Contents
Introduction
In November 2024, FDA issued a warning letter to Applied Therapeutics after a third-party vendor deleted electronic audit trails for all 47 participants enrolled in a clinical trial, just two days after FDA preannounced an inspection [10]. The deleted records included electronic clinical outcome assessments used for primary and secondary efficacy endpoints, leaving FDA unable to access or verify the data. A complete response letter and subsequent shareholder litigation followed the regulatory disclosure [19]. The enforcement chain illustrates what audit trail failure actually costs in clinical development, stripped of abstraction.
The stakes have sharpened as AI enters the document generation and data analysis workflows of clinical trials. A protocol drafted by a language model, an informed consent form built by an automated tool, or a clinical study report assembled through structured AI outputs all raise the same question regulators are increasingly asking: can you demonstrate exactly what the system produced, on what inputs, at what time, and who reviewed and approved it? That question is not new. It is the core definition of an audit trail, codified decades ago under 21 CFR Part 11 [1]. What is new is that the same framework can apply to AI systems with the same rigor historically reserved for electronic data capture platforms and laboratory instruments, and many sponsors may not yet be ready to meet that standard.
Why Audit Trails Matter in AI-Enabled Clinical Research
Audit trail requirements have governed electronic records in FDA-regulated industries since 1997. Under 21 CFR Part 11, Section 11.10(e) [1], sponsors must maintain secure, computer-generated, time-stamped records documenting the creation, modification, and deletion of electronic records. Personnel who create, modify, or delete those records must not be able to alter the audit trail. Retention must last at least as long as the underlying records. FDA's guidance on computerized systems used in clinical investigations [2] further specifies that documentation must capture who made any change, when, and why.
What has changed is the scale and opacity of the systems now generating those records.
A full-enumeration analysis of 1,766 FDA warning letters issued between 2016 and 2023, published in Therapeutic Innovation and Regulatory Science [9], identified data integrity violations as a persistent enforcement priority, with audit trail deficiencies among the most frequently recurring citation categories across the entire study period. The authors found that electronic records violations, incomplete audit trail documentation, and unauthorized data modification consistently appeared regardless of firm size or geography [9]. When FDA inspectors now approach a site that has used an AI tool to generate protocol sections or annotate patient data, they ask for version logs, prompt records, human review timestamps, and change histories. The regulatory expectation exists in current guidance; the organizational readiness often does not.
The Regulatory Framework: Key Requirements in 2025 and 2026
ICH E6(R3) and the Formal Definition of Automated Audit Trails
ICH E6(R3), finalized on January 6, 2025, provides the most authoritative current definition of audit trails in the GCP context [3]. The guideline formally defines them as "metadata records that allow the appropriate evaluation of the course of events by capturing details on actions (manual or automated) performed relating to information and data collection and, where applicable, to activities in computerised systems." The phrase "manual or automated" is consequential. If an AI system generates a sentence in a protocol or modifies a field in an electronic case report form, that action falls within the scope of the audit trail requirement with the same attributability and timestamp standards as a human edit.
E6(R3) adds ten pages of new requirements on data lifecycle integrity, covering capture, metadata, audit trails, access controls, corrections, and secure retention [3]. Sponsors should classify data by criticality, maintain secure and tamper-evident audit records for critical systems within their inventory, and document investigators' read and write permissions clearly. These requirements apply across EDC systems, eTMFs, eConsent platforms, and any AI tool that creates or modifies records within those systems; read-only access logging carries a separate and generally lower documentation burden, but access controls and user attribution remain required even for read operations [3]. The guideline is in Step 4; regulatory adoption by ICH member countries, including the US and EU, is underway [3].
E6(R3) also reframes inspection readiness as a continuous operational state, not a preparation exercise [3]. Regulators expect sponsors to demonstrate real-time control over trial documentation at any point in the study. Audit trail review must occur on a risk-based schedule and must itself be documented. An audit trail that is technically enabled but never reviewed does not satisfy E6(R3) expectations.
FDA's January 2025 Draft AI Guidance
FDA's January 2025 draft guidance on the use of AI to support regulatory decision-making (Docket No. FDA-2024-D-4689) [4], which is currently in draft form and not yet binding, introduced a seven-step risk-based credibility assessment framework for AI models producing information intended for regulatory submissions. The framework covers: defining the AI model's context of use, assessing its risk, developing and executing a credibility plan, documenting deviations, and determining adequacy for the intended regulatory purpose. The guidance supports an expectation that credibility evidence and model performance documentation be organized and available for review, contemporaneous with the AI system's development and operational use rather than assembled retrospectively when a question arises [4].
