In THIS ISSUE
Signal of the Week, Veeva just put agents inside Vault.
Framework of the Week, The Native Agent Test: four checks before you switch one on.
5 Things Worth Reading, deals, regulators, and the MSL shift.
Tool of the Week, Elicit.

Reading time: ~8 min read

🎯 Signal of the Week

Veeva put the agent inside the system of record, and Regeneron and Biogen made it the standard in a single week.

Welcome to Issue 05,

For two years the AI question in Medical Affairs was which tool to bolt onto the workflow: which literature assistant, which insight classifier, which drafting copilot. This week the question changed shape. The agent stopped being something you open in a browser tab and became a feature of the system you already live in.

On 25 August, Veeva announced that Regeneron committed to Veeva Vault CRM globally, and the same day Biogen did too, two weeks after Eli Lilly made the same move. The wires filed these as commercial wins, which they are. The sentence that does the real work sits underneath. Veeva has been rolling agentic AI (Vault AI) directly into the Vault platform, with an AI Tab that routes a question to the right agent inside your Vault, operating only on the data a given user is already permitted to see, and application-specific agents for Medical arriving in the August release wave. The agent now lives in the system of record, not next to it.

Figure 1. The same capability in two architectures. Sources: Veeva roadmap; Regeneron and Biogen commitments (StockTitan, 25 Aug 2026).

Here is why this lands on Medical Affairs and not just commercial. Vault CRM's Agentic Call Report turns every field interaction into structured Commercial Evidence, capturing the insight that used to disappear into dropdowns and compliance hesitation. For an MSL or a medical information team, that means the agent is no longer a research aid you visit; it is embedded exactly where insights are captured, routed, and audited, running on your governed records rather than the open web. The models underneath are Anthropic and Amazon on Amazon Bedrock, and customers can extend the delivered agents or build their own.

Now the opinionated part. When the agent is a separate tool, you can pilot it, sandbox it, and swap it out on a bad quarter. When the agent is a native feature of the platform your entire commercial and medical organization just standardized on globally, the evaluation is happening by default, at the platform level, whether or not Medical Affairs was in the room. This is a better safety story than any bolt-on: the native agent inherits your permissions, grounds in your own records, and writes to your existing audit trail. It is a worse independence story, because the agent's value is now fused to a platform you would have to leave to escape it, and switching costs there are measured in years, not weeks. Both things are true at once. The task this quarter is not whether to allow the native agent, because it arrived with the platform. The task is to govern it before it becomes load-bearing, and to deliberately keep at least one high-stakes workflow, medical information or off-label triage, where you can still see and change how the agent reasons.

🧠 Framework of the Week

The Native Agent Test: four checks before you switch one on.

Every framework we have run in this newsletter so far quietly assumed the same thing: that the agent was something you chose, bought, and bolted on. That assumption expired this week. When agentic AI ships inside the platform of record, your CRM, your medical suite, your safety system, you do not get to run a clean procurement process for it. It is already there, already touching your data, already shaped by the vendor's defaults. The governance question moves from "should we buy this" to "what exactly did we just switch on."

The Veeva move is the clearest example, but read it as a pattern rather than a vendor story. The agent that reads your call notes, drafts your medical response, and routes your insight now sits inside the same system that stores all three, inherits the same role-based access, and writes to the same audit trail. That is genuinely safer than pasting into an open chatbot, and it is also stickier, because the thing that makes the agent useful is now welded to the platform you would have to abandon to get rid of it. Safety and lock-in arrive in the same box, and most teams will only notice the first one.

So this week's framework is a test you run on any agent that lives inside a system of record, before you let it carry real weight. Four checks, in order, each one a question you put to the vendor and to your own team in the same meeting. Score each red, amber, or green. Read it as a pre-flight checklist, not a maturity model: you are deciding whether this specific embedded agent is safe to rely on today, and what it would cost you to walk away tomorrow.

