The FDA-EMA Joint Guiding Principles on Good AI Practice, Plain English
On 14 January 2026, the United States Food and Drug Administration and the European Medicines Agency did something they rarely do: they agreed, jointly and publicly, on what good practice looks like when artificial intelligence is used in drug development. The document they released, the Guiding Principles of Good AI Practice in Drug Development, sets out ten principles spanning the nonclinical, clinical, post-marketing, and manufacturing phases of a medicine's life, and while it is framed as high-level principles rather than binding guidance, it is the closest thing the industry now has to a shared definition of what the two most important regulators expect. For everyone who writes, files, monitors, codes, or defends a regulated submission, this document is the floor, the baseline of expectation that the rest of this program teaches you to meet and exceed. This lesson walks all ten principles in plain English, not as abstractions but as a set of demands on your Monday, because each principle, however lofty it sounds, translates into a concrete question about how you use AI on a real artifact. By the end you will be able to read your own AI use against the ten principles and see immediately which ones it satisfies and which ones it does not, which is the first practical skill of responsible AI in this field.
Why a Shared Floor Matters, and What This Document Is and Is Not
Before the principles themselves, it is worth being precise about what this document is, because misunderstanding its status leads to two opposite errors. It is a set of guiding principles jointly issued by the FDA and EMA, intended to steer the responsible use of AI across the drug-development lifecycle and to lay a foundation for future guidance, standards, and harmonized expectations. It is not, as of its release, a binding regulation or a detailed guidance document with prescriptive procedures, and it does not by itself tell you exactly how to validate a specific tool. The first error is to dismiss it because it is not binding; that is a mistake because it signals, with unusual clarity and rare two-regulator agreement, the direction expectations are heading, and the organizations that align to it now will be ready when the more detailed guidance arrives. The second error is to treat it as a complete compliance checklist; that is a mistake because the principles are high-level and require translation into the specific controls the rest of this program provides.
The right posture is to read the ten principles as the shared vocabulary of expectation, the concepts that FDA and EMA reviewers, inspectors, and future guidance will all be working from. When you can map your AI use to these ten principles, you are speaking the language the regulators have agreed to speak, and you are positioned to meet the expectations as they sharpen from principle into requirement. The principles also sit alongside related developments, the FDA's May 2025 draft considerations on using AI to support regulatory decision-making, which remains in its comment-response window, and the European workstream on jurisdictional implementation, whose timing is still to be determined and which should be tracked through the EMA AI workplan. The joint principles are the stable center of all this motion, which is why this program anchors its regulatory foundation here.
The First Four: Human-Centric Design, Risk-Based Assessment, Fitness for Purpose, Data Quality
The first principle is human-centric, ethical design. In plain terms, the AI should be built and used in service of human wellbeing and ethical values, with human oversight and accountability designed in rather than bolted on. For your Monday, this is the principle behind every place this program insists that a named human owns the judgment and the AI assists; it is the regulatory backing for the claim that the writer's name still goes on the cover page. When you keep the causality call, the benefit-risk conclusion, and the final sign-off with a qualified human, you are honoring human-centric design.
The second principle is risk-based assessment. The rigor of your oversight should scale with the consequence of the AI's use; high-stakes uses warrant more scrutiny than low-stakes ones. This is the principle behind the program's repeated instruction to set verification by the cost of a miss, lighter for an internal summary, heavier for a Module 2.5 statement a reviewer reads, heaviest for a patient-facing dose. The third principle is fitness for purpose. The AI should be appropriate and validated for the specific use it is put to; a tool fit for drafting a first pass is not automatically fit for an autonomous determination. This is the principle behind the intended-use and validation discipline that the applied levels build, and behind the simple daily question of whether the tool you are using was actually designed and qualified for the task you are using it for. The fourth principle is data quality and lifecycle management. The data that trains and feeds AI must be of appropriate quality and managed across its lifecycle, because an AI is only as good as its data, and biased or poor data produces biased or poor output. This is the principle behind the responsible-AI chapter's treatment of bias and the program's insistence on understanding what a model's data does and does not represent.
