Bringing a new drug to market can take over a decade and billions of euros, yet most candidates still fail. According to the European Medicines Agency, only about 10% of drug candidates entering Phase I trials ultimately receive regulatory approval, a figure that underscores the enormous cost of inefficiency in clinical research. Artificial intelligence is changing this by accelerating discovery, optimizing trial design, and delivering real-time patient insights. Beyond data analysis, AI enhances trial efficiency and engagement: identifying eligible participants more precisely, monitoring safety and adherence in real time, and enabling adaptive trial designs that support both innovation and patient trust.
Pharma and biotech companies employing AI in clinical trials, whether in trial design, administration, patient recruitment, use of devices or IVDs, generation of synthetic data, or data analysis, should recognize that regulators are likely to scrutinize these applications, both in relation to the conduct of the trial and its participants, as well as the resulting outputs submitted for authorization.
In this guide:
- AI in Clinical Trials: The Impact of the EU AI Act
- Complementary Application of the EU AI Act and Sector-specific Laws
- When AI in Clinical Trials Falls Outside the EU AI Act?
- Does AI in Clinical Trials Count as High-Risk or Limited-Risk?
- Where the EU AI Act Defines AI in Clinical Trials as High-Risk AI Systems?
- Limited-Risk AI in Clinical Trials
- Practical Considerations for Using AI in Clinical Trials
- How to Automate AI in Clinical Trials Compliance and Governance?
AI in Clinical Trials: The Impact of the EU AI Act on Clinical Trials
TL;DRThe EU AI Act creates a binding legal framework for AI used in clinical trials across the EU. It applies extraterritorially, meaning non-EU sponsors whose AI systems touch EU patients, trials, or regulatory submissions must comply. Existing EMA guidance remains mandatory alongside the Act, so sponsors face dual obligations.
Adding to this already complex regulatory landscape applicable to clinical trials, the EU AI Act introduces a comprehensive framework that governs the development and use of artificial intelligence within the European Union, including AI in clinical trials and its application in life sciences and clinical research.
To make matters more complicated, the EU AI Act's reach is extraterritorial: it applies not only to companies established in the EU, but also to those based outside the Union whenever their AI systems are placed on the EU market or used within the EU. This means that pharmaceutical and biotech companies developing or deploying AI in clinical trials abroad may still fall under its scope if their technologies are intended for EU trials, patients, or regulatory submissions.
Importantly, the EU AI Act does not exempt sponsors from complying with relevant legislation or guidance provided by the EMA. The EU AI Act acknowledges that AI-enabled medical devices may pose risks not fully covered within its scope. For sponsors, this means that even as the EU AI Act introduces new rules, EMA guidance remains essential. From clinical trial design to data integrity and safety monitoring, sponsors must verify that any use of AI aligns with EMA requirements to secure approvals and maintain patient safety.
Complementary application of the EU AI Act and Sector-specific Laws
TL;DRThe EU AI Act functions as a horizontal regulation, but it defers to existing sector-specific legislation for medical devices, IVDs, and clinical trials. AI embedded in devices regulated under the MDR or IVDR follows those frameworks first. AI used within the Clinical Trials Regulation is governed by EMA and national authorities.
The EU AI Act is designed as a horizontal regulation, which means that it sets general rules for the safe and trustworthy use of AI across sectors. Lawmakers recognized that certain industries, like pharmaceuticals and medical devices, already operate under stringent, sector-specific regulations that frequently govern AI in clinical trials.
Medical Devices & IVDs:
If AI in clinical trials is part of a medical device or diagnostic tool, it falls primarily under the Medical Devices Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR).
These laws already prescribe strict requirements on risk management, clinical evidence, safety, and post-market surveillance, making it unnecessary for the AI Act to layer on additional rules.
Clinical Trials:
AI in clinical trials used within the framework of the Clinical Trials Regulation (CTR), such as for patient recruitment, trial monitoring, or data integrity, is subject to trial-specific safeguards enforced by the European Medicines Agency (EMA) and national authorities.
In short, the exemption exists because the risks posed by AI in clinical trials are already addressed through highly specialized legislation.
When AI in Clinical Trials Falls Outside the EU AI Act?
TL;DRAI systems developed and used solely for scientific research and development are exempt from the EU AI Act under Article 2(6) and Recital 25. The exemption protects freedom of science and early-stage experimentation. Any dual-purpose AI, built for both research and potential commercial deployment, remains within scope.
