What the FDA and EMA's New AI Principles Mean for Pharmacovigilance

Jae Fredrick
CTBM

Request a demo specialized to your need.

In January 2026, the FDA and EMA did something they don't do often: they agreed on the same page, literally. The two agencies jointly published ten guiding principles for good AI practice in drug development, and unlike a lot of regulatory guidance, this one isn't narrowly scoped to clinical trials or manufacturing. It covers the full medicines lifecycle, and pharmacovigilance is explicitly named as one of the areas where AI is already being used and where the agencies expect it to keep expanding.

If you're running signal detection, triaging ICSRs, or mining literature for safety signals with any kind of AI or NLP tool, this guidance is written with you in mind, even if your name never comes up specifically. Here's what's actually in it, and what it means once you try to apply it to a real safety operation.

Why this document is different

Most AI guidance up to this point has come from FDA or EMA separately, on their own timelines, often reading like two different philosophies. This one is co-authored. That matters less for the content and more for what it signals: inspectors on both sides of the Atlantic are now working from a shared checklist. If you're a global sponsor building one AI-assisted safety workflow instead of two regional ones, that's the whole point.

The document also doesn't pretend AI in PV is theoretical. It says plainly that AI is already showing up in post-market safety signal detection, and it gives a concrete example close to how a lot of teams are actually working: an NLP model scans incoming reports for keywords, flags the ones that look relevant, and a safety physician reviews the flagged cases every night, checking that patient information stays anonymized and that the flagged signal is real. That's not a hypothetical. That's a description of a workflow a lot of safety teams already run in some form.

Healthcare Safety Reviewer at Muted Dashboard Monitor

The ten principles, translated out of guidance-speak

The full document lays out ten principles. Read cold, they sound like the kind of thing that gets filed away after one skim. Read against an actual PV workflow, they turn into a fairly specific checklist.

Human-centric by design. The AI supports the safety physician's judgment; it doesn't replace it. If your workflow has a human reviewing every AI-flagged case before a decision gets made, you're already living this principle. If a model is auto-closing cases with no review, that's the gap to fix first.

Risk-based approach. Not every AI use case needs the same level of scrutiny. A model that helps prioritize your literature review queue is lower stakes than one that's doing initial signal detection on ICSRs. The validation effort should scale with what's actually at risk if the model gets it wrong.

Adherence to standards. AI tools don't get a pass on GxP. Whatever quality system already governs your PV processes needs to extend to the AI sitting inside them.

Clear context of use. This is the one teams skip and regret. Write down, specifically, what the model is for and where its boundaries are. "This NLP model flags potential adverse events from unstructured clinical notes for PV review; it hasn't been validated on non-English records" is the kind of sentence that should exist for every model you're running, not live in someone's head.

Multidisciplinary expertise. Safety physicians, data scientists, QA, and regulatory all need a seat at the table when these tools get built and maintained, not just at the build stage but for as long as the tool is in use.

Data governance and documentation. Where did the training data come from, what happened to it in processing, and can you trace every step? For ICSR pipelines specifically, this means your AI-assisted coding and classification decisions need the same audit trail your manual ones already have.

Model design and development practices. Favor models you can actually explain over models that just perform well on paper. A black box that flags signals accurately but can't tell you why is a harder sell to an inspector, and a harder tool to trust when it's wrong.

Risk-based performance assessment. Test the whole workflow, human and AI together, not the model in isolation under lab conditions. How it performs in your actual case volume, with your actual data quality, is the number that matters.

Life cycle management. Adverse event terminology and reporting patterns shift over time, and models drift. Build in scheduled re-evaluation rather than validating once and assuming it holds.

Clear, essential information. Whoever relies on the model's output, whether that's a safety physician, a regulator, or eventually a patient, needs to understand what it does, what it doesn't do, and where its limits are, in language that doesn't require a data science degree to parse.

What this means if you're building or buying an AI tool for PV right now

The pattern across all ten principles is consistent: AI is welcome in the safety workflow, but it doesn't get to operate outside the quality system that already governs everything else you do. If a vendor pitches you a signal detection tool, the questions this guidance hands you are specific ones. What's the documented context of use? Can they show you the validation approach and how it was scaled to the risk level? Is there a real human review step, or is "human-in-the-loop" doing a lot of marketing work for very little actual oversight? What does ongoing monitoring look like once the model is live, not just at go-live?

None of this is about slowing AI adoption down for its own sake. It's about making sure that when an inspector eventually asks how a safety signal got flagged, there's a documented, defensible answer waiting, not a shrug and a vendor's sales deck.

The takeaway

This guidance is the clearest signal yet that regulators expect AI in pharmacovigilance to keep growing, and that they're building the oversight framework for it now rather than waiting to react later. Teams that treat these ten principles as a build checklist today will have a much easier time in an inspection than teams that bolt on documentation after the fact. Worth building your next AI vendor evaluation, or your next internal validation plan, directly around this list.