Clinical laboratory researcher in protective gear operating a microscope, representing rigorous data integrity and audit-ready clinical research
    Regulatory Writing

    Audit Trails, Traceability, and AI Regulatory Systems in Clinical Trials

    How 21 CFR Part 11, ICH E6(R3), and the FDA-EMA joint AI principles reshape audit trail and traceability requirements for AI-generated clinical documents.

    Published by Kitsa Editorial Team
    ~18 min read
    Contents

    Introduction

    In November 2024, FDA issued a warning letter to Applied Therapeutics after a third-party vendor deleted electronic audit trails for all 47 participants enrolled in a clinical trial, just two days after FDA preannounced an inspection [10]. The deleted records included electronic clinical outcome assessments used for primary and secondary efficacy endpoints, leaving FDA unable to access or verify the data. A complete response letter and subsequent shareholder litigation followed the regulatory disclosure [19]. The enforcement chain illustrates what audit trail failure actually costs in clinical development, stripped of abstraction.

    The stakes have sharpened as AI enters the document generation and data analysis workflows of clinical trials. A protocol drafted by a language model, an informed consent form built by an automated tool, or a clinical study report assembled through structured AI outputs all raise the same question regulators are increasingly asking: can you demonstrate exactly what the system produced, on what inputs, at what time, and who reviewed and approved it? That question is not new. It is the core definition of an audit trail, codified decades ago under 21 CFR Part 11 [1]. What is new is that the same framework can apply to AI systems with the same rigor historically reserved for electronic data capture platforms and laboratory instruments, and many sponsors may not yet be ready to meet that standard.

    Why AI audit trails are now an inspection-readiness issue
    47 participants
    Applied Therapeutics trial impact
    Electronic audit trails deleted for all enrolled participants [10]
    1,766
    FDA warning letters analyzed
    FDA warning letters analyzed across 2016 to 2023 [9]
    All 47
    Participants affected
    FDA could not access or verify key trial data [10]
    January 2026
    FDA-EMA AI principles
    Joint principles call for traceable, verifiable AI documentation [5]

    Why Audit Trails Matter in AI-Enabled Clinical Research

    Audit trail requirements have governed electronic records in FDA-regulated industries since 1997. Under 21 CFR Part 11, Section 11.10(e) [1], sponsors must maintain secure, computer-generated, time-stamped records documenting the creation, modification, and deletion of electronic records. Personnel who create, modify, or delete those records must not be able to alter the audit trail. Retention must last at least as long as the underlying records. FDA's guidance on computerized systems used in clinical investigations [2] further specifies that documentation must capture who made any change, when, and why.

    What has changed is the scale and opacity of the systems now generating those records.

    A full-enumeration analysis of 1,766 FDA warning letters issued between 2016 and 2023, published in Therapeutic Innovation and Regulatory Science [9], identified data integrity violations as a persistent enforcement priority, with audit trail deficiencies among the most frequently recurring citation categories across the entire study period. The authors found that electronic records violations, incomplete audit trail documentation, and unauthorized data modification consistently appeared regardless of firm size or geography [9]. When FDA inspectors now approach a site that has used an AI tool to generate protocol sections or annotate patient data, they ask for version logs, prompt records, human review timestamps, and change histories. The regulatory expectation exists in current guidance; the organizational readiness often does not.

    Minimum audit trail questions for AI-generated clinical content
    1
    What did the AI system generate?
    Original output before human edits
    2
    What source inputs were used?
    Prompt, retrieval context, source documents, and data references
    3
    Which system state produced it?
    Model version, configuration, guardrails, and post-generation processing
    4
    Who reviewed and approved it?
    Authenticated reviewer identity, timestamp, decision, and rationale
    5
    What changed afterward?
    Every modification, deletion, replacement, and final approval record

    The Regulatory Framework: Key Requirements in 2025 and 2026

    Regulatory signals shaping AI audit trails
    1997
    21 CFR Part 11 establishes electronic records and electronic signature controls [1]
    October 2024
    FDA finalizes guidance on electronic systems, records, and signatures in clinical investigations [20]
    January 6, 2025
    ICH E6(R3) finalizes GCP audit trail and data governance expectations [3]
    January 2025
    FDA publishes draft AI credibility framework for drug and biologic development [4]
    July 2025
    ISPE publishes the GAMP Guide: Artificial Intelligence [8]
    January 14, 2026
    FDA and EMA publish joint guiding principles for good AI practice in drug development [5]

