R.N. Collins has written a series of 20 new articles for cannabis law report on 2026 Psychedelics & Legal Issues.
This is the first
Digital, AI, and Psychedelic Convergence: What This Means for Regulators
I. Introduction
A psilocybin-assisted therapy session that incorporates a digital integration platform and AI-powered emotional state monitoring is not a drug. It is not a device. It is not software. It is all three simultaneously — and current federal regulatory architecture was not built to govern it as such. The convergence of psychedelic pharmacology, digital therapeutics, and artificial intelligence is producing a new class of intervention that no single agency is equipped to regulate alone. This article maps the core regulatory gaps this convergence creates and proposes the structural responses necessary to address them.
II. The Regulatory Object Problem: Defining What Is Actually Being Regulated
The threshold challenge for any regulatory analysis is definitional: what, precisely, is being regulated? Federal law currently parcels regulated products into three categories — drugs, devices, and biological products — with combination products occupying a recognized but still-bounded subcategory. Under 21 C.F.R. § 3.2(e), a combination product is defined as a product comprising two or more regulated components — drug/device, biologic/device, drug/biologic, or drug/device/biologic — that are physically, chemically, or otherwise combined into a single entity, co-packaged together, or separately packaged but intended for use together.¹ Regulatory jurisdiction over combination products is assigned to a lead FDA center based on the constituent part providing the primary mode of action, under the authority of 21 U.S.C. § 353(g).⁴
This framework, though functional for products like insulin delivery systems or drug-eluting stents, buckles under the weight of convergent psychedelic interventions. Consider the following product architecture: a sponsor submits an NDA for a psilocybin compound, integrates a proprietary digital therapeutic platform that delivers cognitive preparation protocols and post-session integration exercises, and deploys an AI monitoring tool that analyzes biometric data — heart rate variability, galvanic skin response, facial microexpressions — in real time to flag dysregulatory states during a dosing session. The drug component is regulated by CDER. The device component falls under CDRH. The AI tool may constitute Software as a Medical Device (SaMD) with its own regulatory pathway. The digital therapeutic may require separate review. The question of which constituent part provides the “primary mode of action” — when a sponsor’s explicit design thesis is that pharmacology and digital intervention are therapeutically inseparable — may not be answerable under the existing algorithm.
The difficulty is not merely administrative. A misassignment of primary jurisdiction means that the wrong center applies the wrong evidentiary standards, the wrong safety framework, and the wrong postmarket surveillance architecture to a product that may produce harms attributable to interactions between its components rather than to any single one.²
The AI monitoring component introduces a further jurisdictional complication. In January 2021, FDA published its AI/ML-Based Software as a Medical Device Action Plan, establishing a five-pronged regulatory approach to AI/ML SaMD built around a total product lifecycle model, predetermined change control plans, good machine learning practices, patient-centered transparency, and real-world performance monitoring.³ In March 2024, FDA published a coordinating white paper — Artificial Intelligence and Medical Products: How CBER, CDER, CDRH, and OCP Are Working Together — representing the first cross-center commitment to align AI oversight across drug, device, biologics, and combination product review.³ᵃ Neither the 2021 Action Plan nor the 2024 white paper addresses the specific context of AI tools whose operation is pharmacologically contingent: a system monitoring biometric signals during an active psychedelic dosing session produces outputs that are only interpretable, and risks that are only assessable, in the context of the pharmacological state the drug is inducing. The SaMD classification framework does not account for this dependency, and the cross-center coordination paper — while important — does not resolve it. What is needed is a specific determination of how AI monitoring tools in psychedelic clinical settings are classified and reviewed, whether under CDRH’s SaMD pathway, CDER’s drug development framework, or a combination product designation — a question the existing guidance infrastructure leaves explicitly open.
III. Data Ethics and the AI-Psychedelic Intersection
Psychedelic-assisted therapy generates uniquely sensitive data. Patients in acute psychedelic states may report, or may be observed exhibiting, experiences that span trauma history, attachment patterns, spiritual content, and somatic memory — none of which maps cleanly onto existing categories of protected health information. When AI tools are introduced into that context to monitor, interpret, and potentially intervene based on biometric or cognitive signals, the regulatory stakes of data governance expand considerably.
