APIs, integration & security — in depth

Surgical Robot Autonomy and Regulatory Constraints

The FDA's "robotically-assisted" label masks surgical robots that already operate autonomously.

Contributing Editor · · 10 min read
Cover illustration for “Surgical Robot Autonomy and Regulatory Constraints”
Industry Deployment · October 5, 2026 · 10 min read · 2,355 words

Surgical robots cleared by the FDA already make decisions, and no surgeon directs them in real time, even though the agency's own vocabulary says otherwise. Since 2015, the FDA has required that cleared systems be called "robotically-assisted surgical devices," a label chosen to assert one thing: the surgeon stays in continuous, direct control, and the machine has no independent judgment of its own.

Why "robotically-assisted surgical device" no longer fits these machines

The phrase "robotically-assisted surgical device" was never just a description. It was built to carry a legal conclusion: the surgeon is the accountable party, and the device is an extension of the surgeon's hands, nothing more. That framing fit the original da Vinci system well enough. It scaled down tremor, it amplified fine motion, and it translated the surgeon's gestures into instrument movement, but a surgeon had already made every decision it carried out.

That description stops matching reality once a device plans a procedure from a patient's own anatomy and then carries out that plan with only intermittent human review. Devices now cleared under the same regulatory label carry out pre-programmed surgical tasks on their own, and they adapt those tasks to the patient on the table, with no surgeon guiding each motion. Calling that "robotically-assisted" isn't a simplification; it obscures the actual division of labor between the person and the machine, and that obscuring has consequences, because the words in a regulatory filing determine which pathway a device enters, what evidence the FDA demands before clearance, and who ends up answering for a bad outcome.

The disclosure side of this gap is just as serious. A 2024 systematic review out of Mount Sinai, published in npj Digital Medicine, found that some cleared systems advertised machine-learning capabilities in their marketing materials that never appeared in the regulatory summaries the FDA itself published. The agency's own public record, in other words, understated what some of these devices can actually do. The classification system hid autonomy by design, so its paperwork still hides it.

The LASR scale and devices already in operating rooms

A framework called Levels of Autonomy in Surgical Robotics, or LASR, gives the field a way to see what the FDA's surgeon-controls-everything model treats as one undifferentiated category. LASR runs from Level 1, pure robot assistance, up to Level 5, full autonomy with no human in the loop. The levels in between track one question: at each stage, who is actually deciding what the instrument does next?

Level 1 is the easiest to picture. The surgeon decides everything, moment to moment, and the robot's job is to stabilize and scale that input. Level 2, task autonomy, looks different: the device carries out a specific, pre-programmed surgical step on its own, and the surgeon's role shifts from guiding each motion to reviewing what the device does. Level 3, conditional autonomy, goes further still. The device builds a procedural plan from the patient's own imaging and anatomical data, then acts on that plan, while the surgeon supervises and retains the ability to step in but isn't directing the work step by step. Level 4 and Level 5 systems don't yet exist among cleared devices, but researchers studying the field have flagged a mechanism, "predicate creep," by which a string of 510(k) clearances, each one only slightly more autonomous than the last, could land the field at Level 4 or beyond without any single clearance ever facing the scrutiny that jump would warrant on its own.

The Mount Sinai review identified 49 FDA-cleared surgical robots, and the analysis by Lee and colleagues found that 86% of them are at Level 1. So a meaningful share, roughly one in seven, already operates at Level 2 or Level 3, executing tasks or plans with only supervisory human involvement. Orthopedic systems, particularly those used in spine, knee, and hip procedures, show up disproportionately among the higher-autonomy devices, and bone-milling is probably the clearest example of Level 3 conditional autonomy already working in operating rooms today. The TSolution One illustrates the pattern concretely: the system plans the bone preparation and carries it out, and the surgeon's job is to supervise that execution.

Diagram: Where Cleared Surgical Robots Fall on the Autonomy Scale. Visualizes: Visualize the distribution of 49 FDA-cleared surgical robots across the LASR autonomy levels.

How the 510(k) pathway assumed surgeons drove everything

Most surgical robots reach the market through the 510(k) pathway, a system built around a single test: is the new device substantially equivalent, in intended use and technological design, to a device already legally on the market? If a manufacturer can show that equivalence, no clinical trial is required. If a tool stays under the surgeon's full control, an incremental improvement to it fits that logic. It stops making sense the moment the new device adds a layer of decision-making that its predicate never had, because equivalence in design says nothing about equivalence in judgment.

