should I trust you?&#x201D;: explaining the predictions of any classifier</article-title><source>KDD &#x2019;16: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining</source><year>2016</year><publisher-name>Association for Computing Machinery</publisher-name><pub-id pub-id-type="doi">10.1145/2939672.2939778</pub-id></nlm-citation></ref><ref id="ref2"><label>2</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kelly</surname><given-names>CJ</given-names> </name><name name-style="western"><surname>Karthikesalingam</surname><given-names>A</given-names> </name><name name-style="western"><surname>Suleyman</surname><given-names>M</given-names> </name><name name-style="western"><surname>Corrado</surname><given-names>G</given-names> </name><name name-style="western"><surname>King</surname><given-names>D</given-names> </name></person-group><article-title>Key challenges for delivering clinical impact with artificial intelligence</article-title><source>BMC Med</source><year>2019</year><month>10</month><day>29</day><volume>17</volume><issue>1</issue><fpage>195</fpage><pub-id pub-id-type="doi">10.1186/s12916-019-1426-2</pub-id><pub-id pub-id-type="medline">31665002</pub-id></nlm-citation></ref><ref id="ref3"><label>3</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Cabitza</surname><given-names>F</given-names> </name><name name-style="western"><surname>Rasoini</surname><given-names>R</given-names> </name><name name-style="western"><surname>Gensini</surname><given-names>GF</given-names> </name></person-group><article-title>Unintended consequences of machine learning in medicine</article-title><source>JAMA</source><year>2017</year><month>08</month><day>8</day><volume>318</volume><issue>6</issue><fpage>517</fpage><lpage>518</lpage><pub-id pub-id-type="doi">10.1001/jama.2017.7797</pub-id><pub-id pub-id-type="medline">28727867</pub-id></nlm-citation></ref><ref id="ref4"><label>4</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Beam</surname><given-names>AL</given-names> </name><name name-style="western"><surname>Kohane</surname><given-names>IS</given-names> </name></person-group><article-title>Big data and machine learning in health care</article-title><source>JAMA</source><year>2018</year><month>04</month><day>3</day><volume>319</volume><issue>13</issue><fpage>1317</fpage><lpage>1318</lpage><pub-id pub-id-type="doi">10.1001/jama.2017.18391</pub-id><pub-id pub-id-type="medline">29532063</pub-id></nlm-citation></ref><ref id="ref5"><label>5</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Vayena</surname><given-names>E</given-names> </name><name name-style="western"><surname>Blasimme</surname><given-names>A</given-names> </name><name name-style="western"><surname>Cohen</surname><given-names>IG</given-names> </name></person-group><article-title>Machine learning in medicine: addressing ethical challenges</article-title><source>PLoS Med</source><year>2018</year><month>11</month><volume>15</volume><issue>11</issue><fpage>e1002689</fpage><pub-id pub-id-type="doi">10.1371/journal.pmed.1002689</pub-id><pub-id pub-id-type="medline">30399149</pub-id></nlm-citation></ref><ref id="ref6"><label>6</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Davis</surname><given-names>SE</given-names> </name><name name-style="western"><surname>Lasko</surname><given-names>TA</given-names> </name><name name-style="western"><surname>Chen</surname><given-names>G</given-names> </name><name name-style="western"><surname>Siew</surname><given-names>ED</given-names> </name><name name-style="western"><surname>Matheny</surname><given-names>ME</given-names> </name></person-group><article-title>Calibration drift in regression and machine learning models for acute kidney injury</article-title><source>J Am Med Inform Assoc</source><year>2017</year><month>11</month><day>1</day><volume>24</volume><issue>6</issue><fpage>1052</fpage><lpage>1061</lpage><pub-id pub-id-type="doi">10.1093/jamia/ocx030</pub-id><pub-id pub-id-type="medline">28379439</pub-id></nlm-citation></ref><ref id="ref7"><label>7</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Finlayson</surname><given-names>SG</given-names> </name><name name-style="western"><surname>Bowers</surname><given-names>JD</given-names> </name><name name-style="western"><surname>Ito</surname><given-names>J</given-names> </name><name name-style="western"><surname>Zittrain</surname><given-names>JL</given-names> </name><name name-style="western"><surname>Beam</surname><given-names>AL</given-names> </name><name name-style="western"><surname>Kohane</surname><given-names>IS</given-names> </name></person-group><article-title>Adversarial attacks on medical machine learning</article-title><source>Science</source><year>2019</year><month>03</month><day>22</day><volume>363</volume><issue>6433</issue><fpage>1287</fpage><lpage>1289</lpage><pub-id pub-id-type="doi">10.1126/science.aaw4399</pub-id><pub-id pub-id-type="medline">30898923</pub-id></nlm-citation></ref><ref id="ref8"><label>8</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Amann</surname><given-names>J</given-names> </name><name name-style="western"><surname>Blasimme</surname><given-names>A</given-names> </name><name name-style="western"><surname>Vayena</surname><given-names>E</given-names> </name><name name-style="western"><surname>Frey</surname><given-names>D</given-names> </name><name name-style="western"><surname>Madai</surname><given-names>VI</given-names> </name><collab>Precise4Q