🎯 Signal of the Week

The EU AI Act high-risk clock hits zero this month

Welcome to Issue 02,

The most consequential date on the pharma calendar this month is not a data readout or a deal. It is a compliance deadline. From August 2026, the core obligations of the EU AI Act for high-risk AI systems move from principle to practice, and healthcare AI sits squarely in the high-risk tier because it can shape diagnosis, treatment, prognosis, and monitoring.

The staged application of the EU AI Act. August 2026 is when high-risk obligations bite.
Source: Educo Life Sciences, EU AI Act and Medical Devices (Feb 2026).

The Act does not replace the Medical Device Regulation or IVDR. It layers on top of them, adding AI-specific duties: robust data governance and bias control, expanded technical documentation of model architecture and performance, meaningful human oversight, a risk-management system aligned to ISO 14971 and IEC 62304, and ongoing post-market performance monitoring for drift and degradation. Systems already regulated as medical devices under MDR get a transition runway to August 2027, but the direction of travel is fixed. Read alongside the ten common AI principles the FDA and EMA published in January, the message is transatlantic: human-centric, risk-based, lifecycle-governed AI is now the baseline expectation, not a nice-to-have.

MY TAKE FOR MEDICAL AFFAIRS

Most of what MA builds, an insight-classification agent, a medical-information drafter, a literature monitor, is not a regulated medical device and will not trigger the Act directly. But the scaffolding the Act codifies, documented data governance, human-in-the-loop oversight, transparency about limitations, and post-deployment monitoring, is exactly the scaffolding a defensible agentic MA deployment needs anyway.

So treat August 2026 less as someone else's compliance headache and more as a free specification for how to govern your own agents. The teams that copy the structure now will move faster later, because their governance will already speak the regulators' language.

Why this lands on Medical Affairs specifically

Two reasons. First, Medical Affairs has spent the last eighteen months moving from experiments to production. The tools that classify field insights, triage medical-information inquiries, and draft first-pass response letters are no longer pilots you can switch off without anyone noticing. They are load-bearing. Load-bearing systems are exactly the ones where a supply-side shock is expensive.

🧠 Framework of the Week

Map the function before you buy the tool

The EU AI Act high-risk clock hits zero this month

Every vendor wants to sell you an agent. Almost none will tell you where it fits. The most useful thing I read this week is a map, published in the American Journal of Healthcare Strategy by Emily Lewis of UCB, that lays Medical Affairs out as five connected domains and shows where autonomous agents actually earn their place.

Start with the distinction the paper insists on, because it is where most buying decisions go wrong. Generative AI responds to a prompt and returns an output, and its usefulness depends entirely on the person judging that output. Agentic AI adds three capabilities. It can plan, decomposing a goal into sequenced sub-tasks and adjusting as intermediate results arrive. It can use tools, querying literature databases, trial registries, and internal systems through APIs rather than relying only on what is in its training data or the prompt. And it can iterate, critiquing its own draft, retrieving more sources, and refining across cycles before a human ever sees it. The strategic question therefore shifts from how to draft documents faster to which workflows can be handed to an autonomous system under oversight. The first question is incremental. The second is architectural.

Five domains of agentic application across Medical Affairs, plus the three workflow patterns agents repeat. Source: Emily Lewis, American Journal of Healthcare Strategy (Jun 2026).

Why Medical Affairs is an unusually strong fit. The paper gives four structural reasons. The unit of work is knowledge, a document, a response, a synthesis, an insight, which is exactly what modern models produce. The reference material is highly structured, from approved labels and PubMed to trial registries, congress abstracts, and curated medical-information libraries, which gives agents authoritative sources to ground in. The regulatory line between scientific exchange and promotion, usually experienced as a constraint, actually simplifies agent design, because the permissible scope, the audiences, and the escalation paths to medical directors, pharmacovigilance, and regulatory affairs are already codified. And there is a chronic mismatch between demand and capacity, with budgets roughly flat while scope expands into real-world evidence, patient engagement, and ever more therapeutic complexity, so an agent that performs the initial reasoning under human review addresses a real structural problem rather than a cosmetic one.

