Regulating AI: Inside the FDA and EMA's road to AI governance

Artificial intelligence has moved quickly from an emerging technology to something regulators increasingly have to account for across the medicines lifecycle.

The regulatory response has been slower and more deliberate. In both the US and Europe, regulators initially approached AI through areas where existing rules could be applied. But, as the technology became more capable, regulators began grappling with a harder question: how do you establish confidence in an AI system when its outputs may influence decisions about a medicine?

The answer has developed differently on either side of the Atlantic. 

2021

 
FDA

The US kicked off 2021 with an action plan. The Center for Devices and Radiological Health (CDRH) published the “Artificial intelligence and Machine Learning Software as a Medical Device Action Plan”, or AI/ML SaMD Action Plan for short. While this document was more device guidance than foundational regulation, it provided a springboard for drug-specific engagement in later years.

In October, the FDA – in a joint effort with Heath Canada and the UK’s Medicines and Healthcare Products Regulatory Agency (MHRA) – unveiled the Good Machine Learning Practice (GMLP).

Like the AI/ML SaMD Action Plan, this was initially developed for medical devices, however, many of its 10 guiding principles, including multidisciplinary expertise, representative data, human-in-the-loop considerations, robust engineering practices, and robust performance monitoring, were reused years later, in subsequent FDA-EU joint principles.

EU

In Europe, the subject of AI regulation was reaching a boiling point among policymakers, most notably in the European Commission (EC). Faced with a growing number of countries investing in AI and an explosion of innovation in the sector, which didn’t fit into the neat boxes of previous technology governance, the Commission had no choice but to act accordingly. And act it did, with the introduction of the AI Act in 2021.

The proposed act sought to introduce regulation that would “harmonise rules on artificial intelligence”, according to the EC. Along with the EC’s Coordinated plan on Artificial Intelligence, which established a strategy to accelerate AI investment, encourage early adoption, and align policy across member states, the announcement sent a clear message that the EU had both the opportunities and risks of AI firmly at the heart of its future plans.

2023

 
FDA

Having initially focused on the use of AI in the medical device field, by 2023, the FDA was grappling with the unique impact – and regulatory requirements – of a surge in AI use for both drug discovery and drug development.

It published two discussion papers. The first, “Artificial Intelligence in Drug Manufacturing”, invited industry representatives and other stakeholders to answer eight practical questions such as “What types of AI do you envision being used in pharma manufacturing? How should data integrity be maintained? How should AI models be validated? What happens when a model changes? Where does human oversight sit within an AI-enabled GMP process?”

This was quickly followed by a second discussion paper, Using Artificial Intelligence & Machine Learning in the Development of Drug & Biological Products", which focused more on the Building on the Framework for Regulatory Advanced Manufacturing Evaluation (FRAME) initiative established the year prior. These two papers were the first explicitly pharma-focused documents to emerge from the FDA’s investigation of AI in healthcare. It marked a turning point for the organisation, separating the use of AI in pharma and medical device into two categories.

The conversation continued in September, when the FDA and the Product Quality Research Institute held a virtual public workshop on AI in pharmaceutical manufacturing. During the event, regulators, industry, and academics were invited to view presentations by interested parties and contribute to discussions on what an appropriate framework might look like.

More than 800 comments were generated across the FDA's 2023 AI discussion papers, helping shape the work that would eventually lead to broader drug and biological product guidance.

EU

Across the Atlantic, policymakers in Europe were already preparing to widen the scope of AI regulation well into the future.

In just a few short years, the technology had evolved dramatically. Keeping pace with this level of change presented a seemingly insurmountable challenge for regulators – how do you create policies to accommodate a version of technology that doesn’t exist yet, but might be standard practice tomorrow?

Undeterred by the scale of the task, the EMA did just that. It published a workplan that sought to address the evolving nature of AI use in pharma, both now and in the future.

Developed under the joint HMA-EMA Big Data Steering Group, the AI Workplan to 2028 set out a bold longer-term strategy, aiming to reflect the complexity of how the European medicines regulatory network would use and govern AI.

Then, in July, the EMA published a draft Reflection Paper on AI in the medicinal product lifecycle.