Two points of scope are important. First, the guidance explicitly excludes AI used solely for operational efficiency in drafting and writing when those uses do not affect patient safety, drug quality, or study reliability [4]. AI document generation that functions as a writing aid without influencing clinical conclusions sits outside the credibility framework's mandatory scope. Second, the guidance does apply when AI outputs inform regulatory decisions about safety, efficacy, or quality: for example, when an AI model processes trial data to generate analytical summaries used in a submission, or when AI-generated protocol content directly shapes trial conduct. Sponsors should assess each AI use case individually against this scope boundary.
A critical review of the guidance published in the Journal of Chemistry in 2026 [13] noted that by December 2024, FDA had authorized more than 1,000 AI-based medical devices, demonstrating rapid progress in AI regulation at the device level. The January 2025 draft guidance represented the first formal credibility framework for AI in non-device drug and biologic development, signaling that the same accountability expectations are moving into the clinical trial documentation space.
FDA-EMA Joint Guiding Principles, January 14, 2026
On January 14, 2026, FDA and EMA jointly published ten guiding principles for good AI practice in drug development [5]. The principles span the full medicines lifecycle, from early research and clinical trials through manufacturing and post-market safety surveillance. Principle 6 addresses data governance and documentation; the joint document specifies that AI systems must support traceable, verifiable documentation where "data source provenance, processing steps, and analytical decisions are documented in a detailed, traceable, and verifiable manner, in line with Good Practices (GxP) requirements" [5]. Principle 9 addresses lifecycle management, requiring ongoing monitoring, drift detection, and periodic re-evaluation of AI systems over time [5].
The principles are currently non-prescriptive, but regulatory observers note that they are expected to underpin binding guidance in both jurisdictions [14]. Together with the January 2025 FDA draft guidance [4], they constitute the most detailed regulatory articulation to date of what "documented AI" means in a clinical context: not merely a statement that AI was used, but a full chain linking context of use, model design, input datasets, performance metrics, and monitoring records.
EU GMP Annex 11 Revision and New Annex 22 on AI
The European Commission published draft revisions to EU GMP Annex 11 (Computerised Systems) alongside an entirely new Annex 22 specifically covering artificial intelligence on July 7, 2025 [7]. It is worth clarifying the scope: Annex 11 and Annex 22 sit within the EU GMP framework, which governs manufacturing, quality control, and quality systems rather than clinical trial conduct directly. Their most immediate relevance in a clinical context is to investigational medicinal product (IMP) manufacturing, laboratory systems, and quality systems that underpin trial operations, not to GCP-governed trial management systems, which fall under ICH E6(R3) and national GCP regulations. Both frameworks can be applicable simultaneously within a single development program, but they are not interchangeable.
Within the GMP context, the revised Annex 11 draft proposes making audit trails mandatory for all GMP-critical computerized systems where data or settings can be changed, requiring logs to capture user identity, timestamp, old and new values, and a documented reason for nearly all edits [7]. This direction had been signaled in the EMA concept paper published in 2022 [12], which identified mandatory audit trails for all GMP-critical systems as a core gap in the then-current Annex 11 and called for explicit guidance on AI/ML systems. The draft further clarifies that audit trails must be tamper-proof: no user should be able to modify or disable them [7].
Annex 22 brings AI and machine learning under explicit GMP compliance requirements, obligating regulated companies to explain and justify AI behavior from training data through real-time use, with model-specific documentation analogous to what the ISPE GAMP AI Guide [8] describes. Final versions of both documents are expected by mid-2026, as of the time of writing, with the final text expected to clarify scope boundaries further.
EU AI Act: Logging Requirements for High-Risk Systems
Under Regulation (EU) 2024/1689 [6], whether a specific AI system qualifies as high-risk depends on the Article 6 classification framework, which looks at whether the system is a safety component of a product regulated under EU harmonized legislation, or falls into one of the Annex III categories (which include AI systems used in critical infrastructure, education, employment, and access to essential services). AI systems used in clinical trials do not automatically qualify as high-risk under Annex III as currently written; classification requires a case-by-case assessment of the AI's role. AI tools that directly influence clinical decision-making, patient eligibility determinations, or safety reporting carry stronger arguments for high-risk classification than systems used purely to draft text [6].
