Hakuna matata? Anthropic has you covered?
This week, an FDA advisory panel considered a medical device with an extraordinary commercial proposition: detect signals from multiple cancers using a single blood draw, then predict where the cancer may have originated.
GRAIL’s Galleri test analyzes cell-free DNA using three locked machine-learning classifiers. One detects a cancer signal. A second predicts one of 18 anatomical origins. A third may characterize aspects of the cancer biology to guide the diagnostic work.
This could create an entirely new screening category.
It also illustrates a risk that MedTech founders often underestimate:
Your competitive advantage also determines the shape of your threat surface.
For Galleri, the advantage is turning one blood draw into a decision about whether—and where—to look for cancer.
Their threat surface is not confined to the algorithm. It extends through every clinical decision that follows the result.
The performance numbers tell 2 stories:
In the two studies reviewed by FDA, Galleri’s overall 12-month sensitivity was 35.0% in PATHFINDER 2 and 31.6% in NHS-Galleri.
Its specificity was much higher: 99.85% and 99.74%. Among positive results, the positive predictive value was 77.0% and 66.2%. The predicted cancer-signal origin was correct in 94.3% and 91.9% of true-positive cases.
These are category-creating numbers.
Galleri can identify cancers for which no routine screening program exists.
A blood test may also achieve better adoption than invasive or cancer-specific screening procedures. FDA noted that approximately 58% of expected US cancer deaths in 2026 involve cancers without a current USPSTF Grade A, B or C screening recommendation.
But aggregate accuracy conceals the operational risk.
Sensitivity varied substantially by cancer type. In PATHFINDER 2, it was 62.5% for colorectal cancer, 47.1% for lung cancer, 26.4% for breast cancer and 10.7% for prostate cancer. The NHS study produced a similar pattern: 53.3%, 63.8%, 19.1% and 10.7%, respectively.
A negative result therefore cannot mean “no cancer.” Nor can it replace established screening.
That distinction is easy to state in labeling and much harder to preserve in real life.
The test is the beginning of the loss.
A false positive does not end with an incorrect screen.
It can initiate imaging, invasive procedures, specialist referrals, anxiety and weeks of diagnostic uncertainty.
In PATHFINDER 2, people with positive results that did not lead to a cancer diagnosis required a median of 75 days to reach diagnostic resolution. Even with false-positive rates of only 0.15% and 0.26%, population-scale deployment makes the downstream workflow material.
A false negative creates a different chain:
The patient receives “No Cancer Signal Detected.”
The patient interprets that as broader reassurance than the test supports.
The patient delays mammography, colonoscopy, lung screening or another recommended procedure.
A cancer is diagnosed later, potentially at a more advanced stage.
The model can perform exactly as validated while the system still produces harm.
This is the crucial founder lesson. For an AI-enabled medical device, the relevant unit of risk is rarely the prediction alone. It is:
prediction → interpretation → action → clinical outcome
Every claim that increases commercial advantage can enlarge that chain.
“Detects multiple cancers” creates a larger market than “detects a particular biomarker.”
“Predicts the cancer’s origin” makes the output more actionable.
“Early detection” creates the strongest clinical and commercial promise of all.
It also creates the largest evidentiary obligation.
The FDA panel voted unanimously that Galleri had reasonable assurance of safety, but only 6–4 for effectiveness. Several members conditioned their support on removing “early” from the proposed indication. The panel voted 7–2, with one abstention, that benefits outweighed risks. Concerns included possible bias in the sensitivity measure and the absence of long-term patient-outcome evidence.
The first screening round of NHS-Galleri did not settle the question. The observed reduction in stage IV cancers was 3% across routinely staged cancers and 13% within a prespecified group of 12 cancers, but the confidence intervals included no effect.
The panel’s recommendation is advisory, not an FDA approval decision.
Preserve the advantage by controlling the pathway
The wrong response is to reduce an innovative device to the smallest claim regulators will tolerate.
The better response is to design countermeasures around the commercial advantage itself.
For a test like Galleri, that means more than a warning in the instructions for use. It could include:
Structured diagnostic pathways for every predicted cancer origin.
Clear escalation rules when the first diagnostic workup is negative.
Active reminders that conventional screening must continue.
Measurement of diagnostic-resolution time, invasive procedures and screening adherence.
Surveillance by cancer type, stage and demographic subgroup—not merely aggregate accuracy.
Evidence connecting detection to changes in treatment, stage and patient outcomes.
These controls do not weaken the product. They make its advantage deployable.
The broader principle applies across AI-enabled medical devices:
If your superiority changes what clinicians or patients do, your threat model must include that behavior.
Do not stop at model failure, unauthorized access or incorrect output. Model the plausible loss events created when a correct output is misunderstood, over-trusted, routed into an unprepared clinical workflow or used as a substitute for something it was designed to supplement.
That is where residual risk lives.
And it is increasingly where regulators will look for evidence.
Worth reading