What the five domains actually contain. Domain I, medical strategy and planning, is where continuous competitive-intelligence and therapeutic-landscape agents turn quarterly, stale analyses into living documents, and where KOL mapping shifts from ranked lists to anticipatory questions about who is changing practice or emerging as influential. Domain II, KOL and HCP engagement, compresses field-insight latency by classifying interaction notes against a taxonomy and surfacing weekly rather than quarterly syntheses, and it drafts pre-call briefs so MSLs spend the hour before a meeting building relationships instead of triaging context. Domain III, publications and scientific communications, puts agents to work as operational copilots for publication planning, manuscript drafting under named authors, congress monitoring, and plain-language summaries, while respecting that journals will not list AI as an author. Domain IV, medical information and content review, sits closest to the regulated edge and is where most deployments concentrate today, collapsing tier-one and tier-two inquiry handling by drafting cited responses that a specialist reviews before transmission. Domain V, real-world evidence and outcomes research, is the highest-stakes column, where agents accelerate literature screening, data extraction, and cohort definition but require human checkpoints at every consequential methodological decision.

Three patterns, always with a human at the end. Across all five domains, agentic work repeats the three patterns shown in the figure: document generation runs draft, self-check, revise, route; insight synthesis runs collect, cluster, theme, route; continuous monitoring runs monitor, detect, investigate, alert. In every case the agent completes a multi-step task and surfaces the result for human review rather than acting unilaterally. That shared shape is what makes the map a description of how agentic work actually gets done, not just a catalogue of use cases.

Govern in proportion to risk. A single policy applied to every deployment will be simultaneously too slow for low-risk work and too lax for high-risk work. A customer-facing medical-information agent in Domain IV warrants validated-system treatment, formal change control, and locked prompts; an internal literature summarizer for MSL pre-reads needs only a documented intended use, a sample-output review, and a periodic audit. The practical refinement is a governance body with real decision rights and service-level agreements for review, plus standing templates so a new agent that resembles an approved one does not restart validation from scratch.

The four risks worth naming. Each maps to specific domains. Hallucination is worst where outputs reach external audiences, in Domains III and IV. Bias is most acute in evidence synthesis across underrepresented populations, in Domain V. Privacy exposure is greatest in registry and EHR-adjacent work, again Domain V. And over-reliance, the automation complacency that conditions reviewers to approve rather than scrutinize, is universal across all five and the hardest to engineer around. Retrieval grounding, fact-checking, and human review manage these risks; they do not remove them.

HOW TO ACTUALLY START

The paper's most quotable fact is that a typical Medical Affairs organization systematically analyzes less than one percent of its field interaction notes, which is the clearest argument for starting in Domain II or IV. Then keep the sequence disciplined: articulate the strategic question first, because AI is a capability, not a strategy; invest in the unglamorous infrastructure, a curated knowledge base, a governance body that decides in days, and baseline agent literacy, before the visible applications; measure outcomes rather than activity; and start narrow and go deep instead of launching a dozen shallow pilots.

Pick one workflow in one domain, reach genuine operational excellence, and only then expand. Map first, buy second.

The point of the map is not to slow anything down. It is to concentrate your governance effort where a supply-side shock would actually hurt, and to let everything else keep moving. Governance that treats every use case as high-risk is just a slower way of getting nothing done.