By the end of the year, the EMA emerged with a two-pronged strategy for encouraging responsible use, while simultaneously protecting public health.

2024

 
FDA

By 2024, the FDA was beginning to build the internal structures needed to manage AI at an agency-wide level.

In March, the agency created the Quantitative Medicine Center of Excellence to coordinate the use of quantitative approaches, including AI. The new centre brought together initiatives across internal review divisions and external stakeholders, with a focus on regulatory science, enterprise planning, and coordination, alongside education and ecosystem development.

The move reflected a broader shift in the FDA's approach to AI regulation. Although multiple CDER groups had been involved in AI projects, including policy and regulatory initiatives, these groups were fragmented and struggled to meet the governance needs of the changing federal environments for AI.

In short, regulatory questions were becoming harder to contain within a single part of the medicines lifecycle and the agency needed a way to coordinate how different parts of the organisation approached the technology.

The answer became clear in September, when Patrizia Cavazzoni, then director of CDER, sent out an all-staff email announcing the creation of the CDER AI Council. It merged three previously separate groups – an AI Steering Committee, an AI Policy Working Group, and an AI Community – into one unified body, responsible for providing oversight, coordination, and consolidation of CDER's activities around AI.

EU

After two years of debate and finessing, the EU AI Act was officially ready for its legal debut. Compared to the 2021 announcement, the final bill focused a lot more on the broader risks of AI, specifically surrounding citizens' health, safety, and fundamental rights. As such, it introduced a uniform risk-based framework across all member states.

Under the new framework, AI risk could be categorised into four options: minimal, specific transparency, high, or unacceptable. In short, the higher the risk of harm to society, the stricter the regulation. Naturally, given its impact on citizens health, pharma fell largely into the high-risk category.

For pharmaceutical companies, that created a second regulatory track. AI used in medicines development could fall under EMA expectations while certain applications, particularly AI embedded in medical devices and diagnostics, could also face obligations under the AI Act.

Critics of the new system, including the European Federation of Pharmaceutical Industries and Associations argued that the broad scope of the Act did not account for the specific use case of AI in medicines development and that AI systems “when used solely for the purpose of medicines R&D”, should be exempt from the requirements of the EU AI Act.

2025

 
FDA

In January 2025, the FDA took its biggest step yet towards a comprehensive framework for AI in medicines.

Just a week into the new year, the regulator published draft guidance titled “Considerations for the Use of AI to Support Regulatory Decision-Making for Drug and Biological Products”, in which it proposed a risk-based credibility framework for any AI model outputs used to support regulatory decision-making, including nonclinical, clinical, manufacturing, and post-marketing applications.

The central idea was relatively straightforward: the regulator was not attempting to regulate “AI” as a single product category. Rather, sponsors would need to demonstrate that an AI model was credible for the particular regulatory question it was being used to answer.

An initial framework laid out in the draft guidance proposed seven steps. Sponsors would define the question the model was addressing and its context of use, assess the risk associated with the model, develop, and execute a credibility assessment plan, then document the results and determine whether or not the model was adequate for its intended purpose.

If the answer was no, the FDA suggested that mitigation could include additional data, greater human oversight, or a narrower context of use.

EU

By 2025, the EU AI Act was beginning to move from prospect into real-world practice.

From February, its first provisions took effect, including bans on certain AI practices and new AI literacy requirements. As such, the scope of AI governance was widening for pharma companies. Alongside understanding which AI system they were using, teams now needed to explain how those systems were being deployed and whether the people working with them had sufficient knowledge to use them appropriately.

The next major step came on 2 August, when obligations covering general-purpose AI models came into effect, a development that particularly impacted to pharma companies experimenting with or fine-tuning large foundation models for clinical applications.

In addition to introducing new requirements, the EMA continued to hone its medicines-specific approach to AI across the product lifecycle. The result was an increasingly layered regulatory environment. Companies working with AI in drug development had to consider the expectations set by the medicines regulator, while also assessing whether their systems fell within the scope of the horizontal AI Act.