The Mount Sinai review found that clinical testing data accompanied only a minority of Level 1 clearances, but every Level 3 system needed it, and so did a large majority of Level 2 systems. The pathway built for incremental tool upgrades is already being pushed well past its original design at the upper end of the autonomy scale, and the strain shows in how much more evidence those upper-level systems need before the FDA will sign off.

Predicate creep is the mechanism that makes this hard to fix one clearance at a time. Each new submission only has to show small equivalence to the version just before it, so across many iterations a device can end up dramatically more autonomous than its original predicate, without a single step along the way ever triggering the kind of heightened review that a direct comparison to that distant ancestor would call for. The machine-learning disclosure gap makes the problem worse: if a cleared device has ML-enabled capabilities absent from its FDA summary, neither the predicate comparison nor any downstream oversight actually captures what the device is doing.

The De Novo pathway offers a partial fix: a genuinely novel device can reach market through it without a predicate at all, if the manufacturer supplies more evidence up front. The Mount Sinai authors go further, suggesting that Level 4 and Level 5 systems, once they exist, may need reclassification as Class III, high-risk devices subject to full premarket approval. That proposal carries a real tradeoff that the field hasn't settled. Class III status would slow innovation and raise development costs substantially for manufacturers. But if high-autonomy systems stay inside the 510(k) framework, that risks safety gaps that stay hidden until a device is already deployed across many hospitals.

What frontier devices are doing beyond cleared frameworks

Research systems have already moved past what any cleared device does, so they have outrun what any current regulatory pathway was built to assess. A research team at Johns Hopkins published results in Science Robotics describing an experiment with a system called SRT-H, which autonomously performed key steps of gallbladder removal, clipping and cutting the cystic duct and artery, on eight ex vivo pig specimens, with no human intervention at any point. The system completed all eight procedures, and it even corrected its own errors and adjusted to anatomical variation between specimens on its own. The surgeon was absent for a full step of cholecystectomy. The tissue was ex vivo, not living, human tissue, so the clinical distance from this result to an operating room remains large, but the capability on display, autonomous error correction combined with real-time anatomical adaptation, is a different kind of achievement than anything built into a cleared Level 3 device today.

A team at Shanghai MicroPort MedBot performed an abdominal surgery on a living pig using the company's Toumai system in December 2025, under full human supervision with surgeons able to intervene at any moment, in what was described as a world-first for in vivo autonomous robotic surgery. No peer-reviewed publication of that trial existed at the time the claim circulated, so the result rests on reporting from the company itself rather than independent scientific validation, and that distinction matters when weighing how much the claim should move anyone's assessment of where the field stands. Toumai has also received FDA clearance under a pathway for clinical remote robotic surgery studies in the United States, but that pathway only permits a controlled clinical investigation. It is not the same as clearance for clinical use, and the regulatory distance between the two remains wide.

Intuitive's da Vinci 5, cleared in January 2026 for cardiac procedures, is in a more modest place on this spectrum but still matters as a marker of pace. The system introduced force feedback, so the surgeon could feel resistance from tissue, and preclinical data showed that it cut the force surgeons applied, at every experience level. That reduction hasn't yet translated into demonstrated clinical superiority in published trials, and the da Vinci 5 stays fully inside the surgeon-controlled model. Its relevance here isn't autonomy. It shows that even the field's most established manufacturer adds capability layers fast, and evaluation frameworks need to catch up.

What the FDA's September 2026 draft guidance covers

The FDA released its most detailed regulatory framework for surgical robots to date on September 25, 2026: a 50-page draft guidance addressing system stability and latency, instrument motion and position control, visualization, software, wireless technology, cybersecurity, sterilization, labeling, and training, all tied to the clinical and non-clinical data a manufacturer needs for a premarket submission. The guidance sets specific clinical endpoints for different categories of procedure and introduces an "umbrella" approval mechanism, under which clearance for a more complex procedure within a category can cover related, simpler procedures, cutting the evidence burden for incremental expansions of an already-cleared system.

