|
Your Mandate Just Grew. Your Budget Didn’t. The mandate keeps widening while the resources keep shrinking, and this week’s news is the proof. Life Sciences CIO Weekly • Coverage: September 7 – 13, 2026 Last week we made the case that the technology estate has quietly become the operating model itself. This week pushes the point somewhere less comfortable. The mandate keeps widening, and the resources keep shrinking. Europe can now hold you accountable for pharmacovigilance vendors you do not run. A cyberattack turned into a hit on a device maker’s full-year guidance. A prediction market put a price on a single trial result. And in the same nine days, Merck, Novartis, and TScan all cut staff. More to own, fewer people to own it. That vice grip is the story this week, and it is worth sitting with. 🔍 The Quick Read
Reading something a colleague should see? Copy the section that fits their world and pass it along, or forward the whole edition. And if this reached you from someone else, you can subscribe free here to get it every week. 🤖 AI & DataEncoded raises $275M and funds gene-therapy manufacturing as a co-equal workstream ↗A biotech is financing commercial manufacturing alongside its pivotal trial, which makes the data foundation for scale-up a day-one problem. On September 9, 2026, Encoded Therapeutics announced a $275 million Series F to run a pivotal study of ETX101 for SCN1A-positive Dravet syndrome and to scale internal commercial manufacturing. GV co-led the round, with ARCH Venture Partners, SoftBank Vision Fund, Illumina Ventures, and others joining (Fierce Biotech). The signal for technology leaders is that manufacturing is being funded as a co-equal workstream with the trial, not deferred as a downstream tech-transfer problem. Internal gene-therapy manufacturing needs a controlled digital thread that joins vector production, batch records, analytical methods, stability data, chain-of-identity, and regulatory-ready CMC documentation across LIMS, MES, QMS, and supplier-quality systems. What to watch: If your organization is heading from clinical proof toward pivotal scale, stand up the manufacturing-data roadmap now, so scale-up does not create a parallel, manually reconciled data estate. Anthropic starts hiring biopharma dealmakers ↗A frontier-AI vendor is building a life-sciences deal team, a shift worth tracking in your AI vendor strategy. On September 8, 2026, Endpoints News reported that Anthropic is hiring a corporate development lead for biopharma, with compensation up to $600,000, alongside other life-sciences roles, as it builds toward deeper vertical partnerships and its own IPO. It is a hiring signal rather than a business event, but it points to frontier-AI vendors pursuing co-development and strategic data partnerships rather than arms-length software licensing. What to watch: Revisit AI vendor due diligence for data rights, model portability, and concentration risk before these relationships get deeper. ⚖️ Regulatory & PolicyEurope can now inspect pharmacovigilance subcontractors, even with no clause in the contract ↗Regulators can reach the third parties doing your safety work whether or not the subcontract allows it, which widens vendor-oversight exposure. On September 10, 2026, the European Medicines Agency and the Heads of Medicines Agencies updated their good pharmacovigilance practice inspection guidance to reflect a European Commission rule on subcontracting. The change is direct: authorities can inspect a third party performing pharmacovigilance work even where the subcontract contains no obligation to submit to inspection (EMA). Pharmacovigilance is spread across CROs, safety case-processing vendors, literature-monitoring firms, local affiliates, and cloud platforms, so a weak or missing audit clause is no longer a practical barrier to regulatory access. The guidance also reflects remote-inspection practice and adds pre-authorization inspection expectations, which move the readiness test earlier in the lifecycle. 💬 Joe’s Take: This is the part of the CIO role that has changed the most. Not long ago the job stopped at the company’s own walls. Now the CIO is accountable for a web of subcontractors the company does not run and cannot fully see. No IT leader untangles that alone. The move I would point to is sitting down with the pharmacovigilance and quality leaders and building one shared map of who actually touches the safety data. And be clear about the technology role here. The application audit trails live inside validated systems the business and IT validate together, and IT’s own piece is the infrastructure and access controls that keep those systems trustworthy and their records retrievable when an inspector asks. Getting your arms around a vendor chain you do not control starts with admitting no single function can see all of it. What to watch: Best practice is converging