Two clinical laboratory researchers in protective gear reviewing samples and digital records at a workstation
    Regulatory Writing

    FDA, EMA, and ICH Expectations for AI Regulatory Systems

    Practical guide to FDA, EMA and ICH expectations for AI in clinical regulatory systems: credibility, validation, lifecycle governance and data integrity.

    Published by Kitsa Editorial Team
    ~20 min read
    Contents

    Introduction

    In September 2024, the EMA finalized its Reflection Paper on AI in the medicinal product lifecycle, establishing expectations for transparency, reproducibility, and human oversight across the full drug development process [2]. Four months later, in January 2025, the FDA published its first draft guidance specifically addressing artificial intelligence in drug and biological product regulation: a 7-step credibility assessment framework that applies to any AI model generating data intended to inform regulatory decisions about safety, effectiveness, or quality [1]. Then, on January 14, 2026, the two agencies jointly published ten Guiding Principles of Good AI Practice in Drug Development [3], the first time FDA and EMA have formally converged on a shared regulatory vision for AI across the full medicines lifecycle.

    These three documents, read alongside ICH E6(R3) (finalized January 2025 and adopted by the FDA in September 2025) [4] and the finalized ICH M11 CeSHarP protocol standard (published in the Federal Register May 2026) [5], represent one of the most significant recent convergences of AI regulatory expectations produced by major health authorities. They span a range of legal instruments: FDA's drug-development guidance is a non-binding draft; EMA's Reflection Paper is a non-binding position; the joint principles are explicitly voluntary; ICH E6(R3) is a formal guidance standard adopted by regulators; and the EU AI Act is binding law. The practical force of the non-binding frameworks is substantial nonetheless, since they help define what regulatory reviewers and inspectors are likely to evaluate or reference when AI is used in a submission or regulated trial. For sponsors, CROs, and medical writing teams deploying AI to generate or support regulatory documentation, these frameworks now define the baseline that reviewers and inspectors are likely to reference when AI is disclosed in submissions or identified during inspections.

    This article breaks down the operative expectations from each framework, explains where they converge and where they differ, and draws out what the combined regulatory environment means for any organization running AI in clinical or regulatory operations today. Status of all cited instruments is current as of June 2026.

    Key regulatory milestones shaping AI regulatory systems
    September 2024
    EMA finalizes its Reflection Paper on AI in the medicinal product lifecycle [2]
    January 2025
    FDA publishes draft AI guidance with a seven-step credibility assessment framework [1]
    January 2025
    ICH E6(R3) is finalized as the updated GCP framework [4]
    November 2025
    ICH M11 CeSHarP is finalized by the ICH Assembly [5]
    January 14, 2026
    FDA and EMA jointly publish ten Guiding Principles of Good AI Practice [3]
    May 2026
    FDA announces availability of finalized ICH M11 CeSHarP guidance [5]

    Why the Regulatory Community Is Paying Attention Now

    The regulatory frameworks arrived because the underlying activity reached a scale that demanded them. FDA has received more than 500 drug and biological product submissions containing AI components since 2016, with a measurable increase year-over-year as AI integration accelerated across oncology, neurology, and pharmacovigilance applications [1],[19]. As of December 2024, FDA had authorized more than 1,000 AI-based medical devices, a figure that reflects years of incremental AI governance work that CDRH began well before CDER's January 2025 drug-development guidance arrived [6].

    On the European side, the EU AI Act (Regulation 2024/1689) entered into force in August 2024 [7]. Its requirements apply on a staggered timeline: prohibitions and AI literacy duties began applying in February 2025, governance obligations for general-purpose AI models took effect in August 2025. Under the original Act, Annex III standalone high-risk systems were due to comply from August 2, 2026, and Article 6(1) systems embedded in Annex I-regulated products from August 2, 2027. Under the Digital Omnibus provisional agreement of May 7, 2026, which is expected to receive formal adoption before August 2, 2026, those deadlines would be extended by different amounts: the Annex III standalone high-risk deadline would move by approximately 16 months to December 2, 2027, and the Article 6(1) product-integrated deadline would move by 12 months to August 2, 2028 [16].

    Not all pharmaceutical or clinical AI is automatically high-risk under the Act. Classification follows two distinct routes in Article 6 [7]. The first covers AI that is a safety component of, or itself a product under, Union harmonization legislation listed in Annex I, most relevantly the EU Medical Device Regulation (MDR 2017/745); AI clinical decision-support tools that meet the MDR definition of a medical device fall here. The second covers AI whose specific intended use falls within one of the Annex III categories; the health-related Annex III entries are narrow, covering biometric categorization using sensitive attributes, AI used by public authorities to determine eligibility for public healthcare benefits, AI for risk assessment and pricing in life and health insurance, and patient triage systems [7]. Clinical trial management AI, pharmacovigilance analytics, and regulatory document generation do not appear in Annex III and are not automatically classified as high-risk: that classification requires analysis of intended use and whether the system materially influences decisions affecting individuals' health, safety, or fundamental rights [7].

