← Back to Articles
The short answer

HSA revised GL-04, its regulatory guidelines for software medical devices, in December 2025. The revision harmonises definitions, adds clarity on cybersecurity and machine learning, and introduces a streamlined pathway for software changes under a change management programme. For AI specifically, it sets expectations around training and validation dataset documentation, post-market performance monitoring for model drift, controls for models that keep learning after deployment, and explainability documentation for clinical decision support.

What changed

HSA updated GL-04, its regulatory guidelines for software medical devices, in December 2025. The headline revisions harmonise definitions with international practice, clarify requirements for cybersecurity and machine learning, and add a streamlined pathway for software changes made under a change management programme.

That last point is the one product teams tend to care about most, because the alternative is a change process that punishes iteration.

The AI-specific expectations

  • Training and validation dataset documentation. Size, demographics, and labelling methodology. Not just that the model was trained, but on whom and how the ground truth was established.
  • Post-market performance monitoring. A documented process for detecting model drift, distribution shift, and degradation in prediction quality over time.
  • Controls for continuous learning. If the model updates based on post-deployment data, the controls around that have to be documented.
  • Explainability for clinical decision support. How outputs should be interpreted, and what a clinical user should do when the algorithm conflicts with their own judgment.

Why the last one matters more than it looks

The requirement to document what a clinician should do when the model disagrees with them is easy to skim past. It is the most operationally demanding item on the list, because answering it forces a position on where authority sits.

If the answer is that the clinician always overrides, the tool provides less value than the business case assumed. If the answer is that the model should usually win, someone has to defend that in a case review. Most submissions we see avoid the question with language about the tool being decision support rather than decision making, which is true and does not answer it.

Our view

Read as a whole, GL-04's AI additions are a demand for evidence that the developer understood their own model. Dataset demographics, drift detection, and interpretation guidance are not regulatory paperwork invented to slow you down. They are the things you would want to know before letting a system near a patient.

The organisations that find this update painful are usually the ones who built first and documented afterwards. The documentation is hard to produce retrospectively because the decisions it describes were never explicitly made.

Our practical advice: if you are a deployer rather than a developer, ask your vendor for these four items directly. A vendor selling into Singapore should already have them. How quickly and completely they answer tells you a great deal about the maturity of what you are buying.

Sources

  1. Health Sciences Authority, GL-04 Regulatory Guidelines for Software Medical Devices, revised December 2025. hsa.gov.sg
  2. Baker McKenzie, "Singapore: HSA Provides Medical Device Regulatory Updates", June 2026. bakermckenzie.com

Preparing an AI-SaMD Submission

We help teams work out what their evidence actually supports before a regulator asks.

Start a Conversation →