on one move. Build a single shared inventory of every party that touches your safety data, tier them by risk, write inspection and audit rights that flow down to subcontractors, and work with the system owners so the supporting evidence, such as audit trails, access logs, and validated reports, can be produced on demand. FDA names permanent CDER and CBER directors and its first deputy commissioner for technology and AI ↗The FDA elevated technology and AI to a dedicated senior role, a directional governance signal for anyone running AI in regulated work. On September 8, 2026, HHS named Michael Davis permanent director of CDER and Karim Mikhail permanent director of CBER, and appointed Jared Seehafer, a quality-management-software founder, as the FDA’s first deputy commissioner for Technology and Artificial Intelligence (RAPS). It changes no requirement today, but it raises the odds that AI-generated evidence, software reliability, and digital submissions receive more centralized attention at the agency. What to watch: Be ready to explain, in plain terms, how any AI in your discovery, manufacturing, or regulatory operations handles human oversight, data lineage, and model change control. EFPIA sets a 15-year path to barcode every dose unit ↗A phased single-unit coding plan turns serialization into a long-horizon product-data and packaging program. On September 7, 2026, EFPIA and the European Association of Hospital Pharmacists issued guidance for a phased, 15-year rollout of single-unit barcoding using GS1 DataMatrix, with the Global Trade Item Number as the required identifier (GS1). New products should support advanced codes within five years, and 80 percent of in-scope medicines within fifteen. For manufacturers this is a product-master-data and packaging-line program, not a bedside-scanning story. What to watch: Serialization programs have never been small undertakings, and this is a large one. Reassess where you stand now. Take inventory of the in-scope products, the serialization programs and software already in place, and the gaps, then build a plan to reach compliance and align packaging lines, artwork governance, and serialization systems to the five, ten, and fifteen-year milestones. 🔒 Cybersecurity & RiskBoston Scientific says its August cyberattack will dent full-year results ↗A device maker put a guidance-level warning on a breach, the week cyber risk showed up in the numbers. Boston Scientific detected a cyberattack on August 25, and in a Form 8-K filed September 8 it said the incident is likely to have a material impact on third-quarter and full-year 2026 results, making it unlikely to meet its 3 percent to 5 percent quarterly sales-growth target or its $5.22 billion to $5.32 billion revenue projection. The attack disrupted manufacturing, order processing and shipping, and remote-monitoring activations for cardiac devices. By September 9 the company reported operations fully restored, with CrowdStrike finding no evidence of compromise to product, manufacturing, or cloud systems, and no breach of personal data (company update). The next update comes on the October 28 earnings call. What to watch: Run the two-week-outage tabletop with finance and operations, and test whether you could still restart manufacturing, release product, ship orders, and produce a defensible materiality estimate. Prediction markets now let people bet on your trial results ↗Event contracts on single clinical outcomes create a new confidential-information risk across your CROs, labs, and vendors. On September 8, 2026, PharmaVoice examined prediction markets that let people trade on discrete clinical-trial outcomes and FDA decisions, following a July pilot from Kalshi and AppliedXL. A recent Commodity Futures Trading Commission action, a $107,539 clawback and trading ban issued on August 28, shows the insider-trading theory applies to these event contracts (CFTC). The twist for life sciences is that a contract can isolate one Phase 3 endpoint, so everyone who sees that nonpublic data early, from CROs and investigators to central labs, biostatisticians, and vendors, becomes a leak surface with a price attached. Lean biotechs are the most exposed. 