    The EU AI Act is sector-agnostic; it does not address the pharmaceutical-specific quality standards that govern how clinical evidence is generated, reviewed, or submitted. The EMA Reflection Paper and the joint FDA-EMA principles fill that gap, translating the Act's broad requirements into the vocabulary of GxP, GCP, and marketing authorization [2],[3].

    The combined effect is this: AI systems that operate anywhere in the regulatory evidence chain are now subject to overlapping, mutually reinforcing expectations from four sources simultaneously: FDA guidance, EMA guidance, ICH standards, and EU law. Organizations that treat these as separate compliance checklists will find themselves managing contradictions. Organizations that understand how the frameworks interlock will find that meeting one set of expectations goes a long way toward meeting the others.

    Why AI regulatory systems are now under multi-framework scrutiny
    500+
    FDA drug and biologic submissions
    FDA submissions containing AI components since 2016 [1],[19]
    1,000+
    FDA AI medical devices
    AI-based medical devices authorized by FDA as of December 2024 [6]
    August 2024
    EU AI Act
    EU AI Act entered into force [7]
    January 2026
    FDA-EMA joint AI principles
    First formally converged FDA-EMA AI principles [3]

    The FDA Credibility Assessment Framework

    FDA's January 2025 draft guidance, "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products" (Docket FDA-2024-D-4689), is the agency's first comprehensive guidance for AI in drug and biologics regulation [1]. It applies to any AI model whose output is intended to inform regulatory decisions about a product's safety, effectiveness, or quality, covering the full drug lifecycle from nonclinical through post-marketing and manufacturing phases, but explicitly excluding AI used solely in drug discovery or internal operational efficiency [1].

    Context of Use

    The guidance centers on a concept called the context of use (COU): the specific role and scope of an AI model for addressing a defined question of interest. Before any other assessment can proceed, sponsors must define the COU precisely: what question the model addresses, what inputs it processes, and what outputs it produces for regulatory purposes [1]. This requirement is deceptively demanding. Generic system descriptions will not satisfy it; COU documentation must be granular enough that a reviewer can assess whether the model's design is actually fit for the claimed purpose.

    Seven-Step Credibility Assessment

    FDA proposes a structured seven-step process for establishing and documenting AI model credibility [1]:

    FDA seven-step AI credibility assessment framework
    1
    Define the question of interest
    Clarify the regulatory question the AI model addresses
    2
    Define the context of use
    Document the model role, inputs, outputs, and scope
    3
    Assess AI model risk
    Evaluate model influence and consequence of decision error
    4
    Develop a credibility assessment plan
    Plan testing proportionate to the model's risk
    5
    Execute the plan
    Run the planned credibility assessment activities
    6
    Document results and deviations
    Record outcomes, deviations, and supporting evidence
    7
    Determine adequacy for COU
    Decide whether performance is sufficient for the intended context of use
    1. Define the question of interest
    2. Define the context of use
    3. Assess the AI model risk
    4. Develop a credibility assessment plan proportionate to that risk
    5. Execute the plan
    6. Document results and deviations
    7. Determine the adequacy of the model for the COU

    Risk, under this framework, is not simply clinical severity; it is a function of two dimensions: the influence the model has on the regulatory decision, and the consequence of a decision error [1]. A model that categorizes patients for outpatient versus inpatient monitoring occupies a different risk tier than a model that flags data anomalies for human review. The guidance provides a worked example of the former to illustrate why the stakes of miscategorization demand proportionally rigorous credibility assessment [1].

    Lifecycle and ALCOA+

    FDA's guidance describes lifecycle evaluation as important in certain contexts of use, particularly where AI models are applied to data distributions that may change over time: not a single validation event, but ongoing monitoring for model drift, distribution shift, and performance degradation relative to the established COU [1]. Data pipelines feeding AI must meet the data integrity standards applicable to the regulatory context. In GMP environments, FDA CGMP guidance articulates these through ALCOA+ principles: Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available [17]. FDA's AI guidance similarly requires that data used for model development and evaluation be accurate, complete, and of sufficient quality to support the intended COU [1]. Under 21 CFR Part 11, AI systems that create, modify, maintain, archive, or transmit electronic records required under an FDA predicate rule are subject to Part 11 obligations, which FDA interprets narrowly and applies with enforcement discretion in certain areas, focusing compliance effort on systems that directly affect product quality, safety, or the integrity of regulatory submissions [8]. For systems within Part 11's scope, validation, tamper-resistant audit trails, and access controls are required in proportion to the system's role in the regulated record-keeping process [8].

