Regulatory Fragmentation Hinders AI Personalized Medicine, 2030
- Authority
- U.S. Food and Drug Administration
- Rule type
- guidance
- Jurisdiction scope
- US federal
- Effective date
- Jan 1, 2025
- Source text
- Read primary rule text ↗
Risk-based credibility assessment for AI in drug development
An AI-personalized therapy can change the legally relevant facts faster than the legal file built around it. A model may help select a patient-specific molecule, tune a cell therapy process, update from new clinical or real-world data, or move between research, manufacturing, clinical decision support, and post-market monitoring. The law still asks more static questions: What is the product? Who is the manufacturer? What indication is being claimed? Which regulator has territorial authority? Which dossier is complete enough to sign?
That is the practical center of legal regulation for AI healthcare and personalized medicine through 2030. The problem is not that regulators are merely slow. It is that adaptive, patient-specific AI systems do not map cleanly onto approval categories designed around stable products, fixed manufacturing processes, and jurisdiction-specific submissions. This analysis is current as of Q3 2026, focuses on adaptive AI-powered personalized therapies, and is not legal advice.

The useful starting point is not a jurisdiction; it is a failure diagnostic
Derraz et al. provide the cleanest diagnostic vocabulary for the problem: outdatedness, over-extension, fragmentation, contradiction, divergence, complexity, and over- or under-stringency. Their article is specifically about AI-based personalized drug and cell therapies in precision oncology, so using it for broader personalized medicine requires a synthesis step. The extension is defensible because the same legal friction appears whenever an AI-enabled intervention is patient-specific, clinically adaptive, and difficult to pin to a single pre-market product file. It is still an extension, not a direct claim by the authors about every form of personalized medicine. [1]
| Failure category | What it catches in AI-personalized therapy regulation |
|---|---|
| Outdatedness | Rules assume a stable product, while the relevant AI, manufacturing, or clinical-selection logic may evolve. |
| Over-extension | Existing drug, device, laboratory, software, or clinical-practice categories are stretched to cover systems they were not built to govern. |
| Fragmentation | FDA, EU AI Act, MDR/IVDR, state healthcare AI laws, and nonbinding international guidance impose different obligations on adjacent activities. |
| Contradiction | One layer may demand speed, updating, or transparency while another layer rewards frozen specifications, narrow claims, or controlled disclosure. |
| Divergence | Jurisdictions define and allocate responsibility differently, especially when the same model supports discovery, selection, manufacturing, and monitoring. |
| Complexity | Compliance work becomes an operational system of audits, evidence packages, contracts, disclosures, and re-review triggers. |
| Over- or under-stringency | Some low-risk uses may be burdened heavily, while high-impact upstream or operational uses may sit outside the main review pathway. |
The table is tidy; the compliance landscape is not. Each new legal instrument can be rational on its own terms. A drug regulator reasonably asks whether an AI model used in development is credible for its proposed context. A product-safety regime reasonably classifies medical AI as high risk. A state legislature reasonably worries that patients will be misled by automated healthcare communications. The mismatch worsens when those rational layers accumulate without agreeing on the regulated object.
FDA’s risk-based approach narrows one lane and leaves others unresolved
The FDA’s January 2025 draft guidance on AI in drug development is a serious attempt to regulate by risk and credibility rather than by slogans. As described by FDLI, the draft guidance uses a risk-based credibility assessment framework for AI use in drug development, but it expressly excludes early-stage discovery and operational AI from its scope. [2]
That scoping decision is defensible. No agency guidance can sensibly govern every internal model used by a sponsor, every vendor tool, and every downstream clinical use at once. But the exclusion matters for personalized therapies because the legally consequential work may happen before the conventional submission boundary. If an AI system helps identify a target, select a patient subgroup, design a construct, optimize a manufacturing step, or decide whether a patient’s sample meets a therapy-specific profile, the compliance question is not simply whether the final dossier contains AI-generated evidence. The question is whether the development chain has produced a therapy whose safety, identity, potency, or claimed clinical rationale depends on model behavior that may sit partly outside the draft guidance.