Under the EU AI Act, Article 2(6) and Recital 25 carve out an important exemption for AI systems developed and used solely for scientific research and development. This reflects the EU's intent to safeguard innovation and respect the freedom of science, so that the Act does not place unnecessary burdens on early-stage experimentation. EFPIA considers that this exemption applies to AI-based drug development tools used in the research and development of medicines because the sole use of these tools is in the R&D of medicine development.
The exemption comes with a crucial caveat, though: only AI systems created exclusively for scientific R&D fall outside the Act's scope. Any AI system with a dual purpose, such as one being developed for both research and potential commercial use, remains subject to the AI Act's requirements.
In practice, this means that while academic or exploratory research may benefit from regulatory breathing space, sponsors and companies must carefully assess whether their AI tools are truly exempt or whether their broader applications bring them back under the Act's obligations.
| **Context** | **Relevant Provision** | **Key Principle** |
|---|---|---|
| Pure scientific R&D use in clinical research | Recital 25 + Article 2(6) | Exempted from AI Act regulation |
| AI in medical devices/IVDs | MDCG-AIB guidance (non-binding) | Requires dual compliance under AI Act and MDR/IVDR (complementary application) |
Does AI in Clinical Trials Count as High-Risk or Limited-Risk?
TL;DRMost AI used in clinical trials falls into the high-risk category because it directly affects trial conduct, patient safety, or regulatory submissions. Systems supporting recruitment, treatment allocation, diagnostics, and data handling trigger strict compliance obligations. Administrative or back-office AI tools are more likely classified as limited risk.
Under the EU AI Act, AI systems are classified according to the level of risk they pose, ranging from minimal risk to limited and high risk, through to outright prohibited uses. We explained prohibited AI systems and explored in more detail the obligations for categories of high-risk AI, as well as what they mean in practice. Building on that foundation, we now apply this risk-based classification specifically to the context of clinical trials, examining how the Act's framework shapes the use of AI in trial design, conduct, and oversight.
The high-risk category represents the most stringent level of AI permitted under the EU AI Act, carrying with it extensive compliance obligations. In the context of clinical research, several types of AI applications are likely to fall into this bracket.
These include systems that support:
- Patient recruitment
- Treatment allocation
- Diagnostic processes
- Data handling and integrity
- Synthetic data generation
- Decision-making in trial conduct.
Likewise, AI embedded in medical devices is explicitly recognized as high risk under the Act.
These systems directly affect trial conduct and participant well-being, which triggers the stricter compliance obligations.
That said, not all AI in clinical trials will automatically be considered high risk. Some tools serve supportive or administrative functions. For instance, AI that helps with workflow scheduling, document drafting, or non-critical data visualization is more likely to be categorized as limited risk. These systems must meet transparency obligations (e.g., making it clear when outputs are AI-generated) but do not face the extensive conformity assessments and oversight required of high-risk AI.
In practice, sponsors should assume that AI touching trial design, patient outcomes, or regulatory submissions will be high risk, while peripheral or back-office applications may fall into the limited-risk tier.
Where the EU AI Act Defines AI in Clinical Trials as High-Risk AI Systems?
TL;DRThe Act classifies clinical-trial AI as high risk through three pathways: when AI is embedded in MDR or IVDR-regulated devices (Article 6(1)), when it performs healthcare functions listed in Annex III (Article 6(2)), or when it directly shapes trial outcomes such as recruitment, treatment allocation, or monitoring.
The EU AI Act explains in Article 6 and Annex III when an AI system is considered high-risk. In practice, this usually happens in three situations:
a. When AI is built into medical devices or diagnostics
If the AI forms part of a product already regulated under the MDR or IVDR, it automatically falls into the high-risk category (Article 6(1)).
b. When AI is used in healthcare functions listed in Annex III
These are activities that could directly affect health, safety, or fundamental rights, such as diagnostic systems or clinical decision support tools (Article 6(2), Annex III).
c. When AI directly shapes clinical trial outcomes
For example, systems used in patient recruitment, treatment allocation, diagnostics, monitoring, data management, or trial-related decision-making are very likely to be treated as high-risk (Article 6(2), Annex III).
Although Annex III does not list clinical trial activities directly, it does cover broader healthcare-related and impactful AI functions, such as healthcare diagnostics, decision support, and patient triage, that map closely to many trial-related uses. This makes it clear that most clinical trial applications will be considered high-risk.
Limited-Risk AI in Clinical Trials
TL;DRAI tools that serve administrative, communication, or non-critical analytical functions in clinical trials typically qualify as limited risk. Sponsors must meet transparency obligations, such as informing users they are interacting with AI, but are not subject to full conformity assessments required for high-risk systems.