    FDA explicitly encourages sponsors to engage early through formal meeting requests or other available channels to set expectations for credibility assessment activities before proceeding, since the appropriate approach depends on the specific COU and risk profile [1].

    EMA's Reflection Paper: Fit-for-Purpose Evidence, Not Just Compliance

    EMA's Reflection Paper on the use of AI in the medicinal product lifecycle (EMA/CHMP/CVMP/83833/2023, final September 2024) takes a different but complementary angle [2]. Where FDA's guidance is structured around a formal framework with defined steps, EMA's paper articulates governing principles and places responsibility squarely on the sponsor or marketing authorization applicant to demonstrate that AI systems are fit for purpose across the range of legal, ethical, technical, scientific, and regulatory standards that apply.

    The paper's core accountability statement is unequivocal: it is the responsibility of the sponsor, MAH, or manufacturer to ensure that all algorithms, models, datasets, and data processing pipelines used are fit for purpose and comply with EU legislation, GxP standards, and current EMA guidelines [2]. The paper does not provide safe harbor for systems that merely meet minimum technical specifications; it demands that each AI application be evaluated against the specific scientific and regulatory context in which it operates.

    Transparency and Explainability

    EMA acknowledges directly that full explainability is not always achievable: some model architectures are inherently opaque, and black-box outputs cannot always be traced to interpretable causal paths [2]. The paper does not disqualify such models outright. Instead, it introduces a practical threshold: where full explainability is not possible, sponsors must demonstrate interpretability, meaning substantive evidence that human oversight is in place and that the model's performance can be monitored, interrogated, and acted upon when it fails or underperforms [2],[9].

    This is a meaningful distinction. Explainability is about understanding why a model makes a specific prediction. Interpretability, as EMA uses it, is about whether the system is governed well enough that a human can identify problems and intervene. A model does not need to be a glass box to meet EMA's expectations, but it must be embedded in a governance structure that prevents unchecked reliance on its outputs.

    What EMA Requires in Scientific Advice

    For any request for scientific advice or opinion involving an AI-supported application, EMA expects sponsors to provide the full model architecture, logs from model development, documentation of training and validation datasets, and evidence of the model's generalizability to the specific target population and regulatory context [2]. This is substantively more than a description of what the model does; it is a technical dossier covering how the model was built and why it performs as claimed.

    EMA's emphasis on dataset integrity is particularly salient for regulatory document generation. A model trained on data that does not reflect the population, endpoints, or regulatory standards relevant to a specific application cannot demonstrate generalizability; and EMA reviewers will ask about this [2].

    What EMA expects sponsors to evidence for AI-supported applications
    1
    Model architecture
    How the model was designed and what it is intended to do
    2
    Training and validation datasets
    Dataset source, quality, representativeness, and limitations
    3
    Generalizability
    Evidence that performance transfers to the target population and regulatory context
    4
    Human oversight
    How qualified humans monitor, challenge, and intervene
    5
    Lifecycle monitoring
    How performance is tracked after deployment

    The Joint FDA-EMA Principles: Ten Points of Convergence

    On January 14, 2026, FDA's CDER and CBER, together with EMA, published ten Guiding Principles of Good AI Practice in Drug Development [3]. The principles are explicitly non-prescriptive; they do not themselves create binding obligations; but they represent the first formally harmonized regulatory statement on AI across the two largest pharmaceutical markets in the world. As Jones Day's regulatory analysis noted, they are likely to shape future mandatory guidance on both sides of the Atlantic [3],[10].

    The ten principles are [3]:

    1
    Human-centric by design
    AI systems must reflect ethical and human values, with patient interests and public health as the primary goal
    2
    Risk-based approach
    Validation, oversight, and safeguards must be proportionate to the COU and associated risk level
    3
    Adherence to standards
    AI applications must comply with applicable legal, ethical, scientific, and regulatory standards
    4
    Clear context of use
    The intended purpose and scope of every AI application must be precisely defined
    5
    Multidisciplinary expertise
    AI development and deployment must draw on diverse expertise, including clinical, statistical, computational, and regulatory knowledge
    6
    Data governance and documentation
    Data pipelines must be documented, controlled, and auditable throughout the AI lifecycle
    7
    Model design and development practices
    Model architecture, training, and validation must be appropriate to the COU and documented
    8
    Risk-based performance assessment
    Performance testing must be proportionate to the AI system's influence on regulated decisions
    9
    Lifecycle management
    AI systems require ongoing monitoring, maintenance, and periodic reassessment
    10
    Clear, essential information
    Users of AI systems must receive accurate and sufficient information about model outputs, limitations, and uncertainty
    1. Human-centric by design: AI systems must reflect ethical and human values, with patient interests and public health as the primary goal
    2. Risk-based approach: validation, oversight, and safeguards must be proportionate to the COU and associated risk level
    3. Adherence to standards: AI applications must comply with applicable legal, ethical, scientific, and regulatory standards
    4. Clear context of use: the intended purpose and scope of every AI application must be precisely defined
    5. Multidisciplinary expertise: AI development and deployment must draw on diverse expertise, including clinical, statistical, computational, and regulatory knowledge
    6. Data governance and documentation: data pipelines must be documented, controlled, and auditable throughout the AI lifecycle
    7. Model design and development practices: model architecture, training, and validation must be appropriate to the COU and documented
    8. Risk-based performance assessment: performance testing must be proportionate to the AI system's influence on regulated decisions
    9. Lifecycle management: AI systems require ongoing monitoring, maintenance, and periodic reassessment
    10. Clear, essential information: users of AI systems must receive accurate and sufficient information about model outputs, limitations, and uncertainty