For systems that are classified as high-risk, the obligations are specific. Article 12 mandates automatic logging of operations to the extent technically feasible. Article 19 requires retention of automatically generated logs for a minimum of six months, or longer where applicable sectoral law requires. Article 18 requires that providers maintain the technical documentation specified in Annex IV, and Article 17 requires a quality management system encompassing data governance and record-keeping [6].
A note on implementation timing is material as of June 2026. The original EU AI Act envisaged that standalone Annex III high-risk AI systems would need to comply from August 2, 2026. On May 7, 2026, the European Parliament and the Council reached a provisional agreement under the Digital Omnibus on AI to delay this: standalone Annex III high-risk systems now face a compliance date of December 2, 2027, and high-risk AI embedded in regulated Annex I products a date of August 2, 2028 [18],[21],[22]. Formal adoption of the Omnibus amendments was expected before August 2026; the substantive requirements themselves have not changed, and regulatory counsel advise that preparation efforts should continue regardless of the extended deadline [18].
ISPE GAMP Guide: Artificial Intelligence
The ISPE GAMP Guide: Artificial Intelligence, published in July 2025 [8], is the first comprehensive GAMP guidance document focused exclusively on AI applications in GxP-regulated environments. Its 290 pages extend GAMP 5 principles to AI's distinct characteristics: non-deterministic outputs, model drift, the absence of conventional software version equivalents, and the challenge of validating systems whose behavior changes after training. The guide calls for AI systems in GxP settings to carry audit trails at least as comprehensive as those mandated for conventional electronic systems, and for validation documents to ground performance claims in logged, traceable evidence rather than assertion [8].
The guide recommends that AI systems in GxP settings carry validation documentation and audit records as rigorous as those required for conventional electronic systems, and the ISPE authors note that as AI use in regulated environments becomes routine, regulators will increasingly scrutinize the underlying validation records and governance documentation [8].
Operational Implications: What Audit Trails for AI Systems Must Capture
A conventional EDC audit trail is a finite record of discrete human actions: user ID, timestamp, original field value, new value, and reason code. AI systems introduce documentation layers that conventional audit trail frameworks do not address.
For a sponsor deploying an AI tool to generate protocol sections or summarize clinical data for a CSR, where the output is a regulated record or supports a regulated decision, a compliant audit trail should capture the model version in use at the time of generation; the specific input context, prompt, or retrieval documents used to produce the output; any guardrails, filters, or post-generation processing applied; the initial AI output before human edits; each subsequent revision with timestamp and author; and the electronic signature on the final approved version. Under ICH E6(R3) [3], all of these elements constitute the metadata record needed to reconstruct "the course of events relating to the creation, modification, or deletion" of the document.
The lifecycle dimension adds another layer. FDA's January 2025 draft guidance (FDA-2024-D-4689) [4], currently in draft form and not yet binding, recommends that sponsors with iteratively updated AI models develop lifecycle maintenance and change management plans documenting what types of changes are permitted, what validation each change class requires, and how rollback is handled. Every retraining event is a documentation event, and the audit trail should reflect it. Model drift, the degradation of real-world model performance as input distributions shift over time, should be monitored and the monitoring itself documented [5].
ALCOA++ principles, the ten-attribute data integrity framework comprising Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available, and Traceable, apply to AI outputs as they do to any other clinical trial record [15]. "Attributable" requires linking each generated output to a specific model version and configuration. "Original" requires that the initial AI-generated text be preserved before human editing. "Traceable" requires that a regulator can follow any data point in the Trial Master File from its first generation through every modification to its final form.
Enabled-but-unreviewed audit trails are not enough. A 2024 FDA inspection of a pharmaceutical manufacturer cited "insufficient high-level audit trail review instructions" as a finding, noting that personnel were unaware of their obligation to review all audit trail data during the inspection. That pattern, documented extensively in FDA warning letter analyses [9], is now transferring to AI contexts.
