Life Sciences CIOs Digest

The AI Governance Bar Just Rose — On Both Sides

Regulators are racing to keep up with AI. So are vendors. So is your own org chart. This week's stories all point at the same gap.

Life Sciences CIO Weekly • Coverage: July 20–26, 2026


This week's theme: nobody has fully caught up to AI's pace — not the regulators writing the guidance, not the vendors building the platforms, and not most IT organizations trying to fund both "keep the lights on" and "transform the business" at once. The stories below all trace back to that same gap, from a different angle each time.


🤖 AI & Data

EMA's AI Observatory sets a working governance baseline

EMA and the Heads of Medicines Agencies published their 2025 AI Observatory report in June 2026, organized around guidance/policy, AI applications, collaboration, and EU-funded research progress. The same update confirmed EMA's AI-enabled Scientific Explorer — which lets assessors search precedent across marketing-authorization applications and public assessment reports — was expanded in March 2026. Regulators are no longer just publishing AI principles; they're running production AI tools directly over the regulatory content your submissions become part of.

💬 Joe's Take: The practice of quality running its own internal audits — something quality organizations have done for years — is directly applicable to this new challenge. CIOs can take the lead here: partner with quality and regulatory to find commercial solutions, or build in-house AI-based tools, that proactively run the equivalent of the audit a regulator would run, before the regulator ever does. It's also worth watching how vertical platforms like Veeva develop features to perform these checks automatically as data is reviewed and committed into the system, rather than as a separate after-the-fact audit step.

BMS deploys NVIDIA's newest architecture to advance a "hybrid intelligence" model

Bristol Myers Squibb announced July 20 it will deploy NVIDIA DGX Vera Rubin NVL72 systems — the first life sciences company to do so — extending a three-year collaboration and giving BMS what it calls the most powerful single-owned AI infrastructure in life sciences, with up to 10x the performance per megawatt of its prior generation. Chief Research Officer Robert Plenge frames the goal as "hybrid intelligence": AI systems handle complex, data-intensive execution while scientists focus on direction, interpretation, and the judgment calls that require deep human expertise.

💬 Joe's Take: There isn't yet enough public detail on how this hybrid intelligence model is actually implemented day to day to have a specific take on it. But this is an important trend to keep an eye on — there's widespread agreement across the industry on the need for "a human in the loop," and BMS putting real infrastructure behind that principle is worth watching as a signal of how seriously it's being taken.

Other AI signals this week

Bio-native AI startup MindWalk gave the first public demo of its LensAI platform at AMD's Advancing AI 2026 event on July 24, arguing the missing piece in AI drug discovery isn't a bigger model but connected biological context — its representation spans 660 million biological patterns and 25 billion relationships. Worth noting this comes from a company-issued press release rather than independent reporting, but it's a useful signal of one more entrant in the build-vs-buy conversation for AI infrastructure.


⚖️ Regulatory & Policy

EMA advances Annex 22 AI-in-manufacturing guidance through expert workshop

EMA's GMP/GDP Inspectors Working Group ran a two-day workshop (open session, then closed drafting session) to gather expert input on Annex 22 — the forthcoming EU guidance on AI in medicines manufacturing. Real tension remains unresolved: a 2025 stakeholder consultation showed some openness to GenAI/LLMs, while draft language has suggested dynamic, adaptive, probabilistic models should stay out of critical GMP applications.

💬 Joe's Take: With AI advancing this fast, both the regulatory agencies and the vertical solution vendors are struggling to keep up — same as the rest of us. That makes the need for IT leaders to partner closely with their counterparts in other departments, and to respond quickly together, unmistakable. The ability to do that well will be a true differentiator for the IT leaders who want to see their influence, impact, and success compound.

Also on the regulatory radar

FDA's own technology leadership keeps thinning: per an FDA regulatory-affairs newsletter, Acting CIO Sridhar Mantha is departing, following the earlier exit of the agency's chief AI officer, plus other recent leadership departures. It's a notable backdrop as CDER and CBER await new leadership alongside an incoming commissioner nominee — the same agency setting the pace on E6(R3), Annex 22, and AI-CSA guidance is doing it with a thinned-out tech bench of its own.

💬 Joe's Take: Over the short term, it's hard to predict what, if anything, this departure will mean. My advice: keep an eye on it, and don't assume any initiatives currently underway at the agency will pause or slow down.


🔒 Cybersecurity & Risk

Qilin lists Turkish pharmaceutical manufacturer Assos Pharmaceuticals on its leak site

Claim only — not independently confirmed: the Qilin ransomware group — one of the most active RaaS operations globally, with roughly 1,500 claimed victims over the past year — listed Assos Pharmaceuticals, a Turkish pharmaceutical manufacturer, on its leak site on July 23, threatening to release data absent negotiation. Beyond the leak-site posting itself, there's no independent confirmation, breach notification, or additional detail available — treat this as an unverified threat-actor claim, not a confirmed incident. Assos is also a regional rather than global player. Still, it's one more data point in Qilin's pattern of targeting pharmaceutical manufacturing specifically, alongside its recent claims against Stryker and others in the sector.


🏢 Leadership & Operating Model

What CDMO consolidation tells CIOs about their own build-vs-buy decisions

Samsung Biologics launched an all-cash tender offer July 19–20 to acquire 100% of PolyPeptide Group, a Swiss CDMO specializing in peptide-based APIs, for roughly CHF 1.46 billion ($1.8 billion) — the largest deal in Samsung Biologics' history, aimed squarely at the booming GLP-1 and peptide-therapeutics market. It's easy to read this as a manufacturing-strategy story that belongs to R&D and supply chain, but M&A activity in your vendor ecosystem is also a live case study in build-vs-buy decision-making, and one CIOs can learn from without having to make an acquisition themselves. Samsung Biologics decided that building peptide-manufacturing expertise organically would take too long against a market moving this fast, and bought the capability instead. Thermo Fisher's selection as CDMO for ImmuPharma's Kapiglucagon program, and Lonza's new partnership with Engitix on antibody-drug conjugate development, are smaller versions of the same calculus playing out across the industry this week.

The parallel for IT is direct: as AI capability requirements shift as fast as peptide-manufacturing demand has, the same build-vs-buy tradeoffs — speed to capability versus control and differentiation — are showing up in decisions about in-house AI platforms, vertical vendor partnerships, and outsourced data/AI services. Watching how your CDMO partners themselves are answering that question, through M&A rather than announcements, is a useful signal for how fast the market believes this capability gap needs to close.


💬 The Bottom Line — Joe's Take

If there is one thread through this week, it is that waiting for someone else to catch up is not a strategy. Regulators are still working out their own AI guidance. Vendors are still building the features that would make compliance easier. Nobody is going to hand IT leaders a finished playbook, so the ones who move first, partnering with quality and regulatory to build proactive audit capability instead of waiting to be audited, will set the terms other companies react to later. That same instinct, moving quickly and closely with other functions, is what turns a CIO from a service provider into a genuine business partner. But none of it works if the organization underneath is still built for "run" while the money and the mandate have shifted to "transform." That gap, more than any single regulation or vendor roadmap, is the real thing to fix this year.

Ready to move beyond the digest? The LS CIO Community is where these conversations continue.

Join the LS CIO Community →


This digest is an interpretive summary of publicly available information and does not constitute legal, regulatory, cybersecurity, or investment advice.

Until next week,

Joe Miller

Founder, Leadership Inklings

Keep Reading