AI in Medical Affairs and Communications: Veeva MedComms, PromoMats, Komodo, Aetion
Medical affairs is the function that sits between the science and the field, and it is the most under-tooled and under-served corner of pharma AI training, which is strange, because it is also where some of the most interesting and most delicate AI use is happening in 2026. A medical science liaison comes back from twelve key-opinion-leader meetings with pages of unstructured notes that someone needs to turn into a structured insight report by Friday. A scientific publications manager is coordinating a manuscript, a plain-language summary, and a congress poster under a strict good-publication-practice regime. A medical-information specialist is converting published evidence into a standard response document for an unsolicited inquiry. Each of these is a real AI opportunity, and each carries a confidentiality and compliance constraint that is sharper than almost anywhere else, because the inputs are often the unpublished thoughts of named external experts and the outputs flow through a medical-legal-regulatory review that exists precisely to keep the function on the right side of promotional rules. This lesson maps the medical-affairs AI landscape, naming the tools and the workflows, and it draws the two lines that matter most here: the confidentiality line around what can go into a model, and the compliance line around what the output is allowed to be.
Why Medical Affairs Is a Different Kind of AI Problem
Medical affairs differs from regulatory writing, clinical operations, and pharmacovigilance in a way that shapes everything about how AI applies to it. The function's core currency is scientific exchange, the non-promotional, peer-to-peer communication of medical and scientific information, and that currency is governed by a bright line between medical affairs and commercial promotion that regulators watch closely. The work is less about producing a single defined dossier artifact and more about synthesizing scattered scientific input, KOL conversations, published evidence, congress developments, into communications that inform without promoting and that survive a medical-legal-regulatory review.
This shapes the AI problem in two ways. First, the inputs are unusually sensitive: an MSL's notes from a meeting with a named investigator who sits on a competitor's advisory board contain personal and competitively sensitive information that cannot be casually fed to a public model. Second, the outputs are unusually constrained: a piece of medical communication has to stay non-promotional, on-label or appropriately flagged off-label, and properly attributed to published evidence, or it crosses into territory that triggers regulatory and legal consequences. So while the underlying AI modalities are familiar, extraction and clustering for insights, generation for documents, retrieval for evidence, the guardrails around them are tighter and more specific to the function than almost anywhere else, which is exactly why medical affairs needs its own clear treatment rather than a borrowed one.
The Field Insight Layer: Capturing and Synthesizing What the MSL Hears
The most distinctive medical-affairs AI use is the synthesis of field insights, turning the scattered, unstructured output of many KOL interactions into structured intelligence the organization can act on. An MSL team generates an enormous amount of valuable signal, what experts think of emerging data, what questions are arising in clinical practice, where the scientific conversation is moving, but that signal arrives as messy notes scattered across many interactions, and turning it into a coherent insight report is a clustering and synthesis task that AI does well. Tools in the medical-affairs space, including capabilities within the Veeva ecosystem for medical communications and field activity, and scientific-exchange capture tools like Abridge's Life Sciences Edition, are aimed at this problem.
The opportunity is real: a model can take a month of de-identified MSL notes, cluster the recurring themes, and draft a structured insights report far faster than a human synthesizing by hand, which lets the medical-affairs team turn field signal into strategy at a cadence that manual synthesis cannot match. But this is exactly where the confidentiality line bites hardest, and it is non-negotiable. KOL meeting notes contain personally identifiable information about named external experts, sometimes including experts who work with competitors or who are investigators on pivotal trials, and that information cannot be exposed to a public, non-governed model. The de-identification of the input and the use of a governed, contractually appropriate tool are the absolute preconditions for this workflow, not optional refinements. The MSL who pastes raw KOL notes into a consumer chatbot has committed a confidentiality breach regardless of how good the resulting report is. The discipline that makes this workflow safe is to de-identify first, use a governed tool always, and treat the protection of the named expert's information as the first obligation, before any efficiency the synthesis provides.
The MLR and Publications Layer: Where Compliance Is the Product
The second major medical-affairs AI domain is the production and review of medical communications, congress decks, publications, scientific response documents, and the workflow that governs them, the medical-legal-regulatory review. Veeva PromoMats and MedComms are the dominant platforms where this content lives and where the MLR review cycle runs, and AI is increasingly applied both to drafting the content and to supporting the review. A congress slide deck that needs updating after a competitor's presentation, a manuscript being shepherded through a good-publication-practice process, a standard response document being assembled from published evidence, are all candidates for AI-assisted drafting.
