Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs
Back to Articles
IntuitionLabs

eu ai act · pharmaceutical regulation

The EU AI Act & Pharma: Compliance Guide + Flowchart

October 18, 2025
Updated August 10, 2026
35 min read

Learn about the EU AI Act's impact on pharma. Updated for 2026 with the Digital Omnibus proposal, GPAI Code of Practice, and revised Product Liability Directive. Includes risk classification, compliance steps, flowchart & SOP starter kit.

The EU AI Act & Pharma: Compliance Guide + Flowchart
Summary
  1. 01Prohibited AI practices became binding on 2 February 2025, and GPAI obligations followed on 2 August 2025 alongside the final GPAI Code of Practice.
  2. 02The Digital Omnibus proposal defers Annex III high-risk obligations to 2 December 2027 and high-risk AI in regulated products like medical devices to 2 August 2028.
  3. 03AI tools used purely in research contexts, such as early drug discovery models, are generally exempt from AI Act obligations.
  4. 04Breaches can trigger fines up to €35 M or 7% of global turnover, making inventorying and classifying AI systems a priority now.
  5. 05Only 9% of life-sciences professionals report understanding AI-related regulations well, despite AI's potential to add $100 billion of value to healthcare.

Updated to reflect the binding AI Act timetable, the GPAI Code of Practice, and the revised Product Liability Directive.

Executive Summary

The EU Artificial Intelligence (AI) Act – the world’s first comprehensive AI law – is profoundly affecting pharmaceutical companies that develop, use, or procure AI systems. Enacted in August 2024, the Act adopts a risk-based approach, categorizing AI into unacceptable, high-risk, limited-risk, and minimal-risk applications ([1]) ([2]). Unacceptable uses (e.g. illegal social scoring) are banned, while high-risk uses (including many life-science applications) face stringent requirements for transparency, data governance, risk management, human oversight, and documentation ([3]) ([4]). Limited-risk applications (e.g. simple chatbots) must observe basic transparency or notice obligations, and minimal-risk uses face only voluntary guidelines ([3]) ([5]).

For pharmaceutical firms, this framework adds a new compliance layer atop existing regulations (such as GMP, medical-device rules, and data privacy laws) ([4]) ([6]). In practice, virtually all AI systems used directly to support patient safety or treatment decisions (e.g. diagnostic algorithms, clinical decision support, patient monitoring apps) will be deemed high-risk ([7]) ([8]). These systems must undergo formal conformity assessment, stringent risk management, and ongoing post-market monitoring. AI tools used in research-only contexts (e.g. early drug discovery models) are generally exempt from AI Act obligations ([9]) ([10]). Notably, the European Federation of Pharmaceutical Industries and Associations (EFPIA) has observed that “AI-enabled tools used in pharma R&D are exempt,” whereas digital health and medical AI (even if low risk) are covered by the Act ([11]).

Compliance deadlines come in phases. Prohibited practices took effect on 2 February 2025, and obligations for general-purpose AI (GPAI) models (such as large language models) became binding on 2 August 2025 alongside the final GPAI Code of Practice ([12]) ([13]). Full high-risk and transparency requirements were originally set for 2 August 2026, but the European Commission's Digital Omnibus proposal (November 2025) proposes deferring Annex III high-risk AI obligations to 2 December 2027 and high-risk AI embedded in regulated products (e.g. medical devices under MDR/IVDR) to 2 August 2028, contingent on the availability of harmonized standards ([14]). These obligations – including hefty fines (up to €35 M or 7% global turnover) for breaches ([15]) ([16]) – require pharma companies to act now. Key preparatory steps include: inventorying all AI uses, classifying each by risk, integrating AI compliance into quality systems (e.g. risk management under ICH Q9), establishing governance and documentation practices, and training staff on AI literacy ([17]) ([18]). A compliance flowchart should guide decision-making (see Figure 1). Likewise, a standardized set of Standard Operating Procedures (SOPs) should be drafted, covering areas like data governance, change control for AI models, performance monitoring, and incident reporting.

This report provides a comprehensive guide to EU AI Act compliance in the pharmaceutical sector. After an introduction and historical background, we analyze the Act’s structure, obligations, and implications for pharma R&D, manufacturing, clinical trials, medical devices, marketing, and data management. We include data (e.g. market trends, investment figures) and expert perspectives, and illustrate with industry examples (Novartis, Pfizer, BMS, Sanofi). Recommended compliance processes are detailed, including flowcharts and sample SOP outlines. The report concludes with a discussion of future directions (liability rules, global impacts, regulatory sandboxes) and a set of practical recommendations. Legal requirements and implementation dates should be verified against the Regulation and current European Commission materials.

01

Introduction and Background

Evolution of AI Regulation

Artificial intelligence – especially machine learning and generative AI (GenAI) – has revolutionized drug discovery, clinical development, manufacturing, and patient care in recent years ([19]) ([5]). Pharmaceutical R&D is increasingly data-driven: the global AI-in-pharma market reached an estimated $4.35 billion in 2025 and is projected to grow to $6.16 billion in 2026, on track toward $35 billion by 2031 (41.5% CAGR) ([20]). AI is credited with compressing development timelines and costs (the industry faces ~$2.6B outlay per new drug) ([21]). Leading companies (e.g. Novartis, Pfizer, BMS, Sanofi) have launched multibillion-dollar initiatives with AI startups and tech partners to apply advanced algorithms to molecular design, clinical trial optimization, and personalized medicine ([22]) ([23]).

