Resources

Regulatory and AI Round-Up: Week of 20 July 2026

Written by Vedant Srivastava | Jul 28, 2026, 9:08:13 PM

Welcome to our weekly round-up for clinical operations, regulatory affairs, quality and pharmacovigilance teams. Each edition covers what moved, what it changes in your systems and SOPs, and the dates worth putting in the diary.

The short version

  • The EU AI Act amendments entered into force on 27 July 2026. High-risk obligations move to 2 December 2027 and 2 August 2028.
  • Article 50 obligations were not part of that deferral. They generally begin applying on 2 August 2026.
  • The "safety component" definition has narrowed, which may change classification conclusions for AI inside regulated products.
  • Three dates have already passed and are live now: the QMSR (2 February 2026), the UK trials regime (28 April 2026) and the ICH M11 EU template (11 June 2026).

In this round-up: EU AI Act · AI governance beyond the EU  · Validation · Trial conduct · Data standards · Pharmacovigilance · Dates to diarise

1. The EU AI Act amendments are now in force

In force since 27 July 2026. The high-risk rules move to 2027 and 2028. Article 50 obligations were not deferred and generally begin applying on 2 August 2026.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, the third day after publication. The regulation justifies that compressed timetable as a matter of urgency, because the general application date it amends falls on 2 August.

It amends the AI Act (Regulation (EU) 2024/1689) alongside the Basic Aviation Regulation and the Machinery Regulation. Parliament adopted the text on 16 June 2026; the Council approved it on 29 June.

For anyone tracking this since the November 2025 proposal, the uncertainty is over. Until publication on 24 July 2026 the deferral was agreed but not yet in force, and 2 August 2026 remained the operative date.

What moved

Recital 40 sets out the position plainly. The date of application of Chapter III, Sections 1, 2 and 3 moves to:

  • 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III
  • 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I

The deferred package is the heavy one: risk management systems, technical documentation, data governance, human oversight and conformity assessment.

The stated reason matters for how you plan. The delay reflects the late availability of standards, common specifications and guidance, and the late establishment of national competent authorities. It is a timing problem, not a change of direction.

What did not move

The AI Act has not been postponed in full. The application of Chapter III, Sections 1, 2 and 3 has been deferred for the affected high-risk systems. Everything else arrives on the original schedule, and the general date of application remains 2 August 2026.

That includes the Article 50 transparency obligations. Depending on whether your organisation acts as a provider or a deployer, and on the particular system and use case, Article 50 may require disclosure, marking or labelling. Those obligations were not included in the high-risk deferral and generally begin applying on 2 August 2026. One narrow accommodation applies: recital 38 introduces a four-month transitional period for providers of generative AI systems already on the market before 2 August 2026, to adapt to the Article 50(2) marking obligations.

The realistic failure mode here is not a missed conformity assessment. It is a team that reads "AI Act delayed to 2027," stands down, and is then exposed on a disclosure obligation that was never deferred.

Two definitional changes worth checking

The "safety component" definition has narrowed. A new Article 6(1a) provides that AI systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components. Article 3(14) is amended in the same direction.

Read the next paragraph before drawing conclusions. Article 6(1b) states that, notwithstanding the above, AI systems whose failure or malfunctioning would endanger health and safety do still qualify. The narrowing is real but bounded, and classification assessments completed under the original text are worth re-running.

AI literacy has been revised. Article 4 is replaced. Providers and deployers must take measures to support the development of AI literacy among staff and others operating systems on their behalf, taking account of technical knowledge, experience, education, training and context of use. The duty remains, but the revised wording is less outcome-specific and expressly states that organisations need not guarantee a particular literacy level in every individual.

The provisions most relevant to life sciences

Several amendments have had little coverage but matter directly to anyone whose AI sits inside a regulated product.

