Compliance explainer · AI and GxPUpdated October 8, 2026

Using AI safely in clinical data capture: a GxP checklist

AI can draft forms, map data and flag anomalies. Each use carries a different risk to data integrity. This checklist sorts out which rules apply as of October 2026 and what to have on file before an AI feature touches your study.

  • Regulatory anchors, draft vs final
  • 10-point checklist
  • Human review by design

Free sandbox · No credit card · 21 CFR Part 11 aligned

AI drafting with human review, demo study
  1. Protocol uploaded

    demo-protocol-v2.pdf

  2. AI drafts visits and forms

    Suggestions only, nothing saved yet

  3. 3

    Data manager reviews every item

    Accept, edit or discard

  4. 4

    Saved as draft forms

    Editable, not yet live

  5. 5

    Approved and locked for live use

    Only approved forms reach the casebook

A person decides what enters the study build. The AI never saves on its own.

What to know first

  • Where the AI sits matters more than what model it uses. A tool that drafts a form for a person to review carries far less risk than one that changes, codes or judges participant data.
  • No AI-specific GCP regulation for data capture is final yet. The main texts are FDA's January 2025 draft guidance, the FDA-EMA Good AI Practice principles (January 2026), EMA's 2024 reflection paper and the existing computerised systems rules.
  • Existing GxP rules still apply in full. Validation, audit trail, access control and change control cover an AI-enabled system like any other.
  • Human review is the main control for generative AI in non-critical uses. Make it part of the workflow, not a policy line.
  • This page is general information, not legal or regulatory advice.

The problem

Why AI in data capture is a GxP question

Clinical data is only usable if it is attributable, accurate and traceable, the ALCOA+ principles. AI puts pressure on each of them. A suggestion accepted without review has no clear author. A model update can change outputs between two sites or two months. A prompt can carry personal data to a place your data protection assessment never covered.

It helps to separate two places AI can sit. Build-time AI helps set up the study: drafting visit schedules, forms, edit checks or lab tables from a protocol. A person reviews the output, then it goes through your normal approval and testing. Data-time AI acts on participant data: auto-coding adverse events, flagging outliers, suggesting query text or deciding eligibility. Build-time errors are usually caught in review and UAT. Data-time errors can flow straight into the analysis, so they need far more evidence.

Regulatory anchors

The documents that apply, and their status in October 2026

Status checked on 8 October 2026 against FDA, EMA, European Commission and Federal Register sources.

DocumentIssuer and dateStatusRelevance to data capture
Considerations for the Use of AI to Support Regulatory Decision-Making for Drug and Biological ProductsFDA, January 2025 (docket FDA-2024-D-4689)Draft, not finalSeven-step credibility framework based on model influence and decision consequence; excludes operational uses that do not affect safety, quality or reliability of results
Guiding Principles of Good AI Practice in Drug DevelopmentFDA and EMA, January 2026Non-binding principlesTen principles including human-centric design, risk-based approach, GxP adherence, data governance and life cycle management
Reflection paper on AI in the medicinal product lifecycleEMA, adopted by CHMP 9 September 2024Final reflection paperRisk-based use of AI from discovery to post-authorisation, including clinical trials
Guideline on computerised systems and electronic data in clinical trialsEMA, effective 9 September 2023In forceApplies to any computerised system used in a trial, AI included
EU GMP Annex 22, Artificial IntelligenceEuropean Commission with PIC/S, consultation July to October 2025DraftWritten for manufacturing; human review expected where AI supports non-critical work
EU AI Act, Regulation (EU) 2024/1689EU, in force since August 2024In force, high-risk duties phasedObligations depend on the use; see our EU AI Act guide
GAMP 5 Second Edition (2022) and ISPE GAMP Guide: Artificial Intelligence (2025)ISPEIndustry good practicePractical validation approach for AI-enabled GxP systems

If you rely on any of these for a decision, read the current version at the issuer's site. Statuses change.

Step one

Classify each AI use before you validate it

FDA's draft guidance gives a usable method even where it does not strictly apply. Define the question the AI helps answer and its context of use: what it does and what else informs the decision. Then rate model risk as a combination of model influence (how much the output drives the decision compared with other evidence) and decision consequence (how bad a wrong decision would be). The guidance's own clinical example, an AI model that alone decides which participants skip inpatient monitoring after dosing, is high influence and high consequence, so high risk.

Apply the same lens to data capture. An AI that drafts eCRF questions which a data manager reviews, edits and then tests in UAT has low influence, because the human review and testing decide what goes live. An AI that auto-codes adverse events into the safety tables has high influence over a consequential output. The depth of validation, monitoring and documentation should follow that rating. The draft guidance also excludes AI used for operational efficiencies that do not affect participant safety, product quality or the reliability of study results. Human review is often what keeps a build-time tool on the right side of that line, so document it.

