Direct Regulator Engagement on AI: FDA EDST, EMA AI Workplan, PMDA, MHRA Airlock
There is a moment, somewhere between the first AI-drafted Module 2.5 paragraph and the enterprise rollout of agentic submission tooling, when a biopharma realizes it can no longer be a passive recipient of regulatory guidance on AI. The guidance is being written right now, in real time, in venues that take comments, host meetings, and run sandboxes, and the sponsors who show up shape the rules they will later be inspected against. As the AI Life Sciences Visionary, you are the person the organization sends into those rooms. You sit across from a reviewer at the FDA Center for Drug Evaluation and Research to discuss a pharmacovigilance signal-triage model. You file a comment on the EMA AI Workplan that a CHMP rapporteur actually reads. You put a tool into the MHRA AI Airlock and let a regulator watch it fail and recover under controlled conditions. This lesson is about doing that well: the named programs that exist in 2026, what each one is and is not for, and the public-comment and advocacy strategy that turns your organization from a rule-taker into a credible contributor to the rules. The stakes are not abstract. The wording that ends up in a finalized FDA credibility framework or an EMA guideline will govern every AI-assisted submission your company files for the next decade, and the comment you do not write is a clause you do not get to influence.
Why the Visionary Engages Regulators Directly
The instinct of a regulated industry is to wait for the final rule and then comply. That instinct is exactly wrong for AI in 2026, because the rules are not final, the regulators are explicitly soliciting input, and the cost of silence is permanent. When the FDA CDER and the EMA jointly released the Guiding Principles of Good AI Practice in Drug Development on 14 January 2026, they did not hand down a finished regulation; they published a set of ten principles and signaled that implementation details would be worked out collaboratively with industry over the following years. That is an invitation, and the sponsors who treat it as one will find their operational reality reflected in the eventual guidance, while the sponsors who wait will find guidance written around the practices of their more engaged competitors. Direct engagement is not lobbying in the pejorative sense; it is the legitimate, documented, on-the-record process by which a regulator learns what is actually happening at the keyboard of a medical writer and a pharmacovigilance scientist, and adjusts the rule to be implementable rather than aspirational.
There is a second reason, and it is about credibility rather than influence. A reviewer at the Office of New Drugs who has met your Head of AI for Regulatory, understood your validation framework, and watched your tooling demonstrated in a structured meeting carries a different prior into your next submission than a reviewer who first encounters your AI use in a cover-letter disclosure on Day 1 of a review cycle. Trust between a sponsor and a regulator is built before it is needed, in the low-stakes venues that exist precisely for that purpose, and it is spent in the high-stakes moment of an actual filing. The Visionary's job is to build that trust deliberately, as an asset on the organization's balance sheet, years before the pivotal submission that will draw on it. The third reason is defensive: engagement surfaces the regulator's unstated expectations early, so that your enterprise architecture is not blindsided two quarters before a Biologics License Application by a requirement no one saw coming.
The FDA Emerging Drug Safety Technology Program
The most concrete door into the FDA on AI is the CDER Emerging Drug Safety Technology Program, which administers Emerging Drug Safety Technology Meetings, announced in a Federal Register notice on 11 June 2024 and active through 2026. The program gives applicants with an approved application, and other parties supporting industry pharmacovigilance such as contract research organizations, pharmacovigilance vendors, software developers, and academia, a structured opportunity to meet with CDER staff to discuss the research, development, and use of AI and other emerging technologies in pharmacovigilance. A meeting is requested by email to the AIMLforDrugDevelopment mailbox with the subject line "Request for an EDSTM," and a meeting is scheduled for up to ninety minutes. For a Visionary running an enterprise pharmacovigilance transformation, this is the venue in which to walk a CDER team through your continuous signal-triage architecture before it is load-bearing in a real PSUR cycle.
The single most important thing to understand about this program is the boundary the FDA drew around it explicitly. The Emerging Drug Safety Technology Meeting is not an avenue to seek regulatory advice on the adequacy or acceptability of a specific drug-safety technology; it is a venue for mutual learning, where the agency expects the information it gains will help it consider providing regulatory advice on specific technologies later, when appropriate. If your Head of AI for Regulatory walks into that meeting expecting a yes-or-no verdict on whether your ArisGlobal LifeSphere NavaX deployment passes muster for expedited 15-day reporting, the meeting will fail, and worse, it will signal that the organization does not understand the regulatory landscape. The correct posture is to bring a genuine, well-characterized technology, present its design and your validation thinking honestly, ask the questions that help the agency understand it, and accept that the deliverable is shared understanding, not approval. The approval pathway is the ordinary submission; the meeting is how you make that later submission legible.
