
How AI Can Assist with Post-Marketing Changes
Key Takeaways
- FDA enforcement signals governance breakdowns spanning unenforced deterministic rules and inappropriate reliance on AI agents, underscoring that accountability cannot be delegated to systems lacking validated controls.
- CIOMS WG XIV, EMA workplans, and EMA–FDA Good AI Practice principles align on lifecycle management, scheduled re-evaluation, and drift monitoring, treating explainability as necessary but insufficient.
Post-marketing governance must be evidenced across the full lifecycle, design, validation, and live monitoring, not documented once and assumed to hold.
For the past 2 years, the conversation about artificial intelligence (AI) in pharmacovigilance (PV) has largely revolved around the question, can the system explain itself? Can it show its reasoning, cite its sources, produce an audit trail? These are genuinely important qualities. But 2026 has been the year the industry, and its regulators, started asking a harder question: not what the system can explain after the fact, but what it prevents from happening in the first place, and how that is governed over time.
That shift matters most in post-marketing changes: the ongoing stream of signal detection, safety labeling updates, and case-processing decisions that don’t stop once a product reaches market. This is where AI’s promise is most real, and where the cost of getting governance wrong is most direct.
Explainability Was Never the Finish Line
An aircraft’s black box and its altitude alarm serve different purposes. The recorder lets investigators reconstruct what happened after an incident, valuable, but too late for anyone on board at the time. The altitude alarm intervenes before a threshold is crossed, while there is still a chance to change the outcome. Most of the AI governance conversation in PV has been built around the recorder. Comparatively, little attention has gone to what it would take to build-in the ability to intervene before a missed or delayed signal becomes a patient safety issue.
Two enforcement actions illustrate exactly what that gap looks like in practice. In March 2026, an FDA warning letter to Novo Nordisk1 documented case-handling failures, including a report excluded from mandatory reporting on assumed causality grounds, and a patient death case invalidated for a missing identifier that the FDA’s own inspectors later found present in the company’s source documents. Notably, the system involved wasn’t AI-based at all. A conventional, rule-based process failed because nothing was actually enforcing the rule, and no one was monitoring closely enough to catch it.
In April 2026, the FDA issued its first warning letter to explicitly name AI overreliance as an inspection finding,2 this time against a drug manufacturer that had used AI agents to generate compliance documents without human review. When investigators found the company hadn’t conducted required process validation, the response was that the AI agent had never flagged it as necessary.
Read together, these 2 letters trace the full arc of governance failure in post-marketing change management: rules that exist on paper but aren’t enforced, and accountability that gets quietly delegated to a system incapable of holding it.
Regulators Are Converging Faster than the Market Has Noticed
This isn’t a scattered set of national concerns. Three threads illustrate just how aligned regulators now are, despite different mandates and methods.
First, none of them believe a single point-in-time approval is sufficient anymore. The Council for International Organizations of Medical Sciences (CIOMS) Working Group XIV report on AI3 in pharmacovigilance, the product of 3 years of work across regulators, industry, and academia, sets out 7 core principles for AI in PV, explicit that explainability is one principle among 7, not the standard on its own, and that human oversight must be risk-calibrated and architecturally enforced.
The European Medicines Agency’s (EMA’s) Network Data Steering Group has translated that same direction into dated commitments4: new AI-enabled signal detection capabilities for authorized products rolled out in the second quarter of 2026, with AI-based suspected unexpected serious adverse reactions (SUSAR) screening for investigational products following in 2027, alongside a life cycle management principle in the EMA-FDA Guiding Principles of Good AI Practice,5 published in January 2026, requiring scheduled monitoring and periodic re-evaluation to catch data drift throughout an AI system’s life, not just at launch.
The United Kingdom’s National Commission into the Regulation of AI in Healthcare reached the identical conclusion from a public-facing consultation of more than 700 respondents:6 between 61% and 68% of every stakeholder group, patients, clinicians, providers, and industry alike, said current post-market surveillance requirements are not sufficient for how AI systems actually behave once deployed.
Second, all 3 sources agree that oversight has to scale with risk and context rather than apply uniformly. The EMA-FDA principles pair a risk-based approach with a requirement for a clearly defined context of use, on the basis that risk cannot be assessed in the abstract, only against a bounded purpose. The UK Commission’s evidence shows broad support for that same logic, while also surfacing where consensus breaks down: 77% of patients and the public described the current regulatory framework as too loose, while 65% of industry respondents described it as too restrictive. Everyone wants proportionality. Nobody agrees yet on which direction the dial needs to move, which is exactly the kind of ambiguity PV teams should expect to navigate rather than wait out.
