AI is moving faster than clinical trial regulation. The Pharma Market needs to talk about it.

Everyone is discussing how artificial intelligence can accelerate clinical development. Fewer people are asking a more difficult question: Is our regulatory infrastructure ready to let AI operate at its full potential?

This is not a call for weaker regulation.

And it is certainly not a suggestion that patient safety, data integrity, scientific validity or Good Clinical Practice should ever be compromised.

Quite the opposite.

If the clinical development ecosystem wants to use AI responsibly across the development lifecycle, we may need a more mature conversation about regulatory modernization, technical standards, inspection readiness and governance.

AI is already being applied across clinical development, from study planning and feasibility to patient recruitment, data review, risk management, documentation, regulatory support and trial oversight.

But the broader system around clinical development still carries many characteristics of a pre-AI operating model: documentation remains heavily PDF-first, review cycles are still highly manual, systems are often disconnected, data flows remain fragmented, interpretation may vary across jurisdictions, accountability can be siloed, validation models were largely designed for deterministic software, and audit trails were not originally conceived for generative AI, adaptive algorithms or autonomous AI agents.

This creates a structural tension.

AI may be technically capable of accelerating clinical development, but its full value will remain limited if the regulatory, administrative and operational environment is not ready to absorb it.

The industry does not need a lower regulatory bar.

It needs a clearer path for responsible adoption.

The good news: regulators are already concerned about AI applicability

It is important to recognize that the conversation has already started.

The FDA published draft guidance in 2025 on the use of AI to support regulatory decision-making for drugs and biological products. The document proposes a risk-based credibility assessment framework for AI models, based on the model’s context of use and the level of risk associated with the decision it supports. [1]

The EMA has also been actively discussing AI in the medicinal product lifecycle, including opportunities and risks related to transparency, bias, validation, drift, governance and human oversight. [2]

The HMA-EMA network has developed an AI workplan for 2023–2028, with the intention of helping the European medicines regulatory network use AI for productivity, process automation, better data insights and more robust decision-making. [3]

ICH E6(R3), adopted in 2025, represents a major modernization of Good Clinical Practice. It reinforces quality by design, risk-based quality management, proportionality, critical thinking and the use of technology and diverse data sources in clinical trials. [4]

The EU AI Act has also entered into force and introduces obligations for high-risk AI systems, including requirements related to risk management, data quality, transparency, user information and human oversight. [5]

ICH M11 is another important step. By moving toward a Clinical Electronic Structured Harmonised Protocol, it may help shift clinical development from document-centric protocol exchange to more structured, interoperable and machine-readable protocol content. [6]

These initiatives show that regulators are engaging with AI.

As the discussion evolves, several strategic and technical gaps deserve close attention from sponsors, CROs, technology providers, regulators and policy-makers.

The purpose of highlighting these gaps is not to criticize the current regulatory environment.

It is to contribute to a necessary awareness discussion: without further alignment, AI may remain useful in specific tasks but limited in its ability to transform clinical development end to end.

Gap 1: Regulatory expectations for operational AI

Much of the current regulatory discussion naturally focuses on AI when it supports regulatory decision-making or contributes to evidence used in submissions.

That focus is appropriate.

However, there is an important intermediate space that deserves further attention: AI used in clinical operations.

These applications may not directly determine safety, efficacy or benefit-risk conclusions, but they can materially influence how a clinical trial is designed, planned, executed, monitored and documented.

This is a critical distinction.

Operational AI may influence study quality without being classified as direct regulatory decision-making AI.

If expectations remain unclear, many organizations may restrict AI to low-risk administrative uses. That would be understandable from a compliance perspective, but it would also limit the technology’s potential impact on clinical trial efficiency.

Pharmaceutical companies, biotechs and CROs need clearer expectations for AI that supports clinical execution, even when it does not directly generate regulatory evidence.

Gap 2: Proportional validation by risk and context of use

Not all AI use cases carry the same level of risk.

This principle is easy to state, but difficult to operationalize.