Figure 2. Five links from source rights to audit record. Score each one before you trust an output. (Source Dr. Issam Chebouti)

  1. Scope. What data and which actions is the agent allowed to touch inside the platform, and who set that boundary? A native agent ships with the vendor's default scope. Rewrite it to yours: name the objects it can read, the fields it can write, and the actions (route, draft, summarize) it may take with no human in between.

  2. Permissions. Does the agent inherit your existing role-based access, so it can never surface to a user anything that user could not already see on their own? Permission inheritance is the single most important safety property of an in-platform agent, and the first thing to verify rather than assume.

  3. Provenance. Can every output be traced back to the governed source record inside the platform, with the prompt, the retrieved passage, and the model version logged and retained? Grounding in your own system is the real upside of native agents. Make sure the audit trail is a retained control, not a demo screen.

  4. Portability. If you leave the platform in three years, what leaves with you, the workflows, the captured insights, the evidence the agent generated, or none of it? A native agent quietly raises your switching cost every quarter it runs. Price that in now, while you still have leverage, not at renewal when you have none.

The first three checks decide whether the agent is safe to trust. The fourth decides whether you can ever change your mind. Most teams will score green on permissions and provenance and never once think about portability until the contract is up for renewal and the number has quietly become a trap. Name the portability cost this quarter, while it is still just a number.

Figure 3. The magnitudes behind the shift. Sources: Veeva; StockTitan; ZS; BioPharm International.

When the agent is a tool, you own the exit. When the agent is a feature of the platform, the vendor does.

📚 5 things worth to read

Five paywall-free reads, each summarized so you get the value without the click

  • 01
    Veeva AI Agents to be released across all Veeva applications (Veeva)

    The primary-source roadmap behind this week's signal, and it repays a slow read. Veeva is adding agentic AI to the Vault platform and shipping deep, application-specific agents across every major area on a staggered calendar: Vault CRM and PromoMats went first in December 2025, Safety and Quality in April 2026, and Clinical Operations, Regulatory, and Medical in the August wave, with Clinical Data to follow in December. The governance detail that matters is that each agent understands its application's context, carries application-specific prompts and safeguards, and has direct, secure access to that application's data, documents, and workflows, while customers can extend the delivered agents or build their own. The models underneath are Anthropic and Amazon on Amazon Bedrock, custom agents run on Veeva-hosted or customer models, and pricing is usage-based. The line to keep: the agent is being sold as a native feature of the system of record, not a separate product you evaluate on its own.

  • 02

    Veeva Vault CRM selected globally by Regeneron (StockTitan)

    The clearest evidence that the platform shift is real and not a slide. On 25 August Veeva said Regeneron committed to Vault CRM globally, and Biogen did the same that day, two weeks after Eli Lilly, three blue-chip commitments inside a single month. The mechanism worth noting is the Agentic Call Report, which turns every field interaction into structured Commercial Evidence and captures the insight that used to vanish into dropdown menus and compliance hesitation. Regeneron's own chief digital and technology officer framed it as giving commercial teams a more connected platform and faster access to the information they need, which is the polite way of saying the agentic layer and the system of record are now one purchase. For Medical Affairs the point is that the platform your MSLs already live in is being standardized globally with agents inside it, so the evaluation is happening whether or not your function is in the room.

  • 03

    What Annex 22 means for AI governance in GMP-regulated environments (Scilife)

    A useful preview of how regulators reason about agents, even though it targets manufacturing rather than Medical Affairs. Draft Annex 22 is the EU's proposed GMP rule for data-trained AI in critical applications, and its current position is deliberately restrictive: generative AI, large language models, and any model that learns during use or can return different outputs for the same input should not be used in critical GMP applications, with a final text targeted for late 2026. The principle that travels well beyond the factory floor is that accountability never moves to the model or the supplier, the regulated user stays responsible, and every consequential output must be reconstructable. The piece also flags an April 2026 FDA warning letter that gave inappropriate use of AI its own subsection after a manufacturer let AI agents write specifications, procedures, and production records without adequate Quality Unit review. Read it as a signal of where scrutiny is heading: when agents write records, someone has to be able to defend every one of them.