By the latter part of 2025, the proposed Biotech Act introduced another potential layer of complexity to the evolving regulatory landscape. Announced in 2025, with adoption expected in 2027, the proposed legislation would prevent individual EU countries from adding their own data or consent requirements under the Clinical Trials Regulation. If adopted, it could reduce the need for country-by-country legal reviews when designing multinational trials. For now, however, those national checks remained part of the process.

2026

 
FDA

By 2026, the FDA was turning its attention to a newer and more difficult problem: generative AI (GenAI) as a decision maker in pharma.

In January, the FDA and EMA jointly published their “Guiding Principles of Good AI Practice in Drug Development”. The non-binding principles covered the full medicinal product lifecycle, from discovery through post-market use, and set out shared expectations around human oversight, data quality and provenance, model validation, lifecycle monitoring, transparency and alignment with GxP.

For companies running global development programmes, this created something regulators had previously lacked: a shared reference point.

Advancements in GenAI allowed researchers to push the realms of possibility further than ever before, at a pace impossible for humans to replicate. But speed didn’t always mean accuracy, and concerns over hallucinations and other potential risks pushed the FDA to take a closer look at the impact of this new technology when used to make care decisions, rather than just supporting them.

There was no easy solution. So, as had been done before, the agency's Center for Devices and Radiological Health sought feedback from invested parties, asking them to weigh in on topics such as risk assessment, premarket evaluation, and post-market monitoring.

One proposal was a competency-based approach to evaluating GenAI-enabled devices. Rather than attempting to test every possible scenario a system might encounter, the FDA suggested that developers could demonstrate the model's underlying capabilities and reasoning through structured assessments, drawing an analogy with how human clinicians are evaluated.

At the same time, the FDA was testing how much regulatory flexibility could be built into the route to market. Four digital health products were accepted into its TEMPO pilot programme, including AI products from Cadence and Limbic, allowing participating developers to release their products without traditional marketing authorisation.

EU

Meanwhile, the EU AI Act was reaching another important stage.

From August 2026, transparency requirements under Article 50 and the Act's enforcement regime became active, allowing authorities to dish out significant financial penalties for non-compliant general-purpose AI models – up to €35 million.

For pharmaceutical companies, the implications extended into areas such as patient-facing content, healthcare professional communications and the use of general-purpose AI.

The timetable for some of the most demanding high-risk requirements had also changed. Amendments introduced through the Digital Omnibus package pushed the deadline for standalone high-risk AI systems to December 2027. High-risk AI embedded in regulated products, including many medical devices and in-vitro diagnostics, was also delayed until August 2028.

A further transparency requirement is scheduled for December 2026, when certain generative AI systems already on the market will need to use machine-readable markers to indicate AI-generated content.

2027 and beyond

 
FDA

By 2027 and 2028, the FDA's framework is expected to be further developed, with its January 2025 draft guidance potentially finalised or approaching finalisation.

The direction of travel is already established. AI used to support regulatory decisions will increasingly be treated as a source of evidence whose credibility must be demonstrated for its particular context of use.

That could give sponsors a clearer framework for using AI in regulatory submissions, while maintaining the distinction between AI used to generate or support regulatory evidence and AI used purely as an internal research or operational tool.

EU

Europe's timeline becomes more concrete.

In December 2027, standalone high-risk AI systems covered by Annex III are due to become subject to the full set of applicable AI Act obligations.

Then, in August 2028, high-risk AI embedded in regulated products covered by Annex I is due to reach its full compliance deadline. For pharma, that is particularly relevant where AI forms part of medical devices or in vitro diagnostics, where the AI Act will sit alongside existing MDR and IVDR requirements.

By then, the regulatory landscape should look considerably different from the one that existed a decade earlier.

About the Author

Eloise McLennan is the editor for pharmaphorum’s Deep Dive magazine. She has been a journalist and editor in the healthcare field for more than five years and has worked at several leading publications in the UK.

Sign up

Supercharge your pharma insights: Sign up to pharmaphorum's newsletter for daily updates, weekly roundups, and in-depth analysis across all industry sectors.

Click on either of the images below for more articles from this edition of Deep Dive: AI 2026