These strides come with new risks and uncertainties. Late-stage trial failures, model biases, data quality gaps, and opaque “black box” algorithms have exposed critical vulnerabilities in AI use ([24]) ([25]). Recognizing this, regulators worldwide are racing to establish guardrails. In Europe, the EU Artificial Intelligence Act (AI Act) emerged as a cornerstone of digital policy. First proposed by the European Commission in 2021, it was negotiated and provisionally agreed by late 2023 ([26]) ([27]). Officially adopted in 2024, it entered into force on 1 August 2024 ([28]). The EU intends the AI Act to be “risk-based”, harmonizing rules across Member States and potentially setting the global standard for AI oversight ([29]) ([30]).

European policymakers take AI governance seriously. The Council of the EU lauded the Act as “ground-breaking” in harmonizing AI rules on a risk-based principle ([29]). It follows earlier digital rulebooks like GDPR, where fundamental rights drove regulation. Notably, under the Act, harm-causing AI uses are banned; high-risk uses face rigorous controls; lower-risk uses have light-touch requirements ([3]) ([2]). The legislation also incorporates provisions on AI literacy (training staff), which entered into force in February 2025 ([31]), and establishes an EU AI Office and multi-national sandboxes to foster safe innovation ([32]) ([33]).

Impact on Pharmaceutical Sector

The pharma industry is uniquely affected. Drugs and medical devices are already among the most regulated products, and AI is now embedded in nearly every aspect of drug development. Examples include: AI algorithms that scan chemical libraries to propose new drug candidates; predictive models for patient recruitment and trial design; image-analysis software for diagnostics; robotic process automation in manufacturing; and even AI chatbots for medical information. Many of these are likely to fall under the AI Act’s high-risk category (see below). The Act’s new requirements will thus layer onto existing regimes like Good Manufacturing Practices (GMP), Medical Device Regulation (MDR), and data protection laws. The European Federation of Pharmaceutical Industries and Associations (EFPIA) has stressed that AI regulation “must be fit-for-purpose, risk-based, non-duplicative, globally aligned, and adequately tailored” ([34]).

For pharma, compliance starts with awareness. Only 9% of life-sciences professionals report understanding AI-related regulations well ([35]) – a gap given AI’s potential to add $100 billion of value to healthcare ([35]). As Leverage et al. note, firms must integrate AI risk management into their Quality Management Systems (QMS) and existing compliance programs ([36]) ([18]). The Act’s requirements – on data quality, traceability, transparency, and human oversight – often mirror GMP and ISO 13485 provisions, easing some integration but also demanding new documentation and training ([17]) ([18]).

In summary, the introduction of the EU AI Act represents a pivotal moment for pharma. It promises safer, more trustworthy AI, but also imposes significant obligations. Companies must now systematically assess each AI use case, assign risk levels, and implement matching controls. The following sections will unpack these obligations in detail and provide tools (flowcharts, SOP outlines) to achieve compliance efficiently.

9%

Share of life-sciences professionals who understand AI regulations well

$100B

Potential value AI could add to healthcare

$35B

Projected global AI-in-pharma market size by 2031

€35M / 7%

Maximum fines for AI Act non-compliance

02

The EU AI Act: Structure and Key Provisions

Risk-Based Classification

The AI Act organizes AI systems into four categories by risk level ([3]) ([2]):

  • Unacceptable Risk: AI uses that contravene EU values or fundamental rights (e.g. subliminal manipulation, social credit scoring, mass biometric surveillance) are outright prohibited ([3]) ([37]). No pharmaceutical application is expressly banned, but deployment of general-purpose AI (GPAI) for unethical profiling in healthcare could similarly be disallowed.

  • High Risk: Systems deemed high-risk face the strictest rules ([3]) ([7]). High-risk AI covers:

  • AI intended to be used as a safety component of a product, or itself as a product, covered by Annex I Union harmonisation legislation, where the applicable product law requires third-party conformity assessment. In pharma, this primarily means software as a medical device: for example, diagnostic algorithms, patient monitoring apps, therapeutic decision support, or any AI integrated into medical devices (MD) or in vitro diagnostics (IVD) requiring third-party conformity assessment ([7]) ([6]). Under the MDR/IVDR definitions, most AI used for diagnosing, treating, or monitoring patients (class IIa, IIb, III devices) is high-risk ([38]) ([6]).

  • Specific uses listed in Annex III. Relevant examples include biometric categorization (e.g. facial recognition for patient ID), eligibility determination for healthcare or insurance, and triage for emergency care ([39]) ([40]). (Notably, an AI tool that assigns patients to treatment arms or predicts disease severity arguably falls into these health-related Annex III cases).

In short, clinical and medical AI systems require a documented, intended-purpose assessment under Article 6; they are not automatically high-risk solely because they are used in healthcare. Analytical tools that influence patient outcomes or resource allocation will require full conformity assessment ([7]) ([8]). Conversely, AI used for administrative or research tasks (e.g. drug discovery algorithms, non-clinical modeling) generally lies in a lower-risk bucket.

  • Limited Risk: Certain AI systems and outputs subject to Article 50 transparency duties get lighter requirements such as mandatory transparency (e.g. chatbots and some biometric categorization) ([3]). For pharma, this could cover internal virtual assistants, marketing chatbots, or customer support bots. Where Article 50 applies, providers and deployers must meet the specific notice, labelling, or disclosure duty for the system or output; for example, providers of systems intended to interact directly with natural persons must inform them that they are interacting with an AI system unless this is obvious from the circumstances and context. ([41]), but do not require full third-party assessments.

  • Minimal/No Risk: All other AI uses (e.g. internal document processing, supply-chain optimizations) face virtually no new regulatory obligations beyond voluntary standards. Even large language models (LLMs) like ChatGPT fall here as “general purpose AI” unless used in a high-risk context ([42]) ([3]). The Act philosophically treats these applications as safe, encouraging innovation while mandating basic data/logging transparency under its horizontal provisions ([43]) ([44]).

