Ask five regulatory affairs professionals where things stand with the FDA, the EMA and the ICH on artificial intelligence (AI), and it would not be surprising to get five different, partially overlapping answers. That is not really anyone's fault. AI regulation drug discovery questions currently sit across a genuinely uneven landscape: a detailed FDA framework that is still in draft form after more than a year, a finished EMA reflection paper that reads more like a statement of expectations than an enforceable rule, and an ICH process that has not issued anything AI-specific at all, leaning instead on general clinical trial principles that happen to have been rewritten recently in AI-friendly, technology-neutral language.
None of that is a reason to wait and see. It connects to the broader guide to AI across drug discovery for how these regulatory questions fit alongside the scientific and technical ones drug discovery teams are already navigating. What follows is a plain accounting of what each regulator has actually published, what it covers, and where real uncertainty remains, as of mid-2026.
The current regulatory landscape
There is no dedicated, binding, global law that says "here is how AI in drug development must be validated." What exists instead is a set of documents at very different stages of maturity, issued by agencies that are visibly coordinating with each other but have not yet converged on identical requirements. The table below summarizes where each stands as of this writing.
Regulator | Key document | Status (mid-2026) | Scope |
FDA | Considerations for the Use of AI to Support Regulatory Decision-Making for Drug and Biological Products | Draft since Jan. 2025; comment period closed; finalization pending | Nonclinical, clinical, postmarketing, manufacturing. Excludes drug discovery and internal operational tools. |
FDA + EMA (joint) | Guiding Principles of Good AI Practice in Drug Development | Published Jan. 2026; non-binding | Full product life cycle; foundation for future guidance in both jurisdictions. |
EMA | Reflection paper on the use of AI in the medicinal product lifecycle | Finalized Sept. 2024 | Full life cycle, explicitly including drug discovery and nonclinical development. |
ICH | No AI-specific guideline; relies on E6(R3) GCP and E8(R1) general considerations | E6(R3) principles/Annex 1 final Sept. 2025; Annex 2 still draft | Technology-neutral, risk-based principles applied to AI use in clinical trials by extension. |
The pattern worth noticing is which stage of the pipeline each document actually reaches. FDA's own framework, by design, does not touch early discovery work at all. EMA's does. ICH has not weighed in on AI specifically in either direction. A drug discovery team building or validating an AI model for hit identification or lead optimization is, strictly speaking, operating in a gap between what US and European regulators currently require, at least until that model's output starts feeding into nonclinical or clinical evidence intended for a regulatory submission.
FDA AI/ML framework and draft guidance
FDA's principal AI document remains a draft guidance first published in January 2025, titled "Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products." It was informed by an expert workshop, more than 800 public comments on an earlier 2023 discussion paper, and the agency's own experience reviewing more than 500 submissions with AI components between 2016 and 2023. The public comment period closed in April 2025, and finalization has been anticipated since, but as of this writing the document remains in draft: FDA's own AI program page still describes it that way.
The draft's central contribution is a seven-step, risk-based credibility assessment framework, built around the idea of a "context of use": the same AI model can warrant very different levels of validation evidence depending on what regulatory question it is being used to answer and how much weight that answer carries.
- Define the question of interest the AI model is meant to help answer.
- Define the model's context of use: its specific role and scope within the development program.
- Assess AI model risk, weighing both the model's influence on the decision and the consequence of getting it wrong.
- Plan the credibility assessment activities needed, scaled to that risk level.
- Execute the credibility assessment plan and generate the supporting evidence.
- Document the results in a credibility assessment report.
- Determine whether the model's demonstrated credibility is adequate for its context of use, with remediation if not.
Two scope details matter for a discovery-focused audience. First, the framework explicitly covers the nonclinical, clinical, postmarketing, and manufacturing phases, and just as explicitly excludes drug discovery and internal operational efficiencies from its reach, at least for now. Second, FDA has paired the draft guidance with internal governance of its own: CDER established an AI Council in 2024 to coordinate the agency's own use of and policy toward AI, on top of the sponsor-facing rulemaking.
EMA's position on AI
The EMA's counterpart document, its reflection paper on the use of AI in the medicinal product lifecycle (EMA/CHMP/CVMP/83833/2023), took a longer road to a more settled destination: drafted in July 2023, opened for public consultation through the end of that year, and formally adopted by both the human and veterinary medicines committees in September 2024. Unlike FDA's framework, it is explicit that drug discovery and nonclinical development are in scope, on the reasoning that AI-generated results from those stages can still end up as part of the evidence submitted in a marketing authorization application.
The paper's stated approach rests on the same two pillars regulators keep returning to: risk-based validation proportionate to how a model's output will actually be used, and a human-centered expectation that AI supports rather than replaces expert judgment. It is also unusually specific about documentation burden for high-impact uses: for AI/ML applications with high regulatory impact or high patient risk that have not been previously qualified for that specific context, EMA notes that the full model architecture, development and validation logs, training data and a description of the data processing pipeline may be requested as part of the dossier reviewed at authorization. It also flags data representativeness as a distinct risk, noting that AI systems trained on data that underrepresents small populations, including children and people with rare diseases, need particular scrutiny for bias.
