HSA AI-SaMD Exemption Pathway: Singapore Public Healthcare Institutions Decision Guide
Singapore's Health Sciences Authority (HSA) has introduced an exemption pathway for artificial intelligence Software as a Medical Device (AI-SaMD) developed by public healthcare institutions, creating a new regulatory option for hospital-built clinical AI systems. For hospital CIOs, clinical informatics teams, and AI engineers in Singapore's public healthcare clusters, this changes the decision tree for when to pursue full product registration versus institutional exemption. We've worked with teams navigating both HSA product registration and institutional deployment pathways, and the differences matter more than most assume.
Key takeaways
- HSA now offers an exemption from manufacturer licensing and product registration requirements for selected AI-SaMD developed by public healthcare entities, subject to conditions [4]
- The exemption pathway is not a shortcut—it requires institutional governance, safety monitoring, and documentation that mirrors commercial SaMD obligations
- Singapore's Model AI Governance Framework provides the operational scaffolding for institutional AI governance, but it is voluntary and principles-based, not prescriptive [1]
- Public healthcare institutions must decide early whether to pursue exemption (institutional use only) or full registration (potential commercialization), as the pathways diverge in documentation, liability, and post-market surveillance design
- The exemption pathway aligns with FDA's adaptive AI/ML-enabled SaMD thinking but places governance accountability squarely on the institution, not a commercial manufacturer [2]
Why HSA introduced the AI-SaMD exemption pathway
Public healthcare institutions in Singapore have been building clinical AI systems for years—risk stratification models, imaging classifiers, early warning scores, clinical decision support tools. Many of these systems are research-grade or deployed under institutional review board (IRB) oversight, but they occupy a regulatory grey zone: they meet the functional definition of SaMD, but they are not commercially manufactured products.
HSA's response to public consultation clarifies that selected AI-SaMD developed by public healthcare entities may qualify for exemption from manufacturer licensing and product registration requirements, provided they meet specific conditions [4]. The exemption is designed to reduce regulatory friction for hospital-built AI while maintaining patient safety standards.
This is not a blanket exemption. HSA has not published exhaustive eligibility criteria in the public domain, but the consultation response signals that exemption is conditional on institutional governance, risk classification, and intended use scope. The pathway is aimed at AI-SaMD used within the developing institution, not distributed commercially.
What qualifies for exemption—and what doesn't
The exemption pathway is not a substitute for HSA product registration if your AI-SaMD will be:
- Distributed to other healthcare institutions (even within the same cluster)
- Commercialized or licensed to third parties
- Used in high-risk clinical decision-making without human oversight (e.g., autonomous diagnostic AI)
- Integrated into third-party EHR or PACS systems as a commercial module
If your AI-SaMD is intended for institutional use only, developed in-house, and subject to institutional clinical governance, the exemption pathway may apply. But "institutional use only" is narrower than it sounds. In our experience, many hospital AI projects start as single-site pilots but are designed with multi-site deployment in mind. If your roadmap includes cross-institution deployment, you are building a product, not an institutional tool, and the exemption pathway will not cover you.
The risk classification of your AI-SaMD also matters. HSA follows the International Medical Device Regulators Forum (IMDRF) risk-based framework for SaMD, which classifies devices by the significance of the information provided and the healthcare situation or condition. High-risk SaMD (e.g., AI that drives critical treatment decisions) will face higher scrutiny even under the exemption pathway, and may not qualify at all.
How the exemption pathway compares to full HSA registration
The exemption pathway is not a documentation-free zone. HSA expects public healthcare institutions to maintain governance structures that mirror commercial SaMD obligations:
- Clinical validation: Evidence that the AI-SaMD performs as intended in the target population, including performance metrics, failure modes, and clinical utility data
- Risk management: ISO 14971-aligned risk assessment, hazard analysis, and mitigation controls
- Post-market surveillance: Continuous monitoring of AI-SaMD performance, adverse events, and model drift (see our earlier post on shortcut bias and continuous monitoring)
- Change control: Documented procedures for algorithm updates, retraining, and version control
- Data governance: PDPA-compliant data handling, consent management, and audit trails
The difference is accountability. Under full HSA registration, the manufacturer is the legal entity responsible for safety and performance. Under the exemption pathway, the public healthcare institution assumes that role. This has implications for liability, insurance, and institutional risk appetite.
