A New Regulatory Blueprint for AI
In January 2026, the U.S. Food and Drug Administration (FDA) and the European Medicines Agency (EMA) jointly published the Good AI Practice in Drug Development — 10 principles. This document outlines ten principles designed to establish a framework for effective practices as artificial intelligence becomes increasingly integrated into the drug product life cycle.
The scope matters. The agencies define AI as system-level technologies used to generate or analyze evidence across the entire drug product life cycle, explicitly naming the nonclinical, clinical, post-marketing, and manufacturing phases (FDA/EMA, 2026, p. 1). This framing pulls regulatory operations directly into this effort.
Regulatory Affairs is uniquely positioned to lead here. No other function offers comprehensive visibility across the submission life cycle, an understanding of Good Practice (GxP) compliance and data integrity, and a well-established relationship with health authorities. Teams that treat these principles as an operating model, not a compliance checkbox, will advance their use of AI confidently while competitors are still running pilots.
The Industry challenge: How can Regulatory Affairs speed up submissions and content creation while bolstering documentation to meet ever-evolving compliance standards?
AI Is Becoming a Core Regulatory Capability
AI in life sciences is no longer confined to target identification and molecule design. The FDA and EMA note that AI use throughout the drug product life cycle has increased significantly in recent years, and that AI is expected to support innovation, reduce time-to-market, and strengthen both regulatory excellence and pharmacovigilance (FDA/EMA, 2026, p. 1).
In regulatory operations specifically, AI is already being applied to:
- Automated dossier assembly – structuring and validating eCTD components
- Submission readiness reviews – gap detection before filing
- Labeling change management – impact analysis across markets and product families
- Regulatory intelligence monitoring – tracking guidance, legislation, and precedent
- Pharmacovigilance signal analysis – case triage and signal detection support
- Generative AI-assisted authoring – first-draft creation of regulatory content
Strategic takeaway: Regulatory Affairs organizations that establish strong AI governance now will be best positioned to scale AI effectively.
What Good AI Practice in Drug Development Principles mean for Regulatory Operations
The FDA/EMA principles are agnostic to specific solutions. Modernizing regulatory practice with this disruptive technology requires thoughtful consideration of the people, process, and technology framework. In this section, we take a closer look at the first 4 of the principles and best practices for application.
Human-centric by design (Principle 1)
The agencies state that development and use of AI technologies should align with ethical and human-centric values (FDA/EMA, 2026, p. 2).
In practice: AI should augment the expertise of regulatory affairs professionals, not replace human judgement. Expert review remains mandatory for any output that reaches health authority. Define a clear human-in-the-loop review process for AI-generated outputs and document which activities AI can support or automate versus which decisions require human review and approval.
Risk-based approach (Principle 2)
Principle 2 calls for proportionate validation, risk mitigation, and oversight based on the context of use and determined model risk (FDA/EMA, 2026, p. 2).
In practice: Not every use case warrants the same rigor. An AI tool that summarizes internal meeting notes has a very different risk profile from one that drafts a CTD Module 2.5 (Clinical Overview). Classify use cases based on their regulatory and business impact then scale validation, controls and human oversight accordingly. This is consistent with the risk-based approach underpinning Computer Software Assurance (CSA).
Adherence to standards (Principle 3)
AI technologies are expected to adhere to relevant legal, ethical, technical, scientific, cybersecurity, and regulatory standards, including Good Practices (GxP) (FDA/EMA, 2026, p. 2).
In practice: Integrate AI into your existing Quality Management System (QMS) rather than building a parallel “AI process”. Apply established quality processes for risk assessment, validation, change control, documentation, and oversight, with additional controls where AI introduces unique risks. This creates a consistent governance framework and a clear, auditable record of how AI is evaluated, approved, and maintained throughout its lifecycle.
Adherence to standards (Principle 3)
AI technologies should adhere to relevant legal, ethical, technical, scientific, cybersecurity, and regulatory standards, including Good Practices (GxP) (FDA/EMA, 2026). [fda.gov]
In practice: Integrate AI governance into your existing Quality Management System (QMS) rather than creating a separate AI-specific quality process. Apply established quality processes for risk assessment, validation, change control, documentation, oversight, and lifecycle management, while implementing additional controls where AI introduces unique risks. This approach promotes consistent governance, regulatory compliance, and a clear, auditable record of how AI systems are evaluated, approved, monitored, and maintained throughout their lifecycle.
Clear context of use (Principle 4)
Principle 4 requires a well-defined context of use: the role and scope for why the technology is being used (FDA/EMA, 2026, p. 2).
In practice: Define the intended use of every AI application – including what it does, what it does not do, and how its outputs will be used regulatory processes or decision-making. Clear scope helps prevent unintended use and ensures that validation and oversight remain proportionate to risk.
Generative AI Content Management Through a Regulatory Lens
The opportunity
Generative AI can materially reduce content creation effort across the highest-volume regulatory work products:
- Module authoring
- Health authority responses
- Variation submissions
- Periodic reports (PSUR/PBRER, DSUR)
- Labeling documentation
- Regulatory correspondence
The challenge:
Speed is only valuable if the output survives inspection. Generated content must remain traceable, auditable, reviewable, and version controlled — the same expectations that apply to any regulated document.

Pro Tip:
Treat GenAI outputs as regulated content assets, not productivity artifacts. The moment AI-generated content is incorporated into a submission-bound document, it should be subject to every documentation, traceability, review and quality control that apply to human-authored content. Design your content management architecture with these requirements in mind from day one.
Building an AI Governance Framework for Regulatory Affairs
Three components turn principles into an operating system.
