FDA says its AI assistant is moving on top of the agency's consolidated application and submission data. The expansion is real, and it raises a fair question for an agency built around evidence: how does the system affect a device review?
Most of what circulates as the answer did not come from FDA. It came from trade coverage, repeated often enough to read as settled fact.
The agency's own record is much thinner.
What FDA has confirmed
FDA launched Elsa agency-wide on 2 June 2025. The agency said it arrived ahead of its 30 June deadline and under budget.
The first use cases sounded practical. Elsa could summarize adverse event reports, compare labels, help with clinical protocol reviews, generate code for nonclinical databases and identify inspection priorities. FDA also said the models would not train on data submitted by regulated companies.
The architecture was less clear. FDA described a high-security GovCloud environment. It did not name AWS, Deloitte, a retrieval architecture or a foundation model in the launch release. Those details arrived later through trade coverage, and they have circulated ever since as though the agency confirmed them.
The public story changed on 6 May 2026. FDA announced Elsa 4.0 and HALO, a platform that consolidated more than 40 application and submission sources across the agency. FDA said it had begun connecting Elsa to HALO, allowing staff to work with agency data without manually uploading it.
Chief AI Officer Jeremy Walsh put it plainly: “Previously, FDA staff would bring data to Elsa. Now, Elsa sits on top of our data.”
Elsa 4.0 added custom agents, document generation, quantitative analysis, charts, OCR, dictation and secure web search. FDA said the system runs in a FedRAMP High Google Cloud environment and still does not train on industry data.
The expansion is meaningful. It does not prove Elsa reads every 510(k), reads a submission before a person or shapes a final decision. A claim needs to stop where the evidence stops.
The device story is still murky
Start with what FDA did not say. The Elsa 4.0 announcement runs several hundred words on new capabilities and mentions medical devices exactly once, in the boilerplate description of the agency at the bottom. No CDRH. No 510(k). Nothing about device review anywhere in it.
The silence proves nothing on its own. It is also the most current evidence available, and it does not support the idea that device review is where Elsa has been pushed hardest.
The clearest account of a device-specific tool is older. NBC News reported in June 2025 that two people familiar with CDRH-GPT described a beta system meant to help device reviewers. They reported failed uploads, broken queries and weak connections to internal systems. They also said it could not reach recent or paywalled literature.
The reporting was solid and it is now fourteen months old. It shows a troubled beta in June 2025. It says nothing about the tool's condition today or whether its functions moved into Elsa 4.0.
The same caution applies to hallucinations. CNN reported in July 2025 that current and former FDA staff had seen Elsa invent or misstate research. Commissioner Marty Makary described its role more narrowly, pointing to tasks such as finding studies and summarizing meetings. He also said use was optional.
Both accounts can be true. A system can save time and still produce confident nonsense, which is why the controls matter more than the demo.
Do not fold inspections into the same claim
FDA also started a one-day inspectional assessment pilot in April 2026. By late April, the agency said it had completed about 46 assessments and most ended with No Action Indicated.
The FDA announcement says facilities are selected using risk-based criteria such as product type, prior inspection outcomes and operational characteristics. Higher-risk or complex facilities are not eligible. The release does not say Elsa chooses the sites. It does not mention Elsa, AI or artificial intelligence at all. A later Sidley analysis reported that Makary linked the pilot to AI-backed risk analysis.
The distinction is easy to lose. FDA is using AI in operations and it is testing shorter inspections. Public evidence does not show that Elsa runs the selection process.
The real gap is traceability
Device companies already know the rule: if software helps create or maintain a regulated electronic record, its controls need to match the risk. Under 21 CFR 11.10, covered systems require validation, access controls and record protection.
Part 11 does not automatically apply to FDA's internal deployment in the same way. The comparison is still hard to ignore. Industry must explain what its systems do, who used them and how the record stayed trustworthy. FDA has not publicly described the equivalent controls around Elsa in enough detail to let sponsors understand its role.
The open questions are basic:
- When can Elsa access a device submission?
- Which review tasks may use its output?
- Does a reviewer have to verify or cite that output?
- Are prompts and responses retained with the decision record?
- How does FDA test a model change before it reaches regulated work?
The last question is not theoretical. NOTUS reported in March 2026 that HHS removed enterprise access to Anthropic's Claude. An internal FDA banner reportedly said Elsa was moving away from Anthropic and that Google's Gemini would become its primary model. FDA's public Elsa releases do not identify the models or explain the change controls.
That does not prove FDA skipped validation. It proves the public cannot assess it.
What device companies can do now
You don't need to write submissions for an imagined robot reviewer. You do need to make them easy for people and software to read.
- Put the conclusion beside the evidence that supports it.
- Use the same device, endpoint and predicate terms throughout the submission.
- Keep tables machine-readable and avoid scans when native text is available.
- Record material FDA communications and ask how an AI-derived issue was verified if it appears in review feedback.
None of that games Elsa. It is sound submission practice.
I think FDA is right to automate clerical work. Reviewers should spend less time hunting through files and more time judging evidence. Faster access to the right record can help both the agency and the company waiting on a decision.
But speed does not replace traceability. FDA asks device companies to show their work. On Elsa, the agency should do the same.