This is where outdatedness and under-stringency can coexist. The inherited drug-approval file still expects a sponsor to present a product, a method, data, and controls. The AI-specific guidance, meanwhile, may apply only to certain model uses within that file. A developer can comply with the guidance and still face unresolved questions about upstream model governance, vendor change control, training-data provenance, and whether a model update should trigger internal revalidation, agency notification, or no formal regulatory event at all.
For legal and regulatory teams, the immediate work is therefore not to label the FDA approach as permissive or restrictive. It is to map every AI function to its legal consequence: evidence generation, patient selection, manufacturing control, clinical recommendation, post-market monitoring, or administrative support. The same model architecture can create different legal exposures depending on which verb it performs.
Europe is trying to simplify a system whose layers do not yet point in one direction
The EU problem is not merely that the AI Act exists alongside medical-device law. It is that companies developing AI-enabled medical technologies must plan under more than one possible simplification path. Harvard’s Petrie-Flom Center described two diverging routes in March 2026: the Digital Omnibus path and a DG SANTE proposal to amend the MDR/IVDR framework. The point for developers is strategic uncertainty, not just administrative burden, because the final relationship between general AI obligations and sector-specific medical technology rules remained in flux. [3]
The May 7, 2026 Digital Omnibus political agreement did not remove medical technologies from high-risk AI Act treatment. MedTech Europe’s response treated that point as confirmation that AI-enabled medical technologies remain subject to high-risk AI Act requirements, while industry continued to call for one coherent framework. [4]
That matters because the EU stack can make fragmentation look like harmonization. A high-risk AI classification may impose risk management, data governance, documentation, transparency, human oversight, accuracy, robustness, and cybersecurity expectations. MDR or IVDR processes may separately require clinical evaluation, conformity assessment, quality management, post-market surveillance, and notified-body interaction. A personalized therapy system may not sit neatly inside one medical-device file if its AI affects drug design, cellular manufacturing, diagnostic stratification, or treatment selection.
The contradiction is subtle. One policy layer encourages ongoing monitoring and improvement of AI systems. Another layer, for good reasons, asks what has changed since the conformity assessment or authorization. In a static device, that tension is manageable. In an adaptive personalized therapy, it becomes a release-management problem with legal consequences: which model change is routine maintenance, which is a substantial modification, which changes the intended purpose, and which requires a new clinical or performance evidence package?
US state laws add conduct risk before product-law answers settle
The state-law layer is not a substitute for FDA review and should not be described as if it were. It is a separate source of disclosure, conduct, and enforcement exposure. Fenwick’s 2025 analysis identifies California AB 489, Illinois WOPRA, Nevada AB 406, and Texas TRAIGA as part of the new state-level healthcare AI compliance reality, with enacted 2025 laws, varying effective dates, different enforcement mechanisms, and penalties described in the $10,000 to $15,000 per-instance range. [5]
For a developer, this patchwork changes the order of compliance work. The company may not yet know whether a future FDA submission will treat a model output as pivotal evidence, supportive evidence, software functionality, manufacturing control, or clinical decision support. But state law may already require decisions about patient-facing disclosures, provider communications, prohibited or regulated AI conduct, contracting language, and internal escalation for covered uses.
The enforcement history is still immature, so the risk assessment should be probabilistic rather than theatrical. The absence of a large enforcement record does not make the obligations irrelevant. It means the compliance officer is left to design controls before courts and agencies have supplied much interpretive texture. That is expensive in a different way from a filing fee: the organization must choose definitions, training, workflow restrictions, and audit trails without knowing which version of diligence will later be treated as sufficient.
State statutes also sharpen the divergence problem. A therapy developer with clinical sites, telehealth touchpoints, laboratory partners, and patient-support programs across multiple states may have one federal product strategy and several state conduct strategies. The regulated artifact is no longer just the therapy candidate. It is the communication about the AI system, the human review process around it, the commercial setting in which it appears, and the state in which the patient or provider encounters it.

