The FDA AI principles, published jointly with the European Medicines Agency on January 14, 2026, are ten short statements about how artificial intelligence should be built and used in drug development. They do not tell a research site to buy anything or ban anything. What they do is set the questions a sponsor, and eventually an inspector, will ask about any AI that touched a study: what it was for, who was accountable for its output, what data it saw, and where all that is written down. This post takes each principle down to what a site can actually do, and sets it beside the FDA's April 2026 move to real-time trials, which is what makes the questions urgent.
In short
- Ten principles, published January 14, 2026 by FDA and EMA, framed as the basis for future AI guidance rather than as rules.
- On April 28, 2026 FDA announced a real-time clinical trials pilot: comments to May 29, criteria in July, trials selected in August 2026.
- FDA's BIMO metrics for fiscal 2024 record 609 clinical investigator inspections, with 1572 and protocol compliance and inadequate records the top observations. Real-time data does not lower that bar; it moves it earlier.
- Every principle reduces, for a site, to four written things: purpose, human check, data trail, and change log.

The ten principles, in a site's terms
| Principle | What FDA and EMA mean | What it looks like at a site |
|---|---|---|
| Human-centric by design | Patients' interests and human oversight come first | A named person confirms every AI output that reaches a record |
| Risk-based approach | Oversight scales with the potential effect on patients | A tool that drafts a visit reminder needs less than one that reads an eligibility criterion |
| Adherence to standards | Established technical and regulatory standards apply | GCP, 21 CFR part 11 and the site's own SOPs still govern |
| Clear context of use | Each model has a stated purpose and limits | One sentence per tool: what it is for, what it must not be used for |
| Multidisciplinary expertise | Clinical, data and regulatory views in the room | The PI, the coordinator and whoever runs IT sign off together |
| Data governance and documentation | Data quality, management and records | What data the tool saw, where it came from, where it is kept |
| Model design and development practices | Rigorous building and validation | Ask the vendor for it; a site cannot produce this and should not pretend to |
| Risk-based performance assessment | Reliability checked in proportion to what it does | Spot-check output against source on a schedule, and write down the result |
| Life cycle management | Oversight for as long as the tool is in use | A change log: version, date, what changed, who approved |
| Clear, essential information | Capabilities and limits communicated plainly | Staff know what the tool does and does not do, and can say so to a monitor |
Seven of the ten rows end in something written. That is the pattern. The principles are not a technology standard a site has to meet; they are a documentation standard, and a site already knows how to keep one. It keeps a regulatory binder full of dated documents for exactly this reason.
Why the April announcement changes the pace

On April 28, 2026 FDA announced what it called major steps to implement real-time clinical trials. Sponsors in the pilot will send FDA data signals and endpoints during the trial rather than in a submission after it. Commissioner Marty Makary put the case in one line: "For 60 years, we've been conducting clinical trials in the same way, where key data signals can take years to reach the FDA." FDA said it had already worked this way with AstraZeneca on TRAVERSE, a phase 2 mantle cell lymphoma study run with MD Anderson and the University of Pennsylvania, and with Amgen on STREAM-SCLC, a phase 1b study in small cell lung cancer.
For a site, real-time means the gap between a source document being written and somebody reading it closes from weeks to hours. That is where AI enters, because no sponsor is going to staff that gap with people. It will be read by a model, and the ten principles are the conditions under which FDA is willing to let that happen. The site's job is to be the place where the model's reading can be checked against the page. FDA's fiscal 2024 BIMO metrics list inadequate or inaccurate case histories and study records among the most common inspection observations, across 609 clinical investigator inspections. A faster pipeline built on the same records finds the same errors sooner. It does not forgive them.
What to do at the site, in order

- List every AI tool that touches a study today. Sponsor systems, the EDC's built-in features, the dictation app on the PI's phone, the chatbot a coordinator uses to reword a consent explanation. If it produces text or a number that reaches a record, it is on the list.
- Write one sentence of context of use for each. "Drafts visit reminder texts from the schedule; never used for eligibility, dosing or adverse event assessment." That sentence is the fourth principle, done.
- Name the human who confirms each output. Not a role, a person. If the tool reads a lab report and suggests a value, who compares it to the report before it is entered, and where is that shown?
- Record what data each tool sees and where it goes. Does it leave the building? Is it stored by the vendor? For how long? If nobody knows, the answer is "stop using it until somebody does."
- Spot-check on a schedule and keep the score. Ten outputs a month against source, by the confirming person, with the count of disagreements written down. That is risk-based performance assessment at a scale a site can run.
- Keep a change log. Vendor updates the model, the log gets a line. The tool is retired, the log gets a line. The principle is called life cycle management; the artefact is a table with four columns.
The mistake most sites make at step 3
They name the tool's vendor as the accountable party. The vendor built the model; the site used its output to make an entry in a case history under the investigator's name. When a monitor asks who confirmed the value, "the software" is the answer that turns a query into a finding. ICH E6(R3), adopted in January 2025, does not care whether a process step was human or automated; it cares that the investigator can show the record is accurate and that someone was responsible for it being so.
The second mistake is the reverse: refusing every tool until the guidance is final. The principles are explicitly a frame for guidance not yet written, and the real-time pilot is running now. A site with a one-page register of its tools, each with a purpose, a confirming person and a change log, is ready for whatever the guidance says. A site with nothing written is not ready for the sponsor's next feasibility questionnaire, which already asks.
What we build for this
Two of the site systems on our clinical research page are AI tools in exactly the sense the principles describe, and they are built to the pattern above. The protocol assistant answers a coordinator's question from the protocol, its amendments and the site's SOPs, cites the section, and logs the question, the answer and who confirmed it. The source digitisation system reads a scanned or paper source document into structured fields and stops there: a named person confirms every field before anything is entered, and the original stays the record. Neither certifies compliance, neither makes a clinical decision, and both keep the log that step 6 asks for, because that log is the product.
Build the register in step 1 this week. It is a spreadsheet with six columns, and it is the document every one of the ten principles ends up pointing at.