For hospital CIOs and legal teams, this means the exemption pathway shifts regulatory risk from HSA oversight to institutional governance. You are not avoiding regulation—you are internalizing it. If your institution lacks mature AI governance infrastructure, the exemption pathway may create more operational risk than full registration.
Singapore's Model AI Governance Framework as operational scaffolding
Singapore's Model AI Governance Framework, published by the Personal Data Protection Commission (PDPC) and Infocomm Media Development Authority (IMDA), provides a principles-based approach to AI governance [1]. It is voluntary, not mandatory, but it offers a useful operational scaffold for public healthcare institutions pursuing the HSA exemption pathway.
The framework emphasizes:
- Internal governance structures: Clear accountability for AI system owners, data stewards, and clinical sponsors
- Human oversight: Mechanisms for human review of AI-generated recommendations, especially in high-stakes decisions
- Operations management: Monitoring, incident response, and change control processes
- Stakeholder interaction: Transparency with patients, clinicians, and regulators about AI system capabilities and limitations
For AI-SaMD under the exemption pathway, the Model AI Governance Framework translates to:
- Assign a clinical owner for each AI-SaMD, accountable for clinical validation, adverse event reporting, and performance monitoring
- Establish a multidisciplinary AI governance committee with clinical, legal, IT, and data protection representation
- Document risk assessments for each AI-SaMD, including failure modes, clinical impact, and mitigation controls
- Implement continuous monitoring for model drift, performance degradation, and unexpected failure modes (see our post on risk stratification model interpretability)
- Maintain audit trails for algorithm updates, retraining events, and clinical decision overrides
The framework is not a checklist—it is a set of principles that must be operationalized. For institutions without existing AI governance infrastructure, this is non-trivial work. We have seen institutions underestimate the operational lift required to maintain exemption-pathway AI-SaMD at scale.
How FDA's adaptive AI/ML-enabled SaMD approach informs HSA's pathway
HSA's exemption pathway for public healthcare institutions echoes themes from the FDA's approach to AI/ML-enabled SaMD, particularly the concept of predetermined change control plans for adaptive algorithms [2]. The FDA has signaled that it will allow certain AI/ML-enabled SaMD to update algorithms within a predefined "region of change" without requiring new premarket submissions, provided the manufacturer has documented change control procedures and performance monitoring.
HSA has not published detailed guidance on adaptive AI-SaMD under the exemption pathway, but the logic is similar: if your institution can demonstrate robust change control and continuous monitoring, HSA may accept algorithm updates without requiring new exemption filings. This is critical for clinical AI systems that retrain on new data or adapt to population drift.
However, the FDA's adaptive SaMD framework is still evolving, and HSA's approach is even less defined. For Singapore public healthcare institutions, this means:
- Document your change control plan upfront: Define what constitutes a "significant" algorithm change (e.g., retraining on new data, architecture changes, feature engineering updates) and what triggers a new safety review
- Establish performance thresholds: Define acceptable performance ranges (e.g., AUC, sensitivity, specificity) and trigger re-validation if performance degrades below thresholds
- Log all algorithm updates: Maintain version control and audit trails for every algorithm change, including rationale, validation results, and clinical sign-off
Without these controls, adaptive AI-SaMD under the exemption pathway becomes a regulatory liability. If an algorithm update causes patient harm and you cannot demonstrate documented change control, your institution assumes full liability.
Why this matters in Singapore and Asia
Singapore's public healthcare system is relatively centralized, with three major clusters (National Healthcare Group, National University Health System, SingHealth) and strong institutional governance. The HSA exemption pathway is designed for this context—large, well-governed public healthcare institutions with the infrastructure to assume regulatory accountability.
This model may not translate easily to other Asian markets. In countries with more fragmented healthcare systems, weaker institutional governance, or less mature AI governance infrastructure, the exemption pathway could create patient safety risks. Singapore's approach works because the public healthcare institutions have the operational maturity to internalize regulatory obligations.