The classification logic can be summarized (see Figure 1). Organizations first determine whether their AI system triggers existing sector rules (like being medical device software) or falls into an Annex III use case. For Annex I product-related systems, it is high-risk only if the Article 6(1) conditions are met; Annex III systems are high-risk subject to the Article 6(3) exception ([38]). If not, they ask whether it complies with minimal transparency rules (if limited risk) or is out of scope (minimal risk).

T.01
Risk CategoryCoveragePharma ExamplesKey Obligations
UnacceptableAI violating fundamental rights or EU values ([3]) (e.g. manipulation, social scoring)None specific to pharma (unlikely to apply)Prohibited outright ([3])
High RiskSystems meeting Article 6(1)'s Annex I intended-purpose and third-party-assessment conditions, or applicable Annex III systems ([38]) ([3])Diagnostic algorithms, AI in patient monitoring, trial recruitment (health triage) ([7]) ([40])The applicable Article 43 conformity-assessment procedure; risk management, data governance, and the Articles 9–15 requirements. Annex IV specifies technical-documentation content ([4]) ([18])
Limited RiskSpecified uses requiring transparency ([3]) (e.g. chatbots, biometric categorization)Customer-facing chatbots, content generators, certain analytic toolsMeet the applicable Article 50 notice, labelling, or disclosure duty ([41])
Minimal RiskAI systems not otherwise prohibited, high-risk, or subject to a specific transparency duty; GPAI models are governed separately under Chapter VBasic R&D models, administrative analyticsNo system-specific AI Act requirements for the residual category; providers of GPAI models must meet the applicable Chapter V obligations

Table 1: EU AI Act risk categories, illustrative pharma use cases, and general obligations. (Sources: EU AI Act text and analyses ([38]) ([3]).)

Key Obligations for High-Risk Systems

Pharma companies should assess each system’s intended purpose and the Article 6 criteria before determining whether high-risk requirements apply ([7]) ([4]). The following summarizes core obligations (many of which must be documented in quality records):

  • Risk Management System (Article 9): A systematic, continuous process to identify and mitigate risks from AI logic and data ([45]). Companies must perform thorough risk assessments throughout the AI lifecycle, including identifying biases, privacy impacts, and failure modes ([45]) ([17]). For example, pharmaceutical firms should integrate AI risk evaluation into their QMS/ICH Q9 frameworks ([17]). Procedures must be in place to handle incidents (e.g. model errors triggering patient harm) and to revert to manual controls if thresholds are exceeded ([46]).

  • Data Governance and Quality (Article 10): High-risk AI must be trained and tested on high-quality data. This means ensuring data sets are accurate, representative, and traceable ([3]) ([18]). Electronic records must comply with 21 CFR Part 11 and EU Annex 11 standards for audit trails and integrity ([47]). In practice, pharma must document data provenance (source, cleansing methods), control for biases (e.g. ensuring clinical trial data doesn’t underrepresent subpopulations), and maintain immutable logs of AI inputs/outputs ([48]) ([45]).

  • Technical Documentation (Article 11 & Annex IV): A comprehensive technical file is required, akin to medical device documentation. This file must describe the system’s purpose, architecture, data handling, validation results, risk management plan, human oversight measures, and instructions for use ([49]) ([50]). Crucially, pharma companies must label their AI systems with a unique identifier and provide instructions on intended use, limitations, and proper operation ([18]) ([51]). All design choices, assumptions, and testing protocols must be recorded. Many of these details overlap with existing medical device technical documentation (e.g. MDR software files), but under the AI Act they must explicitly address AI-specific features (like model adaptivity, “self-learning” behaviors) ([49]) ([6]).

  • Record-keeping, Transparency, Human Oversight, Accuracy, Robustness and Cybersecurity (Articles 12–15): Article 12 requires high-risk AI systems to technically allow automatic event logging; Articles 13–15 address transparency and information for deployers, human oversight, and accuracy, robustness, and cybersecurity ([18]). The Act does not create a general explanation right for patients or healthcare professionals. Article 86 provides a limited right for an affected person subject to an adverse decision by a deployer based on an Annex III high-risk system (other than point 2 systems), where the decision produces legal or similarly significant effects on health, safety, or fundamental rights and the right is not otherwise provided by Union law ([52]). ([53]). In clinical contexts, regulators expect “continuous monitoring” of AI model performance and periodic reporting of any serious malfunctions or biases ([54]) ([55]). Moreover, instructions must clarify the required level of human oversight and the expertise needed to supervise the AI ([56]) ([57]).

  • Human Oversight (Article 14): Pharma AIs must be designed for a defined human role in the loop. For example, clinicians must be able to overrule AI diagnoses, and operators of a manufacturing AI must understand its outputs before acting ([6]) ([58]). Standard operating procedures should specify who monitors the AI and how to intervene if errors or atypical outputs occur.

  • Accuracy, Robustness, and Security (Article 15): High-risk AI must meet strict performance criteria. For medical AI, this entails rigorous validation against clinical gold standards ([59]). Models should be robust to noise and adversarial attacks, as judged by testing under varied conditions. Cybersecurity measures are required to protect AI systems from tampering ([18]). Companies must maintain cybersecurity protocols commensurate with those for other critical software (e.g. encryption, access controls, as emphasized under GDPR and GMP).

  • Audit & Certification: Many high-risk AI systems will require conformity assessment. If an AI is itself a medical device, this assessment will be done by a notified body as part of CE marking ([6]). Otherwise, for stand-alone high-risk AI (like a medical triage tool not yet covered by device legislation), the provider must arrange an independent evaluation (internal or external) demonstrating compliance with the Act’s requirements (the national regulators will publish conformity procedures). All assessment results must be appended to the technical documentation.