The EMA AI Workplan and the Reflection Paper
The European side of the engagement map is organized around two artifacts a Visionary must know cold. The first is the EMA and Heads of Medicines Agencies reflection paper on the use of artificial intelligence in the medicinal product lifecycle, first published in draft in 2023 and adopted in 2024, which reflects on principles relevant to applying AI and machine learning at every step from drug discovery through the post-authorization setting. The second is the multi-year EMA AI Workplan, carried in the European medicines regulatory network's Network Data Steering Group workplan covering 2025 through 2028, which organizes the network's actions into guidance and policy support, tools and technology, collaboration and change management, and experimentation. The 2025 milestones included publishing responsible-AI principles, a terminology guide, and launching a network-wide change-management strategy. For the Visionary, the Workplan is a roadmap of what European expectations will look like before they harden into guideline, and each workstream is a place where industry input is being actively sought.
Engaging the EMA looks different from engaging the FDA, and the difference matters operationally. The European process runs heavily through written consultation, multi-stakeholder workshops, and the channels that industry bodies such as EFPIA aggregate, which means your influence is exercised as much through a well-argued consultation response as through a face-to-face meeting. When the EMA opens a draft guideline or a reflection-paper revision for comment, the Visionary's organization should treat the response as a strategic deliverable, not a compliance chore: a comment that demonstrates real operational experience, names the specific clause that is unworkable, and proposes an implementable alternative is the comment that moves the text. The EMA Innovation Task Force offers an earlier, more exploratory channel for novel approaches that do not yet fit any guideline, and the Visionary who understands the difference between the Task Force, the Workplan consultations, and the formal scientific-advice route can route each question to the venue built to handle it.
PMDA and the Japanese Engagement Channel
Japan is the jurisdiction most often skipped in an AI engagement strategy, and skipping it is a mistake for any organization with a global development footprint. The Pharmaceuticals and Medical Devices Agency stood up an AI Working Group and, in October 2025, published an Action Plan for the Use of AI in Operations, a document describing how the agency itself will use AI to enhance its review and operational capabilities, building models in a secure internal environment and advancing proof-of-concept projects for high-expertise tasks. This is significant for a Visionary because it tells you that the regulator reviewing your submission is itself becoming an AI user, with its own views on interpretability, continuous learning, and training-data quality that it is forming through its own practice. A regulator that is wrestling with the same problems you are is a regulator that can be engaged as a peer on the hard questions rather than lectured as a novice.
The practical entry point on the product side is the PMDA SaMD One-Stop Consultation Desk, which lets developers seek early regulatory advice on classification, clinical evaluation, and application strategy, and which embodies the agency's stated preference for timely and transparent communication between regulators and innovators. The PMDA's working group has also been explicit about the considerations it weighs for AI medical products: continuous-learning capability, result interpretability, and training-data quality, the same triad that runs through the FDA Predetermined Change Control Plan thinking and the EMA reflection paper. For the Visionary, the lesson is that the three major regulators are converging on a shared vocabulary of concerns, and an engagement strategy built around that shared vocabulary, rather than around the idiosyncrasies of any single agency, will scale across the global portfolio with far less rework.
The MHRA AI Airlock as a Live Laboratory
The United Kingdom's MHRA AI Airlock is the most experimental of the four programs and, for that reason, the most instructive about where regulation is heading. The Airlock is a regulatory sandbox for AI as a medical device, and its pilot phase ran from April 2024 through March 2025, producing a programme report and three workshop reports published on 16 October 2025. The pilot deliberately surfaced the hard problems: validating synthetic data, improving the explainability of AI decisions, and confronting AI hallucinations directly rather than pretending a regulated AI system never confabulates. A second cohort, announced in October 2025, brought a new set of tools into the Airlock to test until March 2026, with reporting expected in summer 2026, and the Department of Health and Social Care committed further multi-year funding to extend the programme through the rest of the decade. The Airlock is a live laboratory in which a regulator and a developer jointly discover what a rule should say by watching a real system operate under controlled conditions.
For a Visionary, the Airlock model carries a lesson that reaches well beyond the United Kingdom and well beyond medical-device software. The willingness to let a regulator watch your AI system encounter a hard case, mis-handle it, and recover through a designed control is the single most credibility-building move available to an organization, and it is the opposite of the instinct to present only the polished demo. A sandbox engagement is where you demonstrate that your hallucination controls, your validation gates, and your human-in-the-loop checkpoints actually fire when they are supposed to, which is exactly the evidence a reviewer needs and rarely gets. Even for a sponsor whose primary AI use is in submission drafting rather than device software, studying the Airlock's published findings on synthetic-data validation and explainability is a way to anticipate the controls that the FDA and EMA will eventually expect, because the regulators talk to each other and the good ideas migrate across the FDA-EMA Guiding Principles, the ICH process, and the national sandboxes.