    ICH E6(R3) and the Formal Definition of Automated Audit Trails

    ICH E6(R3), finalized on January 6, 2025, provides the most authoritative current definition of audit trails in the GCP context [3]. The guideline formally defines them as "metadata records that allow the appropriate evaluation of the course of events by capturing details on actions (manual or automated) performed relating to information and data collection and, where applicable, to activities in computerised systems." The phrase "manual or automated" is consequential. If an AI system generates a sentence in a protocol or modifies a field in an electronic case report form, that action falls within the scope of the audit trail requirement with the same attributability and timestamp standards as a human edit.

    E6(R3) adds ten pages of new requirements on data lifecycle integrity, covering capture, metadata, audit trails, access controls, corrections, and secure retention [3]. Sponsors should classify data by criticality, maintain secure and tamper-evident audit records for critical systems within their inventory, and document investigators' read and write permissions clearly. These requirements apply across EDC systems, eTMFs, eConsent platforms, and any AI tool that creates or modifies records within those systems; read-only access logging carries a separate and generally lower documentation burden, but access controls and user attribution remain required even for read operations [3]. The guideline is in Step 4; regulatory adoption by ICH member countries, including the US and EU, is underway [3].

    E6(R3) also reframes inspection readiness as a continuous operational state, not a preparation exercise [3]. Regulators expect sponsors to demonstrate real-time control over trial documentation at any point in the study. Audit trail review must occur on a risk-based schedule and must itself be documented. An audit trail that is technically enabled but never reviewed does not satisfy E6(R3) expectations.

    FDA's January 2025 Draft AI Guidance

    FDA's January 2025 draft guidance on the use of AI to support regulatory decision-making (Docket No. FDA-2024-D-4689) [4], which is currently in draft form and not yet binding, introduced a seven-step risk-based credibility assessment framework for AI models producing information intended for regulatory submissions. The framework covers: defining the AI model's context of use, assessing its risk, developing and executing a credibility plan, documenting deviations, and determining adequacy for the intended regulatory purpose. The guidance supports an expectation that credibility evidence and model performance documentation be organized and available for review, contemporaneous with the AI system's development and operational use rather than assembled retrospectively when a question arises [4].

    Two points of scope are important. First, the guidance explicitly excludes AI used solely for operational efficiency in drafting and writing when those uses do not affect patient safety, drug quality, or study reliability [4]. AI document generation that functions as a writing aid without influencing clinical conclusions sits outside the credibility framework's mandatory scope. Second, the guidance does apply when AI outputs inform regulatory decisions about safety, efficacy, or quality: for example, when an AI model processes trial data to generate analytical summaries used in a submission, or when AI-generated protocol content directly shapes trial conduct. Sponsors should assess each AI use case individually against this scope boundary.

    A critical review of the guidance published in the Journal of Chemistry in 2026 [13] noted that by December 2024, FDA had authorized more than 1,000 AI-based medical devices, demonstrating rapid progress in AI regulation at the device level. The January 2025 draft guidance represented the first formal credibility framework for AI in non-device drug and biologic development, signaling that the same accountability expectations are moving into the clinical trial documentation space.

    FDA-EMA Joint Guiding Principles, January 14, 2026

    On January 14, 2026, FDA and EMA jointly published ten guiding principles for good AI practice in drug development [5]. The principles span the full medicines lifecycle, from early research and clinical trials through manufacturing and post-market safety surveillance. Principle 6 addresses data governance and documentation; the joint document specifies that AI systems must support traceable, verifiable documentation where "data source provenance, processing steps, and analytical decisions are documented in a detailed, traceable, and verifiable manner, in line with Good Practices (GxP) requirements" [5]. Principle 9 addresses lifecycle management, requiring ongoing monitoring, drift detection, and periodic re-evaluation of AI systems over time [5].

