Reimagining Regulatory Operations in the Artificial Intelligence (AI) Age
The rapid evolution of AI is reshaping medicine regulation, shifting the technology from exploratory pilots to becoming a structural capability. A keynote presentation by Hilmar Hamann, PhD, Head of the Information Management Division at the European Medicines Agency (EMA), explored the “shifting frontiers” of the current landscape that will define how AI is developed, governed, and trusted across the medicinal product lifecycle and regulatory environment.
Speaker Background
Hamann’s professional background is notable: prior to joining the EMA, he served as Director for Business Informatics at the US Food and Drug Administration’s (US FDA) Center for Drug Evaluation and Research from 2011 to 2020 Having held senior leadership roles within both the US FDA and the EMA, Hamann is among the relatively few individuals able to engage authoritatively with both sides of the transatlantic regulatory landscape, a perspective that informed and enriched his presentation throughout.
His foundational training is in chemistry and pharmaceutical manufacturing, and he carries from that experience the conviction that technology is only as valuable as its reliability under real operational conditions. As Hamann framed it, the central question for AI is not what it can accomplish in theory, but what it can do consistently, at scale, and with the confidence of the professionals who depend on it daily.
Under his leadership, EMA has made significant advances: publishing the foundational AI reflection paper, launching the widely adopted Scientific Explorer tool, co-authoring the joint EMA/US FDA Guiding Principles of Good AI Practice in Drug Development, and committing to an ambitious five-year AI workplan. These initiatives represent not pilot projects, but the building blocks of a regulatory system preparing itself for a fundamentally different future.
Setting the Scene
Hamann opened his presentation at the 2026 ISPE Europe Annual Conference by acknowledging the ISPE audience's relevance to his professional background, noting that his early career in pharmaceutical manufacturing had shaped his approach to emerging technology. The central lesson he drew from that experience, that any system is only as reliable as its fundamentals, including data quality, cause-and-effect understanding, and process controls, applies equally to AI systems today. In his view, the discussion of AI must begin not with theoretical capabilities but with what AI can reliably and consistently deliver in an operational environment.
He framed the discussion with two contrasting perspectives. Stephen Hawking’s 2016 warning that AI could represent humanity’s greatest or final achievement was set against Andrew Ng’s characterization of AI as simply “the new electricity,” poised to transform every industry. Hamann expressed agreement with both perspectives, noting that electricity also carries risks that society has learned to manage through trained professionals, established standards, and regulatory frameworks. He proposed that AI demands the same approach.
The Dual Role of a Modern Medicines Regulator
Among the most significant observations in Hamann’s presentation was his characterization of the EMA’s uniquely complex position. He described it as “two sides of a coin.” On one side, AI is already being deployed throughout the medicinal product lifecycle, including in manufacturing, which means regulators must develop robust frameworks to oversee its safe use. On the other hand, EMA itself must become an AI-enabled organization to fulfill its mandate more quickly and effectively. The same standards that the EMA applies to industry must apply to itself. The central challenge, as Hamann articulated it, is how to regulate AI with confidence while deploying it with that same level of confidence.
The Evolving Landscape
Hamann identified three “shifting frontiers” shaping the current moment:
- The capability frontier has advanced with remarkable speed. The public launch of ChatGPT in late 2022 shifted the conversation from chatbots and prompt engineering to agentic AI systems with distinct personas, specialized skills, and the capacity to execute complex tasks autonomously with minimal human input. Technology has moved from something users interact with to something that acts on their behalf.
- The policy frontier is where the European Union has moved decisively. The EU AI Act establishes a framework of accountability for high-risk AI systems through a risk-based approach to oversight. The European Health Data Space sets the conditions for applying AI to healthcare data, covering data quality, safety, and both primary and secondary use. Hamann also noted the forthcoming Biotech Act as an additional layer of regulatory consideration and observed that the EU occupies a distinctive global position by having transversal AI legislation already in force.
- The trust frontier represents perhaps the most nuanced dimension. Societal expectations now extend beyond basic transparency and oversight; explainability is increasingly assumed. What Hamann identified as genuinely new is the emerging concept of AI sovereignty: the expectation that organizations maintain meaningful control over the AI models they deploy, including an understanding of the training data, potential biases, and governance structures behind them. He characterized this as a significant shift in expectations with substantial implications for regulatory practice.
