Digital health founders tend to assume regulation is something that happens to hardware — pacemakers, implants, machines that go beep. Then they write a landing page that says their app “detects early signs of skin cancer” or their model “predicts deterioration risk”, and they discover that a sentence of marketing copy has carried them into one of Australia’s more demanding regulatory regimes. Software is squarely a medical device under the Therapeutic Goods Act 1989 (Cth) when it’s intended for a medical purpose, and supplying one without approval is an offence — not a compliance gap to tidy up after launch.
The regime turns almost entirely on one concept, and it’s one founders control: intended purpose.
The Definition: What You Say Your Software Does
Under section 41BD of the Act, software is a medical device if it’s intended to be used for humans for, among other things, the diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease — and, for an injury or disability, its diagnosis, monitoring, treatment, alleviation or compensation. “Prediction” and “prognosis” were added to the disease limb by the February 2021 software reforms precisely to capture the modern product surface: risk scores, early-warning algorithms, triage models.
Intended purpose isn’t what your engineers think the product does — it’s what the manufacturer presents it as doing, assessed from your technical documentation, labels, instructions for use and, critically, your marketing. The TGA’s 2026 guidance on AI and medical device software (summarised here by Clayton Utz) makes the point bluntly: a chatbot, an LLM-based tool or a symptom checker is regulated where it’s presented with clinical intent — providing diagnostic or treatment recommendations — however general-purpose the underlying model is. Your website, your app store listing and your sales deck are regulatory documents. Write them like it.
Three Doors: Excluded, Exempt, or Regulated
When software meets the s41BD definition, there are three possible outcomes, and the differences matter.
1. Excluded — outside the regime entirely. The Therapeutic Goods (Excluded Goods) Determination 2018, amended in 2021 to deal with software, carves out categories the TGA doesn’t regulate at all, including consumer health and wellness products (step counters, sleep trackers, heart-rate and mood monitoring presented for general wellbeing), software for self-management of an existing condition that is not serious where it doesn’t provide specific treatment recommendations, and various digitised paper-based tools and population-level analytics. The TGA’s excluded software guidance walks through the categories. Note the pattern: the exclusions are defined by modest claims. “Track your sleep” is excluded; “screen yourself for sleep apnoea” is not.
2. Exempt — still a medical device, lighter obligations. Certain clinical decision support software is exempt from inclusion in the Australian Register of Therapeutic Goods (ARTG) under Schedule 4, Part 2, item 2.15 of the Therapeutic Goods (Medical Devices) Regulations 2002. The conditions are cumulative and narrower than founders hope: the software must not directly process or analyse a medical image or signal from another medical device, must be intended only to provide or support a recommendation to a health professional, and must not replace the professional’s clinical judgment. Workflow prompts, guideline-matching tools and EMR-layer alerts can qualify; anything that reads an ECG trace, analyses a radiology image or outputs a diagnosis itself does not. The window is narrowing, too: from 1 November 2026, the Therapeutic Goods Legislation Amendment (2026 Measures No. 1) Regulations 2026 tighten the exemption — among other changes, exempt CDSS must not itself make a clinical diagnosis or treatment decision (including as in vitro diagnostic software), the image/signal limb extends to merely compressing or decompressing them, and the software must display the clinical practice guidelines, calculations or logic behind each recommendation so the health professional can readily interpret and verify it. And exempt is not invisible: the TGA’s CDSS guidance confirms it keeps oversight of advertising and adverse events, and exempt devices must still meet the essential principles.
3. Regulated — ARTG inclusion before supply. Everything else must be included in the ARTG before it’s supplied in Australia, with an Australian sponsor (a local entity — this is why overseas digital health companies can’t simply switch on Australian app store availability) and conformity assessment evidence appropriate to the device’s classification.
Classification: The 2021 Software Rules
The February 2021 reforms inserted dedicated classification rules for software — rules 4.5 to 4.8 of Schedule 2 to the Regulations — built around a simple idea: software harms people by being wrong, so the class scales with the consequences of incorrect output. Software that provides information to inform a diagnosis or screening decision, monitors a condition, or recommends a treatment generally starts at Class IIa and climbs to Class IIb or Class III as the stakes rise — serious disease, decisions that could lead to severe deterioration or death. The era of self-certifying your diagnostic app as Class I is over; the transition period for reclassifying legacy software ended on 1 November 2024, so there is no grandfathering left to rely on.
Class matters commercially because it drives the evidence burden. From Class IIa up, you’ll need a certified quality management system (ISO 13485 is the lingua franca) and technical documentation demonstrating compliance with the essential principles in Schedule 1 — which, for software, expressly include cyber security, and for AI products mean documenting model design, training and validation data, and performance monitoring. One genuine mercy: the TGA accepts conformity assessment certification from comparable overseas regulators — an EU MDR CE certificate or MDSAP certification can substantially shortcut the Australian evidence pathway, which is why sequencing your regulatory strategy across markets is a board-level decision, not a compliance afterthought.
The AI Layer: 2025–26 Is the Enforcement Moment
If you’re building with AI, assume you have the regulator’s attention. The TGA’s July 2025 report on clarifying and strengthening the regulation of medical device software including AI (summarised here by MinterEllison) concluded the existing framework broadly captures AI but flagged targeted reforms — including reviews of digital scribes (regulated the moment they suggest diagnoses or treatment pathways rather than just transcribing) and digital mental health tools. It followed with 2026 guidance confirming that LLMs, chatbots and generative AI products are assessed on intended purpose like everything else, and it has named software-based medical devices a priority compliance focus for 2026–27. Supplying a device that should be in the ARTG and isn’t exposes you to criminal offences and civil penalties, and the TGA has shown it will use fines and public cancellations in the software space.
Two traps are specific to AI products. First, boundary drift: a wellness product that ships a feature update (“new: flags possible arrhythmias”) changes its intended purpose and its regulatory status overnight — product and marketing teams can regulate you into the regime without legal ever being in the room. Second, adaptive models: a device is approved as a particular thing, and a model that materially changes its own performance post-market sits awkwardly with that — change management and post-market monitoring need to be designed in, which is also where the Voluntary AI Safety Standard’s guardrails overlap neatly with TGA expectations.
And the TG Act isn’t the whole board. Health information is sensitive information under the Privacy Act — with APP 8 consequences the moment your stack sends it to overseas cloud or AI providers — and the Australian Consumer Law applies to AI-powered products regardless of what the TGA thinks of them.
The Founder Playbook
- Classify before you build the deck. Write down the intended purpose, run it against s41BD, the exclusions and the CDSS exemption, and document the conclusion — investors’ lawyers will ask for exactly this analysis in due diligence, and “we think we’re a wellness app” is not an answer when the pitch deck says “clinically validated diagnostic accuracy”.
- Align marketing with your regulatory position. If you’re relying on an exclusion, your claims have to stay inside it — everywhere, including investor materials that find their way onto the internet.
- If you’re in the regime, sequence it. Pick your classification, choose a conformity assessment route (and consider which overseas certification you’ll want anyway), appoint the sponsor, and treat ARTG inclusion as a milestone on the product roadmap with a realistic lead time.
- Control intended-purpose drift. Make regulatory review a gate in your release process for any feature that touches diagnosis, prediction or treatment language.
This article is general information only, not legal advice — whether your software is a medical device, and in which class, turns on its specific intended purpose, claims and functionality. Viridian Lawyers advises Australian founders, startups and investors on technology, regulatory and corporate matters. If you’re building digital health or AI-enabled software and aren’t sure which side of the line you’re on, get in touch before you launch — or before your next marketing refresh.