What makes this domain distinctive is that compliance is not a constraint on the product; compliance is the product. A medical communication that is scientifically accurate but promotional in tone, or that cites evidence inaccurately, or that fails to flag off-label content, has failed at its actual job, because the entire point of the function is non-promotional, evidence-accurate scientific exchange. AI can accelerate the drafting and can help check consistency and references, which is genuine value, but the MLR reviewers, the medical, legal, and regulatory experts who clear the content, are doing a compliance judgment that does not transfer to the tool. A model can draft a congress deck and flag candidate references, but whether the deck stays non-promotional, whether an off-label mention is appropriately handled, whether a claim is properly supported by the cited evidence, are judgments the MLR reviewers own. The good-publication-practice standards that govern authorship and transparency in publications are likewise human-governance frameworks that AI assists but does not satisfy on its own. As with every other function, the AI does the assembly and the consistency-checking; the human owns the compliance judgment that is the whole reason the review exists.
The Evidence and RWE Layer: Komodo, TriNetX, Aetion, and the Real-World Story
A third domain connects medical affairs to the growing world of real-world evidence, the use of data from routine clinical practice to understand how a product performs outside the controlled setting of a trial. Platforms like Komodo Health, TriNetX, and Aetion generate real-world cohorts and analyses from large healthcare datasets, supporting the patient-journey understanding, the study feasibility work, and the evidence generation that medical affairs and health-economics teams increasingly rely on. AI is woven through these platforms in the cohort generation, the pattern detection, and the analysis, and the outputs feed medical communications, payer dossiers, and the scientific narrative around a product's real-world value.
The discipline here is a blend of the data-quality caution and the judgment line that run through the whole program. Real-world data is messy, and a cohort generated by AI from claims or electronic health record data reflects the biases and gaps of the underlying data, so the analyst has to understand what the cohort represents and what it does not before drawing conclusions, a concern the responsible-AI chapter develops as a fairness and validity issue. And the interpretation of a real-world finding, what it means for the product's value story, whether it supports a claim, how it should be characterized to a payer or in a publication, is a scientific and compliance judgment that the human owns. The RWE platforms surface patterns in data no human could process by hand, which is a genuine and growing capability, and the human supplies the validity assessment and the interpretive judgment that turns a pattern into a defensible scientific or economic claim. The pattern is the same as everywhere; the data-quality stakes are simply higher because the underlying data was never collected for research.
The Advisory Board and the SRD: Two Everyday Cases Where the Lines Meet
To see how the confidentiality and compliance constraints operate together rather than in isolation, it helps to walk two ordinary medical-affairs tasks where both lines are live at once, because in practice they rarely arrive one at a time. Consider advisory-board preparation and follow-up. Before the meeting, a medical-affairs team assembles dossiers on the invited experts, conflict-of-interest summaries, and an agenda, and AI can genuinely help structure this preparation from existing materials. But the expert dossiers are built from information about named individuals, and the conflict and fair-market-value considerations carry their own compliance weight, so the confidentiality line governs how that expert information is handled from the first step. After the meeting, the team produces a report that categorizes the expert input, and here both lines bind simultaneously: the input came from named experts speaking candidly, so it must be handled confidentially and appropriately attributed or de-identified, and the report itself, if it informs strategy or any downstream communication, has to respect the non-promotional boundary. AI can draft the structured report from the meeting notes, but the protection of what the experts said and the compliance of what the organization does with it are both human responsibilities, and they are not separable in this workflow.
The standard response document for a medical-information inquiry is the second everyday case, and it shows the compliance line at its most exacting. When a healthcare professional submits an unsolicited question, the medical-information function answers with a standard response document built from published evidence, and AI can assemble a strong first draft by retrieving and structuring the relevant literature. But the output is a piece of scientific communication going to an external requester, so every element of the compliance line applies: it must be non-promotional even though it concerns the company's product, it must accurately attribute each claim to its published source, and it must handle any off-label dimension of the question with the appropriate care, because an unsolicited off-label inquiry has its own rules about what a response may and may not contain. The model can retrieve the evidence and draft the response, which saves real time across a high volume of inquiries, but the determination that the response is non-promotional, accurately attributed, and appropriate on the on-label and off-label dimensions is a compliance judgment the medical-information professional owns. In both cases, the everyday texture of the work is that the two lines are not abstract principles invoked occasionally; they are present in every step, and the AI's role is to assemble while the human continuously guards the input and governs the output.
