Article

The FDA and EMA’s Good AI Practice Framework

The FDA and EMA’s Good AI Practice Framework

On January 14, 2026, the U.S. Food and Drug Administration and the European Medicines Agency jointly released the Guiding Principles of Good AI Practice in Drug Development — ten high-level principles covering the use of artificial intelligence across the full medication lifecycle, from early research and clinical trials through manufacturing and post-market safety monitoring. For companies operating on both sides of the Atlantic, a divergent regulatory posture on AI would have forced parallel compliance programs and slowed adoption; alignment from the outset is exactly what the industry asked for. The Principles are not binding regulations, but they are a shared foundation that will underpin future AI-specific guidance in both jurisdictions.

The Ten Principles

  1. Human-centric by design. AI development and use must align with ethical, human-centric values.
  2. Risk-based approach. Validation, risk mitigation, and oversight should be proportionate to the model’s context of use and its determined risk. Lower-risk tools warrant lighter controls; higher-risk tools informing critical decisions warrant more rigorous testing and monitoring.
  3. Adherence to standards. AI must comply with relevant legal, ethical, technical, scientific, cybersecurity, and regulatory standards, including Good Practices (GxP).
  4. Clear context of use. The AI’s intended role and scope — why it is being used, its inputs and outputs, and how results feed decisions — must be well-defined.
  5. Multidisciplinary expertise. Expertise covering both the AI technology and its domain of application must be integrated across the model’s lifecycle.
  6. Data governance and documentation. Data provenance, processing steps, and analytical decisions must be documented in a traceable, verifiable way in line with GxP, with privacy and protection for sensitive data maintained throughout.
  7. Model design and development practices. Development should follow sound software and system engineering practices, using fit-for-use data, with attention to interpretability, explainability, and predictive performance appropriate to the context of use. Model and system development of AI technologies promoting patient safety should also promote transparency, reliability, generalizability, and robustness.
  8. Risk-based performance assessment. Evaluate the complete system — including human-AI interactions — using fit-for-use data and metrics appropriate to the intended context of use. Validate predictive performance through appropriately designed testing and evaluation methods.
  9. Life cycle management. Implement risk-based quality management across the AI lifecycle to capture, assess, and address issues, along with scheduled monitoring and periodic re-evaluation to catch problems such as data drift.
  10. Clear, essential information. Use plain language to communicate the AI’s context of use, performance, limitations, underlying data, updates, and explainability to intended audience like users and patients.

Read together, the throughline here is that AI that is involved in a regulated decision must be governed like any other validated system: clearly defined roles, evaluation of risk, documented, monitored, and kept under human accountability.

What the Data Says About AI in Drug Development

The Principles arrive against a backdrop of rapid but uneven adoption; industry numbers tell a story of genuine momentum paired with unproven late-stage results.

An industry analysis from Nvidia reports that roughly 70% of healthcare and life sciences companies now deploy AI in some capacity, with generative AI providing the top AI workload 69%, with data analytics at 65%, predictive analytics at 51% and agentic AI at 47%. 48% of pharma/biotech respondents are using AI agents for drug discovery and biomarker identification, with literature review being their top agentic use case.

The clinical pipeline has also grown in the meanwhile, but with some caveats. Jayatunga et al. found that AI-discovered molecules have a Phase I success rate of 80-90%, along with a Phase II success rate of 40%, in a limited number of samples analyzed. However, no AI-designed drug has been approved by the FDA as of yet; Rentosertib, an AI-designed oral small-molecule inhibitor for idiopathic pulmonary fibrosis just recently launched into Phase III trials in July 2026, and is the furthest along the pipeline for an AI-designed drug.

Regulations at Large

While the ten Principles are themselves non-binding, they are best read as the alignment layer for an international body of regulation that is already translating the same expectations into enforceable form.

The EU AI Act (Regulation (EU) 2024/1689) operationalizes the Principles’ themes of data governance, transparency, human oversight, and lifecycle risk management. The Act classifies what kinds of AI-enabled medical devices and SaMD would be considered as “high-risk”; its transparency obligations took effect in August 2026, while high-risk requirements were deferred by the June 2026 Digital Omnibus to December 2027 for standalone systems and August 2028 for AI embedded in regulated products.

In parallel, the EU’s draft GMP Annex 22 carries the Principles directly into the manufacturing floor: it permits only static, deterministic models in critical GMP applications, excludes generative AI and large language models from those uses, and requires any AI decision to perform at least as well as the validated manual process it replaces.

On the U.S. side, the FDA is currently developing and publishing several AI guidances, with some already in draft or finalized, like AI/ML guidances covering topics like predetermined change control plans, clinical decision support software, and cybersecurity in medical devices. In other words, the ten Principles describe the direction that binding law, existing GxP frameworks, and the guidance still being finalized are all converging toward.

The Bottom Line

The FDA and EMA Principles are non-binding, high-level, but signal the incoming detailed AI guidances and regulations. By signaling clear regulatory intent, these Principles achieve meaningful regulatory alignment, and companies are setting themselves up for success by treating AI governance as an extension of their existing quality systems rather than an afterthought.

The organizations best positioned for AI regulations can start by building structured AI governance now: document AI context of use, perform risk-based validation, provide models with clean and traceable data, monitor models for drift, and keep human judgment firmly in the decision loop. Adoption of AI in life sciences will keep expanding, and so will the expectation that it can withstand an inspector’s scrutiny.

Ready to get started with ACE?

Get answers to your questions and discover how ACE can help you elevate your business.