Life Sciences CIOs Digest

Can You Prove What the AI Did?

Veeva’s agent builds your study in a day. FDA now accepts computer models as evidence. The audit trail is your problem.

Life Sciences CIO Weekly • Coverage: September 21 – 27, 2026


Last week we asked whether you can show your work. This week the question gets sharper, because AI is being let into the regulated record itself. Veeva released an agent that builds a clinical study straight from the protocol. FDA rewrote its rules so computer models count as preclinical evidence, and the UK regulator asked how those models are validated. The cyber news came from outside the walls: a file-transfer vendor told customers to unplug, and federal agencies warned about the integrators who hold plant blueprints. Tools and partners can take on more of the work, and the responsibility for what they produce stays with you.

🔍 The Quick Read

  • AI & Data — Veeva shipped an agent that configures EDC studies from the protocol, and EU regulators set a forum on the data foundations under pharma AI.
  • Regulatory & Policy — FDA now calls animal studies “nonclinical” and names computer models as acceptable, while the MHRA asked how AI safety models are validated.
  • Cybersecurity & Risk — Kiteworks told customers to shut down their servers, Boston Scientific traced its attack to one exposed device, and CISA and the FBI warned about ICS integrators.
  • Leadership & Operating Model — BD hired Lenovo’s former CIO as chief information and digital officer reporting to the CEO, and nine pharma chairs warned Europe is losing ground.

Reading something a colleague should see? Copy the section that fits their world and pass it along, or forward the whole edition. And if this reached you from someone else, you can subscribe free here to get it every week.


🤖 AI & Data

Veeva’s new agent builds an EDC study from the protocol “in as little as one day” ↗

A mainstream clinical platform is handing a validated build step to an AI agent, which moves the hard question to review and sign-off.

On September 24, 2026, Veeva Systems announced Study Builder Agent. It reads a clinical protocol and configures Veeva EDC and Veeva Data Quality System, generating forms, visit schedules, edit checks, data listings, and test data. It uses each sponsor’s own standards and the CDISC Unified Study Definitions Model. Veeva says work that usually takes weeks can be done in as little as a day. The agent ships as a Claude Cowork plugin from a Veeva-managed GitHub repository, so it runs in Anthropic’s desktop agent rather than only inside Veeva’s application. Early-adopter access starts in December, with no license needed beyond EDC. Independent coverage noted the one-day figure is not yet backed by customer results (RuntimeWire).

💬 Joe’s Take: Strip away the headline and this is what many of us already do with AI at our own desks. The agent does the grunt work and hands back a draft build.

What happens next is the same old question: do you throw it over the transom, or put people in the loop to verify it before it touches a live trial? A study build carries real regulatory exposure, so it needs the same review cycle whether an agent built it in a day or a small team built it in a month. Put some of the time the agent saves back into that review.

What to watch: Ask how agent-built edit checks and forms are reviewed, versioned, and tested before go-live, and where the audit trail lives when the agent runs in a third-party desktop client.

EU regulators set a forum on “trustworthy AI on strong data foundations” ↗

European regulators are shifting the AI conversation from principles to the data plumbing underneath.

On September 24, 2026, the Heads of Medicines Agencies and the European Medicines Agency announced an AI and Data Forum for November 12 and 13 in Amsterdam and online. Topics include AI across the medicines lifecycle, the evolving EU rules, and data governance, quality, and interoperability. Its conclusions feed the Network Data Steering Group’s 2026 to 2028 workplan (EMA). It follows the ten FDA and EMA good AI practice principles issued in January.

What to watch: If AI governance and GxP data integrity run as separate programs in your company, this is the push to bring them together around provenance and model lineage.

AbbVie signs an AI discovery deal as money pours into AI biotechs ↗

Each new AI discovery alliance is also a new data-sharing relationship to govern.

On September 21, 2026, AbbVie and Iambic Therapeutics announced a multi-year deal to design small molecules in immunology, neuroscience, and oncology with Iambic’s AI models. In the same week, Enveda raised a $311 million Series E, Basecamp Research closed $140 million with Anthropic’s fund and NVIDIA among its backers, and Genentech agreed a deal worth more than $1.5 billion with AI antibody designer Earendil Labs (BioSpace). BioPharma Dive counts at least 12 AI drug discovery startups with rounds above $100 million since early 2024 (BioPharma Dive).

What to watch: Standardize the playbook for what compound and assay data leaves the building, under what model-training terms, and how results come back in, rather than negotiating it deal by deal.

Anthropic says Claude agents found a new CRISPR-like enzyme system ↗

An AI lab now runs its own wet lab to confirm what its agents propose, and scientists are already pushing back on the claim.