The Middle Three: Transparency, Accountability, and Model Performance Monitoring
The fifth principle is transparency. It should be possible to understand and document how AI was used and how it contributes to a result, so that others can assess and trust it. For your Monday, this is the principle behind the AI use log and the emerging practice of disclosing AI involvement in the cover letter; it is why capturing the run, the sources, and the verification is not optional bureaucracy but a direct response to a stated regulatory expectation. When you document how AI contributed to a section in a way someone else can follow, you are honoring transparency.
The sixth principle is accountability, and it is the one this program returns to most often, because it is the most load-bearing. Clear human and organizational accountability for AI-influenced decisions must be maintained, and, crucially, that accountability does not transfer to the AI or its vendor. This is the regulatory statement behind the entire named-author and qualified-person structure: when the model drafts and the human signs, the human is accountable, and no capability of the tool changes that. The seventh principle is model performance monitoring. The performance of an AI should be evaluated and shown to be adequate for its purpose, with appropriate testing. This is the principle behind the evals concept from the terminology lesson and the validation work of the applied levels; it is the expectation that you can show, not just assert, that a tool performs well enough for what you are using it to do. Together, these three, transparency, accountability, monitoring, form the core of what makes an AI-assisted result defensible: you can show how it was made, you can name who is responsible, and you can demonstrate the tool was adequate.
The Final Three: Ongoing Lifecycle Monitoring, Governance and Documentation, Stakeholder Collaboration
The eighth principle is ongoing lifecycle monitoring. AI is not validated once and forgotten; its performance must be monitored across its operational life, because models can drift and contexts change. For your Monday, this is the principle behind the drift-detection concept and the recognition that a tool which performed well at adoption can degrade silently after a vendor update, which is why ongoing monitoring and a model-update awareness are part of responsible use rather than a one-time validation event. The ninth principle is governance and documentation. There should be appropriate organizational governance over AI use, with the documentation to support it, meaning policies, roles, decision rights, and records rather than ad hoc individual choices. This is the principle behind the function-level governance the strategist level builds, and behind the recognition that responsible AI is an organizational discipline, not only a personal one.
The tenth principle is stakeholder collaboration. Responsible AI in drug development benefits from collaboration among the parties involved, sponsors, regulators, developers, and others, including engagement with regulators on novel AI uses. This is the principle behind the program's encouragement to engage regulators early on significant AI uses, to participate in the consultations and workplans, and to treat the relationship with the regulator as a collaboration rather than only a hurdle. It is also a signal about the spirit of the whole document: the regulators are not trying to prohibit AI but to establish a shared basis for using it well, and they are inviting the industry into the conversation about how the principles become practice. The visionary level of this program is, in large part, about taking up that invitation. It is worth dwelling on how unusual this tenth principle is, because regulators do not ordinarily write collaboration into their expectations; they more often write prohibitions and procedures. The presence of stakeholder collaboration as a named principle tells you that the FDA and EMA understand they are regulating a moving target, that the practice of AI in drug development is being invented in real time by sponsors and developers as much as by agencies, and that a purely top-down rulebook written today would be obsolete before it was finalized. By naming collaboration, the regulators are committing to learn alongside the industry, and they are asking the industry to bring its novel uses forward early rather than hide them until a submission, when surprises are most costly. For a function building its AI practice, the operational reading is concrete: identify your most significant or novel AI uses, the ones that would make a reviewer pause, and plan to discuss them with the relevant agency before they appear in a filing, treating early engagement as a risk-reduction investment rather than an admission.
Reading Your Own AI Use Against the Ten Principles
The value of knowing the ten principles is that they become a diagnostic you can run on any AI use, your own or a vendor's, to see where it stands. Take a concrete example: a writer uses an enterprise tool to draft a Module 2.5 efficacy section. Run it against the ten. Human-centric design: is a named human owning the judgment and the sign-off, or has the writer let the tool decide? Risk-based assessment: is the verification effort scaled to the fact that a reviewer will read this, or is it being treated as casually as a throwaway note? Fitness for purpose: was this tool actually qualified for regulated drafting, or is it a general consumer model pressed into a job it was not built for? Data quality: does the writer understand what the tool's grounding sources are? Transparency: is the run being captured so the AI involvement can be shown? Accountability: is it clear that the writer, not the tool, owns the final words? Model performance and ongoing monitoring: is there any basis for believing this tool performs adequately, and is anyone watching for drift? Governance: is this use within a function policy, or is it an individual improvising? Stakeholder collaboration: for a novel or significant use, has the regulator been engaged?