  • Sectoral equivalence. A new Article 2(13) allows requirements in Articles 9 to 15 and 17 to 25 to be limited where Annex I Section A legislation already provides equivalent or higher protection. That Annex includes the Medical Devices Regulation (EU) 2017/745 and the IVDR (EU) 2017/746. Delegated acts specifying how this works are due by 2 August 2027.
  • One application for notified bodies. A new Article 28(8) requires that a conformity assessment body applying under both the AI Act and Annex I Section A legislation can submit a single application and undergo a unified assessment. A body designated under more than one piece of that legislation applies only once.
  • A transitional assessment window. Under the revised Article 43(3), notified bodies already notified under Annex I Section A may assess high-risk AI systems against Chapter III Section 2, subject to conditions, and must apply for AI Act designation by 28 January 2028.
  • Proportionality for smaller organisations. Simplified technical documentation is available to SMEs and small mid-cap enterprises, on a form notified bodies must accept. Quality management system implementation is to be proportionate to organisational size.
  • Bias detection. A new Article 4a creates a conditional legal basis for processing special categories of personal data for bias detection and correction, subject to six cumulative conditions including deletion once corrected.

Source: Regulation (EU) 2026/1744 on EUR-Lex

2. AI governance beyond the EU

Two non-binding frameworks setting out what regulators describe as good practice for AI in drug development and pharmacovigilance.

FDA and EMA joint principles. On 14 January 2026 the two agencies jointly published Guiding Principles of Good AI Practice in Drug Development: ten high-level principles covering AI used to generate or analyse evidence across nonclinical, clinical, post-marketing and manufacturing phases.

They are not binding guidance. They emphasise human-centric values, a risk-based approach, clear context of use, data governance, multidisciplinary expertise, lifecycle management and clear communication. Notably, they favour continuous monitoring over one-time validation, reflecting concern about model performance degrading as the data environment shifts.

Sources: FDA document and EMA news release

CIOMS Working Group XIV. The final report on Artificial Intelligence in Pharmacovigilance was published on 4 December 2025, built around seven guiding principles: a risk-based approach, human oversight, validity and robustness, transparency, data privacy, fairness and equity, and governance and accountability.

Its scope is deliberately framed around good practice rather than technical prescription, and it is likely to become an important reference for organisations documenting AI governance in pharmacovigilance.

Source: CIOMS Working Group XIV

3. Validation: CSA and the QMSR

A medical device guidance, but the risk-based model behind it is shaping how validation effort gets justified more broadly.

The Quality Management System Regulation took effect on 2 February 2026, amending 21 CFR Part 820 and incorporating ISO 13485:2016 by reference.. FDA published the final rule on 2 February 2024 (89 FR 7496) with a two-year runway.

The day after it took effect, on 3 February 2026, FDA issued an updated final guidance, Computer Software Assurance for Production and Quality Management System Software, superseding the 24 September 2025 version. The update:

  • Aligns CSA with the QMSR and references ISO 13485 clauses directly
  • Adds NIST-based definitions for cloud, IaaS, PaaS and SaaS
  • Confirms that AI and machine learning tools fall within scope when used for production or quality management purposes

One point of precision that often gets lost. The formal scope of CSA is software used in medical device production and in the quality management system. It is not a validation guidance for eClinical systems generally.

Its influence is nonetheless broad, because the underlying model, scaling assurance effort to intended use and process risk rather than documenting uniformly, is the direction of travel across GxP validation. Sponsors borrowing the framework should be clear about where it formally applies and where they are applying it by analogy.

4. Trial conduct: ICH E6(R3) Annex 2 and the UK regime

Annex 2 is final, the EU date is settled at 15 January 2027, and the UK has been operating under the new regime since 28 April 2026.

Annex 2 was adopted at Step 4 on 3 June 2026. It supplements the E6(R3) Principles and Annex 1 with considerations for trials incorporating decentralised elements, pragmatic approaches and real-world data.

Compared with the draft, the final text substantially strengthens expectations around RWD:

  • Sponsor oversight and data governance
  • Access to individual-level data and source records
  • Arrangements where data are owned or controlled by third parties
  • A fit-for-purpose assessment covering reliability, relevance, provenance, traceability, bias and generalisability

The investigator retains medical oversight of trial-related activities even when those activities happen away from a traditional site.

The EU effective date is 15 January 2027. This is worth stating clearly, because published trackers have carried conflicting dates. Annex 2 reached Step 4 following ICH adoption on 3 June 2026 and CHMP adoption on 25 June 2026, and comes into effect on 15 January 2027. The mid-2025 date some sources cite refers to the Principles and Annex 1, which came into effect on 23 July 2025. Two different components, two different dates.