AI Use Case Mapping: Which Framework Applies
The regulatory framework that governs an AI use case depends on its function and context, not on whether AI is involved. The table below maps common clinical AI use cases to their primary compliance anchor:
| AI Use Case | Primary Framework | Binding or Prudent |
|---|---|---|
| Protocol drafting assistance (efficiency only) | 21 CFR Part 11 / ICH E6(R3) for final document records | Binding for records; FDA AI guidance may not apply if no safety/quality impact |
| AI analytical summaries used in regulatory submissions | FDA Jan 2025 draft AI guidance (FDA-2024-D-4689) | Draft/prudent; expected to bind when finalized |
| eCOA data annotation and cleaning | 21 CFR Part 11, ICH E6(R3) | Binding |
| Pharmacovigilance signal detection | FDA AI guidance (scope dependent); FDA-EMA 2026 principles | Draft/prudent |
| IMP manufacturing quality control AI | EU GMP Annex 11 / Annex 22; 21 CFR Part 11 | Binding for GMP records |
| CSR data review and synthesis | FDA AI guidance if outputs support submissions; ICH E6(R3) for source records | Dependent on scope assessment |
| Patient eligibility AI in EU jurisdictions | EU AI Act (if high-risk classification applies after Article 6 assessment) | Prudent now; binding from Dec 2, 2027 only if classified as standalone Annex III high-risk and Omnibus amendments are formally adopted |
This table is a scoping aid, not a legal classification. Each AI deployment requires its own assessment against the specific regulatory texts, product type, and intended use.
Required vs. Prudent: Knowing Where You Stand
A practical distinction is worth drawing. Some audit trail requirements for AI systems are currently binding: 21 CFR Part 11 [1] applies wherever an AI tool creates or modifies electronic records subject to FDA predicate rules; ICH E6(R3) [3] applies in the GCP context and explicitly covers automated actions; and EU GMP Annex 11 [7] applies to AI touching GMP-regulated manufacturing and quality systems. Other requirements are prudent but not yet binding by law: the FDA-EMA joint guiding principles [5] are non-prescriptive at present; the GAMP AI Guide [8] is industry consensus, not regulation; and the EU AI Act [6] high-risk provisions require a classification step before they apply and, under the provisional May 2026 Digital Omnibus agreement [18], the main enforcement dates have been pushed to 2027 and 2028 for most systems. The gap between binding and prudent is narrowing. Sponsors who build AI audit infrastructure to the prudent standard now will not need to retrofit under regulatory pressure later.
The Explainability Problem and Its Documentation Consequences
The compliance challenge particular to AI is not that these systems cannot generate audit trails. It is that the audit trail architecture required for regulated clinical use is fundamentally different from the standard logging most AI deployments produce.
A 2025 systematic review published in Frontiers in Medicine covering a decade of AI medical device regulation [16] identified the black box problem as a central regulatory concern: complex AI models cannot easily explain their decision-making basis to users. Regulatory auditors evaluating AI outputs cannot assess algorithm behavior from code and test results alone when the internal logic is opaque. This creates an approval uncertainty that does not exist for conventional electronic systems.
FDA's credibility assessment framework [4] addresses this by requiring that the context of use be explicitly defined and that model risk be assessed proportionate to the AI's influence on regulatory submissions. A drug safety commentary cited in the ISPE GAMP AI Guide [8] proposed treating every AI prompt-output session as an auditable record, meaning validation documents should contain log excerpts from production sessions. If adopted as a standard operating practice, that approach would require AI systems deployed in clinical regulatory workflows to log individual inference sessions at a granularity that most current implementations do not support out of the box.
A 2026 review in Expert Opinion on Drug Safety [17], examining AI in pharmacovigilance, noted that the widespread adoption of AI safety tools is constrained by the black box problem and requires adherence to principles of explainability, transparency, and auditability. Methods such as SHAP (Shapley Additive Explanations) and LIME (Local Interpretable Model-Agnostic Explanations) have emerged as tools for translating opaque AI outputs into quantifiable risk factors for regulatory review. Their adoption in clinical regulatory writing contexts is early-stage.
Research on AI-generated regulatory documents illustrates why purpose-built architecture matters. Wang et al. developed InformGen specifically to address a gap their literature review documented: prior benchmark studies of standard LLMs found that models including GPT-4 and Gemini could not generate legally compliant ICFs, covering fewer than one-third of required risks, procedural details, and preparatory instructions [11]. InformGen addressed this through structured retrieval and citation-grounded generation, achieving near-100% compliance with core regulatory rules on the InformBench dataset and outperforming vanilla GPT-4o on compliance dimensions [11]. The lesson for audit trail purposes is architectural: InformGen's outputs link to source documents at the point of generation, creating a retrievable provenance record. Generic LLM outputs do not. That structural difference is what regulators are beginning to examine.