📚 5 THINGS WORTH READING

The five that repay the click

  • 01
    FDA and EMA align on ten guiding principles for AI in drug development

    Applied Clinical Trials, Andy Studna · January 2026

    In January 2026 the FDA and EMA jointly published ten guiding principles for good AI practice across the medicines lifecycle, the first concrete output of a renewed EU-US cooperation on novel medical technologies. The principles are deliberately high level and span the whole journey, from early research and clinical trials through manufacturing and post-market safety surveillance, and they are addressed to sponsors, marketing authorization applicants, and authorization holders. Their spine is a human-centric, risk-based approach: proportional validation, a clearly defined context of use, robust data governance, multidisciplinary expertise, transparent model development, lifecycle performance monitoring, and plain communication of a system's limitations to users and patients. The agencies were explicit that these are not prescriptive requirements but a foundation that will evolve into more detailed guidance in both jurisdictions. European Health Commissioner Oliver Varhelyi framed the move as a way to preserve transatlantic leadership in innovation while holding patient safety at the highest level. For Medical Affairs the signal is unambiguous: the expectations now shaping regulatory-grade AI will cascade into evidence generation, real-world data analytics, and any agent that touches a submission. The detail worth remembering is that the FDA reports a steady rise in submissions containing AI components, so these principles describe the environment your evidence will be judged in, not a distant hypothetical.

  • 02

    Q1 2026: when pharma AI partnerships crossed a threshold

    HLTH, Gary Monk · June 2026

    In January 2026 the FDA and EMA jointly published ten guiding principles for good AI practice across the medicines lifecycle, the first concrete output of a renewed EU-US cooperation on novel medical technologies. The principles are deliberately high level and span the whole journey, from early research and clinical trials through manufacturing and post-market safety surveillance, and they are addressed to sponsors, marketing authorization applicants, and authorization holders. Their spine is a human-centric, risk-based approach: proportional validation, a clearly defined context of use, robust data governance, multidisciplinary expertise, transparent model development, lifecycle performance monitoring, and plain communication of a system's limitations to users and patients. The agencies were explicit that these are not prescriptive requirements but a foundation that will evolve into more detailed guidance in both jurisdictions. European Health Commissioner Oliver Varhelyi framed the move as a way to preserve transatlantic leadership in innovation while holding patient safety at the highest level. For Medical Affairs the signal is unambiguous: the expectations now shaping regulatory-grade AI will cascade into evidence generation, real-world data analytics, and any agent that touches a submission. The detail worth remembering is that the FDA reports a steady rise in submissions containing AI components, so these principles describe the environment your evidence will be judged in, not a distant hypothetical.

  • 03

    Pharma bets big on AI platforms with a flurry of new-year deals

    GEN (Genetic Engineering and Biotechnology News), Fay Lin · January 2026

    GEN zooms in on a specific flavor of the deal wave: pharma licensing AI platforms rather than buying single molecules. Three AI-native startups anchor the story, with Chai Discovery partnering Eli Lilly on de novo biologics, Noetik licensing cancer foundation models to GSK, and Boltz building exclusive models with Pfizer. The Noetik-GSK arrangement is notable for its structure, a five-year license with a 50-million-dollar upfront and a subscription-style framework that its CEO calls one of the first true foundation-model licensing deals in biotech. Chai's own Chai-2 antibody model reported double-digit design success rates in a bioRxiv preprint, described as a more than hundredfold improvement over prior computational methods, which is why Lilly reportedly walked into Chai's offices within days of seeing the results. Isomorphic Labs, the Google DeepMind spinout, added Johnson and Johnson as its third pharma partner after Lilly and Novartis, a shift for a group that had kept its models in-house. The framing that lands is that companies are now paying for models as infrastructure, not for one-off answers. For Medical Affairs the lesson is cultural rather than technical: the same appetite to license capability instead of rebuilding it internally is exactly the choice MA teams face with agentic tools.

  • 04

    Agentic AI in Medical Affairs: how autonomous AI is reshaping MSL workflows

    TikaMobile · March 2026

    TikaMobile's field guide is the most operational piece of the week, walking through how agentic AI reshapes an MSL's actual working day rather than listing capabilities. The core distinction it draws is that generative AI reacts to a prompt while agentic AI runs in the background, scanning overnight literature, assembling pre-call briefs, classifying insights in real time, and routing them to the right internal team without being asked. It grounds the urgency in McKinsey's finding that 75 to 85 percent of pharma and medtech workflows contain tasks agents could enhance or automate, potentially freeing 25 to 40 percent of capacity, while cautioning with Gartner's estimate that over 40 percent of agentic initiatives will be cancelled by 2027 without clear business value. The sharpest argument is that the CRM, not the model, is the real unlock, because agents starve without field data and CRM adoption failure rates sit between 50 and 63 percent across enterprise software. Its most useful reframe is on compliance: rather than bolting a check onto a chatbot's output, well-designed agents embed label, safety, and promotional checks into every reasoning step, and it cites 69 percent of Medical Affairs leaders naming privacy and compliance as their top concern. A composite early-adopter example shows pre-call prep dropping from two hours to thirty minutes, CRM completion rising from 62 to 91 percent, and insight-to-action time falling from fourteen days to three. The path it recommends is deliberately modest: start with low-risk, high-value pilots like insight classification and medical-information triage before touching higher-stakes work.