The UK is already inside the new regime. The Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025 were signed into law in April 2025 and, following a twelve-month implementation period, came into force on 28 April 2026. The UK implemented ICH E6(R3) on the same date to avoid two rounds of change, and MHRA published UK-specific annotations on 12 January 2026. The reforms introduce notifiable trials, a fast-track route for lower-risk studies, and the Route B pathway for certain substantial modifications that raise no new safety concerns.

Sources: EMA scientific guideline page and HRA on the UK reforms

5. Data standards: ICH M11 is now in effect in the EU

The EU template took effect on 11 June 2026, creating a standard structure for exchanging protocol information.

The ICH M11 Clinical Electronic Structured Harmonised Protocol was adopted at Step 4 on 19 November 2025. The EMA template reached Step 5 with final CHMP adoption on 11 December 2025 and a date for coming into effect of 11 June 2026. FDA announced the final guidance in the Federal Register on 22 May 2026 (91 FR 30310, Docket FDA-2022-D-3054).

M11 comprises three documents: a guidance, a protocol template with standardised headers and common text, and a technical specification defining harmonised terminologies and data fields for electronic exchange, built on an open non-proprietary standard.

M11 creates a standardised structure through which protocol information can increasingly be represented and exchanged as interoperable data alongside the narrative protocol. That widens what can be automated downstream at study build, and it is a reasonable question to put to your eClinical vendors about their roadmap.

Sources: Federal Register notice and EMA template

6. Pharmacovigilance: the EU framework has already shifted

Applicable from 12 February 2026. Signal management and subcontractor contracts are where the work landed.

Commission Implementing Regulation (EU) 2025/1466 of 22 July 2025 amended Implementing Regulation (EU) No 520/2012. It entered into force on 12 August 2025, with limited provisions applying from that date, and became fully applicable on 12 February 2026. Two changes with particularly direct operational implications are:

  • Signal management. Article 21(2) was deleted. Marketing authorisation holders no longer submit validated signals to EMA and national competent authorities via the standalone signal notification form. Signals from all sources, including EudraVigilance, are handled through the MAH's own signal management process with reference to GVP Module IX. Internal SOPs and role definitions may need revising to match.
  • Subcontracting. Since 12 February 2026, contracts with subcontractors must describe roles and responsibilities, the safety data exchange obligations placed on third parties, and the method by which data are exchanged.

EMA states on its GVP overview page that the amendments are applicable and that GVP guidance will be updated accordingly in upcoming revisions of the modules. That points to rolling SOP and system updates through the year rather than a single planned change.

Source: EMA GVP overview

Dates to diarise

Date What happens
2 August 2026 EU AI Act general application, Article 50 obligations, governance framework
2 December 2026 New Article 5 prohibitions apply; four-month Article 50(2) marking transition ends
15 January 2027 ICH E6(R3) Annex 2 comes into effect in the EU
1 August 2027 Commission guidelines due for operators of Annex I high-risk AI systems
2 August 2027 National AI regulatory sandboxes operational; delegated acts due on sectoral equivalence
2 September 2027 Commission guidance and voluntary template due on post-market monitoring plans
2 December 2027 High-risk obligations apply to stand-alone Annex III systems
28 January 2028 Deadline for Annex I Section A notified bodies to apply for AI Act designation
2 August 2028 High-risk obligations apply to AI embedded in Annex I regulated products

Where this leaves your systems

Read together, these developments converge on one set of questions. What did the system do? Who reviewed it? Can you produce the record on request?

Whether the framing is Article 50 disclosure, CSA assurance evidence, Annex 2 data provenance or CIOMS human oversight, the underlying expectation is the same. It is an evidence expectation rather than a technology one.

Cloudbyz's AI capabilities across eTMF, CTMS, EDC, RTSM and Safety and Pharmacovigilance are designed to support that evidence trail, through confidence thresholds, human review steps, audit trails and documented data governance.

We would rather be precise than promotional about what that means. These features are designed to help teams meet their obligations. They do not discharge them. AI produces a draft, and an authorised human review is what turns a draft into a record. Across these frameworks, the recurring expectation is documented governance, proportionate human oversight and an auditable evidence trail.

Back next week.

This article is for general informational purposes and does not constitute legal or regulatory advice. Regulatory positions and implementation guidance should be checked against the applicable official sources.