💬 Joe’s Take: When I hear this, my mind goes straight to data loss prevention. For years the model was an employee walking information out the door, and we built controls for that. What is different now is that a market can put a price on a single trial readout or approval decision, and the people who see that information early sit all across the CROs, labs, and vendors a company relies on, not just inside the building. The safeguards look familiar, but the surface they have to cover now runs through every partner in the chain. It is one more reason the CIO’s attention cannot stop at the company’s own walls. What to watch: Name prediction markets explicitly in confidential-information training, and check that CRO, lab, and vendor contracts cover access, audit, and incident escalation for clinical and regulatory data. A CVSS 10 firewall-management flaw is under active attack ↗Security-management infrastructure is the exposure, and validated-environment patching runs slow. On September 10, 2026, Cisco reported that a nation-state actor tied to Sandworm and the Qilin ransomware group were actively exploiting two flaws in its Secure Firewall Management Center, including a maximum-severity authentication bypass, CVE-2026-20079, rated CVSS 10.0; U.S. federal agencies had until September 12 to mitigate (CISA KEV). The life-sciences angle is that management and identity infrastructure bridges corporate IT, plants, and labs, and validated-environment change control slows patching, so these interfaces should be assumed to be targeted quickly after disclosure. What to watch: Confirm whether you or any CDMO or lab partner runs the affected product, then check patch status, management-interface exposure, and whether emergency change control can move at the speed exploitation requires. 🎯 Leadership & Operating ModelMerck, Novartis, and TScan all cut in the first nine days of September ↗A cluster of cuts shows cost programs turning into operating-model change while IT’s mandate keeps growing. By September 9, 2026, the Fierce Biotech layoff tracker had logged three actions in nine days: Merck cut 54 more roles at its Rahway headquarters toward a 2027 cost target, Novartis said it will end small-volume biologics production at Kleinbasel by the end of 2027, affecting about 130 jobs, and TScan Therapeutics cut 75 percent of staff after pausing programs. No single number is large, but together they show the sector concentrating capital while cutting fixed cost, even as what IT is expected to own keeps expanding. 💬 Joe’s Take: The real question these cuts raise is how close to the bleeding edge a company wants to live, and who gets to decide. Reductions like these usually start with an assumption at the top of the company, that AI is already delivering enough productivity to run leaner. Someone has to bring realism to that. The returns are uneven, and the roles most affected tend to be lower-level work that still needs an experienced professional checking whether what the AI produced can be trusted. That is where the CIO earns the seat, helping set a risk-based line on how far to lean in, made alongside the board and peers rather than handed down. Lean in hard where AI earns its keep, and stay honest about where it does not yet. What to watch: In every reorganization, make each leader name the ownership, vendor dependencies, validated-state implications, and recovery obligations for critical applications before people leave. Takeda’s R&D chief will retire in 2027 ↗A succession at the top of a partnership-heavy R&D model tests whether digital capabilities outlast individual leaders. On September 10, 2026, Takeda said R&D president Andy Plump will retire in June 2027 after eleven years that reshaped its R&D around external partnerships and the $62 billion Shire acquisition. The transition lands amid a restructuring that affects about 4,500 roles in fiscal 2026. A partnership-heavy model runs on durable standards for external data exchange, identity federation, and governed collaboration. What to watch: Treat leadership succession as a prompt to document the digital capabilities that enable external innovation, so they do not depend on any one leader. 💬 The Bottom Line — Joe’s TakeThis week’s developments tell one story. The mandate keeps widening while the headcount does not, and that is not a passing squeeze. It is the shape of the job now. The instinct is to cling to the comfort of the old role. But this is not a negotiation with where the board and the CEO are taking the company, so the sooner a CIO takes an almost zero-based look at how they spend their time, the better. More to own with fewer people means the old leadership disciplines matter more than ever. Be ruthless about cutting what steals your attention. And put real time into developing the handful of leaders under you that you can genuinely trust and delegate to, because coaching your top people has stopped being a luxury. Many CIOs already live this. For everyone else, this is the world as it is becoming, not the one we might have picked. The job now is to get on with it. Ready to move beyond the digest? The LS CIO Community is where these conversations continue. How this is made: each edition is researched two ways in parallel, once with Perplexity and once with Claude, then reconciled into a single verified brief before Joe adds his take. This digest is an interpretive summary of publicly available information and does not constitute legal, regulatory, cybersecurity, or investment advice. Until next week, Founder, Leadership Inklings |