AI in Regulatory Affairs: What Responsible, Audit-Ready Use Looks Like
AI in Regulatory Affairs: What Responsible, Audit-Ready Use Looks Like
Picture a notified body reviewer pointing at one sentence in your Clinical Evaluation Report (CER) and asking, "Where did this come from?" If the honest answer is "the AI wrote it," you have a problem. If the answer is a reference, a screening record and a named reviewer, you do not.
Responsible use of AI in regulatory affairs means the tool speeds up the drafting while a qualified person stays accountable for every conclusion. For a CER, that comes down to four things: traceable sources, expert human review, versioned outputs and validation of the tool itself. Two recent developments, one from the US and one from the UK, point in the same direction.
What are regulatory leaders saying about AI assistants?
The debate has moved on from "should we use AI?" to "how do we use it defensibly?" Two September 2026 news items show where the conversation is heading.
Why did Califf tell regulatory professionals to stay the gatekeeper?
At RAPS Convergence 2026, former FDA Commissioner Robert Califf said he can see regulatory professionals querying a large language model (LLM) for answers instead of looking things up by hand. He noted that doctors already use retrieval-based tools as consultants. He also said that laws written around static systems need "significant updates" (RAPS, 17 September 2026).
His advice came with a condition. He told the audience to keep the gatekeeper role and to act as a continuous evaluator of data and signals, not only a one-time approver. In short, the assistant can fetch, but the professional still decides.
What did the UK commission recommend?
A commission created by the MHRA (the UK medicines and devices regulator) shared 44 recommendations on regulating AI in healthcare. It called for a shift from one-off pre-market assessment towards oversight across the whole lifecycle of a product. It also asked for proportionate rules and for function-based regulation of hybrid software, so that only the parts that qualify as a medical device are reviewed (RAPS, 17 September 2026).
The commission's own press release, dated 10 September 2026, stresses meaningful human oversight, with AI supporting clinicians rather than replacing their judgement (GOV.UK). These are recommendations to the UK government, not law, and they cover AI as part of a device or care pathway. They do not set rules for the tools you use to write your documents.
Does the EU MDR say anything about AI drafting tools?
The EU MDR (Regulation 2017/745) sets requirements for the clinical evaluation itself, not for the software you use to write it. Article 61(1) requires that conformity with the general safety and performance requirements rests on sufficient clinical evidence. Article 61(11) requires the clinical evaluation and its documentation to be updated throughout the device lifecycle with post-market data (MDR on EUR-Lex).
So the manufacturer stays responsible for the result, whatever tool produced the first draft. How a notified body views AI-assisted drafting can vary, so it is worth asking yours early. What every reviewer will test is the same: can you show how each conclusion was reached?
What makes AI-assisted CER drafting audit-ready?
Audit-ready means you can answer the reviewer's questions from records, not from memory. We think four practices cover most of it.
| Practice | The question an auditor may ask | Evidence to keep |
|---|---|---|
| Traceable sources | "Where does this statement come from?" | Each claim linked to a real reference. Search strategy, screening decisions and exclusion reasons recorded. |
| Human expert review | "Who checked this, and are they qualified?" | Named reviewer, review date, edits made to AI text, and sign-off on conclusions such as the benefit-risk assessment. |
| Versioned outputs | "What did the draft say when you made this decision?" | Version history and a change log showing who changed what and when. |
| Validation | "How do you know the tool is fit for this use?" | A written intended use for the tool, acceptance checks on sample outputs, and re-checks when the tool or model changes. |
Why do traceable sources matter most?
A CER is an argument built on evidence. An AI-drafted sentence with no source is an unsupported claim, however fluent it sounds. General-purpose chatbots can also produce references that do not exist, so every citation must be checked against the actual paper.
The safest pattern is to let the tool draft only from evidence you have already searched and screened. Then each statement can point back to a document and a screening decision.
What should human review actually cover?
Review is more than a proofread. The reviewer checks that the cited study really says what the text claims, that the conclusions follow, and that nothing was left out. They also own the judgement calls, such as equivalence, state of the art and benefit-risk.
Record the review. A sign-off with a name and a date is evidence; "we always check it" is not.
How should you version and validate AI outputs?
Treat AI-generated text like any other controlled document content. Keep drafts, reviews and approvals as separate, dated states, and log every change. Then a reviewer can see what the AI proposed and what a human accepted.
Validation follows your quality management system. If software supports a quality-system process, ISO 13485:2016 expects it to be validated for its intended use. Define what the tool is allowed to do, test it on known examples, and repeat the check whenever the model or the tool changes.
What does this look like in practice?
The diagram below shows the trail an auditor should be able to follow, from the first search to the approved document.

Here is an illustrative example. A team updates the state-of-the-art section of a CER for a class IIb device.
- They run and document a literature search, then screen the results, recording an inclusion or exclusion reason for every record.
- The AI drafts the section using only the included studies and cites each one.
- A regulatory specialist checks every citation against the source paper and rewrites anything the paper does not support.
- The section moves from draft to review to approved, and the log records each step.
When the auditor asks about a sentence, the team opens the reference, the screening record and the review entry. That takes minutes, not days.
What are the red flags of irresponsible AI use?
- Statements without references, or references nobody has opened.
- No record of who reviewed the AI text or what they changed.
- Conclusions such as benefit-risk written by the tool and approved without discussion.
- No documented intended use, testing or change control for the tool.
- Confidential device data pasted into public tools without a data-protection check.
How does Qmedify approach AI in regulatory documents?
We build the platform around the idea that the regulatory professional stays accountable. Every literature screening decision is recorded with a required rationale, and a validation check flags incomplete decisions before export. Documents move through a Draft, In Review, Approved and Issued workflow, with an edit history and audit log of who changed what and when.
AI suggestions for document fields can be reviewed and accepted or dismissed one by one. The goal is regulatory-grade AI that speeds up the work without taking the decision away from you.
Key takeaways
- The question has shifted from whether to use AI in regulatory work to how to defend its use.
- Voices from both sides of the Atlantic stress human oversight and lifecycle thinking.
- The EU MDR regulates the clinical evaluation, not the drafting tool, so accountability stays with the manufacturer.
- Audit-ready AI use rests on traceable sources, documented human review, versioned outputs and tool validation.
- Ask your notified body early how it views AI-assisted documentation.
FAQ
Can I use AI to draft a CER under the EU MDR?
The MDR does not prohibit it, but the CER must still meet Article 61 and Annex XIV, and you remain responsible for its content. Notified bodies may hold different expectations, so check with yours.
Do I have to tell my notified body that AI helped write the CER?
We are not aware of an MDR provision that requires it. Check your quality management system and your notified body's expectations, and consider being open about your process.
Is a general-purpose chatbot enough for CER work?
Usually not. It can invent references, it does not keep a record of your screening decisions, and it raises confidentiality questions. A tool that ties every statement to a screened source is easier to defend.
Do the MHRA commission's recommendations apply in the EU?
No. They are recommendations to the UK government about regulating AI in healthcare, not EU law. They are still a useful signal of where regulators' thinking is going.
Who should sign off AI-assisted content?
A qualified person with the right clinical and regulatory expertise, named and dated in your records. The tool never signs off.
Want to see how audit-ready AI drafting could work for your CER? Contact the Qmedify team.