An AI tool used for administrative productivity should not be treated the same way as an AI model that influences clinical interpretation, patient selection, endpoint assessment or regulatory evidence generation.

The key question should not be simply whether AI can be used.

The better question is:

What level of evidence, validation, documentation, monitoring and human oversight is required for this specific AI use case, in this specific context of use?

The FDA’s risk-based credibility assessment framework is an important step in this direction. [1]

But the industry may need more practical granularity to classify AI use cases across the clinical development lifecycle.

If validation expectations are too vague, organizations hesitate.

If they are too heavy for every use case, innovation slows.

If they are too light for high-impact use cases, quality and trust suffer.

The future of AI in clinical development will depend on proportionality.

Gap 3: Auditability and traceability in the age of GenAI

Clinical development depends on traceability.

Regulators, inspectors, sponsors and CROs need to understand how decisions were made, which data supported them, who reviewed them and how final accountability was applied.

This principle is well established for electronic records and electronic signatures under frameworks such as 21 CFR Part 11. [7]

But generative AI introduces new technical questions.

In an AI-supported workflow, the record may not be limited to the final document, final dataset or final decision. It may also include the model version, input data, prompt or instruction, generated output, human review, rejected suggestions, accepted edits and final rationale.

The audit trail of the future may need to record more than who changed what and when.

It may also need to show which model influenced the decision, which data were used, what output was generated and how human oversight was applied.

Part 11 remains essential.

But its interpretation may need to evolve for workflows involving probabilistic outputs, models updated over time or third-party systems influencing regulated processes.

Without this evolution, AI may create a new form of inspection risk: decisions that cannot be fully reconstructed.

Gap 4: Structured data and interoperability

AI depends on data quality, structure and accessibility.

Clinical development, however, remains heavily document-centric and system-fragmented.

This is one of the most important structural barriers to end-to-end AI.

AI can read documents and extract information. But its highest value emerges when data are structured, standardized, interoperable and reusable across the clinical development lifecycle.

This is why ICH M11 is strategically important.

By creating a harmonized clinical protocol template and technical specification, ICH M11 may help move the industry toward more consistent and machine-readable protocol content. [6]

That matters because the protocol is not just a document.

It is the operational blueprint of the study.

If the protocol becomes more structured, downstream processes may become more connected, from study start-up and EDC build to monitoring strategy, medical writing and regulatory review.

The broader point is simple:

AI cannot reach full efficiency in a PDF-first regulatory environment.

The future of clinical development needs to move progressively toward structured-data-first thinking.

Gap 5: Accountability across sponsors, CROs and vendors

AI in clinical development will rarely be owned, deployed and governed by a single party.

Sponsors, CROs, technology vendors, data providers, sites and functional experts may all participate in the same AI-supported workflow.

This creates a governance challenge.

When AI influences a clinical or operational decision, accountability must be clear before the decision is made, not after a problem occurs.

This requires more than vendor qualification.

It requires clear ownership of context of use, model oversight, change control, validation expectations, human review, escalation pathways and final decision rights.

End-to-end AI in clinical development will require end-to-end accountability.

Without clear ownership, AI adoption will naturally remain concentrated in peripheral, lower-risk activities.

Not because the technology cannot support more strategic use cases, but because the accountability model is not yet mature enough to support them.

Gap 6: Privacy, secondary use of data and cross-border data flows

AI needs large, representative and high-quality datasets.

Clinical development involves some of the most sensitive data categories possible, including health data, genomic data, imaging data, real-world data, wearable data, safety data and historical clinical trial data.

This creates a necessary tension.

Patient privacy and data protection must remain non-negotiable.

At the same time, responsible secondary use of health and clinical data may be essential to train, validate and monitor AI models that could improve study design, recruitment, diversity, safety surveillance and operational efficiency.

This challenge becomes even more complex in global clinical trials, where data protection rules, ethics requirements and regulatory expectations may differ across jurisdictions.