For Singapore hospitals, the exemption pathway creates a strategic choice:
- Pursue exemption if your AI-SaMD is truly institutional-use-only, you have mature AI governance infrastructure, and you do not plan to commercialize
- Pursue full HSA registration if your AI-SaMD has multi-site or commercial potential, even if it starts as a single-site pilot
The wrong choice has consequences. If you pursue exemption and later decide to commercialize, you will need to backfill full HSA registration documentation, which is harder to retrofit than to build upfront. If you pursue full registration for a purely institutional tool, you will incur unnecessary regulatory overhead.
For our clinical AI services, we help institutions map their AI-SaMD portfolio to the right regulatory pathway early, before architecture and governance decisions lock in.
What to do next
- Audit your AI-SaMD portfolio: Identify which systems meet the functional definition of SaMD and map them to HSA risk classifications (IMDRF framework)
- Assess institutional governance maturity: Do you have the infrastructure (clinical ownership, change control, continuous monitoring, audit trails) to assume regulatory accountability under the exemption pathway?
- Define your commercialization intent early: If multi-site deployment or licensing is on your roadmap, pursue full HSA registration from the start
- Engage HSA early: The exemption pathway is new, and HSA has not published exhaustive guidance. Early consultation with HSA can clarify eligibility and documentation expectations
- Operationalize the Model AI Governance Framework: Use Singapore's Model AI Governance Framework [1] as a scaffold for institutional AI governance, but tailor it to your clinical context and risk appetite
- Document change control plans for adaptive AI: If your AI-SaMD will retrain or adapt over time, define upfront what constitutes a significant change and what triggers re-validation
If you are building clinical AI in Singapore's public healthcare system and need help navigating the HSA exemption pathway versus full registration, start a project with our team.
FAQ
Does the HSA exemption pathway apply to AI-SaMD developed by private hospitals or commercial vendors?
No. The exemption pathway is specifically for AI-SaMD developed by public healthcare entities in Singapore [4]. Private hospitals and commercial vendors must pursue full HSA product registration and manufacturer licensing.
Can I use the exemption pathway for an AI-SaMD that will be deployed across multiple public healthcare institutions?
This is unclear from HSA's public guidance. The exemption is framed as "institutional use," which suggests single-institution deployment. If you plan multi-site deployment, even within the same cluster, consult HSA early to clarify whether the exemption pathway applies or whether you need full registration.
What happens if my AI-SaMD performance degrades after deployment under the exemption pathway?
You are responsible for continuous monitoring and adverse event reporting, just as a commercial manufacturer would be under full registration. If performance degrades below acceptable thresholds, you must investigate, document, and remediate—potentially including algorithm retraining, clinical workflow changes, or system decommissioning. See our post on continuous monitoring for shortcut bias for operational guidance.
How does the HSA exemption pathway interact with Singapore's PDPA and data protection requirements?
The exemption pathway does not exempt you from PDPA obligations. You must still comply with consent, data minimization, purpose limitation, and security requirements for personal health data. The Model AI Governance Framework [1] provides guidance on integrating data protection into AI governance, but PDPA compliance is a separate regulatory obligation. For federated learning and privacy-preserving approaches, see our post on federated learning for hospital data governance.
Sources
[1] Personal Data Protection Commission Singapore. (2020). Model AI Governance Framework. https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework
[2] U.S. Food and Drug Administration. Artificial Intelligence and Machine Learning in Software as a Medical Device. https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-software-medical-device
[3] Health Sciences Authority Singapore. Guidance Documents for Medical Devices and Software Medical Devices. https://www.hsa.gov.sg/medical-devices/guidance-documents
[4] Health Sciences Authority Singapore. Response to Feedback from Public Consultation on the Proposed Exemption from Manufacturer's Licensing and Product Registration Requirements for Artificial Intelligence. https://www.hsa.gov.sg/announcements/response-to-feedback-from-public-consultation-on-the-proposed-exemption-from-manufacturer-s-licensing-and-product-registration-requirements-for-artificial-intelligence/