← All news

Summit

AI in Regulatory Affairs: What It Does and Cannot Do

EX Future Summit · 4 September 2026

The FDA now reads submissions with AI too. What AI in regulatory affairs measurably does, where the guidance draws its line, and what it cannot decide.

AI in Regulatory Affairs: What It Does and Cannot Do

AI in regulatory affairs covers two halves of one transaction. On one side, sponsors use machine learning and generative models to prepare, check and maintain what they file: dossier assembly, first-draft authoring, labelling comparison, safety signal triage, horizon scanning across dozens of health authorities. On the other side, those health authorities have started using the same class of tool to read what arrives.

Almost every guide on this subject describes only the first half. That was defensible until May 2026. It is not now, because the reviewer at the other end of the dossier is increasingly querying it through a model, and that changes what a well built submission looks like more than any authoring tool does.

What follows separates the results that have actually been measured from the results that have been marketed, states the line the regulators themselves have drawn around acceptable use, and is honest about the part of the job that has not moved. It is not legal or regulatory advice, and the American guidance central to it is still a draft.

The results that have actually been measured

First drafts, and the quality score underneath the speed

The most cited figure in this field comes from a study of AutoIND, a platform for drafting the nonclinical written summaries of an investigational new drug application. The published results record a 97 percent reduction in initial drafting time, from roughly 100 hours to 3.7 hours across 18,870 pages drawn from 61 source documents, and from roughly 100 hours to 2.6 hours for a second application of 11,425 pages.

The same paper carries the part that rarely travels with the headline. Those drafts scored 69.58 percent and 77.85 percent of the maximum possible quality score. No critical regulatory errors were detected, but an experienced regulatory writing assessor found consistent deficiencies in narrative emphasis, along with problems of length and characteristic AI phrasing, and concluded that expert regulatory writing remains necessary to bring the output to submission-ready quality. Read the two numbers together and the claim is precise: a very large reduction in compilation time, not a reduction in the work of judging what the document should argue.

A dossier filed digitally to several regulators at once

The most instructive deployment is not a drafting tool at all. Amgen ran a chemistry, manufacturing and controls post-approval change for Vectibix as a fully digital filing, described in a paper on the pilot. The package comprised 23 eCTD sections, 12 generated through structured authoring and 4 using generative AI, with the Quality Overall Summary produced by a custom tool. It was uploaded once to a cloud platform and shared with every participating health authority simultaneously, alongside the conventional national submissions.

The result worth noting is a regulatory one rather than a productivity one. A comparable dossier would typically draw over 100 questions globally; as of October 2025 the pilot had received 51. Structured, consistent, machine-readable content produced fewer requests for clarification. That is the mechanism most of this field is actually about.

What the industry benchmark says, as opposed to the pilot

Pilots are not adoption. McKinsey's 2025 regulatory affairs benchmark found that roughly 80 percent of top pharma companies were modernising their regulatory information management systems, with a smaller group having automated core processes beyond writing tools and publishing. It also puts the destination in plain terms: leading companies now deliver filings 8 to 12 weeks after database lock, cutting historical timelines by 50 to 65 percent, and gen-AI-assisted medical writing has been shown to cut clinical study report authoring cycle time by about 40 percent. The technology is one of six building blocks in that account. The other five are process and operating model.

The regulator is now an AI user too

On 6 May 2026 the FDA announced Elsa 4.0 alongside HALO, a platform consolidating more than 40 previously separate application and submission data sources, systems and portals across all agency centres. The agency's chief AI officer described the shift precisely: staff used to bring data to Elsa, and now Elsa sits on top of the data. The announcement also states the safeguards, which are worth knowing as a sponsor: a FedRAMP High cloud environment, no training on input data or on data submitted by regulated industry, no internet connection, and human subject matter experts verifying inputs, analytic processes and output implementation.

The practical consequence for anyone filing is set out in a law firm alert on the release: the agency states that tasks previously taking reviewers two to three days can now be done in six minutes, so sponsors should consider whether their submissions are AI-ready. That means consistent terminology across modules, cross references that resolve, and conclusions that trace directly back to the tables and listings supporting them. None of that is new advice. All of it now has a second reader with no tolerance for a term that changes meaning between Module 2 and Module 5.

