The EU AI Act Caught Up to How Pharmacovigilance Already Works

It’s late on a Tuesday, and a pharmacovigilance officer at a mid-sized biotech is reading an adverse event report an AI tool drafted twenty minutes earlier. The draft is good — plausible causality assessment, the right terminology, a clean narrative. It is also, as far as she’s concerned, not yet real. Before it goes into the safety database, a qualified person has to read it, agree with it or correct it, and put their name behind the judgment. That’s not a formality specific to one company’s SOPs. It’s the definition of pharmacovigilance.

What Actually Changed on August 2

On August 2, 2026, that instinct — a human accountable for the call, whatever produced the first draft — became something the EU AI Act requires by law, at least in part. The Act’s Article 50 transparency obligations took effect exactly on schedule that day: AI chatbots and virtual assistants used in patient or provider communication must disclose that they’re AI; AI-generated or AI-assisted patient materials containing synthetic audio, image, or video have to be marked as such; anywhere emotion-recognition or biometric-categorization tools are in use, the people exposed to them have to be told. The penalties for getting this wrong reach €15 million or 3% of global annual turnover — not a rounding error for anyone.

What didn’t happen on schedule is the part most regulatory affairs teams had actually been bracing for. The Annex III high-risk obligations — the detailed requirements around technical documentation, risk management systems, and formal human oversight that were meant to apply to standalone high-risk AI starting this August — got pushed to December 2, 2027 by the EU’s Digital Omnibus, which itself only entered into force on July 27, 2026. AI embedded in already-regulated products, which under Annex I is likely to cover a meaningful share of AI functionality built into medical devices, now has until August 2, 2028. Whether a specific clinical AI tool ultimately lands under the standalone timeline or the product-embedded one is a classification question for your own regulatory affairs and legal teams to work through, not something a blog post should try to settle. What’s consistent either way is that the substance of what’s required hasn’t changed. Only the calendar has.

An Industry That Was Already Ahead

For most industries, a delay like that is unambiguously good news — more time before the compliance burden lands. For life sciences, it’s something slightly different: confirmation of a head start the industry already had. Pharmacovigilance doesn’t run on human accountability because a regulation demands it. It runs that way because a missed or misjudged safety signal has consequences no automated system should be trusted to own alone. The Act’s high-risk provisions, whenever they fully land, are going to ask every regulated industry to formally document that a qualified human reviews and is accountable for AI-assisted output. Life sciences has been doing the substance of that for longer than the AI Act has existed; what’s new is the expectation that you can prove it, on paper, on request.

That proof matters because AI is already woven into more of this work than most organizations have fully inventoried: drafting and triage support for adverse event reportsclinical trial documentation from protocol through informed consent materials, patient-facing leaflets and instructions translated across a dozen EU languages, regulatory submissions that have to read identically — in substance, not just in words — to the EMA and to every national authority that receives them. None of that has been waiting for December 2027 to become someone’s responsibility. It already is.

Turning an Instinct Into a Documented System

What the runway between now and 2027 is actually for is turning an operating instinct into a documented one: mapping which AI-assisted workflows touch EU-regulated content, naming a qualified reviewer of record for each rather than leaving oversight informal, and treating the multilingual layer of that work as part of the safety case rather than a translation afterthought — because a signal that’s accurate in the source language and imprecise once it crosses into another isn’t really a signal that’s been reviewed at all. None of this asks pharmacovigilance to adopt a new discipline. It asks the existing one to be written down.

How BIG Can Help

BIG Language Solutions’ pharmacovigilance and regulatory translation work already runs on this model — AI supports the first pass, and a qualified linguist, often with grounding in drug safety and regulatory language, reviews and is accountable for what goes out. It’s the same human-in-the-loop discipline behind our neural machine translation post-editing (NMTPE) workflows, applied to some of the most audited content in any industry. If you’re already thinking through how that discipline needs to formalize before 2027 and 2028, we’d welcome the conversation — including in person. BIG will be at World Patient Safety Congress Europe 2026 in Amsterdam, September 22–24, booth #512.

EXPERIENCE THE BIG DIFFERENCE TODAY

See how BIG Language Solutions
can work for your business.