    The principles are currently non-prescriptive, but regulatory observers note that they are expected to underpin binding guidance in both jurisdictions [14]. Together with the January 2025 FDA draft guidance [4], they constitute the most detailed regulatory articulation to date of what "documented AI" means in a clinical context: not merely a statement that AI was used, but a full chain linking context of use, model design, input datasets, performance metrics, and monitoring records.

    EU GMP Annex 11 Revision and New Annex 22 on AI

    The European Commission published draft revisions to EU GMP Annex 11 (Computerised Systems) alongside an entirely new Annex 22 specifically covering artificial intelligence on July 7, 2025 [7]. It is worth clarifying the scope: Annex 11 and Annex 22 sit within the EU GMP framework, which governs manufacturing, quality control, and quality systems rather than clinical trial conduct directly. Their most immediate relevance in a clinical context is to investigational medicinal product (IMP) manufacturing, laboratory systems, and quality systems that underpin trial operations, not to GCP-governed trial management systems, which fall under ICH E6(R3) and national GCP regulations. Both frameworks can be applicable simultaneously within a single development program, but they are not interchangeable.

    Within the GMP context, the revised Annex 11 draft proposes making audit trails mandatory for all GMP-critical computerized systems where data or settings can be changed, requiring logs to capture user identity, timestamp, old and new values, and a documented reason for nearly all edits [7]. This direction had been signaled in the EMA concept paper published in 2022 [12], which identified mandatory audit trails for all GMP-critical systems as a core gap in the then-current Annex 11 and called for explicit guidance on AI/ML systems. The draft further clarifies that audit trails must be tamper-proof: no user should be able to modify or disable them [7].

    Annex 22 brings AI and machine learning under explicit GMP compliance requirements, obligating regulated companies to explain and justify AI behavior from training data through real-time use, with model-specific documentation analogous to what the ISPE GAMP AI Guide [8] describes. Final versions of both documents are expected by mid-2026, as of the time of writing, with the final text expected to clarify scope boundaries further.

    EU AI Act: Logging Requirements for High-Risk Systems

    Under Regulation (EU) 2024/1689 [6], whether a specific AI system qualifies as high-risk depends on the Article 6 classification framework, which looks at whether the system is a safety component of a product regulated under EU harmonized legislation, or falls into one of the Annex III categories (which include AI systems used in critical infrastructure, education, employment, and access to essential services). AI systems used in clinical trials do not automatically qualify as high-risk under Annex III as currently written; classification requires a case-by-case assessment of the AI's role. AI tools that directly influence clinical decision-making, patient eligibility determinations, or safety reporting carry stronger arguments for high-risk classification than systems used purely to draft text [6].

    For systems that are classified as high-risk, the obligations are specific. Article 12 mandates automatic logging of operations to the extent technically feasible. Article 19 requires retention of automatically generated logs for a minimum of six months, or longer where applicable sectoral law requires. Article 18 requires that providers maintain the technical documentation specified in Annex IV, and Article 17 requires a quality management system encompassing data governance and record-keeping [6].

    A note on implementation timing is material as of June 2026. The original EU AI Act envisaged that standalone Annex III high-risk AI systems would need to comply from August 2, 2026. On May 7, 2026, the European Parliament and the Council reached a provisional agreement under the Digital Omnibus on AI to delay this: standalone Annex III high-risk systems now face a compliance date of December 2, 2027, and high-risk AI embedded in regulated Annex I products a date of August 2, 2028 [18],[21],[22]. Formal adoption of the Omnibus amendments was expected before August 2026; the substantive requirements themselves have not changed, and regulatory counsel advise that preparation efforts should continue regardless of the extended deadline [18].

    ISPE GAMP Guide: Artificial Intelligence

    The ISPE GAMP Guide: Artificial Intelligence, published in July 2025 [8], is the first comprehensive GAMP guidance document focused exclusively on AI applications in GxP-regulated environments. Its 290 pages extend GAMP 5 principles to AI's distinct characteristics: non-deterministic outputs, model drift, the absence of conventional software version equivalents, and the challenge of validating systems whose behavior changes after training. The guide calls for AI systems in GxP settings to carry audit trails at least as comprehensive as those mandated for conventional electronic systems, and for validation documents to ground performance claims in logged, traceable evidence rather than assertion [8].