    Applied Clinical Trials' analysis of the principles noted that the joint publication builds on prior FDA-EMA collaboration following bilateral discussions in 2024, and signals intent for deeper convergence in future jurisdiction-specific guidance [11]. For sponsors, the practical effect is that a credibility assessment plan designed to satisfy FDA's seven-step framework will, if adequately detailed, also address the governance and documentation expectations embedded in EMA's principles and vice versa.

    What the Frameworks Mean for Specific AI Use Cases

    How the combined framework applies depends substantially on what the AI system does. The table below maps common pharmaceutical AI uses to their primary compliance obligations.

    AI Use CaseFDA Jan 2025 GuidanceEMA Reflection PaperICH E6(R3)EU AI Act
    Protocol design and generationIn scope if output influences safety/efficacy/quality [1]In scope (sponsor accountability) [2]Computerized system validation applies if used in GCP trial [12]Article 6 classification required; likely not Annex III [7]
    CSR or DSUR generationIn scope for safety/efficacy content [1]In scope [2]Applies if used in a regulated trial context [12]Classification required [7]
    Pharmacovigilance signal detectionIn scope (post-marketing AI) [1]In scope [2]Out of E6(R3) scopeClassification required; potential Annex III relevance [7]
    Patient eligibility screeningIn scope [1]In scope [2]E6(R3) validation obligations apply [12]Not automatically Annex III; clinical trial inclusion/exclusion screening is distinct from Annex III's public-authority healthcare benefit eligibility [7]
    Site selection and feasibilityLower risk; out of scope if no safety/quality outputIn scope generally [2]Limited direct applicationLikely not Annex III [7]
    Manufacturing process AICovered by FDA process guidanceEMA GMP Annex 22 (in development) [13]Out of E6(R3) scopeAnnex I (MDR) or Article 6(1) if embedded in device [7]

    This mapping is not exhaustive, does not constitute legal advice, and does not substitute for formal legal or regulatory analysis of specific systems and their intended use. EU AI Act classification in particular requires a documented Article 6 assessment for each system; the entries above reflect the most likely classification but not a definitive determination. Regulatory expectations in this area are actively evolving: FDA's January 2025 drug AI guidance remains in draft, EMA GMP Annex 22 is under development, and the EU AI Act Digital Omnibus has not yet been formally enacted as of this article's publication in June 2026.

    ICH E6(R3): GCP Meets the Digital Trial

    ICH E6(R3), finalized January 6, 2025 by the ICH Assembly, adopted by EMA with effect from July 23, 2025 [18], and adopted by FDA in September 2025 [4], is not an AI-specific guideline. Its scope is Good Clinical Practice broadly; trial design, conduct, monitoring, documentation, and data governance. But it carries material implications for any organization deploying AI within a GCP-regulated trial.

    The guidance introduces a dedicated chapter on computerized systems with requirements for validation, access controls, user accountability, and audit trails [12]. Systems used in data capture, remote monitoring, or source record management must be validated to a standard appropriate to their clinical risk; digital platforms performing these functions are explicitly subject to the expanded computerized systems requirements that R3 adds to the R2 baseline [12]. For AI systems operating in these roles; including systems that flag data anomalies, generate monitoring signals, or automate documentation workflows; the validation obligation applies in full.

    E6(R3)'s data governance framework also extends to CROs and technology vendors. Sponsors must ensure adequate oversight even where trial tasks are outsourced; the responsibility for AI system performance does not transfer to a vendor [12]. This has specific implications for organizations using commercially developed AI tools for protocol generation, clinical data review, or regulatory writing, where the underlying model training data and validation documentation typically reside with the vendor, not the sponsor.