Not every AI tool used in research will be classed as high-risk. Some fall into the limited-risk category, which comes with lighter obligations focused mainly on transparency:
a. Administrative support tools
AI that helps with scheduling, workflow management, or document handling but does not impact patient safety (Article 52(1)).
b. Non-critical data analysis
Systems that visualize trial data for efficiency or reporting purposes, without making decisions that affect trial outcomes (Article 52(1)).
c. Communication aids
Chatbots or AI tools that answer routine questions for trial staff or participants, provided they are clearly identified as AI (Article 52(1)).
In these cases, sponsors must inform users when interacting with AI or receiving AI-generated outputs, but they are not required to go through the strict conformity assessments that apply to high-risk systems.
Practical Considerations for Using AI in Clinical Trials
TL;DRSponsors and CROs should evaluate AI tools across ten dimensions: model design, data quality, validation, interpretability, adaptability, bias awareness, regulatory compliance, operational impact, user training, and data privacy. Mapping each dimension against specific EU AI Act obligations helps identify compliance gaps early.
AI has the potential to transform clinical trials, but only if it is applied responsibly. Sponsors and CROs need to balance innovation with safeguards that maintain accuracy, compliance, and patient trust. Here are some key points to keep in mind when evaluating AI tools in research:
- Model design : Understand how the system was built and trained.
- Data quality : Check that datasets are reliable, representative, and well-managed.
- Validation : Make sure the tool is properly tested and re-evaluated over time.
- Interpretability : Confirm that outputs are clear enough for clinicians and researchers to use confidently.
- Adaptability : Verify the system can handle new or unexpected trial data.
- Bias awareness : Look for risks of biased results that could affect patient outcomes.
- Compliance : Check alignment with existing regulatory standards, including GDPR compliance obligations.
- Practical impact : Consider effects on timelines, costs, and trial efficiency.
- People first : Provide staff with the right training and support to use AI effectively.
- Privacy : Protect patient data in line with GDPR and ethical standards.
At its best, AI does not replace human judgment; it amplifies it, helping researchers run safer, faster, and more reliable trials.
To better understand how these practical considerations connect with regulatory requirements, it helps to map them directly against the EU AI Act. This side-by-side view shows how common steps in evaluating AI for clinical trials align with the Act's obligations, giving sponsors a clearer picture of where compliance and best practice meet.
Here is the breakdown of these obligations and the relevant EU AI Act provisions:
| **Practical Step** | **Relevant EU AI Act Obligation** |
|---|---|
| Model design and training : Clarify how the AI was built, its algorithms, and training methods | Technical documentation & risk management |
| Data sources : Review the origin, scope, and representativeness of training and analysis datasets | Data governance & quality requirements |
| Quality controls : Procedures to detect and correct data errors, gaps, or inconsistencies | Accuracy, robustness & cybersecurity obligations |
| Pre-processing safeguards : Verify measures to protect data accuracy and integrity before AI processing | Record-keeping & transparency |
| System validation : Check how the AI is tested initially and reassessed regularly | Conformity assessment & post-market monitoring |
| Interpretability : Confirm that clinicians and staff can understand and explain outputs | Transparency & human oversight |
| Adaptability : Assess how the system handles new or unexpected data | Risk management obligations |
| Bias risks : Evaluate whether the model could introduce or amplify bias | Fairness & non-discrimination requirements |
| Compliance checks : Align AI use with MDR/IVDR, CTR, and sector-specific frameworks | Sectoral law alignment (complementary application) |
| Operational impact : Consider implications for timelines, efficiency, and costs | Not mandated by AI Act, but critical for feasibility |
| User enablement : Confirm training and support resources for staff | Human oversight obligations |
| Data protection (GDPR) : Safeguard patient rights, lawful processing, and secure health data | Complements AI Act via GDPR obligations |
How to automate AI in Clinical Trials compliance and Governance?
Organizations must establish comprehensive AI governance frameworks, supported by a dedicated AI governance platform, to safeguard patient trust, promote ethical use of technology, and stay compliant in an evolving regulatory landscape.
This is where Whisperly can make a real difference. By offering an end-to-end compliance solution, Whisperly helps sponsors manage every stage of the EU AI Act journey, whether it qualifies as a high-risk AI system or limited-risk, simplifying oversight, documentation, monitoring, and reporting. With Whisperly, life sciences organizations can innovate with confidence, knowing their AI use in clinical trials is both effective and compliant.
Further Reading on Whisperly

Reviewed by: Tamara Zavisic, AI Governance Specialist