    The guide recommends that AI systems in GxP settings carry validation documentation and audit records as rigorous as those required for conventional electronic systems, and the ISPE authors note that as AI use in regulated environments becomes routine, regulators will increasingly scrutinize the underlying validation records and governance documentation [8].

    Operational Implications: What Audit Trails for AI Systems Must Capture

    A conventional EDC audit trail is a finite record of discrete human actions: user ID, timestamp, original field value, new value, and reason code. AI systems introduce documentation layers that conventional audit trail frameworks do not address.

    For a sponsor deploying an AI tool to generate protocol sections or summarize clinical data for a CSR, where the output is a regulated record or supports a regulated decision, a compliant audit trail should capture the model version in use at the time of generation; the specific input context, prompt, or retrieval documents used to produce the output; any guardrails, filters, or post-generation processing applied; the initial AI output before human edits; each subsequent revision with timestamp and author; and the electronic signature on the final approved version. Under ICH E6(R3) [3], all of these elements constitute the metadata record needed to reconstruct "the course of events relating to the creation, modification, or deletion" of the document.

    What an AI regulatory document audit trail should reconstruct
    1
    Source inputs
    Protocol, ICF, IB, CSR source data, retrieval documents, prompts, and context
    2
    AI system state
    Model version, configuration, guardrails, filters, and generation timestamp
    3
    Original AI output
    Unedited generated text, tables, annotations, or data summaries
    4
    Human review and revision
    Reviewer identity, edits, timestamps, decision rationale, and escalation
    5
    Final approved record
    Electronic signature, approved version, retention location, and audit trail lock
    6
    Lifecycle monitoring
    Model drift checks, retraining events, change control, rollback, and periodic review

    The lifecycle dimension adds another layer. FDA's January 2025 draft guidance (FDA-2024-D-4689) [4], currently in draft form and not yet binding, recommends that sponsors with iteratively updated AI models develop lifecycle maintenance and change management plans documenting what types of changes are permitted, what validation each change class requires, and how rollback is handled. Every retraining event is a documentation event, and the audit trail should reflect it. Model drift, the degradation of real-world model performance as input distributions shift over time, should be monitored and the monitoring itself documented [5].

    ALCOA++ principles, the ten-attribute data integrity framework comprising Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available, and Traceable, apply to AI outputs as they do to any other clinical trial record [15]. "Attributable" requires linking each generated output to a specific model version and configuration. "Original" requires that the initial AI-generated text be preserved before human editing. "Traceable" requires that a regulator can follow any data point in the Trial Master File from its first generation through every modification to its final form.

    Enabled-but-unreviewed audit trails are not enough. A 2024 FDA inspection of a pharmaceutical manufacturer cited "insufficient high-level audit trail review instructions" as a finding, noting that personnel were unaware of their obligation to review all audit trail data during the inspection. That pattern, documented extensively in FDA warning letter analyses [9], is now transferring to AI contexts.

    AI Use Case Mapping: Which Framework Applies

    The regulatory framework that governs an AI use case depends on its function and context, not on whether AI is involved. The table below maps common clinical AI use cases to their primary compliance anchor:

    AI Use CasePrimary FrameworkBinding or Prudent
    Protocol drafting assistance (efficiency only)21 CFR Part 11 / ICH E6(R3) for final document recordsBinding for records; FDA AI guidance may not apply if no safety/quality impact
    AI analytical summaries used in regulatory submissionsFDA Jan 2025 draft AI guidance (FDA-2024-D-4689)Draft/prudent; expected to bind when finalized
    eCOA data annotation and cleaning21 CFR Part 11, ICH E6(R3)Binding
    Pharmacovigilance signal detectionFDA AI guidance (scope dependent); FDA-EMA 2026 principlesDraft/prudent
    IMP manufacturing quality control AIEU GMP Annex 11 / Annex 22; 21 CFR Part 11Binding for GMP records
    CSR data review and synthesisFDA AI guidance if outputs support submissions; ICH E6(R3) for source recordsDependent on scope assessment
    Patient eligibility AI in EU jurisdictionsEU AI Act (if high-risk classification applies after Article 6 assessment)Prudent now; binding from Dec 2, 2027 only if classified as standalone Annex III high-risk and Omnibus amendments are formally adopted

    This table is a scoping aid, not a legal classification. Each AI deployment requires its own assessment against the specific regulatory texts, product type, and intended use.