Table 2 below summarizes these obligations and typical pharma controls. In all cases, companies should integrate AI Act processes into existing compliance channels (e.g. Lean QMS, GMP change control, design reviews). Quality units should explicitly include “AI model modification” in their change-control protocols and treat AI software defects as “non-conformances” requiring corrective action plans.

T.02
Obligation CategoryRequirements & Examples in PharmaControl Measures/Documentation
Risk Management (Art.9)Continual risk analysis of AI impact on patients/productsMaintain risk register; include AI-specific risks (algorithmic bias, data drift) in QMS ([45]) ([17]); SOPs for incident response.
Data Governance (Art.10)High-quality training/test data; GDPR-aligned processing ([60])Data lineage records, Part 11 audit trails, data access policies; bias-mitigation methodology (e.g. diverse datasets) ([45]) ([60]).
Documentation (Art.11 & Annex IV)Complete technical file covering design, use, validation ([18])Documents within QMS: Intended Use, System Architecture, Validation Reports, Clinical Performance Data, User Manuals ([18]).
Record-keeping and transparency (Arts. 12–13)Automatic event logging where required; information enabling deployers to interpret and use the system appropriatelySystem logs, version control, and instructions for use; assess any separate patient-information duties under applicable sectoral and data-protection law.
Human Oversight (Art.14)Clear human roles; overrides; training requirementsSOPs detailing personnel responsibilities; training records; human-in-loop controls.
Accuracy & Security (Art.15)Performance standards; resilience; cybersecurityValidation studies (sensitivity/specificity analyses); penetration tests; encryption, user auth systems.
Conformity assessment (Art. 43; Annexes VI/VII)Apply the procedure required by the system’s classification and applicable product legislation.For Annex I product-related systems, integrate the AI Act assessment into the relevant sectoral procedure; for Annex III systems, use internal control unless Article 43 requires a notified-body procedure. Retain the technical documentation required by Article 11 and Annex IV.

Table 2: Key compliance obligations under the AI Act for high-risk AI and corresponding controls in pharmaceutical operations (Sources: EU AI Act Articles and expert guidance ([18]) ([45])).

Prohibited Practices and Other Provisions

While no routine pharma use is completely banned, companies must avoid unacceptable practices. The AI Act forbids any AI that manipulates subject behavior or infringes on rights (e.g. predictive scoring to deny treatment, biometric ID of patients without consent) ([3]). Decision-makers should screen for these risks; any AI flagged “unacceptable” must not be deployed.

Additionally, Article 50 transparency obligations apply only to specified systems and outputs. Providers of qualifying systems that generate synthetic audio, image, video, or text must mark outputs in a machine-readable format, subject to the stated exceptions. Deployer disclosure applies to deepfakes and to AI-generated or manipulated text published to inform the public on matters of public interest, subject to the Regulation’s exceptions. Ordinary AI-assisted pharmaceutical sales copy is not categorically subject to a clear-disclosure duty under Article 50.

Finally, the Act contains special rules for general-purpose AI (GPAI) models (large pretrained LLMs and foundation models). These obligations became applicable on 2 August 2025, accompanied by the final GPAI Code of Practice published by the EU AI Office on 10 July 2025. The Code – developed through a multi-stakeholder process with nearly 1,000 participants – is organized into three chapters: Transparency, Copyright, and Safety & Security. Providers of GPAI models (e.g. OpenAI, Google, Anthropic, Meta) must comply with transparency and copyright obligations; those with models posing “systemic risk” face additional safety requirements. Providers of GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to bring models into compliance ([43]). A pharmaceutical organisation using an LLM must assess its legal role and use case: Chapter V obligations attach to GPAI-model providers, while the organisation may also have obligations as a deployer or provider of an integrated AI system, including any applicable Article 50 transparency duty. Internal use alone does not determine the applicable obligations. Nevertheless, companies deploying LLMs should monitor guidance and applicable liability rules. The revised Product Liability Directive applies to products placed on the market or put into service after 9 December 2026; its scope includes software and applies to damage caused by defective products under the Directive’s conditions.

Implementation Timeline

The AI Act’s provisions come into effect in stages ([12]) ([13]):

  • 1 Aug 2024: Act entered into force. ✅
  • 2 Feb 2025: Ban on prohibited AI practices (Article 5) became binding, and AI literacy obligations (training) also took effect ([12]) ([31]). ✅
  • 2 Aug 2025: Obligations for General-Purpose AI (GPAI) models became applicable, accompanied by the final GPAI Code of Practice published by the AI Office on 10 July 2025. Member States were required to designate national competent authorities and adopt national laws on penalties. The EU AI Board, Scientific Panel, and Advisory Forum were established ([12]). ✅
  • 2 Aug 2026: The Regulation’s general application date; Article 50 transparency obligations also apply from this date, subject to the transitional provision for certain systems already on the market.
  • 27 Jul 2026: Regulation (EU) 2026/1744 entered into force, amending the high-risk application timetable.
  • 2 Dec 2027: Chapter III high-risk rules apply to systems classified as high-risk under Article 6(2) and Annex III.
  • 2 Aug 2028: Chapter III high-risk rules apply to systems classified as high-risk under Article 6(1) and Annex I.
  • 2 Aug 2027: Compliance deadline for GPAI models placed on the market before 2 August 2025.

Pharmaceutical firms must track this evolving schedule carefully. The EU AI Office was established in 2024 and is now operational, coordinating cross-border enforcement and overseeing GPAI model compliance. Spain’s AI watchdog (AESIA) published 16 non-binding, sandbox-derived practical guides on 16 December 2025; they support compliance but do not replace or develop the applicable regulations. Companies should have internal governance (AI risk committees, guidelines) in place now and use the extended timeline to refine system audits and sectoral conformity-assessment preparations rather than delay them.