EMA's reflection paper is, by its own description, a statement of current thinking rather than a binding requirement, which leaves it doing more of the interpretive work than the enforcement work for now. It sits alongside, and is explicitly referenced by, the joint FDA-EMA guiding principles published in January 2026, a ten-point, non-binding framework the two agencies developed together as groundwork for future, more detailed guidance in both jurisdictions.
There is a separate, broader layer worth flagging for European operations: the EU AI Act, a horizontal, sector-agnostic law rather than a medicines-specific one, entered into force in August 2024, with obligations for general-purpose AI models phasing in from August 2025 and the higher-risk obligations most likely to touch clinical AI applications phasing in from August 2026. Where a medicinal product's AI component also qualifies as a high-risk AI system under that Act, a sponsor may need to satisfy both the Act's requirements and EMA's medicines-specific expectations at once, and the two frameworks are not yet fully reconciled in public guidance.
ICH E8 and AI trial design
Of the three bodies covered here, ICH is the one that has said the least about AI directly, and that absence is itself informative. There is no ICH guideline written specifically for artificial intelligence. What ICH has done instead, over the past several years, is rewrite two of its core clinical trial guidelines in more flexible, risk-based, technology-neutral language, and regulators are now leaning on that language to cover AI by extension rather than by name.
The more foundational of the two, E8(R1), general considerations for clinical studies, finalized back in 2021 and built around a quality-by-design philosophy, asks sponsors to identify the factors genuinely critical to a trial's quality up front rather than treating every process step as equally important. E6(R3), the revised good clinical practice guideline, reached final status for its core principles and Annex 1 in September 2025, explicitly built to accommodate innovations in trial design, conduct and technology; a second annex covering decentralized and pragmatic trial elements and real-world data sources, arguably the part most relevant to AI-heavy trial designs, remains in draft.
EMA's own reflection paper draws the connection explicitly, stating that AI and machine learning used within a clinical trial should meet the applicable requirements of ICH E6 good clinical practice, with additional documentation expected for high-impact or previously unqualified uses. In practice, that means a sponsor using AI to support trial design or conduct is not working from an AI-specific rulebook at all, but from the same risk-based, critical-to-quality thinking that now governs every other element of a modern clinical trial.
AI model transparency requirements
Transparency is the theme every one of these documents converges on fastest, even where they disagree on scope and bindingness. The clearest single statement of what regulators actually mean by it is in the joint FDA-EMA guiding principles, which lay out ten points covering the full AI life cycle from design through decommissioning.
- Human-centric by design: AI supports human decision-making rather than substituting for it.
- Risk-based approach: validation, mitigation and oversight scale with model risk and context of use.
- Adherence to standards: AI use follows applicable legal, ethical, technical and GxP requirements.
- Clear context of use: each model has a well-defined role and scope.
- Multidisciplinary expertise: both AI and domain expertise are involved throughout the model's life cycle.
- Data governance and documentation: data provenance and processing decisions are traceable and verifiable.
- Model design and development practices: models are built with interpretability and robustness in mind.
- Risk-based performance assessment: the full human-AI system is evaluated, not the model in isolation.
- Life cycle management: models are monitored and periodically re-evaluated after deployment.
- Clear, essential information: plain-language disclosure of a model's use, performance and limitations.
The recurring thread across FDA, EMA and this joint document is documentation that survives contact with an outside reviewer: not just a model that performs well, but a traceable record of what data trained it, how it was validated, and what its known limits are, pitched at a level a non-specialist regulator or inspector can actually evaluate. Interpretability and explainability show up repeatedly as distinct, valued properties rather than nice-to-haves, which is a notably higher bar than most internal industry validation practices have historically set for exploratory, discovery-stage models.
What pharma companies are doing to prepare
With final rules still pending in more than one jurisdiction, most organizations working seriously with AI in drug development have stopped waiting for the last document to land before acting. A few practices are becoming common well ahead of finalization.
- Standing up an internal AI governance body, echoing FDA's own CDER AI Council, to coordinate policy, risk assessment, and documentation practice across programs rather than leaving it to individual project teams.
- Writing a context-of-use and risk statement for significant AI models before a regulator asks for one, using FDA's seven-step framework as a template even while it remains in draft.
- Building data lineage and provenance tracking into AI pipelines from the start, rather than reconstructing it retroactively, since both FDA and EMA treat traceable data documentation as close to non-negotiable for high-impact uses.
- Treating discovery-stage AI output as though lifecycle documentation will eventually be expected, since EMA's reflection paper already reaches that stage even though FDA's current draft does not.
- Engaging regulators early through FDA's established engagement pathways, rather than presenting a finished validation package for the first time at submission.
The organizations furthest along tend to treat all of this as a documentation and governance exercise layered on top of existing GxP quality systems, rather than a separate compliance project. That framing tracks what regulators themselves keep signaling: none of the frameworks covered here invent a new discipline from scratch so much as extend familiar risk-based validation thinking to a class of tools that did not clearly exist when most of the underlying rules were first written.
Key takeaways
|
This article was produced in accordance with Drug Discovery News’ Editorial Policies.

