These two examples also reveal why medical affairs cannot simply borrow the AI playbook of the regulatory or safety functions, even though the underlying modalities overlap. A regulatory writer's verification is dominated by accuracy against a source; a safety reviewer's by medical determinations on a case. The medical-affairs professional carries those same concerns and adds two that are sharper here than anywhere else: a confidentiality obligation to named external people who spoke in confidence, and a promotional-boundary obligation that can be breached by tone and framing rather than by a factual error. That is why this function deserves its own treatment and its own discipline, and why the two-line frame is the right one: it captures precisely the pair of obligations that make medical-affairs AI distinct, and it gives the professional a portable test to apply to any tool, any workflow, and any new capability the vendors introduce.
The Two Lines That Govern Everything in Medical Affairs
Step back from the tools and two lines organize the entire medical-affairs AI landscape, and a professional who holds both clearly is equipped for any tool the function adopts. The first is the confidentiality line, governing what can go into a model. Because medical affairs handles the sensitive, often personally identifiable, often competitively sensitive input of named external experts, the rule is that this information is de-identified and handled only in governed, contractually appropriate tools, never in public consumer models. This line is not a matter of degree; pasting raw KOL notes or unpublished competitive intelligence into a public model is a breach, full stop, and the discipline is to treat the protection of that input as the precondition for any AI use, not a checkbox after the fact.
The second is the compliance line, governing what the output is allowed to be. Because the function's purpose is non-promotional, evidence-accurate scientific exchange, the output of any AI-assisted medical communication has to clear the same bar a human-authored one does: non-promotional, properly attributed, appropriately handling on-label and off-label content, and cleared through MLR. The AI can draft and check, but the compliance judgment, the determination that the communication is on the right side of the promotional line and faithful to the evidence, is the human's, and it is the actual work of the function. A medical-affairs professional who internalizes these two lines, guard the input, govern the output, can adopt the field-insight, MLR, and RWE tools with confidence, because they know that the AI is doing the synthesis and assembly the function has always needed help with, while the two judgments that define the function, the confidentiality of the expert and the compliance of the communication, remain firmly and properly human. That is the equipped, calm posture the whole chapter has been building toward, applied to the function that needed it most.
Key Takeaways
- Medical affairs is a different AI problem because its currency is non-promotional scientific exchange, governed by a watched line between medical affairs and commercial promotion. The inputs are unusually sensitive (named experts' unpublished thoughts) and the outputs unusually constrained (non-promotional, evidence-accurate, MLR-cleared), so the guardrails are tighter than elsewhere.
- The field-insight layer (Veeva ecosystem capabilities, Abridge Life Sciences Edition) clusters and synthesizes scattered KOL notes into structured insight reports. De-identification of the input and use of a governed tool are non-negotiable preconditions, because KOL notes contain personally identifiable, often competitively sensitive information; pasting raw notes into a consumer chatbot is a breach regardless of output quality.
- In the MLR and publications layer (Veeva PromoMats, MedComms), compliance is the product, not a constraint on it. AI accelerates drafting and consistency-checking, but the MLR reviewers own the compliance judgment, whether the content stays non-promotional, handles off-label appropriately, and is faithful to cited evidence, and good-publication-practice frameworks are human governance AI assists but does not satisfy.
- The RWE layer (Komodo Health, TriNetX, Aetion) generates real-world cohorts and analyses from healthcare data. The data-quality stakes are higher because the data was never collected for research, so the analyst owns the validity assessment of what the cohort represents and the interpretive judgment of what a finding means for the product's value story.
- Two lines govern everything: the confidentiality line (what can go into a model) and the compliance line (what the output is allowed to be). Guard the input by de-identifying and using governed tools; govern the output by keeping it non-promotional, evidence-accurate, and MLR-cleared. The AI does the synthesis and assembly; the confidentiality of the expert and the compliance of the communication stay human.
Skill.re