Existing federal privacy protections provide a floor that is poorly calibrated to this context. The HIPAA Privacy Rule and Security Rule, codified at 45 C.F.R. pts. 160 and 164, protect individually identifiable health information held by covered entities and their business associates.⁵ The Privacy Rule was finalized December 28, 2000, became effective April 14, 2001, and required compliance by April 14, 2003 for most covered entities — well before the emergence of AI systems capable of generating predictive psychological profiles from passively collected biometric streams.⁶ HIPAA’s protections attach to data that has been collected, not to the inferences that AI systems derive from that data. A downstream AI-generated profile characterizing a patient’s psychological vulnerability, fear response thresholds, or likelihood of psychedelic crisis is not itself PHI in any explicit statutory sense — yet its clinical and commercial sensitivity may exceed that of any underlying data point. The FTC has begun to address this inference problem in non-HIPAA contexts, asserting in its 2023 biometric information policy statement that biometric information technologies that determine characteristics such as individuals’ personality traits, aptitudes, or demeanor are subject to consumer protection obligations under Section 5 of the FTC Act.⁷ No equivalent standard has been established for AI-derived inferences generated in clinical therapeutic contexts.
The 21st Century Cures Act of 2016 addressed a related but distinct problem: information blocking by health systems and technology developers. Section 4004 of the Act added section 3022 to the Public Health Service Act, directing the Office of the National Coordinator for Health Information Technology (ONC) to establish a framework prohibiting practices that unreasonably restrict the exchange or use of electronic health information.⁸ ONC finalized information blocking rules at 45 C.F.R. pt. 171, effective April 2021.⁹ These rules create affirmative obligations to enable data flow — but say nothing about the governance of AI-derived inferences generated from psychedelic-state biometric data, nor about whether such inferences constitute electronic health information within the Act’s meaning.
The Federal Trade Commission holds concurrent authority over unfair or deceptive data practices under Section 5 of the FTC Act, 15 U.S.C. § 45.¹⁰ The Commission has increasingly applied this authority to health data contexts — including a 2023 policy statement asserting expansive enforcement jurisdiction over the commercial misuse of sensitive health information by non-HIPAA-covered entities.¹¹ But FTC enforcement is reactive, case-by-case, and focused on deception or unfairness to consumers rather than on defining prospective data governance standards for novel therapeutic modalities. The gap between what FTC can do after the fact and what regulatory architecture can require prospectively is where psychedelic-AI data practices will develop in the absence of affirmative rulemaking.
IV. Adaptive Trial Design: Where Current Guidance Reaches Its Limits
Clinical trials for convergent psychedelic interventions require adaptive designs — designs that allow prospectively planned modifications to one or more aspects of the trial based on accumulating data from participants.¹² FDA finalized guidance on adaptive trial designs in December 2019, providing recommendations on adaptive methods including group sequential designs, sample size re-estimation, and Bayesian adaptive approaches.¹³ The guidance applies to sponsors submitting INDs, NDAs, and BLAs under 21 C.F.R. pts. 312, 314, and 601.¹⁴
The 2019 guidance is sound for conventional single-modality pharmacological trials. Its core principles — prespecification of adaptations, control of Type I error inflation, management of unblinding risks, and independent data monitoring — reflect mature biostatistical practice. Where it does not reach is the specific challenge of adaptive endpoints in trials where the pharmacological agent and the digital/AI component are jointly therapeutic and analytically interdependent.
In a conventional psilocybin trial, the primary endpoint might be a validated psychiatric scale — CAPS-5 for PTSD, MADRS for depression — assessed at a fixed timepoint following a manualized number of dosing sessions. In a convergent trial where an AI monitoring tool adaptively adjusts the therapeutic protocol in real time based on patient biometric signals, the endpoint is partially a function of an algorithm that is itself modifying the intervention being measured. The adaptive design guidance does not address this recursion: it was written for designs in which adaptations are made to the trial structure, not designs in which the intervention itself adapts as a function of AI decision-making during dosing. Whether the resulting data constitute “substantial evidence of effectiveness” under 21 U.S.C. § 355(d) — when substantial components of the intervention are generated dynamically by software — is a question the guidance does not answer.