    ICH M11 CeSHarP, finalized by the ICH Assembly in November 2025 and adopted by FDA in May 2026 [5], adds a structured protocol format layer. The standard provides harmonized content structure, terminologies, and data fields for clinical trial protocols to enable interoperable electronic exchange across regulatory regions [5]. For AI-assisted protocol generation, this creates both a compliance target and an opportunity: a system that outputs CeSHarP-structured protocol content aligned with the standard's data elements is, by design, producing content formatted for direct regulatory review. Sponsors planning global trials in 2026 and beyond should author protocols using the CeSHarP template; the structured format facilitates electronic extraction by regulators rather than manual assessment [5].

    How ICH E6(R3) and ICH M11 shape AI regulatory systems
    1
    ICH E6(R3)
    GCP framework for validation, access controls, audit trails, sponsor oversight, and data governance
    2
    AI system in a GCP trial
    Protocol generation, clinical data review, monitoring signals, or regulatory writing workflow
    3
    ICH M11 CeSHarP
    Structured protocol content, standardized headers, terminologies, and data fields
    4
    Review-ready documentation
    Regulatory reviewers can evaluate structured, traceable, electronically exchangeable protocol content
    5
    Human and sponsor accountability
    Validation, auditability, quality management, and sponsor oversight remain required

    EMA GMP Annex 22: AI in Manufacturing Takes Shape

    EMA's efforts to govern AI extend beyond clinical and regulatory operations. The EMA GMP/GDP Inspectors Working Group is actively developing Annex 22 of the EU GMP Guide, which will establish binding requirements for AI in pharmaceutical manufacturing [13]. A July 2025 draft introduced a structured, risk-based framework for AI adoption in manufacturing, with expectations for intended use documentation, validation, lifecycle management, explainability, and human-in-the-loop oversight [14].

    The draft initially stated that dynamic, adaptive, and probabilistic AI models; including generative AI and large language models; should not be used in critical GMP applications. Following stakeholder consultation in 2025 that revealed significant industry support for enabling these technologies, EMA convened a multistakeholder expert workshop in June-July 2026 to reassess this position and develop appropriate control measures [13]. The outcome will determine whether generative AI can be used in GMP-critical contexts under defined safeguards, or whether the categorical restriction will hold.

    For organizations using LLM-based tools in regulated manufacturing or documentation contexts, this is an active regulatory boundary. The question of whether generative AI's probabilistic outputs can meet the deterministic, auditable standards that GMP requires is not yet settled in European regulation, and the answer will have direct implications for how regulatory document generation systems are validated and deployed.

    EU AI Act: The Legal Floor Beneath All Guidance

    All of the guidance frameworks discussed above operate above a legal baseline established by the EU AI Act (Regulation 2024/1689) [7]. Unlike the EMA Reflection Paper, FDA's draft guidance, or the joint principles, the Act is law once its provisions take effect: obligations are binding and enforceable by national market surveillance authorities.

    Whether a pharmaceutical or clinical AI system qualifies as high-risk requires analysis under Article 6 [7]. The first classification pathway (Article 6(1)) covers AI embedded as a safety component in a regulated product that requires third-party conformity assessment under Annex I-listed Union harmonization legislation, most relevantly the EU Medical Device Regulation (MDR 2017/745). An AI clinical decision-support tool that meets the MDR definition of a device, and whose safety function requires third-party assessment, is high-risk on this pathway. The second pathway (Article 6(2)) covers AI whose specific intended use falls within one of the eight Annex III categories. Health-related Annex III entries are narrow: they cover biometric categorization using sensitive attributes, AI used by public authorities to determine eligibility for public healthcare benefits, AI for risk assessment and pricing in life and health insurance, and patient triage systems [7]. General pharmaceutical R&D applications, including regulatory document generation, protocol development tools, and pharmacovigilance analytics, are not listed in Annex III and do not automatically qualify as high-risk [7]. Even where a system does fall within an Annex III category, Article 6(3) provides that it need not be treated as high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights and does not materially influence the outcome of decision-making [7].

    When high-risk classification does apply, obligations include [7]:

    • Mandatory risk management systems covering the entire lifecycle
    • Data and data governance requirements for training and test datasets
    • Technical documentation of system design and intended use
    • Record-keeping sufficient to support post-deployment auditing
    • Transparency and information provision to users
    • Human oversight mechanisms built into system design
    • Performance standards for accuracy, robustness, and cybersecurity

    Under the Digital Omnibus provisional agreement of May 7, 2026, expected to be formally adopted before August 2, 2026, the compliance timeline would be extended: standalone Annex III systems would comply by December 2, 2027, and AI embedded in Annex I regulated products by August 2, 2028 [16]. Compliance with EU AI Act requirements does not discharge obligations under EMA guidelines or GxP standards; the Act is additive, not substitutive [7].