On September 23, 2026, Anthropic reported that about 950 Claude agents, working for roughly 21 hours, screened more than 200,000 reverse transcriptases and surfaced a system it calls array-associated reverse transcriptases. Twenty candidates went to human review, and Anthropic scientists confirmed the proteins in the company’s own lab. The system’s function is still unknown. Two days later, scientists quoted by Bloomberg Law said the significance was overstated.

What to watch: Expect R&D to ask for bursts of agent compute, governed access to sequence and assay data, and records showing which agent proposed which candidate.


⚖️ Regulatory & Policy

FDA opens its rules to computer models as MHRA asks how AI safety models are validated ↗

Two regulators in two days made room for computational evidence, which pulls preclinical computing toward regulatory-grade controls.

On September 21, 2026, FDA issued a direct final rule replacing “animal tests” with “nonclinical tests” across its drug and biologic regulations. Animal studies remain allowed and the evidence bar is unchanged. What the rule adds is explicit acceptance of human cell-based methods, organs-on-chips, and computer models. FDA also launched a database of 25 real examples of these new methods from its own reviews. One day later, the UK MHRA opened “Beyond ADMET,” a call for evidence on how companies use AI to predict drug safety problems early, and on the barriers they face in validation and data sharing (GOV.UK). It will shape a regulatory sandbox and closes December 22.

💬 Joe’s Take: Letting computer models stand in for some animal studies is a real shift, and it pulls preclinical computing toward the rigor we have kept for GxP systems. The quieter risk is that we get used to impressive output and stop checking it, as individuals and as companies.

A faster, more polished result does nothing to remove the duty to verify it, and you will need to reproduce that model’s answer years from now when it shows up in a submission. Use the tools well, pay attention, and remember the human is still in charge.

What to watch: Coordinate one company response to the MHRA survey across toxicology, data science, and IT, so the validation and data-sharing limits your teams face are on the record.

FDA drafts guidance for robotic surgical systems and sets a workshop on autonomy ↗

Remote operation turns network reliability and security into part of the device safety case.

On September 24, 2026, FDA published draft premarket guidance for robotically-assisted surgical devices, which it calls “teleoperated, software-controlled systems.” Comments are due November 24. FDA also set a December 2 and 3 workshop on devices with autonomous or remote teleoperation features (Federal Register).

What to watch: Medtech IT and product-security leads should engage early on the connectivity, latency, and logging evidence FDA is likely to expect.


🔒 Cybersecurity & Risk

Kiteworks tells customers to shut down their servers over a possible zero-day ↗

A vendor ordered a shutdown of the channel many sponsors use to move regulated files.

On September 25, 2026, Kiteworks, the secure file-transfer platform formerly known as Accellion, told customers to take their systems offline for a weekend window. Its CISO said the company had received “credible threat intelligence from federal intelligence authorities” that a threat actor may target some Kiteworks systems (Kiteworks). No compromise was confirmed, no CVE was published, and customers were told to run release 9.5.1. In 2020 and 2021 the Clop gang used zero-days in Accellion’s older file-transfer product to steal data from many large organizations.

💬 Joe’s Take: A core service provider telling customers to pull the plug is a big deal, and it shows how far our risk surface now reaches past our own walls.

I would want the CIO to have a live view of critical outside dependencies, watched for health like any other piece of infrastructure, not a diagram on the wall. Before that call comes, know what breaks, what the fallback channel is, and who can approve a weekend shutdown.

What to watch: Check whether Kiteworks or a similar tool sits in your estate or your CRO and CMO partners’ estates, and confirm they are on 9.5.1.

CISA and FBI warn about the integrators who hold your plant blueprints ↗

One breached integrator can expose the plant networks of many companies at once.

This week CISA and the FBI issued a fact sheet on third-party industrial control system integrators. They cited a 2025 breach in which foreign actors staged about 800 network diagrams, device configurations, and customer records taken from a US automation integrator. The agencies recommend least-privilege access, security terms in contracts, logged remote sessions, and access granted on demand rather than left always on. Separately, NIST released a draft revision of its main operational technology security guide, SP 800-82, adding cloud and industrial IoT and a zero trust architecture. Comments are due November 30.

💬 Joe’s Take: Some of the most sensitive documents about our networks, like diagrams and device configurations, sit with integrators and service providers outside our control. That is a risk amplifier.

Should access to that material expire by default, or live inside our walls behind credentials that time out? Just-in-time access and rights-managed documents exist; the harder part is requiring them of every partner. If you have made this work, I would like to hear how.