V. Rethinking REMS for Convergent Therapies
Risk Evaluation and Mitigation Strategies (REMS) represent FDA’s primary mechanism for imposing postapproval safety conditions on drugs with serious identified or potential risks. REMS authority derives from 21 U.S.C. § 355-1, enacted by the Food and Drug Administration Amendments Act of 2007, Pub. L. No. 110-85, which authorizes FDA to require a REMS whenever it determines such a strategy is necessary to ensure that the benefits of a drug outweigh its risks.¹⁵ REMS programs currently address pharmacological safety: certified prescriber networks, mandatory patient registries, dispensing protocols, and periodic safety assessments.
For psychedelic-assisted therapies that incorporate AI and digital platforms, the pharmacological safety architecture of a conventional REMS is insufficient. The risks in these contexts are not solely pharmacological — they are relational, algorithmic, and informational. A future REMS for a convergent psilocybin therapy would need to address at minimum: (1) psychological safety protocols governing how AI-flagged dysregulation is communicated to and acted upon by human facilitators; (2) data security requirements governing the storage, de-identification, and access controls applicable to biometric data collected during dosing sessions; and (3) algorithmic transparency requirements ensuring that the AI tool’s decision logic is reviewable and does not operate as an unauditable black box influencing clinical decisions.
FDA’s May 2024 draft guidance on the REMS Logic Model — REMS Logic Model: A Framework to Link Program Design With Assessment, Docket No. FDA-2024-D-1032 — is the current procedural vehicle through which a redesigned REMS would need to be built.¹⁶ The Logic Model guidance establishes a three-phase framework of Design, Implementation, and Evaluation, and requires applicants to conduct a Risk Assessment and Care Gap Assessment that define both the serious risks the REMS must address and the gap between ideal and actual care delivery. These phases provide a structural opening for the requirements that a convergent REMS would need: an AI risk assessment would map the decision points at which algorithmic outputs affect clinical practice; a care gap assessment would identify where current safety standards fail to address the psychological, informational, and relational risks unique to psychedelic-AI contexts. The Logic Model guidance does not itself extend REMS to algorithmic or data security risks — but it provides the design architecture within which those extensions could be proposed and negotiated with FDA. No sponsor has yet done so. The existing REMS infrastructure — searchable through FDA’s REMS@FDA database — reflects a drug-centered design logic that has not been adapted for digital or AI components.¹⁷ An integrated REMS framework for convergent therapies would require collaboration across CDER, CDRH, and potentially ONC — an intercenter coordination challenge that FDA’s existing Standard Operating Procedure for intercenter consultation was not designed to resolve at the speed and complexity that convergent product development demands.¹⁸
VI. Cross-Agency Complexity: Statutory Authority Without Coordination
Convergent psychedelic interventions implicate at least four federal agencies, none of which has coordinated jurisdiction with the others over this product class.
FDA holds primary authority over drug safety and efficacy under the FD&C Act, with CDER reviewing the pharmaceutical component, CDRH reviewing any device or SaMD component, and the Office of Combination Products managing jurisdictional assignments.
DEA retains scheduling authority over controlled substances under 21 U.S.C. § 811.¹⁹ Psilocybin and MDMA remain Schedule I substances, meaning that any sponsor developing convergent interventions incorporating these compounds must maintain DEA Schedule I research registrations while simultaneously navigating FDA’s approval process. The DEA’s scheduling determination is independent of FDA approval, and while 21 U.S.C. § 811(b) requires DEA to request a scientific and medical evaluation from HHS — including an FDA recommendation — before initiating proceedings to control a substance, no equivalent mechanism requires DEA to initiate rescheduling proceedings in response to an FDA marketing approval decision. The result is a structural gap that could produce the anomalous outcome of an FDA-approved convergent psilocybin therapy remaining a Schedule I controlled substance, with each prescribing physician, dispensing pharmacy, and service center required to hold separate DEA Schedule I research registrations to handle the approved drug lawfully.²⁰
FTC holds broad authority to prevent unfair or deceptive acts or practices affecting commerce under 15 U.S.C. § 45.²¹ In the context of AI-powered therapeutic tools, this authority extends to claims made about algorithmic efficacy, data privacy practices, and marketing representations that target vulnerable patient populations.