    Classification pathways
    1. 1Article 6(1): AI as a safety component of a regulated Annex I product
    2. 2Article 6(2): AI intended use falls within an Annex III category
    3. 3Article 6(3): Certain Annex III systems may avoid high-risk treatment if they do not materially influence decisions or pose significant risk
    High-risk obligations when classification applies
    • Risk management system
    • Data governance requirements
    • Technical documentation
    • Record-keeping
    • Transparency to users
    • Human oversight
    • Accuracy, robustness, and cybersecurity controls

    The financial scale of compliance is not trivial. Research published in a peer-reviewed analysis of the Act's healthcare implications estimated annual compliance costs of approximately EUR 29,277 per AI unit, with certification costs ranging from EUR 16,800 to EUR 23,000 per unit [15]. These figures reinforce why organizations that integrate regulatory compliance into system design from the start, rather than retrofitting it, will carry a material cost advantage.

    Regulatory and Documentation Considerations for AI Systems

    Across FDA, EMA, ICH, and EU AI Act requirements, several documentation obligations apply to any AI system operating in the regulatory evidence chain:

    Credibility assessment plan
    Required by FDA; must document the COU, risk assessment rationale, planned testing methods, and performance thresholds before testing begins. It is not a post-hoc narrative; it must be developed prospectively and maintained through the lifecycle [1].
    Training and validation data documentation
    Required by both FDA's guidance and EMA's Reflection Paper. Dataset provenance, selection criteria, known limitations, and representativeness relative to the target population must all be recorded [1],[2].
    Model architecture documentation
    Descriptions of algorithmic design, training methodology, and known failure modes are expected for any scientific advice request to EMA and are implied by FDA's seven-step framework [1],[2].
    Audit trails
    Where required under 21 CFR Part 11 or ICH E6(R3), must be computer-generated, timestamped, and attributed [8],[12]. An AI system that modifies regulated electronic records without traceable documentation of what changed, when, and under whose authorization does not meet GCP or Part 11 standards where those frameworks apply.
    Lifecycle monitoring records
    Must document performance against established metrics across the system's deployed lifetime, with evidence that detected deviations were assessed and addressed [1],[3].

    None of these documentation requirements are novel in principle; they reflect the same quality management expectations that apply to validated computerized systems in GxP environments. What changes with AI is the complexity of producing this documentation for systems whose internal logic is probabilistic, whose training data shapes outputs in ways that are difficult to trace, and whose performance may shift over time without obvious warning.

    How Kitsa Fits Into This Problem

    Kitsa positions KScribe as a regulatory document generation platform built for this compliance environment. Kitsa describes KScribe as producing regulatory documents from structured clinical intelligence rather than from general probabilistic text generation: protocol content, regulatory specifications, and cross-document dependencies are represented explicitly and intended to be auditable. For sponsors and medical writing teams whose documentation will face regulatory inspection, the compliance question is not just whether the output is accurate; it is whether the system generating it can demonstrate how.

    KScribe · AI Regulatory Documentation Built for Governance

    FDA, EMA, and ICH expectations are converging around context of use, validation, source traceability, lifecycle monitoring, and human accountability. KScribe is designed to support AI-assisted regulatory document generation from structured clinical intelligence, helping teams produce protocols, ICFs, IBs, DSURs, and CSRs with traceability and review workflows built into the process.

    Explore KScribe

    Key Takeaways

    • FDA's January 2025 draft guidance (FDA-2024-D-4689) introduced a seven-step credibility assessment framework that applies to any AI model generating data for regulatory decision-making on drug safety, efficacy, or quality; the first such framework from the agency.
    • EMA's September 2024 Reflection Paper (EMA/CHMP/CVMP/83833/2023) places full accountability on sponsors and MAHs for ensuring AI systems are fit for purpose, and accepts that full explainability is not always achievable; but requires interpretability and human oversight in its place.
    • The ten FDA-EMA Guiding Principles published January 14, 2026 represent the first formally harmonized regulatory statement on AI across both agencies, emphasizing risk-based approaches, defined context of use, lifecycle management, and human-centric governance.
    • ICH E6(R3), finalized January 2025 and adopted by FDA in September 2025, adds dedicated computerized systems requirements; including validation, audit trails, and access controls; that apply directly to AI systems operating in GCP-regulated trials.
    • ICH M11 CeSHarP, finalized November 2025 and adopted by FDA in May 2026, provides a structured protocol standard that AI-assisted protocol generation tools should target for output alignment.
    • The EU AI Act (Regulation 2024/1689) creates binding obligations for AI systems that qualify as high-risk under Article 6; pharmaceutical and clinical AI is not automatically classified as high-risk and requires a specific Article 6 classification assessment. Under the May 2026 Digital Omnibus provisional agreement, pending formal adoption, the compliance deadline for standalone Annex III systems would move to December 2, 2027 [16].
    • Across all frameworks, four documentation requirements are consistent: credibility or validation plans, training and test data provenance, model architecture records, and lifecycle monitoring evidence.