    Required vs. Prudent: Knowing Where You Stand

    A practical distinction is worth drawing. Some audit trail requirements for AI systems are currently binding: 21 CFR Part 11 [1] applies wherever an AI tool creates or modifies electronic records subject to FDA predicate rules; ICH E6(R3) [3] applies in the GCP context and explicitly covers automated actions; and EU GMP Annex 11 [7] applies to AI touching GMP-regulated manufacturing and quality systems. Other requirements are prudent but not yet binding by law: the FDA-EMA joint guiding principles [5] are non-prescriptive at present; the GAMP AI Guide [8] is industry consensus, not regulation; and the EU AI Act [6] high-risk provisions require a classification step before they apply and, under the provisional May 2026 Digital Omnibus agreement [18], the main enforcement dates have been pushed to 2027 and 2028 for most systems. The gap between binding and prudent is narrowing. Sponsors who build AI audit infrastructure to the prudent standard now will not need to retrofit under regulatory pressure later.

    Required today vs prudent preparation
    Binding today where applicable
    • 21 CFR Part 11 for predicate-rule electronic records [1]
    • ICH E6(R3) for GCP computerized systems and automated actions [3]
    • EU GMP Annex 11 for GMP-regulated manufacturing and quality systems [7]
    Prudent but not always binding yet
    • FDA-EMA joint AI principles [5]
    • ISPE GAMP AI Guide [8]
    • FDA January 2025 draft AI guidance when outside direct scope [4]
    • EU AI Act high-risk obligations after classification and applicable dates [6]

    The Explainability Problem and Its Documentation Consequences

    The compliance challenge particular to AI is not that these systems cannot generate audit trails. It is that the audit trail architecture required for regulated clinical use is fundamentally different from the standard logging most AI deployments produce.

    A 2025 systematic review published in Frontiers in Medicine covering a decade of AI medical device regulation [16] identified the black box problem as a central regulatory concern: complex AI models cannot easily explain their decision-making basis to users. Regulatory auditors evaluating AI outputs cannot assess algorithm behavior from code and test results alone when the internal logic is opaque. This creates an approval uncertainty that does not exist for conventional electronic systems.

    FDA's credibility assessment framework [4] addresses this by requiring that the context of use be explicitly defined and that model risk be assessed proportionate to the AI's influence on regulatory submissions. A drug safety commentary cited in the ISPE GAMP AI Guide [8] proposed treating every AI prompt-output session as an auditable record, meaning validation documents should contain log excerpts from production sessions. If adopted as a standard operating practice, that approach would require AI systems deployed in clinical regulatory workflows to log individual inference sessions at a granularity that most current implementations do not support out of the box.

    A 2026 review in Expert Opinion on Drug Safety [17], examining AI in pharmacovigilance, noted that the widespread adoption of AI safety tools is constrained by the black box problem and requires adherence to principles of explainability, transparency, and auditability. Methods such as SHAP (Shapley Additive Explanations) and LIME (Local Interpretable Model-Agnostic Explanations) have emerged as tools for translating opaque AI outputs into quantifiable risk factors for regulatory review. Their adoption in clinical regulatory writing contexts is early-stage.

    Research on AI-generated regulatory documents illustrates why purpose-built architecture matters. Wang et al. developed InformGen specifically to address a gap their literature review documented: prior benchmark studies of standard LLMs found that models including GPT-4 and Gemini could not generate legally compliant ICFs, covering fewer than one-third of required risks, procedural details, and preparatory instructions [11]. InformGen addressed this through structured retrieval and citation-grounded generation, achieving near-100% compliance with core regulatory rules on the InformBench dataset and outperforming vanilla GPT-4o on compliance dimensions [11]. The lesson for audit trail purposes is architectural: InformGen's outputs link to source documents at the point of generation, creating a retrievable provenance record. Generic LLM outputs do not. That structural difference is what regulators are beginning to examine.