F.01
EU AI Act Compliance Timeline
03

Compliance Workflow: Decision Flowchart

F.02
Six steps triage an AI system from identification to audit
01Identify AI System

Check whether the tool meets the EU's statutory definition of an AI system before any further analysis.

02Check for Exclusions

Assess whether the sole scientific R&D or pre-market research exclusions under Article 2(6) or 2(8) apply.

03Determine Risk Category

Verify Article 6 conditions for Annex I or Annex III systems to classify the system's risk level.

04Apply Controls

Apply the obligations and conformity-assessment procedure matching the system's risk classification.

05Internal Approvals & Training

Route deployments through a compliance review board spanning Legal, Regulatory, IT, and Data Science.

06Documentation and Audit

Maintain records of decisions, risk analyses, tests, and training for ongoing compliance evidence.

Documented classification and matched controls support compliant deployment.

Undocumented or misclassified AI systems risk regulatory non-compliance and fines.

To operationalize the above, we propose a compliance flowchart (schematic below) that the lead AI project manager or regulatory officer can use to triage AI systems:

  1. Identify AI System: Does the digital tool meet the EU definition of an AI system: a machine-based system designed to operate with varying levels of autonomy that, for explicit or implicit objectives, infers from inputs how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments? If no, the Act does not apply; maintain normal best practices. If yes, proceed.

  2. Check for Exclusions: Determine whether Article 2(6) applies because the system or model was specifically developed and put into service solely for scientific research and development, or whether Article 2(8) applies because the activity is pre-market research, testing, or development. Clinical-phase use alone is not the statutory test. If neither exclusion applies, continue as below.

  3. Determine Risk Category:

  • Banned? If the AI falls under any of the prohibited categories (e.g. it uses biometric surveillance of patients without consent), it cannot proceed ([3]).
  • High-Risk? Assess the AI system’s intended purpose under Article 6. For an Annex I product-related system, verify the Article 6(1) conditions, including the applicable third-party conformity-assessment requirement; for an Annex III system, assess whether the Article 6(3) significant-risk exception applies. Classify as High Risk only where the statutory criteria are met ([38]) ([6]).
  • Limited-Risk? If not high-risk but triggers transparency obligations (e.g. generative content tools, certain biometric functions), mark as Limited Risk.
  • Minimal: Otherwise, the system is minimal-risk.
  1. Apply Controls Accordingly:
  • Prohibited: Redesign the approach or cancel the project.
  • High-risk: Allocate responsibilities by legal role; implement the Article 9–15 requirements; prepare Article 11 and Annex IV technical documentation; and complete the Article 43 conformity-assessment procedure that applies to the system.
  • Article 50 system or output: Implement the specific notice, labelling, or disclosure duty that applies. Do not use a generic disclosure in place of the Article 50 assessment.
  • GPAI model: Where the organisation provides a GPAI model, comply with the applicable Chapter V obligations; document downstream-provider and deployer responsibilities for any integrated system.
  • Other AI: Record the scope assessment and apply relevant non-AI-Act obligations and proportionate internal controls.
  1. Internal Approvals & Training: Regardless of category, any AI deployment should go through a compliance review board (involving Legal, Regulatory, IT, Data Science). Employees working with AI must be trained on the Act’s basics ([31]) ([18]).

  2. Documentation and Audit: Maintain records of the above decisions, risk analyses, tests, and training. Update this assessment whenever the AI’s intended use or algorithm is significantly changed (which under the Act may trigger a new conformity review) ([18]).

EU AI Act Compliance Flowchart by Burges Salmon

Figure 1: EU AI Act Compliance Flowchart. Click to view full size.

Source: Burges Salmon LLP - "Navigating the EU AI Act". Used for educational purposes. We are not the authors of this flowchart.

The Council of the EU lauded the Act as “ground-breaking” in harmonizing AI rules on a risk-based principle

04

Standard Operating Procedures (SOP) Starter Kit

Pharmaceutical companies should translate the flowchart into actionable SOPs. The following outline describes key SOP modules; each should reference internal documents (e.g. quality manuals) and be customized for company structure.