Complexity becomes a budget line, not a governance aspiration
Responsible AI oversight often sounds abstract until the invoice arrives. Harvard Gazette coverage of I. Glenn Cohen’s analysis reported an estimated $300,000 to $500,000 cost per algorithm for vetting, and discussed The Joint Commission and Coalition for Health AI recommendations from September 2025, including the idea of assurance labs. [6]
Those figures are not proof that every personalized therapy model will cost that amount to review, and they should not be casually imported into every budget. Their value is diagnostic. They show why “audit the algorithm” is not a trivial operational instruction. If a personalized therapy platform uses separate models for target selection, candidate design, eligibility matching, manufacturing deviation detection, adverse-event signal review, and clinician-facing recommendations, the question becomes which algorithms require what form of vetting, by whom, and at what interval.
Assurance labs may reduce duplication if regulators, hospitals, payers, and developers accept their outputs. They may also become another layer if their work does not align with FDA submissions, EU technical documentation, state-law disclosure duties, or institutional review requirements. The compliance value of third-party assurance depends less on the elegance of the audit report than on whether the relevant legal regimes treat that report as meaningful evidence.
Soft law can shape expectations, but it cannot sign the application
International guidance, including WHO ethics and regulatory-considerations materials, can be useful for board governance, policy drafting, and cross-border vocabulary. It should not be allowed to impersonate enforceable harmonization. Soft law may influence what regulators, hospitals, procurement teams, and plaintiffs’ lawyers regard as responsible conduct. It does not itself replace an FDA submission, an EU conformity assessment, a state-law disclosure analysis, or a local clinical-practice rule.
The same caution applies when companies compare the United States, European Union, United Kingdom, Japan, and China. MHRA, PMDA, NMPA, FDA, and EU bodies may all be engaging with AI and medical innovation, but engagement is not equivalence. For a personalized therapy developer, the practical question is not whether every jurisdiction recognizes that AI matters. The question is whether the same model update, manufacturing change, or patient-selection rule triggers the same classification, evidence demand, filing obligation, and post-market duty. In most product roadmaps, the safer assumption is that it will not.
What the 2030 roadmap should assume if current trends continue
The year 2030 is a planning horizon here, not a statutory effective date and not a prediction that a particular law will say a particular thing. The defensible forecast is structural: if present trends continue, AI-personalized therapy developers should expect more compliance tracks, not fewer.
| 2030 planning assumption | Developer-facing consequence |
|---|---|
| Multi-track submissions | One development program may require FDA drug-development credibility work, EU AI Act documentation, MDR/IVDR analysis where applicable, state-law controls, and local clinical governance materials. |
| Inconsistent definitions | The same system may be described as AI, software, clinical decision support, manufacturing analytics, drug-development evidence, or medical technology depending on jurisdiction and use. |
| Overlapping assurance demands | Model validation, bias assessment, cybersecurity review, data-governance controls, human oversight, and post-market monitoring may be requested by different institutions in different formats. |
| Uncertain update triggers | A model change may require internal documentation only in one setting, contractual notice in another, regulator engagement in another, and renewed clinical or performance evidence in another. |
| Earlier state and institutional scrutiny | Hospitals, state regulators, procurement teams, and clinical partners may require disclosures and audit evidence before the central product-law question is finally resolved. |
The most difficult internal governance question will be validation scope. Traditional validation asks whether a defined product or process meets defined requirements. Adaptive personalized systems require a more layered answer: whether the model was trained and tested appropriately, whether it remains credible for the intended context, whether the patient-specific output can be explained or bounded, whether human review is meaningful, and whether changes in data, practice patterns, or manufacturing conditions have degraded performance.