    From black-box output to inspectable provenance
    1
    Generic LLM output
    Generated text without reliable source linkage
    2
    Review burden increases
    Human reviewer must manually verify every factual claim
    3
    Source-grounded generation
    Retrieval and citation architecture links output to source passages
    4
    Inspectable provenance record
    Reviewer and inspector can trace generated content back to input evidence
    5
    Audit trail plus validation
    Provenance supports review, but does not replace Part 11, E6(R3), or validation controls

    How Kitsa Fits Into This Problem

    KScribe, Kitsa's AI-native regulatory document generation platform, is built on a structured clinical intelligence architecture that captures source provenance at the point of generation. Each protocol, ICF, DSUR, or CSR section produced by KScribe links to the structured inputs and reference documents used to create it, generating a retrievable content provenance chain. When sponsors deploy KScribe within a validated GxP workflow, that chain, combined with documented human review and approval stages, is designed to support the documentation requirements of 21 CFR Part 11 [1], ICH E6(R3) [3], and the FDA's AI credibility framework [4]. Kitsa's platform is built to meet enterprise data security and privacy standards, with deployment infrastructure providing the access controls and data isolation that audit trail security requires.

    KScribe · Traceable AI Regulatory Document Generation

    Audit-ready AI regulatory systems require more than generated text. They need source provenance, model-version traceability, human review records, access controls, and retrievable document history. KScribe is built to support source-grounded regulatory document generation across protocols, ICFs, DSURs, IBs, and CSRs with structured review and traceability built into the workflow.

    Explore KScribe

    Key Takeaways

    AI-specific audit trail fields conventional systems often miss
    [1]
    Model version at inference time
    Exact model and configuration used for a given output
    [2]
    Prompt-level logging
    Prompt, retrieval context, and generation instructions
    [3]
    Training dataset lineage
    Documented source and governance of training and fine-tuning data
    [4]
    Post-generation processing
    Filters, guardrails, transformations, and automated edits
    [5]
    Drift monitoring
    Evidence that model behavior remains within validated expectations
    • Under 21 CFR Part 11, Section 11.10(e), audit trails must be secure, computer-generated, and time-stamped records of all electronic record creation, modification, and deletion; personnel must not be able to alter the trail, and retention must match the records' required retention period.
    • ICH E6(R3), finalized January 6, 2025, formally defines audit trails to encompass automated actions as well as human entries, adding ten pages of data lifecycle governance requirements and establishing routine audit trail review as a continuous GCP obligation.
    • FDA's January 2025 draft AI guidance (FDA-2024-D-4689), currently non-binding, sets out a framework for documenting a traceable chain linking AI model context of use, design, datasets, performance metrics, and monitoring plans before regulatory submissions rely on AI outputs.
    • The FDA-EMA joint guiding principles of January 14, 2026 call for AI systems in drug development to generate traceable, GxP-aligned documentation of data provenance and processing; though currently non-prescriptive, these principles are expected to underpin future binding guidance in both jurisdictions.
    • EU AI Act Regulation (EU) 2024/1689 requires automatic logging, minimum six-month log retention, and full technical documentation for high-risk AI systems; under a May 2026 provisional Digital Omnibus agreement, the compliance date for standalone Annex III systems is now December 2, 2027, and for embedded Annex I product systems August 2, 2028 (pending formal adoption). Classification as high-risk is not automatic and requires a case-by-case Article 6 assessment.
    • AI-specific audit trail gaps include model version control at inference time, prompt-level logging, training dataset lineage documentation, post-generation filtering records, and post-deployment drift monitoring, none of which are captured by conventional electronic record audit frameworks.
    • The same data integrity enforcement patterns that generated decades of 21 CFR Part 11 warning letters are now being directed at AI-generated clinical documents; the ISPE GAMP AI Guide (July 2025) calls for AI systems in GxP settings to carry validation documentation and audit records as rigorous as those for conventional electronic systems, and recommends proactive conformance with its framework as the most defensible industry posture when AI use comes under regulatory scrutiny [8].