What to watch: Inventory every integrator with access to plant or lab systems, own the credentials, and require proof that copies of your configurations are deleted when the work ends.

Boston Scientific traces its attack to one exposed network device ↗

The plants were never touched, and production still stopped for nearly two weeks.

On September 22, 2026, Boston Scientific published the final CrowdStrike findings on its August 25 attack. The attacker got in through an external-facing network device and reached a limited part of the on-premises IT environment. Investigators found no compromise of manufacturing systems, SCADA, cloud applications, or device-maintenance systems. Even so, the company’s September 8 filing said the outage halted production and shipping for nearly two weeks and would likely cause it to miss 2026 guidance (8-K).

What to watch: Treat internet-facing appliances as priority assets, and map which plant operations depend on enterprise IT for orders, scheduling, and release.

Labcorp settles with 44 states and agrees to a vendor-security overhaul ↗

A seven-year-old vendor breach still produced a regulator-written checklist for third-party risk.

This week 44 state attorneys general announced a $2.3 million settlement with Labcorp over the 2019 breach at its collections vendor, which exposed data on 10.2 million Labcorp customers. Labcorp must restrict what it shares with vendors, create a dedicated vendor-risk team, put security terms in every vendor contract, audit vendors regularly, and retain an independent assessor.

What to watch: Benchmark vendors that hold patient, trial, or HCP data against this list, and confirm that offboarding really removes their data and access.


🎯 Leadership & Operating Model

BD hires Lenovo’s Arthur Hu as chief information and digital officer ↗

A combined title, a CEO reporting line, and an explicit AI mandate give peers a benchmark.

On September 21, 2026, BD named Arthur Hu executive vice president and chief information and digital officer, effective September 30, reporting to CEO Tom Polen. Hu was global CIO of Lenovo’s Solutions and Services Group and spent a decade at McKinsey. His mandate is to modernize enterprise systems and embed AI across operations. Current CIO Denise Russell Fleming retires at year-end (MedTech Dive).

What to watch: Expect boards to ask whether their own technology leadership role is scoped for an enterprise AI mandate.

Nine pharma chairs warn Europe is losing ground ↗

Where trials and R&D move, data residency and platform choices follow.

On September 23, 2026, the chairs of AstraZeneca, Boehringer Ingelheim, Chiesi, Ipsen, GSK, Novo, Novartis, Roche, and Sanofi warned that Europe’s share of global pharma R&D has fallen from 43 percent in 1990 to 31 percent. Its share of commercial clinical studies has halved in a decade to 9 percent. They asked for faster trials, stronger IP, and “sensible digital policies.” A week earlier, the industry group EFPIA warned that the EU Cloud and AI Development Act must not become de facto data localization (EFPIA).

What to watch: Model how EU sovereignty rules and a shifting trial footprint would change your data residency and cloud architecture.

BMS cuts 265 more headquarters roles ↗

Headquarters cuts under savings programs often assume automation will absorb the work.

A New Jersey filing reported September 22, 2026 shows Bristol Myers Squibb will cut 265 roles at its Princeton headquarters between December and May. That brings its 2026 New Jersey cuts to 718, in support of a $2 billion annual savings target by the end of 2027. The affected functions were not disclosed.

What to watch: Know which processes can run with fewer people without control risk, and tighten access removal and knowledge transfer before departures.


💬 The Bottom Line — Joe’s Take

Leadership wants us to lean into AI, and the competitive case is real. This week AI moved from pilots into regulated workflows and regulatory evidence faster than most validation and governance programs have adapted, and the risk to the company is rising right along with the benefit.

Even the people building these models are saying so. On September 12, Anthropic’s Dario Amodei called for slowing the pace of frontier AI, and OpenAI’s Sam Altman and xAI’s Elon Musk agreed (Axios). On September 23, Altman and Amodei took the case for shared safety standards to the UN Security Council, where Altman said “we should not train models that we cannot keep under human control” (Axios). People will debate their motives, but the direction is clear: the risks are growing with the benefits, and we cannot ignore them.

The one thing I would ask of a life sciences CIO this quarter is to build a single living picture of where AI now touches your critical processes and where outside parties touch them, then monitor it actively. Without that picture, every other safeguard is guesswork.

Ready to move beyond the digest? The LS CIO Community is where these conversations continue.

Join the LS CIO Community →


How this is made: each edition is researched two ways in parallel, once with Perplexity and once with Claude, then reconciled into a single verified brief before Joe adds his take.

This digest is an interpretive summary of publicly available information and does not constitute legal, regulatory, cybersecurity, or investment advice.

Until next week,

Joe Miller

Founder, Leadership Inklings