|
AI Governance Just Got Teeth For the first time, the AI models in your stack have a regulator that can fine, evaluate, and recall them. Here is what landed this week and what it asks of you. Life Sciences CIO Weekly • Coverage: July 27 – August 2, 2026 Last week I wrote that the AI governance bar was rising on both sides, from regulators and from your own vendors. This week the bar stopped being a talking point. On August 2 the EU gained the power to fine AI model providers up to 3% of global revenue, and the models sitting inside your discovery, safety, and commercial tools are squarely in scope. The same week, Novartis handed a chunk of its IT operations to AI agents. Speed and governance showed up together, which is exactly the tension this digest keeps circling. As always, Joe’s Take notes turn the headlines into something you can use in this week’s staff meeting. The through-line: none of this is a challenge to hand the CIO alone. The organizations that come out ahead will name an accountable owner for AI governance before a regulator or a board asks who it is. 🤖 AI & DataICON embeds Anthropic’s Claude across clinical trial operationsOn July 28, CRO ICON announced a multi-year collaboration with Anthropic to run Claude across its Orbis agentic platform and the wider trial lifecycle: site intelligence, enrollment-risk detection, protocol optimization, and sponsor access to ICON insights inside Claude. It rolls out in role-based tiers, with Claude Science for clinical and scientific teams. This is a board-level foundation-model commitment, not a pilot, and it raises the bar for what “AI-enabled” trial operations should mean. 💬 Joe’s Take: This is a board-level bet, not a point tool, and that is exactly why the CIO has to stay close to it. A company far enough along to be pushing hard on enrollment and site selection has a lot of moving parts, and the upside is real if the AI solution is designed and structured well. When the board is named in a technology move like this, staying on top of it is not optional for the CIO. GSK signs up to $110M AI discovery deal with Relation TherapeuticsOn July 30, GSK inked a deal worth up to $110M with UK biotech Relation Therapeutics, the same day Relation unveiled MORGAN, a foundation model trained on large-scale multi-omic perturbation data. CEO David Roblin framed it as “a data problem as much as a modelling one.” The structure, lab automation generating proprietary data to train a model, is the build-versus-partner template CIOs overseeing R&D informatics will keep being asked to weigh. Ono Pharmaceutical embeds agentic AI “Biomni Lab” across discoveryAlso on July 28, Osaka-based Ono partnered with startup Phylo to deploy its Biomni Lab “integrated biology environment,” where AI agents reason over proprietary data, design experiments, and run computational tasks alongside scientists. It is another move from AI-as-tool to AI-as-agent embedded at the bench. ⚖️ Regulatory & PolicyEU AI Act enforcement powers go live for general-purpose AIOn August 2, the European Commission’s enforcement powers over general-purpose AI (GPAI) model providers took effect. The Commission can now demand technical documentation, run model evaluations, order mitigation up to market withdrawal, and levy fines of up to 3% of worldwide turnover or 15 million euros, whichever is higher. The exposure for life sciences is downstream: the foundation models inside your discovery, pharmacovigilance, regulatory-writing, and commercial tools are GPAI, and a company that integrates one into an EU-facing system becomes a “downstream provider” that depends on the upstream vendor’s documentation. 💬 Joe’s Take: This one demands IT leaders’ attention, and it is simply not a job that can be done alone. Sit down with your counterparts in quality, legal, and any business unit that has been running pilots on these models. Plenty of organizations jumped on the AI bandwagon ahead of the regulators, and anyone who leaned hard on those models could now be in a bind. Assess the exposure together, build a plan to mitigate it, and keep watching the regulatory backdrop so your plans stay defensible. Section 232 pharmaceutical tariffs take effect July 31U.S. Customs began enforcing a tiered Section 232 tariff on patented pharmaceutical imports on July 31. Generics get a two-year reprieve before rates of 100% to 200% arrive in 2028, leaving sponsors and CDMOs tracking two timelines at once. Duty classification, landed-cost math, and country-of-origin tracking for APIs and finished product now need more granularity than most legacy trade-compliance modules carry. 💬 Joe’s Take: This is another instance where working shoulder to shoulder with the business is critical. The job is making sure the data associated with those imported APIs is clean and granular enough to blunt the financial hit. For most pharma, that data and information will run through the existing supply chain systems, so those systems need enough functionality to track it, and both IT and the business have to stay on the requirements. Get that right and you avoid an ugly surprise on the P&L later. EU medicines regulators shift from AI “adoption” to “implementation”The EMA and Heads of Medicines Agencies published their second annual AI Observatory report (analysis dated July 31), explicitly reframing from mapping AI’s potential to practical implementation. The 2026 to 2028 workplan foresees new guidance on AI in manufacturing, pharmacovigilance, and clinical development. Read alongside the enforcement milestone above, the message is one direction of travel: map your AI tools against that roadmap now rather than waiting for final text. FDA finalizes guidance curbing overly restrictive cancer trial eligibilityOn July 28, FDA finalized three oncology eligibility guidances, including one on washout periods and concomitant medications, directing sponsors to justify exclusions with drug-specific rationale rather than copy-forward boilerplate. For clinical-systems leads, that means auditing protocol-template libraries and CTMS eligibility defaults, since standardized exclusions carried across studies are now a named enrollment-risk and compliance factor. 