The checklist

A GxP checklist for AI in clinical data capture

Work through it for each AI feature, per study. Keep the answers in your validation file.

1. Intended use written down

What the AI does, what it does not do, which data it sees and which decision its output feeds.

2. Risk rated

Model influence times decision consequence, with the rationale. High risk means more testing and more oversight.

3. Human review enforced by the system

Outputs cannot reach the study or the data without a named person accepting them. A policy alone is not enough.

4. Validation of what goes live

For build-time AI, test the forms and checks that result, in UAT, like any hand-built form. For data-time AI, test performance on fit-for-use data.

5. Audit trail and traceability

You can show who accepted, changed or rejected each output, and when. Approval steps are recorded.

6. Data privacy assessed

Know what is sent to the model, where it is processed and kept, and whether participant data is involved. Update your DPIA.

7. Change control for the model

The vendor tells you when the model or prompts change, and you decide whether to re-test.

8. Supplier assessment covers AI

Ask how the vendor validates and monitors the AI feature, and what documentation you get.

9. Users trained

Reviewers know the AI's limits and what a careful review looks like, and the training is recorded.

10. Periodic review

Look at acceptance and correction rates and incidents, and check for drift where the model acts on data.

Put the checklist to work on a real draft

Upload a protocol in the free sandbox, review what the AI drafts and see the approval steps for yourself. No credit card required.

Try AI study building free

How Capture applies it

Where Capture's AI study builder sits on the checklist

Capture uses AI at build time only. The AI study builder reads a protocol (PDF, DOCX or DOC) and drafts the visit schedule and forms. On a single form, it can read a description or an uploaded file (CSV, XLSX, PDF or DOCX) and draft questions or a lab table. Nothing is saved without human review, and the AI only works on draft forms, so it cannot change an approved form that is live. Reviewed drafts then follow the normal lifecycle: forms move from draft to approved, approved forms are locked, and only approved forms appear in the casebook. Participant data entered later carries the usual field-level audit trail. See protocol to study setup for the full flow.

That covers checklist items 3 and 4 by design: the review step is part of the product and the output is testable in UAT. Items 1, 2 and 9 are yours to write. For items 6, 7 and 8, ask us during your supplier assessment, as you would ask any vendor with AI features. The computer system validation guide shows where these answers sit in your validation file.

Worked example

Validating AI form drafting for one study

  1. 1

    Write the context of use

    The AI drafts visit schedule and eCRF forms from protocol version 2; a data manager reviews every item; output is not used until approved and tested.

  2. 2

    Rate the risk

    Low model influence, because review and UAT decide what goes live. Record the rationale.

  3. 3

    Draft and review

    Upload the protocol in the sandbox, compare the draft schedule with the protocol's schedule of assessments and correct differences.

  4. 4

    Test the result

    Run UAT scripts on the reviewed forms: edit checks, skip logic, calculations and signatures, exactly as for hand-built forms.

  5. 5

    Approve and file

    Approve the forms, then file the context of use, risk rating, review record and UAT report together.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is there a final FDA guidance on AI in clinical trials?

Not as of 8 October 2026. FDA's guidance on using AI to support regulatory decision-making for drugs and biologics was issued as a draft in January 2025 and is still marked draft on FDA's site. FDA and EMA published non-binding Good AI Practice principles in January 2026.

Does FDA's draft AI guidance cover AI that drafts eCRF forms?

Possibly not. The draft excludes AI used for operational efficiencies that do not affect participant safety, product quality or the reliability of study results. Whether a tool falls outside depends on how it is used, and human review is a large part of that argument. If you are unsure, FDA encourages early engagement.

Does a human-in-the-loop remove the need for validation?

No. It lowers the model's influence, so less evidence is needed about the model itself. You still validate what goes live, such as the forms and edit checks the AI drafted, through normal UAT.

Does Capture's AI touch participant data?

Capture's AI study builder works at build time: it drafts visit schedules, forms, questions and lab tables for review, only on draft forms. Nothing is saved without human review.

Does the EU AI Act apply to AI in an EDC?

It depends on the use. Most obligations depend on whether a system falls in a high-risk category. Read our EU AI Act guide for clinical trial software and check with your legal team.

What should I ask an EDC vendor about its AI features?

What the AI does and does not do, whether outputs need human acceptance, how the vendor tests and monitors it, how model changes are notified, and what data is sent where.

See AI drafting with human review

Upload a protocol in the free sandbox and review every suggestion before it is saved. No credit card, and you pay only when you go live.

Try AI study building free