1 AI use-case inventory
A single register documenting, for every deployed and proposed use case — operationalizing the risk-based approach, life cycle management, and data governance principles at the core of the January 2026 FDA/EMA guidance:
- Purpose and defined context of use
- Risk classification
- Business owner and accountable reviewer (closing the “shadow AI” gap — tools adopted by teams without organizational visibility or sign-off)
- Approval Status; Date of Review
- Validation requirements and status
- Model, version, and vendor
If you cannot produce this register on request, your AI governance does not provide sufficient visibility or control.
2 Cross-functional governance board
Principle 5 calls for multidisciplinary experts covering both the AI technology and its context of use, integrated throughout the technology’s life cycle (FDA/EMA, 2026, p. 3).
Establish a cross-functional AI governance structure with representation from the functions responsible for both AI oversight and the regulated business process in which the technology is used. Typical participants may include:
- Regulatory Affairs
- Quality Assurance (QA)
- Medical Monitor
- Clinical Operations
- Information Technology (IT)
- Data Science / AI Specialists
- Legal
This multidisciplinary approach helps ensure that AI systems are developed, validated, deployed, monitored, and governed in a manner consistent with regulatory expectations and organizational quality requirements.
3 Validation framework
Principle 8 calls for risk-based performance assessments that evaluate the complete system — including human-AI interactions — using fit-for-use data and metrics appropriate to the intended context of use (FDA/EMA, 2026, p. 3). Principle 9 adds that risk-based quality management systems should run across the life cycle, with scheduled monitoring and periodic re-evaluation to address issues such as data drift (FDA/EMA, 2026, p. 3).
Your framework needs:
- Defined testing criteria tied to context of use
- Acceptance thresholds agreed before testing begins
- Ongoing monitoring cadence and re-evaluation triggers
- A documented path for capturing, assessing, and addressing issues
Guiding AI Principles supported: risk-based approach (2), multidisciplinary expertise (5), risk-based performance assessment (8), life cycle management (9).
The Future of Regulatory Excellence
Once appropriate AI governance is established, organizations can expand the use of AI to enhance efficiency, consistency, and strategic decision-making across Regulatory Affairs.
- AI-enabled regulatory intelligence: Continuous monitoring of FDA guidances, EMA publications, ICH developments, and global regulatory trends, with potential impacts identified and routed to affected programs, products, and stakeholders.
- Authoritative content reuse: AI-assisted identification of previously approved and health-authority-accepted content within the regulatory archive to support consistent, traceable content reuse across submissions.
- Quality and compliance monitoring: Early identification of missing documentation, inconsistent claims, potential data integrity concerns, and other quality or regulatory compliance risks throughout the product lifecycle.
- Strategic outcome: Regulatory Affairs evolves from a primarily document-focused function into a strategic intelligence and decision-support partner, helping inform regulatory and development strategy while maintaining appropriate human oversight for regulatory decisions.
Conclusion: Responsible AI Will Define the Next Generation of Regulatory Affairs
The EMA/FDA principles are not merely compliance expectations. They are a roadmap for responsible innovation, explicitly intended to lay the foundation for good practice and to cultivate growth in a rapidly progressing field (FDA/EMA, 2026, p. 1).
Regulatory Affairs leaders who establish strong governance, validation, traceability, and life cycle management for AI today will be best positioned to accelerate submissions, streamline content management, and strengthen compliance tomorrow. Success will belong to
organizations that balance automation with accountability — leveraging AI not as a replacement for regulatory expertise, but as a force multiplier for regulatory excellence.
Frequently Asked Questions
What is the FDA/EMA guiding principles for AI in drug development? They are 10 principles published jointly in January 2026 covering human-centric design, risk-based approach, adherence to standards, clear context of use, multidisciplinary expertise, data governance and documentation, model design and development practices, risk-based performance assessment, life cycle management, and clear, essential information.
Do the principles apply to regulatory operations, not just drug discovery? Yes. The agencies define AI in scope as system-level technologies used to generate or analyze evidence across the drug product life cycle, including nonclinical, clinical, post-marketing, and manufacturing phases.
Are the principles legally binding? They are guiding principles, not regulation. The document positions them as a basis for advancing good practice, international harmonization, and consensus standards that may inform regulatory policies and guidelines in different jurisdictions.
How should we validate generative AI used for regulatory content? Apply a risk-based approach proportionate to context of use, assess the complete system including human review steps, and maintain documented traceability of sources, model versions, and human edits under your existing GxP quality system.
Ready to Operationalize AI Governance?
Is your Regulatory Affairs organization ready for AI at scale? Start by mapping your current automation and generative AI initiatives against the EMA/FDA’s 10 principles, then identify the governance gaps that must close before AI becomes mission critical.
Astrix brings 30+ years of life sciences consulting experience across Regulatory Affairs transformation, technology selection, CSA/CSV validation, enterprise integration, and organizational change management.
Contact Astrix | Life Sciences Technology Services
About Astrix:
Astrix is the global leader in delivering innovative strategies and solutions to the life sciences industry. Powered by world-class people, proven processes, and advanced technology, Astrix partners with clients to drive measurable improvements in business performance, scientific advancement, and clinical outcomes—ultimately driving towards a goal of improving quality of life. Founded by scientists to address industry’s most complex challenges, Astrix provides a growing portfolio of strategic and technical services that deliver immediate impact while enabling long-term digital transformation. Our deep expertise spans strategic planning, data strategy, AI/ML readiness and technologies, lab informatics, and modern clinical operations and eClinical platforms so we can successfully deliver solutions that have high impact and drive better outcomes for everyone.
Reference:
U.S. Food and Drug Administration, & European Medicines Agency. (2026, January). Guiding principles of good AI practice in drug development. European Medicines Agency. Retrieved from: https://www.ema.europa.eu/en/documents/other/guiding-principles-good-ai-practice-drug-development_en.pdf