
When Does the TGA Regulate AI as a Medical Device? What Australian AI Companies Need to Know
If your AI product touches health, the most important regulatory question in Australia right now is not about the coming AI-specific laws. It is about a framework that already exists, already has teeth, and already applies: the Therapeutic Goods Administration's regulation of software as a medical device, known as SaMD.
The TGA has been steadily clarifying how that framework applies to AI, including large language models, chatbots, symptom checkers and digital scribes. The clarification matters because many founders assume medical device regulation is about hardware, or about software that ships inside hospital equipment. It is not. The framework is technology-neutral, and it turns on a single idea: intended purpose.
The test is what your product is for, and what you say it is for
Software is a medical device in Australia when it is intended for a therapeutic use, broadly, the diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of a disease, injury or disability in people. Crucially, intended purpose is not read from what your engineers had in mind. It is read from what you publish: your technical documentation, labelling, instructions, website, app-store listing and marketing.
A single landing page that promises to "detect skin cancer early" or "diagnose from your symptoms" can bring a product into the medical device framework on its own, regardless of what the engineering team intended.
On the regulated side of the line sit products such as:
- Digital therapeutics: software products that deliver a medical intervention themselves
- Clinical decision support tools that provide diagnostic or treatment recommendations
- AI chatbots and LLM-based products presented for clinical purposes
- Symptom checkers marketed as informing clinical decisions
- Digital scribes that go beyond transcription and add suggested diagnoses, codes or next steps
Outside the framework sit general health and wellness apps, and software genuinely presented as informational only. But note the asymmetry: those products stay out of scope only while their claims stay general. The TGA's approach means feature creep and marketing creep both count. A wellness app that adds a "risk score" feature, or a scribe that starts suggesting diagnoses, has changed its regulatory position, whether or not anyone noticed internally.
What being regulated actually means
If your software is a medical device, the obligations are substantial and sit with manufacturers and sponsors:
- Inclusion on the Australian Register of Therapeutic Goods (ARTG) before the product is supplied
- Risk classification, which drives how much evidence and assessment is required
- Robust, transparent evidence of safety and performance against the Essential Principles, and for AI that means documented model design, training and validation processes, data quality and risk management
- Marketing that stays aligned with the approved intended purpose, and monitoring for off-label use
- Adverse event reporting once the product is in the market
Two things make this urgent rather than theoretical. First, the TGA has signalled that SaMD compliance is a priority for its 2026-27 enforcement activities. Second, adding a feature that changes your intended purpose can require a variation or a new registration before the feature ships, which is a product-roadmap problem, not just a legal one. The practical advice from regulatory lawyers is to build a regulatory checkpoint into the development cycle itself, so the question "does this change our intended purpose?" gets asked while a feature is still a ticket, not a launch.
Not sure where you stand? Start with two minutes
We have built a free self-check based on the TGA framework: five questions on your product's purpose, who relies on its output, and what your marketing claims. It is general information rather than advice, but it will tell you quickly whether you are clearly out of scope, clearly in it, or in the borderline zone where the details decide, and what sensible next steps look like in each case.
Where responsible AI certification fits
It is worth being precise about the relationship between TGA regulation and Responsible AI Australia certification, because they answer different questions and neither replaces the other. The TGA regulates the product: whether it is safe, performs as claimed, and may lawfully be supplied. Certification assesses the organisation: whether the business behind the AI governs it responsibly, with documented design decisions, attention to training data, validation, risk management, human oversight and accountability.
Certification is not TGA approval and is no substitute for it. But the two stack naturally. The evidence the TGA expects for an AI medical device, documented model design, data quality, validation, monitoring, is precisely the governance discipline certification assesses. A health AI company that builds that discipline once serves both: the regulator that oversees its product, and the hospitals, insurers and patients who want proof the organisation behind it takes responsible AI seriously. And for health AI products that sit outside the TGA's scope, certification remains one of the few independent signals of governance available at all.
Our certification application now asks health-sector applicants an optional question about their product's TGA status, so assessors can see the full regulatory context, and businesses already on the ARTG get credit for the work that took.
The takeaway
If you are building AI that touches health in Australia, do the intended purpose thinking now. Write down what your product is for. Read your own marketing the way a regulator would. If there is any doubt, get advice from a regulatory affairs professional, because the cost of resolving this before launch is a fraction of resolving it after.
This article is general information, not legal or regulatory advice. Whether a particular product is a medical device is a question only the TGA can determine; for guidance on your own product, consult the TGA's software and AI guidance or a regulatory professional.