Disclosure will also be harder than the usual transparency language suggests. A patient-facing notice that AI is used in a care pathway may satisfy one conduct obligation and do little for product approval. A technical appendix prepared for a regulator may be useless to a patient or clinician. A vendor audit report may help procurement and still fail to answer whether a therapy-specific model output changed the clinical risk-benefit case. By 2030, the better-run companies will not ask whether they have an “AI disclosure.” They will maintain a disclosure matrix tied to audience, jurisdiction, use case, and legal function.
Audit design will need the same discipline. A single enterprise AI policy is unlikely to carry a personalized therapy platform through regulatory review, clinical adoption, and state-law scrutiny. The audit trail will need to show who approved the model for a particular use, what evidence supported that approval, what monitoring thresholds apply, who reviews drift or failure signals, what vendor changes must be escalated, and when a change is material enough to reopen regulatory analysis.
The consequence for product planning is blunt: regulatory strategy must move upstream. If legal review begins when the clinical package is nearly complete, it will be too late to reconstruct why a model was selected, what data were excluded, which patient subgroups were underrepresented, whether updates were controlled, and who had authority to override or retire the system. The compliance file for an adaptive personalized therapy starts when the model enters the development chain, not when the submission clock starts.
The serious reform counterpoint: AI2ET
The strongest reform material in the current literature is the AI-enabled Ecosystem for Therapeutics, or AI2ET, framework proposed in Frontiers in Medicine in 2025. The proposal reimagines drug regulation around an AI-enabled therapeutic ecosystem rather than treating AI as a marginal tool bolted onto legacy drug-development categories. [7]
AI2ET is important because it addresses the level at which the mismatch actually occurs. Personalized AI therapies are not just products with unusual documentation. They are systems of data, models, sponsors, clinical sites, manufacturing processes, regulators, and post-market learning loops. An ecosystem framework could, in principle, make it easier to align evidence standards, model governance, lifecycle monitoring, and accountability across the therapeutic chain.
It is not, however, a compliance safe harbor. A framework article does not amend the Federal Food, Drug, and Cosmetic Act, rewrite the EU AI Act, resolve MDR/IVDR negotiations, preempt state law, or bind foreign regulators. Its value is directional: it shows the kind of institutional redesign that would have to gain traction for the 2030 trajectory to change.
The default forecast
The seven-category diagnostic from Derraz et al. does not show a system failing because no one is paying attention. It shows a system in which attention is producing more layers before it produces fit. FDA’s scoped risk-based guidance, the EU’s unsettled AI Act and MDR/IVDR relationship, 2025 state healthcare AI laws, assurance-lab proposals, and soft-law ethics frameworks may each respond to a real governance need. Together, they leave the developer of an adaptive AI-personalized therapy with more questions about what must be validated, disclosed, audited, frozen, updated, or re-reviewed.
By 2030, fragmentation should be treated as the default planning assumption. Transformative reform may arrive, and AI2ET is the kind of proposal worth monitoring closely. Until it changes binding law, regulatory affairs teams should build product roadmaps for a world of overlapping authorities, inconsistent definitions, and jurisdiction-specific evidence demands.
References
- New regulatory thinking is needed for AI-based personalised drug and cell therapies in precision oncology, Nature npj Precision Oncology, 2024.
- Regulating the Use of AI in Drug Development: Legal Challenges and Compliance Strategies, FDLI, July 2025.
- Simplification or Back to Square One? The Future of EU Medical AI Regulation, Harvard Petrie-Flom Center, March 5, 2026.
- Joint industry voice calls for one coherent framework for AI-enabled medical technologies, MedTech Europe, May 7, 2026.
- The New Regulatory Reality for AI in Healthcare: How Certain States Are Reshaping Compliance, Fenwick, 2025.
- AI is speeding into healthcare. Who should regulate it?, Harvard Gazette, January 2026.
- Reimagining drug regulation in the age of AI: a framework for the AI-enabled Ecosystem for Therapeutics (AI2ET), Frontiers in Medicine, 2025.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →