The AI conversation in pharmacovigilance has moved beyond the technology’s proof and systems’ validation. The now-published CIOMS XIV report provides detailed, principles-based guidance on use case readiness and how to demonstrate that a system can continue to be trusted when being used at scale. ArisGlobal’s Jason Bryant reflects on a recent podcast discussion with Denny Lorenz of the CIOMS XIV working group, to highlight some important provisions within the framework.
One of the fundamental objectives of the CIOMS Working Group XIV report, published at the end of last year[1], is around evidencing that an AI system used in pharmacovigilance (PV) can continue to be trusted once live, updated and running at scale. The global framework, developed with regulators, academia and industry, advocates a set of principles designed to endure irrespective of the specific technology or the particular use case.
Where early drafts of the guidance potentially neglected some practical considerations, the finalised report details how the proposed framework should interoperate with existing regulatory and quality systems organisations, and what counts as evidence in practice, leaving nothing to chance. Its seven principles – from a risk-based approach, human oversight, validity and robustness, to transparency, data privacy, fairness and equity, and governance and accountability – together describe how organisations are expected to build, monitor and account for AI in drug safety.
Pinpointing, then mitigating, appropriate risk
Above all, the CIOMS XIV guidance advocates a risk-based approach to AI governance, against which all other factors are calibrated. In essence this means that a low-stakes productivity tool shouldn’t be subject to the same scrutiny as a system feeding into causality assessment – the guidance is explicit that they don’t have to.
Yet that calibration can derail in the context of human oversight, where teams place too much store on it, neglecting other considerations. Too many organisations treat having a reviewer in the workflow as provision enough, when the guidance is clear that oversight should only be one of several controls. A single reviewer checking every case could still leave plenty unaddressed elsewhere (an undocumented PV system master file, unaddressed data privacy, and no real confirmation that the reviewer is delivering something meaningful). For the existence of a human reviewer to serve as evidence for a risk-based approach, the reviewer’s own judgement should be measured too. Go too heavy on human reviewers, meanwhile, and the benefits of using AI could be compromised.
Validity and robustness, a separate principle in its own right in the guidance, meanwhile, call for monitoring that continues well into production, on the basis that prompts and models could vary over time – so provisions need to be adaptable. This logic applies whether a tool was built specifically for PV or has been adopted informally. A reviewer using a general-purpose AI licence for case notes, for instance, should still come under scrutiny.
In all scenarios, accountability for the safety judgement lies with a qualified professional.
AI governance in pharmacovigilance: From principle to practice
The CIOMS XIV guidance includes a useful governance grid, or diagnostic tool, to help determine whether a new PV AI use case is ready to go into production. Does a documented risk assessment exist, for instance? Is there a described oversight process, and what provision is there for revisiting governance? None of this needs a perfect score to proceed – as long as any gaps are known and these are being addressed.
One issue the CIOMS XIV Working Group had to overcome when developing the guidance was how early a subject matter expert should be involved in a new AI project. The published guidance proposes early involvement, the logic being that understanding a model’s limitations before it has been built should give rise to a better risk assessment than one performed after the fact.
Such an assessment should pay dividends over time – once a system has built up a real track record. A single case might comprise 200-300 distinct fields, and at the moment most organisations will still check each one – even if their AI extraction capability has been well proven. This makes no sense, and good data will provide the driver for change. Once a specific field has built up a sufficient track record of evidenced reliable performance (say, a year’s worth), the guidance’s logic supports narrowing review down to only the low-confidence extractions. At what point regulators will accept that shift in practice is yet to be seen, but this emphasises the importance of continued dialogue between the industry and regulators through bodies like CIOMS.
In the meantime, regulators are reaching similar conclusions about where AI governance needs to go from a drug safety perspective. The EMA and FDA’s own joint principles for AI across the medicines lifecycle, published in January 2026[2], call for oversight and validation that scale with risk, plus scheduled monitoring throughout a system’s lifecycle rather than a single check at the start. All of this leaves little doubt about where the industry needs to be focusing their attention now.
This article draws from a recent AI Exchange podcast discussion with Denny Lorenz, who has spent more than two decades working in Safety and Pharmacovigilance and is an active member of the CIOMS XIV working group.
About the author
Jason Bryant is general manager, AI platforms at ArisGlobal. He leads the build-out and scaling of the company’s AI-native platform, NavaX, across the life sciences industry, with a focus on bringing agentic AI into pharmacovigilance in a way that keeps governance and human judgement central to the process.
References
[1]Council for International Organizations of Medical Sciences (CIOMS), ‘Artificial Intelligence in Pharmacovigilance’, CIOMS Working Group XIV report, Geneva, 4 December 2025. Available at: https://cioms.ch/working_groups/working-group-xiv-artificial-intelligence-in-pharmacovigilance/
[2]European Medicines Agency and U.S. Food and Drug Administration, ‘EMA and FDA set common principles for AI in medicine development’, 14 January 2026. Available at: https://www.ema.europa.eu/en/news/ema-fda-set-common-principles-ai-medicine-development-0