Hamann referenced a 2025 McKinsey survey on AI adoption across industries. Several findings were of particular relevance. While overall AI adoption continues to expand, agentic AI remains primarily in pilot phases across most sectors, with efficiency gains and cost savings as the primary drivers. Healthcare and life sciences present a different profile: the focus there is on drug discovery, new diagnostics, and personalized medicine, making it more a driver of top-line growth and new services than an efficiency measure. Hamann noted this distinction as particularly significant. He also observed that while traditional machine learning has been applied in manufacturing for quality and process control for a number of years, generative AI has not yet reached the factory floor at scale, though he acknowledged the conference program contained sessions directly addressing this question.
EMA’s Journey
Hamann provided a comprehensive overview of EMA’s progress, organized into three overlapping phases:
- Foundations (2023–2024): During this phase, EMA published its AI Reflection Paper, launched the five-year HMA/EMA AI Workplan, and developed its AI risk assessment framework. The Agency also deployed Scientific Explorer, an AI-powered search tool that enables regulatory assessors to retrieve prior scientific advice and assessment precedents efficiently. The tool now serves up to 400 daily users. Two challenges were central to its successful implementation: validation and adoption. EMA benchmarked the tool’s outputs against a manually maintained database, and the AI-driven system demonstrated superior accuracy and completeness, reflecting the inevitable gaps that accumulate in manually maintained records over time. Regulatory assessors were directly involved in the validation process, which was critical to establishing institutional trust. Ensuring compliance with data protection requirements and the EU AI Act was also integral to the deployment, establishing this as a reference implementation for AI tools in a regulatory context.
- Exploration (2025–2026): A significant milestone was reached when the Committee for Medicinal Products for Human Use (CHMP) issued its first-ever qualification of an AI-generated methodology, formally recognizing AI-derived evidence in clinical trials as scientifically sound. Earlier in 2026, EMA and US FDA jointly published their Guiding Principles of Good AI Practice in Drug Development, a document that required substantial alignment efforts but that sends a clear transatlantic signal of regulatory convergence on AI in medicines development.
- Integration (2027 and beyond): The focus shifts to embedding AI tools into everyday regulatory operations, including AI-assisted workflows and a framework for sharing AI capabilities across the European medicines regulatory network.
The 10 EMA/US FDA Guiding Principles
Hamann reviewed the ten shared principles in detail, noting that they were deliberately formulated at a high level of abstraction. In a rapidly evolving field, excessive prescription would be counterproductive; the principles are designed to be durable. Patient safety is the common thread running through all ten. Key provisions include: the requirement that AI support, rather than replace, human judgment; a risk-based approach that applies proportionate controls to higher-stakes applications; adherence to existing scientific and regulatory standards; an explicit declaration of the context of use; and transparency regarding the intended function. Multidisciplinary expertise is emphasized, integrating clinical, scientific, and regulatory knowledge with technical capability. Rigorous data governance and documentation are required, reflecting the principle that AI is only as sound as the data and records underpinning it. Models must be designed for transparency and robustness, validated against their intended use and identified risks, and actively maintained throughout their lifecycle. Finally, those working with AI systems must have access to clear and sufficient information to operate them safely and reliably.
From Principles to Practice
Hamann concluded by identifying three fundamental shifts he anticipates in regulatory operations:
- From data management to data intelligence: Organizations will be increasingly required to account not only for model outputs, but also for the underlying data, assumptions, and governance frameworks that inform them.
- From compliance controls to dynamic oversight: Regulators will expect to understand how AI systems are continuously monitored and updated, rather than validated at a single point in time.
- From human oversight to human-centric design: Maintaining human involvement in AI-enabled processes is not merely a compliance requirement; it means designing systems in which human judgment is structurally embedded and meaningfully exercised.
Conclusion
Hamann closed with an instructive analogy: AI should be understood as an augmented cockpit, not an autopilot. Algorithms may manage turbulence, but humans must chart the course. Whether AI ultimately proves to be a transformative technology or a source of existential risk, he concluded, depends entirely on how effectively society embraces its opportunities while genuinely addressing its risks.
The path forward, in his view, requires the systematic sharing of best practices, including not only successes but also failures, global alignment of principles among EMA, US FDA, and ICH, and the development of AI literacy across all relevant disciplines, both technical and non-technical. Hamann proposed that “AI maturity” should become a shared objective between regulators and the industry they oversee.
Disclaimer
This is a summary of a presentation made on 20 April at the 2026 ISPE Europe Annual Conference in Copenhagen, Denmark. It has not been vetted by any of the regulators or agencies mentioned in this article, nor should it be considered the official position of the agencies mentioned.
ISPE members: View ISPE Communities of Practice.
Not an ISPE member? Join today.
Submit Your Best Content to ISPE
ISPE’s official blog, iSpeak accepts contributions from our Members and professionals in the pharma industry.