Running this diagnostic turns the ten principles from a list to memorize into a working instrument, and it reveals something important: most casual AI use fails not one principle but many, in the same way the ALCOA+ confession sentence fails all nine attributes, because the failures are correlated. The writer who pastes from a consumer tool without capturing the run fails fitness for purpose, transparency, accountability evidence, performance monitoring, and governance all at once, while the writer who uses a governed tool with loaded sources, captured runs, claim verification, and named sign-off satisfies most of them as a matter of course. This is the deep reason the principles and the practical disciplines of this program align so tightly: the program's workflows were built to satisfy exactly these expectations, so doing the work the program's way is, in regulatory terms, honoring the joint principles by construction. The ten principles are the why, the program's workflows are the how, and a professional who holds both can not only use AI well but explain, in the regulators' own vocabulary, why their use is sound.
From Principle to Practice: The Foundation for Everything That Follows
The reason this lesson sits where it does, near the end of the awareness level, is that the ten principles are the bridge from understanding AI to using it responsibly, and they organize everything the rest of the program teaches. The two remaining chapters of this level, on the specific regulations like 21 CFR Part 11 and the Predetermined Change Control Plan, and on the responsible-AI concerns of bias, confidentiality, and accountability, are detailed treatments of what the principles demand in particular areas. The applied levels, the assisted drafting, the integrated workflows, the function strategy, the enterprise transformation, are progressively more sophisticated ways of satisfying the principles at greater scale and stakes. The whole structure is, in a sense, an answer to the question the joint principles pose: given that the regulators expect human-centric, risk-based, fit-for-purpose, well-governed, transparent, accountable, monitored, collaborative AI use, how do you actually do that on a real dossier, week after week.
What a professional should take from this lesson is both the specific content of the ten principles and the larger reassurance they offer. The reassurance is that responsible AI in drug development is not a mystery or a moving target dependent on the latest tool; it is a defined set of expectations that two major regulators have agreed on and that a disciplined professional can meet deliberately. The principles do not ask you to slow down or to fear the technology; they ask you to use it in a way that keeps the human accountable, the data sound, the use transparent, and the performance demonstrated, which is exactly the way this program teaches you to use it. When the more detailed guidance arrives, and it will, the professional who has internalized these ten principles and built their practice around them will not have to change course; they will simply find that the floor they have been standing on has been formalized beneath them. That is the position this lesson is designed to put you in, and it is the foundation on which the rest of the certification builds.
Key Takeaways
- On 14 January 2026 the FDA and EMA jointly released the Guiding Principles of Good AI Practice in Drug Development, ten principles spanning nonclinical, clinical, post-marketing, and manufacturing AI. It is high-level principles rather than binding guidance, but it is the closest thing the industry has to a shared regulator definition of good practice and the floor the rest of the program teaches you to meet.
- The ten principles are: human-centric ethical design, risk-based assessment, fitness for purpose, data quality and lifecycle management, transparency, accountability, model performance monitoring, ongoing lifecycle monitoring, governance and documentation, and stakeholder collaboration. Each translates into a concrete Monday question about how you use AI on a real artifact.
- Accountability is the load-bearing principle: clear human and organizational accountability for AI-influenced decisions must be maintained and does not transfer to the AI or its vendor, which is the regulatory statement behind the entire named-author and qualified-person structure.
- Run the ten principles as a diagnostic on any AI use and the failures correlate: casual consumer-tool use fails fitness for purpose, transparency, accountability evidence, performance monitoring, and governance at once, while governed-tool use with loaded sources, captured runs, verification, and named sign-off satisfies most of them by construction.
- The principles are the why and the program's workflows are the how. They are not binding yet but signal where expectations are heading, alongside the FDA May 2025 draft considerations (in comment-response) and the EMA implementation workstream (timing to be determined); the professional who builds practice around them will find the floor formalized beneath them when detailed guidance arrives.
Skill.re