This is not only an American development. A survey of agency-side adoption records the EMA's Scientific Explorer, introduced in March 2024 to search across large volumes of regulatory documents using natural language processing, CDRH-GPT supporting medical device review, and AIM-NASH as the first FDA-qualified AI tool for clinical research. The same source states the point that survives every change of tooling: compliance accountability sits with the sponsor, not with the AI system.

Where the guidance draws its line

The FDA framework, and what it deliberately excludes

The FDA's draft guidance, Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products, proposes a seven step risk-based credibility assessment framework: define the question of interest, define the context of use, assess model risk, develop a credibility plan, execute it, document the results, and discuss deviations. Model risk is defined as a combination of model influence, meaning how much the model's evidence contributes relative to everything else, and decision consequence, meaning how bad an incorrect decision would be. The stringency of everything downstream scales with those two factors.

The most useful sentence in the document is the one describing what it does not cover. The guidance excludes AI used in drug discovery, and AI used for operational efficiencies such as internal workflows, resource allocation and drafting or writing a regulatory submission, where those uses do not affect patient safety, drug quality or the reliability of results from a nonclinical or clinical study. Drafting a summary from data you already generated is out of scope. Using a model to generate the evidence itself is in. That distinction decides whether a use case needs a credibility plan, and it is missing from almost every vendor guide on the subject.

The Federal Register notice accompanying the draft gives its provenance and its limit in the same breath. The framework was informed by over 800 comments on the agency's 2023 discussion papers and by FDA experience reviewing over 300 submissions containing AI and machine learning components. And sponsors remain responsible for compliance with statutory and regulatory requirements regardless of the technology used.

What the EMA expects before you build

The European position sits in a reflection paper rather than a rule. EMA/CHMP/CVMP/83833/2023 asks applicants to perform a regulatory impact and risk analysis of all AI and machine learning applications, and to seek regulatory interaction where no clearly applicable written guidance exists, through the Innovation Task Force or the Scientific Advice Working Party. Where regulatory impact is high, it recommends that interaction begin at the planning stage. It also extends GxP standard operating procedures on data and algorithm governance to cover all data, models and algorithms in cases of high regulatory impact or high patient risk, and it is to be read together with the AI Act, GDPR and medicines legislation rather than instead of them.

That last point was deliberate. The record of the consultation, which drew 1,342 comments from 66 stakeholders, notes that the term high risk was replaced with high regulatory impact and high patient risk, precisely to keep the paper's vocabulary distinct from the AI Act's risk tiers and to make clear that most of these requirements are founded in medicines law. Two overlapping regimes, two different meanings for the same phrase. It is a small illustration of why governance and regulation are not the same job.

The record-keeping regimes an agentic workflow walks into

Once a tool stops summarising and starts acting, the applicable rules change. A DIA Global Forum analysis of agentic AI in regulatory affairs makes the mapping explicit: any SOP or submission document generated or modified by an agent is a regulated electronic record, which triggers 21 CFR Part 11 in the United States and EU GMP Annex 11 in Europe. Chained workflows touching regulated outputs fall under GAMP 5 computer system validation. Where AI-generated risk scores influence prioritisation of filings or escalation of a safety signal, ICH Q9(R1) applies. The same piece notes the FDA and EMA Guiding Principles of Good AI Practice in Drug Development, published jointly in January 2026.

Where it cannot go

A hallucinated citation in a marketing brochure is embarrassing. In a dossier it is a compliance event, and the agency's own tool has demonstrated the failure mode at scale. CNN reported in July 2025 that Elsa had fabricated studies that do not exist and misrepresented research, according to three FDA employees and documents. One described it as hallucinating confidently and said the heightened vigilance required to check it consumed the time it was meant to save.

A 2026 analysis of the Elsa 4.0 and HALO transition generalises the risk rather than dismissing it. With a unified data platform, a retrieval or synthesis error is no longer confined to one query and can propagate across the review pipeline. Verification capacity is not guaranteed either: roughly 3,500 FDA employees were terminated in April 2025 before partial rehiring began. And repeated reliance on AI for synthesis carries the slower danger of regulatory deskilling, as reviewers spend less time engaging directly with primary evidence and lose the ability to spot when the summary is wrong. The identical argument applies inside a sponsor. It is the same shape as the risks that follow AI into a clinical setting, and it is why the honest version of every efficiency claim includes who is checking.

The harder limit is not accuracy at all. As one practitioner account puts it, reading a Complete Response Letter and understanding what the agency is implying about its evidentiary threshold, rather than what it explicitly wrote, is a skill built from years of health authority relationships. AI gets a team to the starting line faster. It does not decide what to argue when it arrives.