Consortium</collab></person-group><article-title>Explainability for artificial intelligence in healthcare: a multidisciplinary perspective</article-title><source>BMC Med Inform Decis Mak</source><year>2020</year><month>11</month><day>30</day><volume>20</volume><issue>1</issue><fpage>310</fpage><pub-id pub-id-type="doi">10.1186/s12911-020-01332-6</pub-id><pub-id pub-id-type="medline">33256715</pub-id></nlm-citation></ref><ref id="ref9"><label>9</label><nlm-citation citation-type="web"><article-title>Marketing submission recommendations for a predetermined change control plan for artificial intelligence-enabled device software functions</article-title><source>U.S. Food and Drug Administration</source><year>2025</year><access-date>2026-05-01</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/media/166704/download">https://www.fda.gov/media/166704/download</ext-link></comment></nlm-citation></ref><ref id="ref10"><label>10</label><nlm-citation citation-type="web"><article-title>Use of real-world evidence to support regulatory decision-making for medical devices</article-title><source>U.S. Food and Drug Administration</source><year>2025</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices">https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices</ext-link></comment></nlm-citation></ref><ref id="ref11"><label>11</label><nlm-citation citation-type="web"><article-title>Quality Management System Regulation (QMSR)</article-title><source>U.S. Food and Drug Administration</source><access-date>2026-05-01</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr">https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr</ext-link></comment></nlm-citation></ref><ref id="ref12"><label>12</label><nlm-citation citation-type="web"><article-title>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending regulations (EC) no 300/2008, (EU) no 167/2013, (EU) no 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (text with EEA relevance)</article-title><source>European Union</source><year>2024</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng</ext-link></comment></nlm-citation></ref><ref id="ref13"><label>13</label><nlm-citation citation-type="web"><article-title>Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC (text with EEA relevance)</article-title><source>European Union</source><year>2024</year><access-date>2026-05-01</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng">https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng</ext-link></comment></nlm-citation></ref><ref id="ref14"><label>14</label><nlm-citation citation-type="web"><article-title>Digital Medical Products Act</article-title><source>Ministry of Food and Drug Safety, Republic of Korea</source><access-date>2026-05-01</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=259299#0000">https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=259299#0000</ext-link></comment></nlm-citation></ref><ref id="ref15"><label>15</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Lee</surname><given-names>JH</given-names> </name><name name-style="western"><surname>Choi</surname><given-names>B</given-names> </name><name name-style="western"><surname>Jeong</surname><given-names>K</given-names> </name><etal/></person-group><article-title>Diverging regulatory DNA in adaptive medical AI: US agility and EU accountability in lifecycle governance</article-title><source>Front Med (Lausanne)</source><year>2026</year><volume>13</volume><fpage>1758708</fpage><pub-id pub-id-type="doi">10.3389/fmed.2026.1758708</pub-id></nlm-citation></ref><ref id="ref16"><label>16</label><nlm-citation citation-type="web"><article-title>Software as a Medical Device (SaMD): key definitions</article-title><source>International Medical Device Regulators Forum</source><year>2013</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.imdrf.org/documents/software-medical-device-samd-key-definitions">https://www.imdrf.org/documents/software-medical-device-samd-key-definitions</ext-link></comment></nlm-citation></ref><ref id="ref17"><label>17</label><nlm-citation citation-type="web"><article-title>Software as a Medical Device: possible framework for risk categorization and corresponding considerations</article-title><source>International Medical Device Regulators Forum</source><year>2014</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.imdrf.org/documents/software-medical-device-possible-framework-risk-categorization-and-corresponding-considerations">https://www.imdrf.org/documents/software-medical-device-possible-framework-risk-categorization-and-corresponding-considerations</ext-link></comment></nlm-citation></ref><ref id="ref18"><label>18</label><nlm-citation citation-type="web"><article-title>Software as a Medical Device (SaMD): clinical evaluation</article-title><source>International Medical Device Regulators Forum</source><year>2017</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.imdrf.org/documents/software-medical-device-samd-clinical-evaluation">https://www.imdrf.org/documents/software-medical-device-samd-clinical-evaluation</ext-link></comment></nlm-citation></ref><ref id="ref19"><label>19</label><nlm-citation citation-type="web"><article-title>Business guidelines for the implementation of Digital Medical Products Regulations</article-title><source>Ministry of Food and Drug Safety, Republic of Korea</source><year>2025</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.mfds.go.kr/brd/m_1060/view.do?seq=15629">https://www.mfds.go.kr/brd/m_1060/view.do?seq=15629</ext-link></comment></nlm-citation></ref><ref