AI can draft forms, map data and flag anomalies. Each use carries a different risk to data integrity. This checklist sorts out which rules apply as of October 2026 and what to have on file before an AI feature touches your study.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Protocol uploaded
demo-protocol-v2.pdf
AI drafts visits and forms
Suggestions only, nothing saved yet
Data manager reviews every item
Accept, edit or discard
Saved as draft forms
Editable, not yet live
Approved and locked for live use
Only approved forms reach the casebook
What to know first
The problem
Clinical data is only usable if it is attributable, accurate and traceable, the ALCOA+ principles. AI puts pressure on each of them. A suggestion accepted without review has no clear author. A model update can change outputs between two sites or two months. A prompt can carry personal data to a place your data protection assessment never covered.
It helps to separate two places AI can sit. Build-time AI helps set up the study: drafting visit schedules, forms, edit checks or lab tables from a protocol. A person reviews the output, then it goes through your normal approval and testing. Data-time AI acts on participant data: auto-coding adverse events, flagging outliers, suggesting query text or deciding eligibility. Build-time errors are usually caught in review and UAT. Data-time errors can flow straight into the analysis, so they need far more evidence.
Regulatory anchors
Status checked on 8 October 2026 against FDA, EMA, European Commission and Federal Register sources.
| Document | Issuer and date | Status | Relevance to data capture |
|---|---|---|---|
| Considerations for the Use of AI to Support Regulatory Decision-Making for Drug and Biological Products | FDA, January 2025 (docket FDA-2024-D-4689) | Draft, not final | Seven-step credibility framework based on model influence and decision consequence; excludes operational uses that do not affect safety, quality or reliability of results |
| Guiding Principles of Good AI Practice in Drug Development | FDA and EMA, January 2026 | Non-binding principles | Ten principles including human-centric design, risk-based approach, GxP adherence, data governance and life cycle management |
| Reflection paper on AI in the medicinal product lifecycle | EMA, adopted by CHMP 9 September 2024 | Final reflection paper | Risk-based use of AI from discovery to post-authorisation, including clinical trials |
| Guideline on computerised systems and electronic data in clinical trials | EMA, effective 9 September 2023 | In force | Applies to any computerised system used in a trial, AI included |
| EU GMP Annex 22, Artificial Intelligence | European Commission with PIC/S, consultation July to October 2025 | Draft | Written for manufacturing; human review expected where AI supports non-critical work |
| EU AI Act, Regulation (EU) 2024/1689 | EU, in force since August 2024 | In force, high-risk duties phased | Obligations depend on the use; see our EU AI Act guide |
| GAMP 5 Second Edition (2022) and ISPE GAMP Guide: Artificial Intelligence (2025) | ISPE | Industry good practice | Practical validation approach for AI-enabled GxP systems |
If you rely on any of these for a decision, read the current version at the issuer's site. Statuses change.
Step one
FDA's draft guidance gives a usable method even where it does not strictly apply. Define the question the AI helps answer and its context of use: what it does and what else informs the decision. Then rate model risk as a combination of model influence (how much the output drives the decision compared with other evidence) and decision consequence (how bad a wrong decision would be). The guidance's own clinical example, an AI model that alone decides which participants skip inpatient monitoring after dosing, is high influence and high consequence, so high risk.
Apply the same lens to data capture. An AI that drafts eCRF questions which a data manager reviews, edits and then tests in UAT has low influence, because the human review and testing decide what goes live. An AI that auto-codes adverse events into the safety tables has high influence over a consequential output. The depth of validation, monitoring and documentation should follow that rating. The draft guidance also excludes AI used for operational efficiencies that do not affect participant safety, product quality or the reliability of study results. Human review is often what keeps a build-time tool on the right side of that line, so document it.
The checklist
Work through it for each AI feature, per study. Keep the answers in your validation file.
What the AI does, what it does not do, which data it sees and which decision its output feeds.
Model influence times decision consequence, with the rationale. High risk means more testing and more oversight.
Outputs cannot reach the study or the data without a named person accepting them. A policy alone is not enough.
For build-time AI, test the forms and checks that result, in UAT, like any hand-built form. For data-time AI, test performance on fit-for-use data.
You can show who accepted, changed or rejected each output, and when. Approval steps are recorded.
Know what is sent to the model, where it is processed and kept, and whether participant data is involved. Update your DPIA.
The vendor tells you when the model or prompts change, and you decide whether to re-test.
Ask how the vendor validates and monitors the AI feature, and what documentation you get.
Reviewers know the AI's limits and what a careful review looks like, and the training is recorded.
Look at acceptance and correction rates and incidents, and check for drift where the model acts on data.
Upload a protocol in the free sandbox, review what the AI drafts and see the approval steps for yourself. No credit card required.
How Capture applies it
Capture uses AI at build time only. The AI study builder reads a protocol (PDF, DOCX or DOC) and drafts the visit schedule and forms. On a single form, it can read a description or an uploaded file (CSV, XLSX, PDF or DOCX) and draft questions or a lab table. Nothing is saved without human review, and the AI only works on draft forms, so it cannot change an approved form that is live. Reviewed drafts then follow the normal lifecycle: forms move from draft to approved, approved forms are locked, and only approved forms appear in the casebook. Participant data entered later carries the usual field-level audit trail. See protocol to study setup for the full flow.
That covers checklist items 3 and 4 by design: the review step is part of the product and the output is testable in UAT. Items 1, 2 and 9 are yours to write. For items 6, 7 and 8, ask us during your supplier assessment, as you would ask any vendor with AI features. The computer system validation guide shows where these answers sit in your validation file.
Worked example
The AI drafts visit schedule and eCRF forms from protocol version 2; a data manager reviews every item; output is not used until approved and tested.
Low model influence, because review and UAT decide what goes live. Record the rationale.
Upload the protocol in the sandbox, compare the draft schedule with the protocol's schedule of assessments and correct differences.
Run UAT scripts on the reviewed forms: edit checks, skip logic, calculations and signatures, exactly as for hand-built forms.
Approve the forms, then file the context of use, risk rating, review record and UAT report together.
Not as of 8 October 2026. FDA's guidance on using AI to support regulatory decision-making for drugs and biologics was issued as a draft in January 2025 and is still marked draft on FDA's site. FDA and EMA published non-binding Good AI Practice principles in January 2026.
Possibly not. The draft excludes AI used for operational efficiencies that do not affect participant safety, product quality or the reliability of study results. Whether a tool falls outside depends on how it is used, and human review is a large part of that argument. If you are unsure, FDA encourages early engagement.
No. It lowers the model's influence, so less evidence is needed about the model itself. You still validate what goes live, such as the forms and edit checks the AI drafted, through normal UAT.
Capture's AI study builder works at build time: it drafts visit schedules, forms, questions and lab tables for review, only on draft forms. Nothing is saved without human review.
It depends on the use. Most obligations depend on whether a system falls in a high-risk category. Read our EU AI Act guide for clinical trial software and check with your legal team.
What the AI does and does not do, whether outputs need human acceptance, how the vendor tests and monitors it, how model changes are notified, and what data is sent where.
Keep exploring
AI study builder
How Capture drafts studies from a protocol.
FDA AI guidance in 2026
What FDA has issued so far, draft vs final.
EU AI Act for clinical trial software
How the AI Act applies to trial tools.
Protocol to study setup
From uploaded protocol to a testable build.
ALCOA+ data integrity checklist
The principles AI must not erode.
Computer system validation
Where AI answers sit in your validation file.
Upload a protocol in the free sandbox and review every suggestion before it is saved. No credit card, and you pay only when you go live.