How Kitsa Fits Into This Problem
KScribe, Kitsa's AI-native regulatory document generation platform, is built on a structured clinical intelligence architecture that captures source provenance at the point of generation. Each protocol, ICF, DSUR, or CSR section produced by KScribe links to the structured inputs and reference documents used to create it, generating a retrievable content provenance chain. When sponsors deploy KScribe within a validated GxP workflow, that chain, combined with documented human review and approval stages, is designed to support the documentation requirements of 21 CFR Part 11 [1], ICH E6(R3) [3], and the FDA's AI credibility framework [4]. Kitsa's platform is built to meet enterprise data security and privacy standards, with deployment infrastructure providing the access controls and data isolation that audit trail security requires.
Audit-ready AI regulatory systems require more than generated text. They need source provenance, model-version traceability, human review records, access controls, and retrievable document history. KScribe is built to support source-grounded regulatory document generation across protocols, ICFs, DSURs, IBs, and CSRs with structured review and traceability built into the workflow.
Explore KScribeKey Takeaways
- •Under 21 CFR Part 11, Section 11.10(e), audit trails must be secure, computer-generated, and time-stamped records of all electronic record creation, modification, and deletion; personnel must not be able to alter the trail, and retention must match the records' required retention period.
- •ICH E6(R3), finalized January 6, 2025, formally defines audit trails to encompass automated actions as well as human entries, adding ten pages of data lifecycle governance requirements and establishing routine audit trail review as a continuous GCP obligation.
- •FDA's January 2025 draft AI guidance (FDA-2024-D-4689), currently non-binding, sets out a framework for documenting a traceable chain linking AI model context of use, design, datasets, performance metrics, and monitoring plans before regulatory submissions rely on AI outputs.
- •The FDA-EMA joint guiding principles of January 14, 2026 call for AI systems in drug development to generate traceable, GxP-aligned documentation of data provenance and processing; though currently non-prescriptive, these principles are expected to underpin future binding guidance in both jurisdictions.
- •EU AI Act Regulation (EU) 2024/1689 requires automatic logging, minimum six-month log retention, and full technical documentation for high-risk AI systems; under a May 2026 provisional Digital Omnibus agreement, the compliance date for standalone Annex III systems is now December 2, 2027, and for embedded Annex I product systems August 2, 2028 (pending formal adoption). Classification as high-risk is not automatic and requires a case-by-case Article 6 assessment.
- •AI-specific audit trail gaps include model version control at inference time, prompt-level logging, training dataset lineage documentation, post-generation filtering records, and post-deployment drift monitoring, none of which are captured by conventional electronic record audit frameworks.
- •The same data integrity enforcement patterns that generated decades of 21 CFR Part 11 warning letters are now being directed at AI-generated clinical documents; the ISPE GAMP AI Guide (July 2025) calls for AI systems in GxP settings to carry validation documentation and audit records as rigorous as those for conventional electronic systems, and recommends proactive conformance with its framework as the most defensible industry posture when AI use comes under regulatory scrutiny [8].
FAQ
Are AI-generated regulatory documents subject to 21 CFR Part 11?
What does ICH E6(R3) specifically require for AI audit trails?
What does FDA's January 2025 AI guidance require for documentation?
How does the EU AI Act affect audit trail obligations for clinical AI tools?
What makes AI audit trails structurally different from conventional EDC audit trails?
Can sponsors use AI for regulatory writing without a purpose-built audit trail system?