id="ref20"><label>20</label><nlm-citation citation-type="web"><article-title>Guidelines for the approval and review of digital medical devices applying artificial intelligence technology</article-title><source>Ministry of Food and Drug Safety, Republic of Korea</source><year>2025</year><access-date>2026-02-16</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.mfds.go.kr/brd/m_1060/view.do?seq=15657">https://www.mfds.go.kr/brd/m_1060/view.do?seq=15657</ext-link></comment></nlm-citation></ref><ref id="ref21"><label>21</label><nlm-citation citation-type="web"><person-group person-group-type="author"><collab>Ministry of Health and Welfare (Republic of Korea)</collab></person-group><article-title>Healthcare 4.0 Era for Healthy Korea</article-title><source>Ministry of Health and Welfare</source><year>2023</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.mohw.go.kr/board.es?act=view&#x0026;bid=0032&#x0026;list_no=375996&#x0026;mid=a20401000000">https://www.mohw.go.kr/board.es?act=view&#x0026;bid=0032&#x0026;list_no=375996&#x0026;mid=a20401000000</ext-link></comment></nlm-citation></ref><ref id="ref22"><label>22</label><nlm-citation citation-type="web"><article-title>The world&#x2019;s first blood pressure measurement mobile app approved as medical device</article-title><source>Ministry of Food and Drug Safety, Republic of Korea</source><year>2020</year><access-date>2026-04-22</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.mfds.go.kr/eng/brd/m_61/view.do?seq=9">https://www.mfds.go.kr/eng/brd/m_61/view.do?seq=9</ext-link></comment></nlm-citation></ref><ref id="ref23"><label>23</label><nlm-citation citation-type="web"><article-title>Ethics and governance of artificial intelligence for health</article-title><source>World Health Organization</source><year>2021</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.who.int/publications/i/item/9789240029200">https://www.who.int/publications/i/item/9789240029200</ext-link></comment></nlm-citation></ref><ref id="ref24"><label>24</label><nlm-citation citation-type="web"><article-title>Health data governance for the digital age</article-title><source>Organisation for Economic Co-operation and Development</source><year>2022</year><access-date>2026-02-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.oecd.org/en/publications/health-data-governance-for-the-digital-age_68b60796-en.html">https://www.oecd.org/en/publications/health-data-governance-for-the-digital-age_68b60796-en.html</ext-link></comment></nlm-citation></ref><ref id="ref25"><label>25</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Price</surname><given-names>WN</given-names>  <suffix>2nd</suffix></name><name name-style="western"><surname>Gerke</surname><given-names>S</given-names> </name><name name-style="western"><surname>Cohen</surname><given-names>IG</given-names> </name></person-group><article-title>Potential liability for physicians using artificial intelligence</article-title><source>JAMA</source><year>2019</year><month>11</month><day>12</day><volume>322</volume><issue>18</issue><fpage>1765</fpage><lpage>1766</lpage><pub-id pub-id-type="doi">10.1001/jama.2019.15064</pub-id><pub-id pub-id-type="medline">31584609</pub-id></nlm-citation></ref><ref id="ref26"><label>26</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Gerke</surname><given-names>S</given-names> </name><name name-style="western"><surname>Minssen</surname><given-names>T</given-names> </name><name name-style="western"><surname>Cohen</surname><given-names>IG</given-names> </name></person-group><person-group person-group-type="editor"><name name-style="western"><surname>Bohr</surname><given-names>A</given-names> </name><name name-style="western"><surname>Memarzadeh</surname><given-names>K</given-names> </name></person-group><article-title>Ethical and legal challenges of artificial intelligence&#x2013;driven health care</article-title><source>Artificial Intelligence in Healthcare</source><year>2020</year><publisher-name>Academic Press</publisher-name><fpage>295</fpage><lpage>336</lpage><pub-id pub-id-type="doi">10.1016/B978-0-12-818438-7.00012-5</pub-id></nlm-citation></ref><ref id="ref27"><label>27</label><nlm-citation citation-type="other"><person-group person-group-type="author"><name name-style="western"><surname>Leslie</surname><given-names>D</given-names> </name></person-group><article-title>Understanding artificial intelligence ethics and safety: a guide for the responsible design and implementation of AI systems in the public sector</article-title><source>SSRN</source><access-date>2026-05-01</access-date><comment>Preprint posted online on  Aug 18, 2020</comment><comment><ext-link ext-link-type="uri" xlink:href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3403301">https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3403301</ext-link></comment></nlm-citation></ref><ref id="ref28"><label>28</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Moln&#x00E1;r-G&#x00E1;bor</surname><given-names>F</given-names> </name></person-group><article-title>Implementing the human right to science in the context of health-related data processing</article-title><source>J Law Biosci</source><year>2024</year><volume>11</volume><issue>1</issue><fpage>lsae004</fpage><pub-id pub-id-type="doi">10.1093/jlb/lsae004</pub-id><pub-id pub-id-type="medline">38495856</pub-id></nlm-citation></ref></ref-list></back></article>