  1. AI Inventory SOP:
  • Objective: Systematically identify all AI systems (existing and planned) in the company’s scope.
  • Steps: Maintain a register of AI systems, noting purpose, development status, data used, and deployer (R&D group, manufacturing, etc.). Review this register quarterly.
  • Responsibility: Data Governance or Digital Strategy office, in coordination with IT and department heads.
  1. Risk Classification SOP:
  • Objective: Assign each AI system to an EU AI Act risk category.
  • Steps: For each AI in the register, answer criteria per Table 1. Document the classification rationale. For borderline cases, consult legal/regulatory affairs.
  • Records: Classification forms should be stored in the QMS. If classified as high-risk, automatically generate a project folder for compliance documentation.
  1. Quality & Data Governance SOP (Art.10):
  • Objective: Ensure training/validation data quality and traceability.
  • Actions: Implement data management plans: unique identifiers for datasets, lineage tracking, provenance logs. Data used to train AI must be checked for accuracy and bias.
  • Controls: Incorporate Part 11/GMP Annex 11 controls for electronic records, including access controls and audit trails ([47]).
  • Outputs: Data Quality Reports; data stewardship assignments; formal validation of data pipelines.
  1. Risk Management SOP (Art.9):
  • Objective: Institute continuous risk analysis for AIs.
  • Procedures: Use ICH Q9 framework adapted for AI. At introduction of any high-risk AI, perform a preliminary hazard analysis. Update risk log whenever model outputs cause any deviation or if underlying data changes.
  • Documentation: Risk assessment forms with likelihood and impact scores; classes of risk (e.g. patient safety, privacy); mitigation plans.
  • Review: Monthly or every release, whichever sooner.
  1. Technical Documentation SOP (Art.11 & Annex IV):
  • Objective: Compile and maintain a technical file for each high-risk AI.
  • Contents: Implementation of items in Table 2: system description, architecture, algorithms, intended use, risk assessments, validation and test results, cybersecurity measures, user instructions (with human oversight requirements), and incident logs.
  • Maintenance: Document must be regularly updated, e.g. for each software release. All versions must be archived as per QMS.
  1. Change Control SOP:
  • Objective: Control modifications to AI systems.
  • Process: Any change to model architecture, training data, or intended use triggers a change request. The request must be reviewed for its impact on risk classification. Significant changes for high-risk AI require re-assessment under the Act.
  • Verification: Test results for new version, updated risk analysis, sign-off by compliance officer.
  1. Incident Reporting SOP:
  • Objective: Handle AI malfunctions and near-misses.
  • Actions: Define internal escalation criteria for AI incidents and near-misses, and maintain logs for external audits. Under Article 73, a provider of a high-risk AI system placed on the Union market must report a qualifying serious incident to the relevant market-surveillance authority; the reporting deadlines, legal role, system type, and applicable sectoral reporting regime determine the external obligation. For medical devices and IVDs, Article 73 limits AI Act notification to the specified Article 3(49)(c) incidents. Broader internal reporting may be adopted as company policy.
  • Template: Incident report form with timeline, impact assessment, root cause.
  1. Training and AI Literacy SOP:
  • Objective: Ensure personnel understand AI compliance requirements.
  • Content: Mandatory training modules on basics of AI Act, data ethics, and company AI policies. Special sessions for AI developers on documentation and validation standards.
  • Records: Certification of attendance; refresher courses at least annually.
  1. Vendor and Outsourcing SOP:
  • Objective: Manage third-party AI procurement.
  • Procurement clause: Contracts for AI (software/services) must include clauses ensuring the vendor’s compliance with EU AI Act.
  • Due Diligence: Before adopting external AI tools, verify providers’ compliance (e.g. that their AI models have conformity declarations).
  1. Monitoring and Audit SOP:
  • Objective: Periodically audit AI compliance and governance.
  • Procedure: Internal audits at least annually, covering all SOPs above, current classifications, and documentation completeness. External audits may follow after introduction of complex AI.
  • Audit Trail: Maintain a checklist of applicable regulatory requirements and implementation dates, and track readiness.

These SOPs form a starter kit. Firms should refine each to align with their size and structure. For instance, a small biotech might combine some steps (e.g. risk classification done by CTO) whereas a large pharma would have dedicated AI governance teams. The key is to document each step.

05

Pharma-Specific Considerations

While the general framework above applies to all industries, the pharmaceutical context raises special points:

  • Integration with Medical Device Regulation (MDR/IVDR): If an AI application also qualifies as a medical device by EU law (e.g. a diagnostic app or AI-driven test kit), it already follows MDR conformity assessment. In practice, this means the AI Act’s requirements must be folded into the MDR processes ([6]) ([38]). For example, CE-marking a device will now include certification that the embedded AI meets AI Act criteria. Thus, medical-device quality engineers should update templates (e.g. Device Master Records) to incorporate AI Act checklists (risk analysis, human oversight plan, etc.) ([6]) ([17]). Conversely, non-device AIs (e.g. an AI used for internal process monitoring) must get treated in parallel via the AI Act framework.

  • R&D Exclusions: Article 2(6) excludes AI systems and models specifically developed and put into service for the sole purpose of scientific research and development. Separately, Article 2(8) excludes research, testing, or development activity before an AI system or model is placed on the market or put into service; testing in real-world conditions is not covered by that exclusion. Research use, use in a clinical phase, or work on medicinal products alone does not decide the question. Companies should document the applicable statutory test and reassess scope when the intended purpose, market status, or deployment changes.

  • Clinical Trials: AI is increasingly used in trials (from patient matching to virtual cohorts). The Act revitalizes obligations to ensure trial AI is high-quality. For example, synthetic control arms (simulated patient groups generated by AI) are likely high-risk due to their impact on safety and efficacy decisions ([61]). Sponsors should treat these algorithms like significant new decision tools: document them fully, validate against real data, and include human researchers in the loop ([61]) ([53]). Informed consent forms may need to note AI involvement if patient data or decision-making is affected.

  • Manufacturing: AI is used in process optimisation and quality control, including anomaly detection on production lines. A system does not become high-risk merely because it is safety-critical or affects product quality; classify it under Article 6 and its intended purpose. Separately, robust validation, change control, and oversight may be required by applicable GMP and product-quality rules. Documenting sterilisation or stability-prediction models can support those obligations.

  • Marketing and Administration: AI in marketing (personalized advertising, content creation) generally is low risk under the Act, but may still be subject to future labeling rules (e.g. the Spanish law requiring “AI-generated content” labels ). Administrative chatbots and assistants (e.g. answering physician queries) should follow limited-risk rules: they must inform users of the AI nature and verify outputs. Companies can mitigate compliance work by differentiating tools: classify internal-only automation (no patient involvement) as minimal-risk and focus resources on patient-facing AI.

  • Cross-border and Exterritorial Effects: Non-EU affiliates of a global pharma must comply if their AI systems are used in EU-regulated activities. The Act binds providers and users worldwide if the deployment affects the EU market ([62]) ([63]). Accordingly, multinational companies should consider establishing an EU representative or local legal entity to liaise with EU authorities ([63]). Post-Brexit, UK-based AI still must obey EU rules for use in Europe; fortunately, UK regulators (MHRA) are aligning their approach (e.g. the “AI Airlock” sandbox ([64])).