    Frequently Asked Questions

    Does FDA's 2025 AI guidance apply to AI tools used for regulatory document writing, such as protocol or CSR generation?
    FDA's January 2025 draft guidance applies to AI models whose outputs are intended to support regulatory decision-making regarding safety, effectiveness, or quality of drug and biological products [1]. It does not extend to AI used solely in drug discovery, or to operational efficiency functions that do not affect patient safety, drug quality, or the reliability of study results [1]. For regulatory document generation specifically, the key question is whether the AI's output is intended to produce information that directly influences a regulatory decision, such as safety labeling language in an IND protocol, endpoint definitions in a pivotal trial protocol, or safety narratives in a CSR. Where AI-generated content shapes a sponsor's regulatory position on safety or efficacy, FDA's credibility framework is relevant; where the tool is used to format or assemble document structure without generating novel safety or efficacy claims (such as populating a standard section header, reformatting tabular data already reviewed by a statistician, or applying a template to pre-approved text), the analysis is less straightforward and may fall outside the guidance's scope. That determination requires case-by-case evaluation. Sponsors planning to use AI for regulatory submissions are encouraged to engage FDA early to establish expectations for the specific context of use [1].
    What does EMA mean by 'interpretability' versus 'explainability' for AI systems?
    Explainability refers to the ability to trace why an AI model made a specific prediction; which features drove a particular output. The EMA Reflection Paper acknowledges that some model architectures make full explainability impossible. Interpretability, as EMA uses it, means that adequate human oversight and monitoring are in place so that when a model underperforms or produces unexpected outputs, a human reviewer can identify, investigate, and act on the problem [2],[9]. In practical terms, a well-governed black-box model with strong monitoring infrastructure can satisfy EMA's interpretability standard; an unexplainable model with no performance tracking cannot.
    Are the FDA-EMA joint AI principles legally binding?
    The ten Guiding Principles of Good AI Practice published January 14, 2026 are currently non-prescriptive and voluntary [3]. They do not constitute binding regulatory requirements under either US or EU law. However, they represent the stated positions of both agencies on what responsible AI governance looks like, and they are expected to inform and shape future binding guidance in both jurisdictions [10]. Legal and regulatory analysis from multiple firms advising on the principles recommends treating them as proactive compliance targets.
    When does the EU AI Act fully apply to AI systems used in clinical trials?
    The EU AI Act entered into force August 2024. Prohibitions took effect February 2025; governance obligations for general-purpose AI models applied from August 2025. Under the original Act, Annex III standalone high-risk systems were due from August 2, 2026, and Article 6(1) product-integrated systems from August 2, 2027. Under the Digital Omnibus provisional agreement of May 7, 2026, pending formal adoption, both deadlines would be extended: standalone Annex III high-risk AI systems would comply by December 2, 2027, and AI embedded in Annex I regulated products by August 2, 2028 [16]. However, not all AI used in clinical trials or regulatory submissions qualifies as high-risk; classification depends on intended use, whether the system is embedded in a regulated product like a medical device, and whether its use falls within the Act's specific Annex III categories, which for health-related AI cover biometric categorization, healthcare benefit eligibility determinations by public authorities, risk assessment and pricing in life and health insurance, and patient triage [7]. Sponsors and vendors should conduct a formal Article 6 classification assessment for each AI system in use.
    What documentation must a sponsor maintain for an AI system used in a GCP-regulated trial under ICH E6(R3)?
    ICH E6(R3) requires sponsors to maintain validation documentation demonstrating that computerized systems perform as intended, audit trails that are computer-generated, timestamped, and attributed, access controls limiting changes to authorized personnel, and data backup and disaster recovery procedures [12]. For AI systems specifically, this baseline extends to cover training data documentation, model performance records, and any evidence of system changes or drift during the trial period, consistent with the lifecycle management principles in the joint FDA-EMA guidance.
    How does ICH M11 CeSHarP affect AI-generated clinical trial protocols?
    ICH M11 CeSHarP provides a harmonized standard for the content, structure, and electronic exchange of clinical trial protocols, adopted at Step 4 in November 2025 and finalized by FDA in May 2026 [5]. AI systems used to generate protocol content should produce output that aligns with the CeSHarP template's standardized headers, data fields, and terminologies, as this enables direct electronic extraction and review by regulatory authorities in ICH member regions rather than manual assessment. Sponsors using AI-generated protocols for global submissions should validate that their AI tool's output maps correctly to CeSHarP-compliant structure.