    FAQ

    Are AI-generated regulatory documents subject to 21 CFR Part 11?
    Yes, to the extent they create or modify electronic records required by FDA predicate rules (such as 21 CFR Parts 312 or 314), the underlying system must meet 21 CFR Part 11 requirements for audit trails, electronic signatures, and system validation. FDA's October 2024 finalized guidance on electronic systems, records, and signatures in clinical investigations explicitly reiterates that sponsors retain responsibility for their vendors' Part 11 compliance and that delegation does not transfer regulatory liability [20].
    What does ICH E6(R3) specifically require for AI audit trails?
    ICH E6(R3) defines an audit trail as a secure, computer-generated, time-stamped record capturing creation, modification, or deletion of electronic records, explicitly including automated actions. Sponsors must maintain audit trails across EDC, eTMF, and eConsent systems, define which metadata requires routine review, conduct that review on a risk-based schedule, and document the review process itself. Systems that generate audit trails but leave them unreviewed do not satisfy E6(R3) expectations [3].
    What does FDA's January 2025 AI guidance require for documentation?
    The draft guidance (FDA-2024-D-4689) establishes a seven-step credibility assessment framework covering: defining the AI model's context of use, assessing its risk, developing a credibility plan, executing that plan, documenting all deviations, and determining the model's adequacy before relying on its outputs for regulatory submissions. The framework is a draft, not yet finalized, but it signals that sponsors will need organized, retrievable evidence of how each AI model was developed, tested, and governed. The FDA-EMA joint principles published January 14, 2026 [5] extend this further, calling for data source provenance, processing steps, and analytical decisions to be documented in a traceable, verifiable manner aligned with GxP standards.
    How does the EU AI Act affect audit trail obligations for clinical AI tools?
    Classification as high-risk under Regulation (EU) 2024/1689 is not automatic for clinical AI tools; it depends on a case-by-case Article 6 assessment. For systems that are classified as high-risk, Article 12 requires automatic logging of operations, Article 19 requires log retention for at least six months (or longer under applicable sectoral law), and Article 17 requires a documented quality management system covering data governance. On timing: the original August 2, 2026 compliance date for standalone Annex III high-risk systems has been provisionally delayed to December 2, 2027 under the EU Digital Omnibus on AI agreement of May 7, 2026 [18], with a further extension to August 2, 2028 for AI embedded in regulated Annex I products. Formal adoption of the Omnibus amendments was pending as of June 2026; sponsors should track final published text.
    What makes AI audit trails structurally different from conventional EDC audit trails?
    A conventional EDC audit trail records discrete human field edits against defined data fields. An AI audit trail must additionally capture the model version at inference time, the specific prompt or retrieval context used for each generation, training dataset lineage, any post-generation filtering, and human review timestamps for each AI output. The ISPE GAMP AI Guide (July 2025) recommends treating each AI prompt-output session as an independently auditable record [8].
    Can sponsors use AI for regulatory writing without a purpose-built audit trail system?
    The regulatory risk is substantial. The ISPE GAMP AI Guide (July 2025) [8] calls for regulated entities to treat AI use in GxP environments with the same validation rigor and audit trail depth as conventional electronic systems, and describes conformance with its framework as the most defensible industry posture when AI validation comes under regulatory scrutiny. Without an audit trail demonstrating source provenance, model version, human review, and output integrity, a sponsor may face difficulty satisfying the requirements of ICH E6(R3) [3], 21 CFR Part 11 [1], or the FDA's AI credibility framework [4] during inspection or submission review.

