September  2026 • PharmaTimes Magazine • 34-35

AI


Leap of fAIth

What does CIOMS XIV mean for operationalised AI use in pharmacovigilance?

Image

With AI now embedded in day-to-day pharmacovigilance, most drug safety operations have moved beyond considerations about whether a system can be validated for its intended use.

The bigger test comes further down the line, once inputs vary and models have been updated, at which point organisations still need to show the system remains safe and properly governed.

Here, ArisGlobal’s Jason Bryant reflects on the implications for pharma organisations now operationalising AI use in a PV context, drawing on a recent podcast discussion with Denny Lorenz, an active member of the CIOMS XIV working group.

The Council for International Organizations of Medical Sciences (CIOMS) Working Group XIV AI in Pharmacovigilance report is a landmark piece of work. The international guidance, published in December 2025, is a comprehensive global consensus-based report on using artificial intelligence in drug safety.

Its detailed framework provides a structured approach for integrating AI and machine learning into PV without compromising patient safety or human accountability. Its publication confirms that the age of AI-driven pharmacovigilance has properly arrived, though the guidance itself has been a long time in the making.

The CIOMS Working Group first convened in Geneva back in May 2022 – about six months before OpenAI launched ChatGPT to the public, picking up a million users in five days, then around 100 million within a couple of months. Before that, the guidance had been built around organisations training their own machine learning models on proprietary data.

The mainstream arrival of GenAI in the form of pre-trained, general-purpose models necessitated a return to the drawing board. The Working Group rewrote most of the guidance. This settled on seven principles for the safe, accountable use of AI in pharmacovigilance, rather than serving as specific advice wedded to a particular technology.

Its principles-based approach is one of the main reasons the published advice feels so current, with widespread applicability.

But what of the plumbing – the operational detail that turns those principles into something a PV department can run day to day? This came up as a possible omission during a formal public consultation pre-publication, resulting in more detail on how the framework interoperates with the quality and regulatory frameworks organisations already work within.

The published guidance is also more specific on life cycle and on governance, and clearer about what counts as practical evidence, so that these factors aren’t left to guesswork.

Risk sets the scale for everything else

Because it ties everything else together, the principle of taking a risk-based approach to AI use tops the guidance list.

This is about determining how much validation evidence, monitoring and documentation is needed, and how this requirement should scale – based on what’s actually at stake if something goes wrong in each scenario (rather than indiscriminately applying excessive measures, which could undermine the efficiency benefits AI is meant to deliver).

Human oversight is where this risk-based logic breaks down most often, something the guidance hasn’t changed. Too many organisations still treat a reviewer in the workflow as the control – the one guard rail that covers everything else.

But the guidance treats oversight as one control among several, not a stand-in for the rest. A reviewer can check every single case without the PV system master file being documented, data privacy being addressed, or performance metrics existing to show whether that reviewer is actually catching what matters.

Human oversight only counts as evidence for a risk-based approach if the reviewer’s own judgement is being measured too.

Ongoing performance monitoring lies within a further principle – validity and robustness – separate from watching the reviewer. Since an AI system’s inputs vary case by case, and a model that appears unchanged may have a new prompt or a discrete version update behind it, validating it once at launch isn’t enough.

Accountability for the safety judgement remains with a qualified PV professional throughout.

How the governance grid works

To aid accessibility and application, the report sets out a governance grid to test whether a use case is ready for production. The grid works less like a pass-or-fail checklist and more like a diagnostic.

Is there a documented risk assessment, for instance, and what about a described oversight process? Is there a governance structure that’s revisited, rather than signed off once? A use case doesn’t need every box ticked to move forward.

A pilot still running on a limited case set is fine, provided the gaps are known and being worked on.

The CIOMS Working Group’s toughest disagreement during its deliberations, by most accounts, wasn’t about any of the seven principles but rather timing – around the point at which a PV subject matter expert (SME) should join a project.

Some members wanted SME involvement kept to a formal sign-off at production; others pushed for input from the conceptual phase, alongside vendors from day one.

The guidance builds early involvement into the governance grid, on the basis that an SME who understands a model’s limitations before it is built will produce a better-informed risk assessment.

Full field-by-field review won’t be the default forever. A year of reliable data on a given field should be enough to justify checking only the low-confidence extractions and waving the rest through. Regulators haven’t yet said whether they’ll accept that in practice, though.

One early signal already exists in what regulators are doing elsewhere. The EMA and FDA published their own ten joint principles for AI across the medicines life cycle in January 2026, and the overlap with the work of CIOMS XIV is no coincidence – it all reflects the same shift.

The question of whether AI can be trusted isn’t a one-off test, or something with a static answer. It will resurface every year, with each new model version – which is what governance now needs to be built around.


Jason Bryant is General Manager, AI platforms at ArisGlobal