06

Data and Market Analysis

Pharma’s shift to AI is underscored by strong market trends. The global AI-in-pharma market was estimated at $4.35 billion in 2025 and is projected to reach $6.16 billion in 2026, growing toward $35 billion by 2031 (41.5% CAGR). The broader AI in pharma and biotech market was valued at $6.63 billion in 2025 and is expected to reach $154 billion by 2034 (43.6% CAGR) ([20]) ([65]). Investment drivers include reduced discovery timelines, improved predictive accuracy, and regulatory impetus (e.g., agencies opening ”AI sandboxes” to de-risk innovation) ([66]). Indeed, strategic alliances abound: Bristol-Myers Squibb’s $674M tie-up with VantAI and Sanofi’s collaboration with OpenAI signal that AI is now core to R&D pipelines ([22]).

However, adoption is uneven. Surveys indicate substantial uncertainties: only 9% of pharma professionals feel well-versed in AI regulations ([35]). Smaller biotech firms often lead in agility, embedding compliance quickly, whereas larger legacy companies have more friction in evolving data governance ([67]). Manufacturers are concerned about the complexity of aligning AI Act requirements with GMP: for example, integrating “AI change control” into existing versioning processes still lacks standardized guidance ([67]) ([51]).

Stakeholders also note only partial harmonization with global regimes. While the EU Act is pioneering, analogous efforts continue globally (e.g. evolving US FDA AI/ML guidance, the UK's pro-innovation AI framework, China's AI regulations, and interoperability with GDPR). The first harmonized standard for AI – prEN 18286 (AI Quality Management System) – entered public enquiry on 30 October 2025, providing a product-focused framework for AI lifecycle governance under Article 17. Pharma companies therefore must prepare not only for EU law but for a patchwork of AI rules worldwide ([68]) ([69]).

The Act does not create a general explanation right for patients or healthcare professionals.

07

Case Examples and Expert Views

Expert Perspectives: Industry analysts warn that vague definitions in the Act could burden innovation ([70]) ([17]). For instance, Altimetrik’s Vikas Krishan notes the broad, evolving AI definition may force firms to rehearse compliance for many systems (e.g., predictive analytics in trials) that are likely “high risk” ([5]). He, along with other commentators, emphasizes the need for harmonized global standards (EU vs. US vs. UK) to avoid fragmentation ([68]). In contrast, others (e.g. IFPMA, EFPIA) view the Act as a “clear message” boosting trust in AI, urging firms to see compliance as an opportunity to strengthen data governance and patient safety ([18]) ([17]).

Industry Collaboration: Recognizing the compliance challenges, regulatory sandboxes are being established across Member States. The Act requires Member States to ensure that at least one AI regulatory sandbox is operational by August 2026. Pharma companies may consider using eligible supervised environments to test new AI tools while also meeting the applicable clinical, data-protection, and product-law requirements. Larger companies (Sanofi, Roche, etc.) are already teaming with smaller biotechs to jointly pilot AI innovations, combining agility with resources ([71]). For example, the US-based Novartis real-life AI implementations (drug target identification via deep learning) and Pfizer’s use of AI in trial design have demonstrated that, when managed correctly, AI can slash development phases without compromising compliance ([23]).

Case Scenarios:

  • Case 1: Digital Pathology AI. A European hospital biotech develops software that uses deep learning to analyze biopsy images. If the software is a safety component of, or itself, a product covered by Annex I legislation and is subject to third-party conformity assessment, it is high-risk under Article 6(1). The company should incorporate the applicable AI Act requirements into the relevant sectoral conformity assessment under Article 43(3), maintaining the technical documentation required by Article 11 and Annex IV, including model-training, validation, and post-market-monitoring information as applicable. A human pathologist always reviews AI outputs (Article 14), and the system must technically allow automatic event logging for its lifetime (Article 12). This conforms with EU rules on medical-device AI ([38]) ([6]).

  • Case 2: AI in Drug Discovery. A large pharma uses an in-house machine-learning tool to suggest novel molecules. The AI Act may be outside scope if the Article 2(6) sole-purpose scientific-R&D exclusion or the Article 2(8) pre-market activity exclusion applies; no-immediate-patient-use alone is not determinative ([9]). The firm nonetheless follows internal quality guidelines: it validates the model on known active compounds and documents the results under its QMS (anticipating future regulations like FDA’s guidance on AI/ML in drug development ([69])). It proactively trains chemists on data bias and holds an internal audit of the AI pipeline annually.

  • Case 3: Virtual Clinical Recruiter. A CRO deploys an AI tool that screens electronic health records to match patients to oncology trials. Ordinary trial recruitment is not, by itself, the Annex III healthcare-eligibility use, which concerns systems intended to be used by public authorities or on their behalf to determine eligibility for healthcare services. The CRO should assess the tool’s intended purpose under Article 6, Annex III, and other applicable law, including GDPR. If it is high-risk, the provider must apply the requirements and the appropriate Article 43 conformity-assessment procedure; if it is not, other legal and ethical obligations may still apply. Any participant information should be assessed under the applicable clinical-trial, data-protection, and AI Act rules rather than attributed to Article 50 as a blanket consent requirement.

These scenarios illustrate that while the AI Act does not alter core scientific and regulatory standards (safety, efficacy, data quality), it mandates processual compliance steps. Pharma entities must build internal processes to ensure these steps occur, not just assume “business as usual.”

08

Implications and Future Directions

Enforcement and Liability

EU enforcement will involve national AI authorities and the EU AI Office, which is now fully operational. Member States were required to designate national competent authorities by August 2025, and the EU AI Board, Scientific Panel, and Advisory Forum have been established. The AI Office coordinates cross-border issues and oversees GPAI model compliance, with enforcement powers applicable from 2 August 2026 ([72]). Early enforcement has focused on prohibited practices (in force since February 2025) and GPAI transparency obligations (since August 2025) ([13]).