The EU AI Act adds another layer to an already complex environment that includes GDPR, Clinical Trials Regulation, GCP and, depending on the use case, other sector-specific frameworks. [5]

The industry does not need weaker privacy protection.

It needs clearer pathways for responsible, governed and auditable secondary use of clinical and health data.

Without that clarity, organizations may avoid using the very data required to make AI clinically and operationally meaningful.

And AI without reliable data is only a sophisticated interface.

Gap 7: Inspection readiness for AI-supported clinical trials

Perhaps one of the most important emerging topics is inspection readiness.

If AI becomes part of clinical trial execution, AI governance becomes part of GCP readiness.

Future inspections may not only evaluate whether clinical data were accurate, complete and reliable.

They may also need to understand how AI-supported processes contributed to data generation, review, escalation, documentation or decision-making.

This may require evidence of context of use, model governance, validation rationale, human oversight, vendor qualification, change control, training, audit trails and risk management.

Sponsors, CROs and technology partners should not wait for inspection findings to define what good AI governance looks like.

Inspection readiness should be built into AI adoption from the beginning.

The real issue: AI will remain fragmented without modernization

If these gaps are not addressed, AI will still create value — but mostly in isolated tasks.

It may improve productivity, accelerate documentation and support better analysis. But it will not fully transform clinical development unless the system around it evolves as well.

The real promise of AI is not simply to make existing processes faster.

It is to help reduce avoidable delays, improve decision-making, increase operational predictability and bring high-quality medicines to patients faster — without compromising safety, ethics, data integrity or scientific rigor.

That requires more than technology.

It requires regulatory alignment, structured data, proportional validation, auditability, clear accountability and inspection readiness.

The point is not deregulation.

The point is modernization.

Regulation is not the obstacle to AI. Uncertainty is.

The industry should not frame this debate as a request for flexibility at the expense of rigor. The real need is a more consistent, technically grounded and AI-ready regulatory environment.

At the same time, pharmaceutical companies, biotechs, CROs and technology partners should not wait passively for perfect guidance. They need to build governance now, align functions internally and prepare their processes for a future in which AI becomes part of clinical execution.

AI may help us design smarter trials, detect risks earlier and accelerate clinical development.

But unless regulation, data standards, inspection models and clinical workflows evolve together, we may keep using 21st-century intelligence inside 20th-century infrastructure.

That is the conversation the industry needs to have now.

References

[1] FDA — Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/considerations-use-artificial-intelligence-support-regulatory-decision-making-drug-and-biological

[2] EMA — Reflection paper on the use of artificial intelligence in the lifecycle of medicines. https://www.ema.europa.eu/en/news/reflection-paper-use-artificial-intelligence-lifecycle-medicines

[3] EMA — Artificial intelligence workplan to guide use of AI in medicines regulation. https://www.ema.europa.eu/en/news/artificial-intelligence-workplan-guide-use-ai-medicines-regulation

[4] ICH — Guideline for Good Clinical Practice E6(R3). https://database.ich.org/sites/default/files/ICH_E6%28R3%29_Step4_FinalGuideline_2025_0106.pdf

[5] European Commission — Artificial Intelligence in healthcare. https://health.ec.europa.eu/ehealth-digital-health-and-care/artificial-intelligence-healthcare_en

[6] EMA / ICH — ICH M11 Clinical Electronic Structured Harmonised Protocol. https://www.ema.europa.eu/en/ich-m11-guideline-clinical-study-protocol-template-technical-specifications-scientific-guideline

[7] eCFR — 21 CFR Part 11: Electronic Records; Electronic Signatures. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11


Originally published on LinkedIn on June 15, 2026.

Rafael Ioschpe

Rafael Ioschpe

Clinical development and pharmaceutical R&D leader with more than 20 years of experience.Executivo de desenvolvimento clínico e P&D farmacêutico com mais de 20 anos de experiência.

Comments

Leave a Reply

Discover more from Rafael Ioschpe

Subscribe now to keep reading and get access to the full archive.

Continue reading