A Public-Comment and Advocacy Strategy That Works
Engagement without a strategy is a series of disconnected meetings that consume executive time and change nothing. The Visionary's job is to convert the available channels into a coordinated advocacy program with a named owner, a calendar, and a position. The mechanics start with monitoring: someone in the organization, typically the Head of AI for Regulatory working with regulatory intelligence, watches the FDA dockets, the EMA consultation calendar, the MHRA Airlock cohort announcements, and the ICH Step-2 comment periods, so that no comment window opens without the organization knowing. The ICH Step-2 comment period is particularly high-leverage, because a comment that shapes an ICH guideline shapes the rule in every ICH region at once, which is a return on a well-written comment that no single-jurisdiction docket can match.
A comment that moves guidance has a recognizable shape, and it is not the shape of a generic endorsement. It identifies the specific clause at issue by number, it explains the operational consequence of the current wording using the organization's real experience without disclosing confidential information, it proposes a concrete alternative wording, and it ties the proposal back to a principle the regulator has already endorsed, such as the FDA-EMA fitness-for-purpose or risk-based-assessment principles. A comment that says "we support responsible AI" is noise; a comment that says "Principle 7's model-monitoring expectation, as drafted, requires re-validation on every model update, which is incompatible with the Predetermined Change Control Plan framework the same agency finalized in December 2024, and we propose the following reconciling language" is signal, and signal gets read by the people drafting the final text. The Visionary also coordinates the organization's voice across the industry consortia, DIA, RAPS, TransCelerate, PHUSE, and ISMPP, so that the company's position is amplified by aligned bodies rather than diluted by a contradictory one. Every comment, every meeting, and every Airlock interaction is logged, because the engagement record is itself an asset that demonstrates to an inspector, a board, and a future regulator that the organization has been a serious, consistent, on-the-record participant in shaping the rules it operates under.
From Engagement to Enterprise Readiness
The final discipline is closing the loop from the regulator's room back into the enterprise. An engagement that does not change what the organization actually does is theater, and a regulator will eventually notice the gap between what your Visionary said in a meeting and what your medical writers do at their keyboards. When an Emerging Drug Safety Technology Meeting surfaces a CDER concern about training-data provenance, that concern becomes a requirement in your model-card standard. When an EMA consultation reveals that the network expects a documented change-management strategy, that expectation becomes a workstream in your enterprise AI governance. When the Airlock's published findings show that explainability is becoming a hard expectation, your validation framework grows an explainability gate before the FDA or EMA makes it mandatory. The Visionary operates a two-way valve: the organization's operational reality flows out to shape the guidance, and the guidance's emerging expectations flow back in to shape the organization, ahead of the moment they become enforceable.
This is what separates a mature AI life-sciences organization from one that is merely compliant. The compliant organization reads the final rule and retrofits. The mature organization has been in the room, has watched the rule take shape, has shaped it where it could, and has been quietly building the controls the rule will require for two years before it lands. When the Biologics License Application finally goes in and the Day 74 Information Request asks how AI was used and governed, the answer is not improvised; it is the natural output of an engagement strategy that began long before the submission, ran through the Emerging Drug Safety Technology Program and the EMA Workplan and the Airlock, and is documented end to end. That is the posture this program is building toward, and the new roles that make it operational, the Chief AI Officer, the Head of AI for Regulatory, the AI Validation Lead, are the subject of the next lesson.
Key Takeaways
- The rules for AI in drug development are being written now, in venues that take comments, so silence is a forfeited clause. The 14 January 2026 FDA-EMA Guiding Principles were an invitation to shape implementation, not a finished regulation, and the sponsors who engage will see their operational reality reflected in the eventual guidance while those who wait inherit rules written around their competitors' practices.
- The FDA Emerging Drug Safety Technology Program offers up-to-ninety-minute meetings for mutual learning, not approval. Requested via the AIMLforDrugDevelopment mailbox, it lets a sponsor walk CDER through a pharmacovigilance AI architecture, but it is explicitly not an avenue to seek a verdict on a specific technology's acceptability, and treating it as one signals a misread of the landscape.
- The EMA AI Workplan (2025 to 2028) and the EMA-HMA reflection paper are the European roadmap, and influence there runs through written consultation. A strategic consultation response that names the unworkable clause, cites real operational experience, and proposes implementable wording moves the text, while a generic endorsement is noise; the Innovation Task Force handles the earlier, more exploratory questions.
- The PMDA AI Working Group and the MHRA AI Airlock reveal a converging regulator vocabulary of interpretability, continuous learning, and training-data quality. The Airlock's willingness to watch real systems hallucinate and recover is the model of credibility-building engagement, and its published findings on synthetic-data validation and explainability preview controls the FDA and EMA will eventually expect.
- A public-comment strategy needs a named owner, a monitored calendar across FDA dockets, EMA consultations, and ICH Step-2 windows, and a closed loop back to the enterprise. ICH Step-2 comments shape the rule in every region at once; every meeting and Airlock interaction is logged as an asset; and every emerging expectation flows back to become a control before it is enforceable.
Skill.re