ONC oversees the interoperability and information blocking framework established by the 21st Century Cures Act. ONC certification criteria for health IT systems, codified at 45 C.F.R. pt. 170, determine the technical standards applicable to electronic health information — including, potentially, data generated during psychedelic-assisted therapy sessions if captured within certified EHR systems.²²
The challenge is not that each agency lacks authority. It is that their authorities were granted independently, without anticipation of product types that implicate all four simultaneously. No existing interagency coordination mechanism — not FDA’s Product Jurisdiction Order process, not the National Technology Transfer and Advancement Act frameworks — was designed to produce integrated regulatory guidance for a product that is a Schedule I drug, a digital therapeutic, an AI monitoring system, and a health data generator in a single clinical encounter.
VII. Conclusion
The regulatory architecture governing psychedelic medicine was not designed for convergence. The combination product framework assigns jurisdiction based on primary mode of action in a pharmacological product — it cannot resolve jurisdictional ambiguity when the product’s therapeutic premise is that pharmacology and digital AI are jointly and inseparably effective. The adaptive design guidance provides principles for modifying trial structure, not for evaluating trials in which the intervention itself adapts in real time. The REMS framework addresses pharmacological risk without tools for algorithmic, relational, or data security risks. And four agencies hold overlapping but uncoordinated authority over different dimensions of the same product.
None of these gaps requires wholesale legislative reform to begin addressing. FDA could initiate an intercenter working group — spanning CDER, CDRH, and the DHCoE — specifically tasked with developing combination product guidance for psychedelic-digital-AI interventions, including a SaMD classification framework for AI monitoring tools whose function is pharmacologically contingent. ONC could formally clarify whether AI-derived inferences from psychedelic-state biometric data constitute electronic health information under the Cures Act’s information blocking framework. FTC could extend its 2023 biometric information policy to clinical contexts, establishing prospective governance standards for AI health data generated during therapeutic encounters rather than waiting for enforcement cases to define the standard. DEA could initiate a legislative or administrative dialogue with FDA about the procedural pathway for coordinating scheduling status with marketing approval decisions, eliminating the structural gap that could leave approved therapies in Schedule I. What is required is the institutional willingness to recognize that the convergent psychedelic intervention is a genuinely new regulatory object — and that novel objects require novel frameworks, built proactively rather than assembled from enforcement actions after harm has occurred.
Endnotes
- 21 C.F.R. § 3.2(e) (defining combination product), https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-3/subpart-A/section-3.2.
- See FDA, Postmarketing Safety Reporting for Combination Products, Guidance for Industry (Jan. 2021), https://www.fda.gov/media/111788/download.
- FDA, Artificial Intelligence/Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan (Jan. 2021), https://www.fda.gov/media/145022/download; FDA, Artificial Intelligence in Software as a Medical Device, https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-software-medical-device.
3a. FDA, Artificial Intelligence and Medical Products: How CBER, CDER, CDRH, and OCP Are Working Together (Mar. 15, 2024, revised Feb. 2025), https://www.fda.gov/media/177030/download.
- 21 U.S.C. § 353(g), https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title21-section353&num=0&edition=prelim.
- 45 C.F.R. pts. 160, 164, U.S. Dep’t of Health & Human Servs., https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html.
- U.S. Dep’t of Health & Human Servs., Privacy Rule General Overview (final rule Dec. 28, 2000; effective Apr. 14, 2001; compliance date Apr. 14, 2003 for most covered entities), https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/general-overview/index.html.
- Federal Trade Commission, Policy Statement on Biometric Information and Section 5 of the FTC Act, Matter No. P225402 (May 18, 2023), https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-warns-about-misuses-biometric-information-harm-consumers.