🔒 Cybersecurity & RiskAmgen discloses a material breach, and the data came out of a third-party cloudIn a July 31 SEC 8-K, Amgen said proprietary data and protected patient health information were exfiltrated from a third-party cloud environment, not its own core systems. It found no impact to products, manufacturing, or financial reporting. Because the stolen data includes PHI, the SEC materiality clock and a HIPAA breach-notification clock now run in parallel, on different deadlines, with a business-associate agreement determining who notifies first. 💬 Joe’s Take: We have always lived with regulatory clocks. What is new is that there are several of them now, and some belong to the vendors whose infrastructure we rely on. As more of our data moves into third-party cloud environments, more of these breaches are landing there rather than in the company’s own systems, which makes the response trickier. The real work is coordinating with those third parties so the regulatory and financial risk gets managed jointly, not in isolation. CISA and Five Eyes publish “CI Fortify” guidance on isolating OTOn July 28, CISA and partners released CI Fortify, a six-step method for isolating operational technology during an incident, with explicit attention to hidden IT-to-OT dependencies like shared Active Directory, DNS, and backup services. Written for critical infrastructure broadly, it maps directly onto pharma production lines, cleanroom controls, and cold-chain systems. Treat it as a benchmark for auditing whether your plant-floor OT can actually be separated from corporate IT on demand. Spanish biopharma Diater listed on the DeadLock ransomware leak siteMadrid allergy-immunotherapy firm Diater was listed by the Russia-linked DeadLock group in a double-extortion claim, with attackers citing quality-management files and up to a decade of patient records. The company has not confirmed it. The point for CIOs: mid-size specialty manufacturers hold clinical-grade data on thin security budgets, which makes them, and the smaller partners in your data-sharing chain, preferred targets. Extend vendor due diligence past your top tier. 🎯 Leadership & Operating ModelNovartis hands global IT operations to agentic AI in expanded Cognizant dealOn July 27, Novartis and Cognizant expanded a 20-year relationship into a five-year deal to run Novartis’s applications, infrastructure, security, and digital workplace through an agentic, automation-driven operating model. The goal is predictive operations, autonomous self-service, and AI-led engineering across the estate. This is a top-10 pharma restructuring how it resources and governs core IT, not a pilot in a corner. 💬 Joe’s Take: It is not clear yet exactly what is being handed to the agents, and that is the point. Before anyone does this, run a real risk assessment across all processes, and wherever a step scores high risk, keep a human in the loop. Lean on agents for the routine, repetitive, low-risk work, and stay cautious with the high-risk and difficult tasks. The relationship will improve over time, but the guardrails and human checkpoints have to be there from day one. Merck names Gaurav Gupta as EVP and Chief Information & Digital OfficerMerck appointed Gaurav Gupta as CIDO effective September 1, succeeding the retiring Dave Williams. Gupta comes from 27 years at EY’s life sciences digital practice, with a consolidated mandate over IT, enterprise data, cybersecurity, and digital strategy. Two signals worth noting: the single-executive CIDO scope, and a consulting-transformation background rather than an internal IT career path, which may say something about the profile boards now want at the top of technology. GSK ties a 1.9 billion pound restructuring to AI and support-services cutsOn its July 28 earnings call, GSK unveiled a three-year plan targeting about 1.9 billion pounds in annual savings, with AI adoption and support-services streamlining as primary levers (roughly 45% of savings), paired with plans to nearly double Phase 3 trial starts. Analysts called it double what they expected. It is one of the year’s clearest examples of a board putting AI to work as a support-function cost lever, alongside the more familiar R&D productivity case. Risk rarely arrives aloneIn the same week as its breach disclosure, Amgen also confirmed roughly 40 layoffs and an active FDA dispute over its Tavneos withdrawal. One company, three high-visibility risk events inside seven days. It is a clean reminder that operating-model, regulatory, and cyber risks tend to compound at once, and that enterprise risk dashboards should correlate them rather than track each in its own lane. 💬 The Bottom Line — Joe’s TakeThe theme this week is that AI’s pace is forcing technology leaders to think strategically across a lot of fronts at once, and to advise the rest of the C-suite while they do it. There are pitfalls only the CIO sees clearly, because judging where the technology is mature enough, and where a human still belongs in the loop, comes down to how it actually works under the hood. The business will have instincts here, but the CIO is best positioned to give that granular read. More than ever, this week shows the CIO has to be a business leader who brings technical judgment, not only a technologist. Ready to move beyond the digest? The LS CIO Community is where these conversations continue. This digest is an interpretive summary of publicly available information and does not constitute legal, regulatory, cybersecurity, or investment advice. Until next week, Founder, Leadership Inklings |