AI Regulation Tracker / Medicines and life sciences
EMA Sets Risk-Based AI Expectations Across the Medicine Lifecycle
A reflection paper, not a regulation, but the EMA's working expectation for AI in drug development and use. Adopted by the CHMP on September 9, 2024, it applies a risk-based approach from early development to decommissioning and puts responsibility for AI tools squarely on sponsors and marketing authorisation holders.
This is a 2024 instrument, and I am flagging that clearly. The EMA finalized this reflection paper in September 2024, so it is not new, but it is the settled European reference for AI in medicines and it deserves a place in the tracker because a lot of US life-sciences teams working the EU pipeline still treat it as optional reading. It is not optional. It is the document the EMA will lean on when it asks how you built and validated the AI in your submission, and it is the seed for the binding guidance that follows.
Start with what a reflection paper is, because the label controls how much weight it carries. It is the EMA setting out its current thinking, not issuing a rule you can be fined for breaching. But the direction is unambiguous, and the paper is explicit that the bar can be high. In its own words, "A risk-based approach for development, deployment, and performance monitoring of AI/ML tools allows developers to pro-actively define the risks to be managed throughout the system lifecycle." That is the organising idea of the whole document.
How does the EMA's risk-based approach work?
The EMA sorts AI systems by how much damage a failure could do. The paper uses two labels. A system that affects patient safety is treated as "high patient risk." A system whose output has a substantial effect on regulatory decision-making is treated as "high regulatory impact." The higher the risk or impact, the more validation, documentation, transparency, and human oversight the EMA expects, and the more it advises early regulatory interaction before you commit to a design. A low-stakes tool used for an internal administrative task sits at one end. A model that helps assign treatment, set dosing, or drive a regulatory conclusion sits at the other, and it will draw close scrutiny, especially if it is a non-transparent model.
Crucially, the paper says the degree of risk is not just a property of the technology. It depends "on the context of use and the degree of influence the AI technology exerts," and it can change across the system's life. That is a sensible framing. The same model can be low risk in one use and high risk in another, so the assessment has to be tied to how and where the tool is actually used, not to a one-time label slapped on at procurement.
Who is responsible for the AI, the vendor or the company?
The EMA closes the door on outsourcing accountability. The paper states a key principle plainly: "it is the responsibility of the clinical trial sponsor, marketing authorisation applicant/holder or manufacturer to ensure that all algorithms, models, datasets, and data processing pipelines used are fit for purpose and are in line with legal, ethical, technical, scientific, and regulatory standards." Read that carefully. If you buy an AI tool from a vendor and use it in your medicines work, you own the obligation to prove it is fit for purpose. The paper even warns that these expectations "may in some respects be stricter than what is considered standard practice in the field of data science." You cannot point at the supplier when the regulator asks how the model was validated.
What should US life-sciences teams do about it?
If any part of your development, manufacturing, or pharmacovigilance touches the EU market, treat this reflection paper as your working checklist. Classify each AI use by patient risk and regulatory impact, and scale your documentation and oversight to match. Keep validation evidence, data provenance, and performance-monitoring records for anything in a high-stakes setting, and be ready to show them. Where a tool could affect the benefit-risk balance of a product, take the EMA's advice and open regulatory dialogue early rather than after the fact. And do not assume a vendor's assurances discharge your duty. The accountable party under this framework is you. None of this is compelled by the paper alone, but it maps directly onto how the EU AI Act and formal EMA guidance are heading, so building to it now is the cheap path.
Questions professionals are asking
Is the EMA reflection paper legally binding?
No. A reflection paper states the EMA's current thinking, not a binding regulation or enforceable guideline. This one was adopted by the CHMP on September 9, 2024 and by the CVMP on September 11, 2024. It signals where formal guidance is heading and interacts with binding law such as the EU AI Act, GxP standards, and existing EMA guidelines, so it carries real practical weight even though it is not a rule.
What is the EMA's risk-based approach?
The EMA scales its expectations to how much an AI system could affect patient safety or a regulatory decision. It uses the terms "high patient risk" for systems affecting patient safety and "high regulatory impact" for systems that substantially affect regulatory decision-making. Higher-risk uses draw more validation, documentation, transparency, human oversight, and early regulatory interaction, and risk is judged by context of use, not only the technology.
Who is responsible for an AI tool bought from a vendor?
The sponsor, marketing authorisation applicant or holder, or manufacturer is. The paper states it is their responsibility to ensure all algorithms, models, datasets, and data pipelines are fit for purpose and in line with legal, ethical, technical, scientific, and regulatory standards. Buying the tool from a supplier does not transfer that duty, and the EMA notes its expectations may be stricter than standard data-science practice.
Does it apply to US companies?
It applies to activities in the EU medicines pipeline, so a US sponsor, applicant, holder, or manufacturer working toward or holding an EU authorisation should treat it as the operative standard for AI in that work. It does not govern purely domestic US submissions, but US teams with EU exposure should classify AI uses by risk and keep validation and monitoring evidence accordingly.
RELATED BRIEFINGS
- Browse the full AI Regulation Tracker
- EMA reflection paper on AI in the medicinal product lifecycle (primary source, PDF)
- FDA AI device lifecycle and predetermined change control plan guidance
- EU MDCG 2025-6 on AI medical devices and the AI Act interplay
- UK MHRA AI Airlock sandbox for medical devices
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal or regulatory advice. Confirm how any EMA expectation applies to your product and submission with qualified life-sciences counsel in the relevant jurisdiction.