- 21st Century Cures Act § 4004, Pub. L. No. 114-255, 130 Stat. 1033 (2016) (adding Pub. Health Serv. Act § 3022, 42 U.S.C. § 300jj-52), https://www.congress.gov/bill/114th-congress/house-bill/34/text.
- 45 C.F.R. pt. 171, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program, 85 Fed. Reg. 25642 (May 1, 2020), https://www.federalregister.gov/documents/2020/05/01/2020-07419/21st-century-cures-act-interoperability-information-blocking-and-the-onc-health-it-certification.
- 15 U.S.C. § 45, https://www.law.cornell.edu/uscode/text/15/45.
- Federal Trade Commission, Policy Statement on Biometric Information and Section 5 of the FTC Act, Matter No. P225402 (May 18, 2023) (full text), https://www.ftc.gov/legal-library/browse/policy-statement-federal-trade-commission-biometric-information-section-5-federal-trade-commission.
- FDA, Adaptive Designs for Clinical Trials of Drugs and Biologics: Guidance for Industry (Dec. 2019), https://www.fda.gov/regulatory-information/search-fda-guidance-documents/adaptive-design-clinical-trials-drugs-and-biologics-guidance-industry.
- Adaptive Designs for Clinical Trials of Drugs and Biologics; Guidance for Industry; Availability, 84 Fed. Reg. 65463 (Nov. 27, 2019), https://www.federalregister.gov/documents/2019/12/02/2019-25986/adaptive-designs-for-clinical-trials-of-drugs-and-biologics-guidance-for-industry-availability.
- 21 C.F.R. pts. 312, 314, 601, https://www.ecfr.gov/current/title-21.
- 21 U.S.C. § 355-1 (REMS authority; Food and Drug Administration Amendments Act of 2007, Pub. L. No. 110-85, 121 Stat. 823 (2007)), https://www.law.cornell.edu/uscode/text/21/355-1; see also FDA, REMS: FDA’s Application of Statutory Factors in Determining When a REMS Is Necessary (Apr. 2019), https://www.fda.gov/regulatory-information/search-fda-guidance-documents/rems-fdas-application-statutory-factors-determining-when-rems-necessary-guidance-industry.
- FDA, REMS Logic Model: A Framework to Link Program Design With Assessment, Draft Guidance for Industry, Docket No. FDA-2024-D-1032 (May 7, 2024), https://www.fda.gov/regulatory-information/search-fda-guidance-documents/rems-logic-model-framework-link-program-design-assessment; see also 89 Fed. Reg. 38161 (May 7, 2024), https://www.federalregister.gov/documents/2024/05/07/2024-09928/risk-evaluation-and-mitigation-strategy-logic-model-a-framework-to-link-program-design-with.
- FDA, Approved Risk Evaluation and Mitigation Strategies (REMS), REMS@FDA Database, https://www.accessdata.fda.gov/scripts/cder/rems/index.cfm.
- FDA, Artificial Intelligence and Medical Products: How CBER, CDER, CDRH, and OCP Are Working Together (Mar. 15, 2024), supra note 3a; FDA, Risk Evaluation and Mitigation Strategies, https://www.fda.gov/drugs/drug-safety-and-availability/risk-evaluation-and-mitigation-strategies-rems.
- 21 U.S.C. § 811 (scheduling authority for controlled substances), https://www.law.cornell.edu/uscode/text/21/811.
- See 21 U.S.C. § 811(b) (requiring DEA to obtain an HHS scientific and medical evaluation, including an FDA recommendation, before initiating scheduling proceedings — but creating no reciprocal obligation requiring DEA to act upon an FDA marketing approval decision); 21 U.S.C. § 822(a) (registration requirements for controlled substance handlers), https://www.law.cornell.edu/uscode/text/21/811.
- 15 U.S.C. § 45, https://www.law.cornell.edu/uscode/text/15/45.
- 45 C.F.R. pt. 170 (ONC Health IT Certification Program), https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-D/part-170.
Contact RN Collins: https://www.linkedin.