    References

    1. [1] U.S. Food and Drug Administration. "21 CFR Part 11: Electronic Records; Electronic Signatures." Code of Federal Regulations, Title 21, Part 11. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
    2. [2] U.S. Food and Drug Administration. "Guidance for Industry: Computerized Systems Used in Clinical Trials." FDA Bioresearch Monitoring Program, 1999. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/fda-bioresearch-monitoring-information/guidance-industry-computerized-systems-used-clinical-trials
    3. [3] International Council for Harmonisation. "ICH Harmonised Guideline E6(R3): Good Clinical Practice." Step 4 Finalization, January 6, 2025. https://www.ich.org/page/efficacy-guidelines
    4. [4] U.S. Food and Drug Administration. "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products." Draft Guidance, Docket No. FDA-2024-D-4689. Federal Register, January 7, 2025. https://www.federalregister.gov/documents/2025/01/07/2024-31542/
    5. [5] U.S. Food and Drug Administration and European Medicines Agency. "Guiding Principles of Good AI Practice in Drug Development." Joint Publication, January 14, 2026. https://www.fda.gov/science-research/artificial-intelligence-and-medical-products/guiding-principles-good-ai-practice-drug-development
    6. [6] European Parliament and Council of the European Union. "Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act)." Official Journal of the European Union, August 1, 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689
    7. [7] European Commission. "Stakeholders Consultation: EudraLex Volume 4 GMP Guidelines, Chapter 4, Annex 11 (Computerised Systems) and Annex 22 (Artificial Intelligence)." EC Health, July 7, 2025. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
    8. [8] International Society for Pharmaceutical Engineering. "ISPE GAMP Guide: Artificial Intelligence." ISPE, July 2025. https://ispe.org/topics/gamp
    9. [9] Park Y, Kwon K. "Trends in FDA Data Integrity Enforcement Before and After the COVID-19 Pandemic: An Analysis of 1766 Warning Letters (2016-2023)." Therapeutic Innovation and Regulatory Science. 2026;60(1):190-198. doi:10.1007/s43441-025-00870-3. PMID: 41071512. https://pubmed.ncbi.nlm.nih.gov/41071512/
    10. [10] U.S. Food and Drug Administration. "Warning Letter to Applied Therapeutics, Inc." Warning Letter ID 696833-12032024, November/December 2024. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/applied-therapeutics-inc-696833-12032024
    11. [11] Wang Z et al. "InformGen: An AI Copilot for Accurate and Compliant Clinical Research Consent Document Generation." arXiv preprint, April 2025. arXiv:2504.00934. https://arxiv.org/abs/2504.00934
    12. [12] European Medicines Agency. "Concept Paper on the Revision of EU GMP Annex 11: Computerised Systems." EMA, August 2024. https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/concept-paper-revision-annex-11-guidelines-good-manufacturing-practice-medicinal-products-computerised-systems_en.pdf
    13. [13] Niazi SK. "A Critical Review of the FDA's Draft Guidance on Artificial Intelligence in Drug and Biological Product Regulation." Journal of Chemistry. Wiley Online Library, 2026. doi:10.1155/joch/5202999. https://onlinelibrary.wiley.com/doi/10.1155/joch/5202999
    14. [14] Applied Clinical Trials. "FDA and EMA Align on Ten Principles to Guide Artificial Intelligence Use in Drug Development." Applied Clinical Trials Online, January 2026. https://www.appliedclinicaltrialsonline.com/view/fda-ema-align-ten-principles-artificial-intelligence-use-drug-development
    15. [15] Quanticate. "The ALCOA++ Principles for Data Integrity in Clinical Trials." Quanticate Blog, August 2025. https://www.quanticate.com/blog/alcoa-principles
    16. [16] Frontiers in Medicine Editorial. "A Decade of Review in Global Regulation and Research of Artificial Intelligence Medical Devices (2015-2025)." Frontiers in Medicine, 2025. PMC12310608. https://www.frontiersin.org/journals/medicine/articles/10.3389/fmed.2025.1630408/full
    17. [17] Pharmacovigilance Expert Review. "From Black Box to Clear Box: Explainable AI for Next-Generation Pharmacovigilance." Expert Opinion on Drug Safety, February 2026. doi:10.1080/14740338.2026.2628822. https://doi.org/10.1080/14740338.2026.2628822
    18. [18] Hogan Lovells. "EU Legislators Agree to Delay for High-Risk AI Rules." Hogan Lovells Client Alert, May 7, 2026. https://www.hoganlovells.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rules
    19. [19] Cooley LLP. "Complete Response Letter, Warning Letter and Shareholder Lawsuit Follow FDA Data Integrity Findings." Cooley Insights, January 14, 2025. https://www.cooley.com/news/insight/2025/2025-01-14-beware-of-bimo-complete-response-letter-warning-letter-and-shareholder-lawsuit-follow-fda-data-integrity-findings
    20. [20] U.S. Food and Drug Administration. "Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers." Final Guidance for Industry, Docket No. FDA-2017-D-1105. October 2, 2024. https://www.fda.gov/media/166215/download
    21. [21] Gibson Dunn. "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes." Gibson Dunn Client Alert, May 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
    22. [22] Council of the European Union. "Provisional Agreement on the Digital Omnibus on AI: High-Risk AI System Timeline Amendments." Official Press Release, May 7, 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/

    Related Articles