    References

    1. [1] U.S. Food and Drug Administration. "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products; Draft Guidance for Industry." FDA Docket No. FDA-2024-D-4689. Published in Federal Register, January 7, 2025. https://www.federalregister.gov/documents/2025/01/07/2024-31542/considerations-for-the-use-of-artificial-intelligence-to-support-regulatory-decision-making-for-drug
    2. [2] European Medicines Agency. "Reflection Paper on the Use of Artificial Intelligence (AI) in the Medicinal Product Lifecycle." EMA/CHMP/CVMP/83833/2023. Adopted September 2024. https://www.ema.europa.eu/en/documents/scientific-guideline/reflection-paper-use-artificial-intelligence-ai-medicinal-product-lifecycle_en.pdf
    3. [3] U.S. FDA and European Medicines Agency. "Guiding Principles of Good AI Practice in Drug Development." Joint Publication, January 14, 2026. https://www.fda.gov/media/189581/download
    4. [4] International Council for Harmonisation. "E6(R3) Good Clinical Practice." Step 4 Final, January 6, 2025. FDA adoption September 9, 2025. https://www.federalregister.gov/documents/2025/09/09/2025-17311/e6r3-good-clinical-practice-international-council-for-harmonisation-guidance-for-industry
    5. [5] ICH / U.S. FDA. "M11 Clinical Electronic Structured Harmonised Protocol (CeSHarP)." ICH Step 4 November 19, 2025; FDA Federal Register May 22, 2026. https://www.federalregister.gov/documents/2026/05/22/2026-10295/m11-clinical-electronic-structured-harmonised-protocol-cesharp-international-council-for
    6. [6] U.S. FDA. "FDA Roundup: December 20, 2024." https://www.fda.gov/news-events/press-announcements/fda-roundup-december-20-2024
    7. [7] European Union. Regulation (EU) 2024/1689 (EU AI Act). Entered into force August 1, 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
    8. [8] U.S. FDA. "Part 11, Electronic Records; Electronic Signatures: Scope and Application." August 2003. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application
    9. [9] Sommer J, Chatzidimitriadou Z (Sidley Austin). "European Regulator Clarifies Guidance on the Use of AI in the Medicinal Product Lifecycle." October 22, 2024. https://goodlifesci.sidley.com/2024/10/22/european-regulator-clarifies-guidance-on-the-use-of-ai-in-the-medicinal-product-lifecycle/
    10. [10] Jones Day. "EMA and FDA Align on Good AI Practice in Drug Development." January 2026. https://www.jonesday.com/en/insights/2026/01/ema-and-fda-align-on-good-ai-practice-in-drug-development
    11. [11] Applied Clinical Trials. "FDA and EMA Align on Ten Principles to Guide Artificial Intelligence Use in Drug Development." 2026. https://www.appliedclinicaltrialsonline.com/view/fda-ema-align-ten-principles-artificial-intelligence-use-drug-development
    12. [12] ICH / U.S. FDA. "E6(R3) Good Clinical Practice: Final Guideline." ICH Step 4 January 6, 2025; corrected October 24, 2025. https://database.ich.org/sites/default/files/ICH_E6(R3)_Step4_FinalGuideline_2025_0106_ErrorCorrections_2025_1024.pdf
    13. [13] European Medicines Agency. "GMP Multistakeholder Workshop on AI Guidance Development (Annex 22)." June-July 2026. https://www.ema.europa.eu/en/events/good-manufacturing-practice-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22
    14. [14] Stassen M, Schmucki M, Valero F, Manzano T. "Bridging Guidance and Regulation: Interpreting the Draft Annex 22 on Artificial Intelligence in GMP Manufacturing." PDA Journal. 2026 Apr 10;80(2):248-254.
    15. [15] "Balancing Innovation and Control: The European Union AI Act in an Era of Global Uncertainty." PMC12574960. https://www.ncbi.nlm.nih.gov/pmc/articles/PMC12574960/
    16. [16] European Commission. "Commission welcomes political agreement on Digital Omnibus." Press Release IP/26/1024, May 7, 2026. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1024
    17. [17] U.S. FDA. "Data Integrity and Compliance With Drug CGMP: Questions and Answers." December 2018. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/data-integrity-and-compliance-drug-cgmp-questions-and-answers
    18. [18] European Medicines Agency. "ICH E6 (R3) Guideline for GCP Step 5." Effective July 23, 2025. https://www.ema.europa.eu/en/ich-e6-r3-guideline-good-clinical-practice-gcp-step-5-scientific-guideline
    19. [19] U.S. FDA. "FDA Proposes Framework to Advance Credibility of AI Models Used for Drug and Biological Product Submissions." January 6, 2025. https://www.fda.gov/news-events/press-announcements/fda-proposes-framework-advance-credibility-ai-models-used-drug-and-biological-product-submissions

    This article reflects regulatory status as of June 2026. FDA's January 2025 AI guidance remains in draft. EMA GMP Annex 22 is under development. The EU AI Act Digital Omnibus amendments are provisionally agreed but pending formal enactment. Readers should verify current status of all cited instruments before implementation decisions.

    Related Articles