Third, transparency and human oversight are treated as the mechanism for accountability, not a nice-to-have. The EMA-FDA principles call for plain-language disclosure of an AI system’s context of use, performance, and limitations, addressed to the intended audience rather than buried in technical documentation. The UK Commission’s evidence found the same expectation from the public side: 77% to 88% of respondents across every group said the current liability framework has significant gaps, tied directly to how difficult it is to trace accountability through an AI system whose reasoning isn’t transparent. Regulators are drawing a straight line from explainability to who is answerable when something goes wrong.
The FDA and EMA have also formalized a standing cluster on AI in pharmacovigilance,7 meeting every 2 to 3 months with Japan’s Pharmaceuticals and Medical Devices Agency and Health Canada as observers, working through use cases spanning the full PV workflow from adverse event extraction through signal evaluation. Regulators are deploying AI in the same workflows they will be inspecting industry for. As an MHRA spokesperson put it earlier this year, the agency’s consistent position is that AI should augment expert judgement, not replace it.
The Risk Explainability Quietly Makes it Worse
There’s a subtler problem worth naming directly. When AI produces fluent, well-explained output, human reviewers tend to scrutinize it less, not more. A confident, well-formatted recommendation creates an illusion of verification: the reviewer feels they’ve checked something they’ve actually just approved. In a PV environment where a case manager may be processing hundreds of cases a day with AI assistance, that’s a foreseeable consequence of deploying explainable AI without controls on reviewer behavior, not a hypothetical one. Complete governance has to monitor what happens to human judgment when the system is working well: approval velocity, override rates, whether a required review step actually happened, not just whether it was scheduled.
What This Means for How Post-Marketing Changes Actually Get Made
Put these threads together and a practical picture emerges. Effective AI governance for post-marketing change management treats deterministic and probabilistic processing as a deliberate choice, not a default. Decisions that need the same correct answer every time, whether a report meets a reporting threshold regardless of assumed causality, for instance, are handled by fixed logic that cannot be configured around. Judgment calls that genuinely require interpretation are handled by AI reasoning, scoped tightly to the question at hand, with confidence thresholds that trigger escalation rather than confident silence when uncertainty is high. Governance itself has to be evidenced across the full lifecycle, design, validation, and live monitoring, not documented once and assumed to hold.
This is consistent with conversations the author has had with customers and echoes a pattern seen repeatedly the author’s experience at a large biopharma safety organization. The appetite has shifted noticeably: less patience for AI framed purely as incremental case-processing efficiency, more urgency around faster, more defensible signal detection and inspection-readiness that’s built in rather than retrofitted. Several enterprise sponsors have independently raised interest in standardizing signal detection methodology across the industry, precisely so regulatory acceptance doesn’t have to be re-litigated company by company. That’s where the practitioners doing this work every day are already heading.
The Measure that Actually Matters
None of this means explainability is unimportant. It’s necessary. But it answers only 1 part of the question that post-marketing change management now demands. The more useful measure of readiness isn’t whether a system can explain itself when asked. It’s whether anyone would have noticed if it were no longer able to.
References
- Warning Letter to Novo Nordisk Inc., MARCS-CMS 717576 / FDA Ref. 26-HFD-45-03-01. March 5, 2026. FDA. fda.gov.
- FDA, Warning Letter to Purolea Cosmetics Lab, FEI 3011669383 / Ref. 320-26-58. April 2, 2026. fda.gov
- CIOMS Working Group XIV, Artificial Intelligence in Pharmacovigilance. Council for International Organizations of Medical Sciences. December 4, 2025. cioms.ch
- EMA/HMA. Network Data Steering Group Workplan 2026–2028. Adopted February 2026. ema.europa.eu
- Joint FDA/EMA document: Guiding Principles of Good AI Practice in Drug Development. FDA. Accessed August 19, 2026
https://www.fda.gov/about-fda/artificial-intelligence-drug-development/guiding-principles-good-ai-practice-drug-development - National Commission into the Regulation of AI in Healthcare: research, engagement and call for evidence findings. 2026. Medicines and Healthcare products Regulatory Agency (MHRA). Accessed August 19, 2026.
https://www.gov.uk/government/groups/national-commission-into-the-regulation-of-ai-in-healthcare - Guiding principles for the EMA–US FDA cluster teleconferences on artificial intelligence in pharmacovigilance. EMA/422032/2023. European Medicines Agency and US FDA. Published March 2, 2026. Accessed August 19, 2026.
https://www.ema.europa.eu/en/documents/other/guiding-principles-ema-us-fda-cluster-teleconferences-artificial-intelligence-pharmacovigilance_en.pdf
About the Author
Beena Wood is chief product officer at Qinecsa Solutions, where she leads product strategy across the company’s pharmacovigilance technology portfolio.