  • 05

    How agentic AI is reshaping the launch playbook for pharma

    Pharmaceutical Executive, Natalie Harb and Vineet Purwar (IQVIA) · April 2026

    Written by two IQVIA launch leaders, this feature lays out a four-pillar framework for running product launches with agentic AI: planning, alignment, execution, and intelligence. The stakes it cites are sobering, with IQVIA research showing fewer than 10 percent of launches achieve international excellence across two or more countries and more than half of new launches generating under 5 million dollars in their first year in the top eight markets. In the planning pillar, agents benchmark hundreds of analog launches and run HTA-trained predictors to forecast uptake, peak share, and which value arguments will move payers, compressing weeks of analyst work into days. The alignment pillar targets the coordination tax of a launch, where commercial, medical affairs, medical communications, and market insights report through different hierarchies and must respect compliance firewalls. Execution puts role-specific agents in the hands of reps, key account managers, and MSLs, and early deployments report 27 percent time savings in call preparation and follow-up, 85 percent satisfaction with generated insights, and more than a 15 percent lift in omnichannel-equivalent calls. The intelligence pillar acts as connective tissue, compressing market-analysis cycles from weeks to minutes so teams catch competitor moves as they happen. The authors are candid that technology alone does not deliver results, that not every problem needs an agent, and that human-in-the-loop review is essential in early deployments.

🔧 TOOL OF THE WEEK

NotebookLM: a grounded reader for your evidence base

NotebookLM, recently rebranded by Google as Gemini Notebook, is a research assistant with one rule that makes it useful for regulated work: it answers only from the sources you give it, and it cites every claim back to the passage it came from. That constraint is the opposite of an open-web chatbot, and it is exactly what a scientific function should want.

Pick the tier by your data sensitivity, not by the feature list. Source: Google Workspace, NotebookLM product and Enterprise security docs (2026).

How to use it for Medical Affairs and MSL work

Build a therapeutic-area notebook: upload published papers, congress abstracts, the approved label, and a clinical study report as sources, then ask questions and get grounded, cited answers instead of open-web guesses. Each source can hold up to 500,000 words or a 200MB file, so a whole evidence base fits. Generate an audio overview to turn a stack of papers into a podcast-style briefing for the commute to a congress, or a video overview for a fast visual summary before an advisory board. It is a strong fit for the document-generation and insight-synthesis patterns in this week's framework, with a human still reviewing every output.

Where to get it

The consumer version is free at notebooklm.google.com. NotebookLM Enterprise is available through Google Cloud and Google Workspace; see the Workspace product page.

COMPLIANCE NOTE

Treat the tier as a data-sensitivity decision. The consumer tier is fine for public literature but is not the place for PHI, unpublished trial data, or anything confidential. NotebookLM Enterprise keeps content inside your project, does not use it to train the models, encrypts at rest, and supports customer-managed keys (CMEK) and data-residency control, which is the version to route through your governance and MLR process. Grounding in your own sources reduces hallucination but does not remove it, so keep a human reviewer on anything that leaves the building.

That is Issue 02. If a colleague forwarded this to you, you can get it yourself every Monday at newsletter.ichealth-ai.com/subscribe.
One email a week. No sponsorship. See you next Monday.

iCHealth Pathway is a weekly research note by Dr. Issam Chebouti on AI transformation for Pharma, Medical Affairs, and Healthcare leaders.

Issue 02, Monday 10. August 2026. 8 minutes of signal.