Analysts at Evercore ISI read the guidance as a genuine win for industry, since it replaces a prior framework that left real ambiguity with a defined pathway, and they singled out software and cybersecurity requirements as areas that can otherwise become costly, unpredictable hurdles without a standardized set of expectations. On those fronts, the guidance represents substantial, concrete progress for the field.

The guidance states that it does not address remotely teleoperated robotically-assisted surgical devices, nor autonomous robots that carry out significant aspects of an operation independent of a qualified practitioner. That is exactly the category where the autonomy gap runs deepest. The FDA has produced real clarity for the lower-autonomy devices already on the market while setting aside, by its own explicit statement, the harder question the rest of this piece has been tracing.

The FDA has scheduled a public workshop for December 2 and 3, 2026, devoted specifically to autonomous and remotely operated robotic devices, with an agenda covering terminology, technical considerations, and the benefits and risks that come with greater autonomy and remote control. The workshop marks the start of a formal conversation on the harder question, not its resolution. Comments on the September draft guidance are due November 24, 2026, and the December workshop itself is open to the public.

Accountability and autonomy beyond the surgeon's hands

A Level 1 device keeps the surgeon's hands on every motion, so when something goes wrong, responsibility falls on the person who was, in fact, controlling the instrument at every step. That mapping between control and accountability is clean, legally and ethically, because it tracks who actually made the decisions.

Level 2 and Level 3 devices break that mapping. A surgeon supervising a device that plans its own procedure and carries out that plan is reviewing output, not directing action, and assigning that surgeon full responsibility for an error the algorithm introduced treats legal fiction as if it were operational fact. Researchers call this the "moral crumple zone": a survey of surgeons working with these systems found that blame landed on the human operator even in cases where that operator had no real role in the decision that caused the harm. The system absorbs the complexity; the person nearest the controls absorbs the consequences.

That ambiguity is built into the structure of these devices, not an accident of how any one case unfolds. When an autonomous decision leads to a bad outcome, at least three parties could reasonably bear responsibility: the surgeon, for trusting a flawed recommendation; the hospital, for inadequate training or maintenance of the system; or the manufacturer, for a defect in the underlying algorithm. Current law has no clean rule for sorting a claim among those three, and that uncertainty shapes how hospitals adopt these systems and how manufacturers write their warnings and training materials.

The "human-in-the-loop" idea, as currently applied, risks becoming a formality rather than a genuine safeguard once autonomy climbs past Level 1. A surgeon who monitors a plan without directing its execution is not exercising meaningful control over what the device does, yet that surgeon's nominal presence in the room still counts, under the current framework, as sufficient oversight.

The Mount Sinai authors frame the fix as a standard of "meaningful human control," one they argue still holds up for today's Level 2 and Level 3 systems but won't hold once Level 4 and Level 5 devices arrive, absent a genuinely new accountability structure built for them. Informed consent carries the same unresolved problem one layer up: existing consent frameworks assume a surgeon making real-time decisions, and they have not been rebuilt for a procedure where the operating algorithm makes those decisions and the surgeon's role is to watch. Surgical training faces a slower version of the same question. As autonomous systems take on more of the physical and cognitive work of an operation, the competency standards and training pipelines built around manual technique will need to change, and nothing in the current regulatory framework requires that change to happen.

None of this argues against pursuing greater autonomy in surgical robotics. A human-in-the-loop model that pairs algorithmic precision with surgical judgment may well be the right design for high-stakes procedures, and the engineering case for that collaborative approach deserves to be taken seriously rather than dismissed in favor of a race toward full autonomy. But "meaningful" collaboration needs an actual definition, one with legal and clinical teeth, and neither the FDA's September 2026 guidance nor any existing standard has supplied it yet.

Sources

  1. Levels of autonomy in FDA-cleared surgical robots: a systematic review
  2. Federal Register :: Robotically-Assisted Surgical Devices-Premarket Submissions; Draft Guidance for Industry and Food and Drug Administration Staff; Availability
  3. At the cutting edge: the potential of autonomous surgery and challenges faced
  4. Schmidgall et al., Sci. Robot. 10, eadt0187 (2025) 23 July 2025
  5. npj
  6. Surgical Robot Global Market Access 2026 Guide
  7. Medical robotics—Regulatory, ethical, and legal considerations for increasing levels of autonomy
  8. Identification of predicate creep under the 510(k) process: A case study of a robotic surgical device - PMC

More in Industry Deployment