On the liability front, the AI Liability Directive was withdrawn by the European Commission in February 2025 (formally scrapped in October 2025), citing a lack of legislative consensus ([73]). However, the revised Product Liability Directive (Directive 2024/2853) applies to products placed on the market or put into service after 9 December 2026 and includes software within its product definition. It establishes a liability regime for damage caused by defective products; the Directive’s disclosure and evidential-presumption provisions apply only under their specified conditions. For pharma, this means that if an AI-driven product (say, a diagnostic program) injures someone, the producer faces strict liability where non-compliance with the AI Act can be used as evidence of defectiveness. Documentation and audit trails (as mandated by the AI Act) become crucial evidence of due diligence.

Strategic and Competitive Effects

While compliance imposes costs, many experts view it as a competitive edge in the long run. The Act explicitly encourages the EU to become a global AI leader by building trust ([26]) ([30]). Early adopter companies can market their AI tools as “Act-compliant”, signaling safety to patients and partners. Moreover, robust AI governance often aligns with better general data practices. For example, systematic bias checks not only satisfy Article 10 but also improve drug trial demographics.

However, concerns remain. Some stakeholders worry that the burden of dual regulation (AI Act + healthcare laws) could slow innovation ([74]) ([17]). For instance, small biotech firms note that complex compliance processes require specialized legal/tech expertise ([67]) ([75]). In response, the Commission’s AI Pact initiative has encouraged voluntary early adoption of a compliance mindset. Regulation (EU) 2026/1744 has now set the binding high-risk application dates, reflecting the need for additional time and support tools, including harmonised standards and practical guidelines.

Global and Future Outlook

The EU AI Act sets a precedent. Other economies (US, UK, China) are developing their own AI regulations, and the Act’s approach informs these debates. Pharmaceutical multinationals will likely strive for “one-fits-all” compliance, leveraging EU standards as a model. Indeed, the Act’s extraterritorial scope means that any AI system placed on the EU market – whether made in Bangalore or Boston – must meet its requirements ([62]) ([63]).

Pharma companies should thus anticipate a future where AI regulatory alignment is expected. Initiatives like the International Coalition of Medicine Regulatory Authorities (ICMRA) or ISO/IEC standard-setting may incorporate AI Act principles. R&D teams should design studies with regulatory scrutiny in mind (e.g. adopting explainable AI methods from the outset).

Finally, innovation continues. Foundation models (e.g. open-domain LLMs) are catalyzing new therapeutic approaches (e.g. protein design, medico-scientific text mining) ([76]). With the GPAI Code of Practice now in place, the compliance landscape is rapidly materializing. Pharma firms using foundation models must monitor provider disclosures and assess the obligations applicable to their downstream systems and uses. Meanwhile, constant vigilance on emerging technology will be needed, as the Act foresees further adjustments and the AI Omnibus has updated the high-risk application timetable.

09

Conclusion

The EU AI Act introduces transformative rules that will reshape how pharmaceutical companies manage AI. Achieving compliance demands thorough understanding, organization-wide governance, and proactive planning. This report has detailed the Act’s core components, timeline, and the specific implications for pharma – from R&D and clinical trials to manufacturing and marketing. We have outlined practical steps: a compliance flowchart, tables linking obligations to Pharma use cases, and an SOP framework to operationalize the law.

Moving forward, pharma firms should act now and plan against the binding timetable: the Regulation generally applies from 2 August 2026; Article 50 transparency duties also apply from that date; Annex III high-risk rules apply from 2 December 2027; and Article 6(1) product-related high-risk AI obligations apply from 2 August 2028. Key priorities include assessing AI inventories, launching training programmes (AI literacy has applied since February 2025), monitoring applicable standards and Commission guidance, and consulting experts on adapting SOPs. Combining legal compliance with robust ethics will not only avoid hefty fines ([15]) but also build patient trust and sustain innovation. The revised Product Liability Directive applies to products placed on the market or put into service after 9 December 2026 and includes software within its product definition; companies should assess its relevance alongside the AI Act and applicable sectoral rules. By integrating AI Act requirements into existing quality and risk systems, the industry can turn regulatory challenge into a driver of excellence. In the era where AI holds immense promise for drug development and patient care, a well-prepared pharma organization will navigate the new regulations to deliver both safe products and innovative solutions in tandem.

References: Sources are cited throughout the text. Key references include EU Commission releases and legislative text ([28]) ([77]), industry analyses ([26]) ([4]), and expert commentaries ([5]) ([18]), among others. These provide the factual basis for all statements above.

Sources / 77
Adrien Laurent

Need Expert Guidance on This Topic?

Let's discuss how IntuitionLabs can help you navigate the challenges covered in this article.

I'm Adrien Laurent, Founder & CEO of IntuitionLabs. With 25+ years of experience in enterprise software development, I specialize in creating custom AI solutions for the pharmaceutical and life science industries.

Disclaimer

The information contained in this document is provided for educational and informational purposes only. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information contained herein. Any reliance you place on such information is strictly at your own risk. In no event will IntuitionLabs.ai or its representatives be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from the use of information presented in this document. This document may contain content generated with the assistance of artificial intelligence technologies. AI-generated content may contain errors, omissions, or inaccuracies. Readers are advised to independently verify any critical information before acting upon it. All product names, logos, brands, trademarks, and registered trademarks mentioned in this document are the property of their respective owners. All company, product, and service names used in this document are for identification purposes only. Use of these names, logos, trademarks, and brands does not imply endorsement by the respective trademark holders. IntuitionLabs.ai is an AI software development company specializing in helping life-science companies implement and leverage artificial intelligence solutions. Founded in 2023 by Adrien Laurent and based in San Jose, California. This document does not constitute professional or legal advice. For specific guidance related to your business needs, please consult with appropriate qualified professionals.

Related Articles

Need help with AI?

© 2026 IntuitionLabs. All rights reserved.