References
- [1] U.S. Food and Drug Administration. "21 CFR Part 11: Electronic Records; Electronic Signatures." Code of Federal Regulations, Title 21, Part 11. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- [2] U.S. Food and Drug Administration. "Guidance for Industry: Computerized Systems Used in Clinical Trials." FDA Bioresearch Monitoring Program, 1999. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/fda-bioresearch-monitoring-information/guidance-industry-computerized-systems-used-clinical-trials
- [3] International Council for Harmonisation. "ICH Harmonised Guideline E6(R3): Good Clinical Practice." Step 4 Finalization, January 6, 2025. https://www.ich.org/page/efficacy-guidelines
- [4] U.S. Food and Drug Administration. "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products." Draft Guidance, Docket No. FDA-2024-D-4689. Federal Register, January 7, 2025. https://www.federalregister.gov/documents/2025/01/07/2024-31542/
- [5] U.S. Food and Drug Administration and European Medicines Agency. "Guiding Principles of Good AI Practice in Drug Development." Joint Publication, January 14, 2026. https://www.fda.gov/science-research/artificial-intelligence-and-medical-products/guiding-principles-good-ai-practice-drug-development
- [6] European Parliament and Council of the European Union. "Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act)." Official Journal of the European Union, August 1, 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689
- [7] European Commission. "Stakeholders Consultation: EudraLex Volume 4 GMP Guidelines, Chapter 4, Annex 11 (Computerised Systems) and Annex 22 (Artificial Intelligence)." EC Health, July 7, 2025. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
- [8] International Society for Pharmaceutical Engineering. "ISPE GAMP Guide: Artificial Intelligence." ISPE, July 2025. https://ispe.org/topics/gamp
- [9] Park Y, Kwon K. "Trends in FDA Data Integrity Enforcement Before and After the COVID-19 Pandemic: An Analysis of 1766 Warning Letters (2016-2023)." Therapeutic Innovation and Regulatory Science. 2026;60(1):190-198. doi:10.1007/s43441-025-00870-3. PMID: 41071512. https://pubmed.ncbi.nlm.nih.gov/41071512/
- [10] U.S. Food and Drug Administration. "Warning Letter to Applied Therapeutics, Inc." Warning Letter ID 696833-12032024, November/December 2024. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/applied-therapeutics-inc-696833-12032024
- [11] Wang Z et al. "InformGen: An AI Copilot for Accurate and Compliant Clinical Research Consent Document Generation." arXiv preprint, April 2025. arXiv:2504.00934. https://arxiv.org/abs/2504.00934
- [12] European Medicines Agency. "Concept Paper on the Revision of EU GMP Annex 11: Computerised Systems." EMA, August 2024. https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/concept-paper-revision-annex-11-guidelines-good-manufacturing-practice-medicinal-products-computerised-systems_en.pdf
- [13] Niazi SK. "A Critical Review of the FDA's Draft Guidance on Artificial Intelligence in Drug and Biological Product Regulation." Journal of Chemistry. Wiley Online Library, 2026. doi:10.1155/joch/5202999. https://onlinelibrary.wiley.com/doi/10.1155/joch/5202999
- [14] Applied Clinical Trials. "FDA and EMA Align on Ten Principles to Guide Artificial Intelligence Use in Drug Development." Applied Clinical Trials Online, January 2026. https://www.appliedclinicaltrialsonline.com/view/fda-ema-align-ten-principles-artificial-intelligence-use-drug-development
- [15] Quanticate. "The ALCOA++ Principles for Data Integrity in Clinical Trials." Quanticate Blog, August 2025. https://www.quanticate.com/blog/alcoa-principles
- [16] Frontiers in Medicine Editorial. "A Decade of Review in Global Regulation and Research of Artificial Intelligence Medical Devices (2015-2025)." Frontiers in Medicine, 2025. PMC12310608. https://www.frontiersin.org/journals/medicine/articles/10.3389/fmed.2025.1630408/full
- [17] Pharmacovigilance Expert Review. "From Black Box to Clear Box: Explainable AI for Next-Generation Pharmacovigilance." Expert Opinion on Drug Safety, February 2026. doi:10.1080/14740338.2026.2628822. https://doi.org/10.1080/14740338.2026.2628822
- [18] Hogan Lovells. "EU Legislators Agree to Delay for High-Risk AI Rules." Hogan Lovells Client Alert, May 7, 2026. https://www.hoganlovells.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rules
- [19] Cooley LLP. "Complete Response Letter, Warning Letter and Shareholder Lawsuit Follow FDA Data Integrity Findings." Cooley Insights, January 14, 2025. https://www.cooley.com/news/insight/2025/2025-01-14-beware-of-bimo-complete-response-letter-warning-letter-and-shareholder-lawsuit-follow-fda-data-integrity-findings
- [20] U.S. Food and Drug Administration. "Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers." Final Guidance for Industry, Docket No. FDA-2017-D-1105. October 2, 2024. https://www.fda.gov/media/166215/download
- [21] Gibson Dunn. "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes." Gibson Dunn Client Alert, May 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- [22] Council of the European Union. "Provisional Agreement on the Digital Omnibus on AI: High-Risk AI System Timeline Amendments." Official Press Release, May 7, 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