A defensible way to start

Sequence by risk, not by enthusiasm. Regulatory intelligence and monitoring produce an internal alert, which is a low consequence output; generative drafting of submission content produces a regulated record. Build the first before the second. Scope the pilot to one high volume workflow with a fixed evaluation window and metrics agreed in advance, such as time to action, missed update rate and hours reallocated.

Treat the tool selection as a validation decision rather than a procurement one. A medtech-focused guide sets out the standard well: validation follows risk-based approaches such as GAMP 5 and the FDA's Computer Software Assurance principles, AI tools used in submission preparation may themselves be reviewed during inspection, and system logic, output review processes and change control therefore need documenting from the start. It also flags the deadline behind all of this, which is that the FDA's Quality Management System Regulation took effect on 2 February 2026, aligning 21 CFR Part 820 more closely with ISO 13485 and reinforcing the expectation that digital systems in regulated processes are validated and traceable. That sits inside the wider question of what AI regulatory compliance requires today, and the answer differs by jurisdiction and by month.

The room where both sides are present

The structural problem in this article is that two groups are adopting the same technology in parallel, for opposite purposes, with very little shared forum. Sponsors are optimising documents for machine readability. Agencies are building the machines that read them. Each mostly learns what the other is doing from a press release.

The EX Future Summit programme is organised around closing that kind of distance, with a Government track and a Health Tech track running alongside eight hosted meet-and-greet sessions that put university research teams in front of private partners. It runs from 18 to 20 November 2026 as a single continuous thirty hour broadcast between Las Palmas in the Canary Islands and Bali, twelve hours apart, and online attendance is free for verified researchers, students and the EX community.

Where a jurisdiction is willing to go further, the gap closes faster still. Bali Province's digital residency sandbox opens a cohort at the summit, granting a ninety day residency, a policy pilot lane and access to municipal data. A sandbox is not a substitute for a credibility plan. It is a place to find out what a rule does before it is written, which is the same instinct that produced AI governance inside a health system as a discipline separate from compliance.

FAQ

Will AI replace regulatory affairs professionals?

Nothing in the measured evidence points that way. The demonstrated gains sit on compilation, formatting and retrieval, and even there the drafts required expert revision for emphasis and conciseness before they were fit to file. Interpreting what a health authority implies about its evidentiary threshold is not a summarisation task, and the agency's own tool was reported as unable to assist with review work itself. The role shifts toward verification and strategy rather than disappearing.

Do I have to tell the FDA that AI was used to write our submission?

The draft guidance's credibility framework applies to AI producing information or data intended to support a regulatory decision on safety, effectiveness or quality. Operational uses, including drafting or writing a submission, are outside its scope where they do not affect patient safety, drug quality or the reliability of study results. That is a scope statement, not a permission slip: the sponsor still owns the accuracy of everything filed, and the guidance encourages early engagement with the agency where the boundary is unclear. Take the specific case to counsel and to the agency.

What does an AI-ready submission mean in practice?

It means writing on the assumption that a reviewer will query the dossier through a model sitting on consolidated agency data rather than opening each document. Consistent terminology throughout, cross references that resolve, and every conclusion traceable back to the underlying tables and listings. The Amgen pilot suggests the payoff is fewer health authority questions, not just faster reading.

Does the EU AI Act govern AI used in regulatory affairs?

It applies alongside medicines and device law rather than replacing it. The EMA's reflection paper is explicit that it must be read together with the AI Act, GDPR and medicines legislation, and the agency deliberately changed its own risk vocabulary to avoid collision with the Act's high risk tier. An AI tool in a regulated pharmaceutical process can sit under both regimes at once, with different obligations arising from each.

Which use case should a regulatory team start with?

Monitoring and regulatory intelligence, because the output is an internal alert rather than a regulated record, which keeps the validation burden proportionate while the team learns where the tool fails. Generative drafting of submission content is a later step and a heavier one, since the artefact it produces is subject to electronic records requirements from the moment it exists.

EX-AI-Summit 2026 · 18–20 November · Las Palmas (WET) · Bali (WITA) · Online
Presented by EX Venture Inc. · Seraph SL · Equation Labs SL

ProgramPartnersAboutContactLegalPrivacy

We use essential cookies to run this site and optional analytics cookies to understand how it is used. You can accept all or reject optional cookies. See our privacy notice and legal.