  • 04

    AI in medical affairs: five investments to win in an AI-driven ecosystem(ZS)

    The strategic companion to this week's framework, written for Medical Affairs leaders rather than vendors. ZS argues the function has to move beyond siloed pilots, because only about 40 percent of them ever scale, and that the real constraint is not the model but the data, with up to 80 percent of available data going unanalyzed as dark data no agent can use. Its five investments run from building a unified knowledge foundation and a genuine medical intelligence function to reinventing engagement as a continuous sense, decide, act, learn loop with MSL copilots embedded directly in the CRM. The through-line, which lands neatly against the Veeva signal, is that AI layered onto legacy workflows produces pockets of excellence and little else, and that the payoff comes only from redesigning how decisions get made. A good piece to hand to an executive who still thinks the AI question is a tooling question.

  • 05

    The agentic pivot: from AI experimentation to operational transformation in biopharma (BioPharm International)

    The wider industry frame, and a bracing reality check on the gap between spend and results. It notes that the AI pharmaceutical market is projected near 6.16 billion dollars this year, yet only 22 percent of life sciences leaders report scaling AI beyond the pilot stage, and argues the bottleneck is organizational readiness and data architecture rather than algorithmic sophistication. Its most useful contribution is a clean operating rule: separate the work you can fully automate, such as business development screening and supply-chain forecasting, from the regulated work that demands governed augmentation, such as clinical study reports, pharmacovigilance, and medical writing, where retrieval-grounded drafting still sits under a human who stays accountable. That distinction maps directly onto the native-agent question, because it tells you which embedded agents can run with a light touch and which need a hand on them at all times. The line to keep: automate the low-risk work, govern the regulated work, and never confuse the two.

🔧 TOOL OF THE WEEK ELICT

What it is: an AI research assistant that runs the mechanical parts of a literature review. It searches an indexed corpus of academic papers (more than 138 million as of mid 2026), then extracts exactly what you specify into a structured table, one row per paper, with a link back to the source behind every cell. It was built by the public benefit corporation Elicit, and unlike a chat box, its output is a spreadsheet you can audit column by column rather than a paragraph you have to take on trust.

How to use it for Medical Affairs and MSLs: define a scientific question and let Elicit assemble a cited evidence table before a KOL meeting or an advisory board; use its screening workflow to triage a therapeutic-area literature scan, title and abstract first, then full text, instead of reading 300 abstracts by hand; extract endpoints, sample sizes, and methods across a set of trials into one comparable grid for an evidence brief. Treat the table as a first pass with citations attached, then verify each row against the primary paper.

Where to access it: 
elicit.com on the web. There is a free tier for core search and extraction, and paid Pro and Enterprise tiers that add systematic-review workflows able to screen thousands of papers at a time.

COMPLIANCE NOTE

Elicit is a research and preparation aid, not a source of MLR-approved or promotional copy. Keep it strictly separate from promotional review, never paste unpublished trial data, patient-identifiable information, or pipeline detail into it, and verify every extracted number and citation against the source before it informs anything external. The vendor-reported accuracy figures are exactly that, vendor-reported, so read them that way. Grounding in retrieved papers reduces hallucination but does not remove it, and a confident table is still a draft.

That is Issue 05. If a colleague forwarded this to you, you can get it yourself every Monday at newsletter.ichealth-ai.com/subscribe.
One email a week. No sponsorship. See you next Monday.

iCHealth Pathway is a weekly research note by Dr. Issam Chebouti on AI transformation for Pharma, Medical Affairs, and Healthcare leaders.

Issue 05, Monday, August 31th, 2026.
Parts of this issue were produced with AI assistance and checked before publication.