What EMA Permits When AI Drafts Your Product Information
EMA wrote one paragraph about generative models drafting product information, and it contains a word most readers skate past. That word is what turns a human-oversight slogan into a quality control system you can actually build.
Section 2.3.5 of the EMA reflection paper on the use of artificial intelligence in the medicinal product lifecycle runs to two sentences. Here they are in full: "AI/ML applications used for drafting, compiling, editing, translating, tailoring, or reviewing medicinal product information documents should be used under close human supervision. Given that generative language models are prone to include plausible but erroneous or incomplete output, quality review mechanisms need to be in place to ensure that all model-generated text is both factually and syntactically correct before submission for regulatory review."
That is a permission with two conditions attached, and both conditions are testable. The first, close human supervision, is the sentence every guidance document writes. The second is unusual. EMA did not ask for output that is accurate; it asked for output that is factually and syntactically correct. Those are different failure modes, they are caught by different mechanisms, and only one of them needs a human. The syntactic half is a machine-checkable specification against documents EMA has already published, which means the quality review mechanism the clause demands is buildable rather than aspirational.
The paper carries the reference EMA/CHMP/CVMP/83833/2023, was adopted by CHMP on 9 September 2024 and by CVMP on 11 September 2024, and is a reflection paper. It states EMA's current thinking; it is not law and creates no free-standing legal obligation. It is also, on the evidence of the document itself, the Agency's only applicant-facing sentence on this subject: searching the 18-page final PDF on 31 August 2026 returns exactly one occurrence of "generative", in section 2.3.5, and one of "large language models", in section 2.7 on memorisation risk. The companion guiding principles on the use of large language models of 29 August 2024 are addressed to regulatory authorities and their staff, not to marketing authorisation holders.
- Section 2.3.5 permits AI drafting, compiling, editing, translating, tailoring and reviewing of product information, conditional on close human supervision and a quality review mechanism for factual and syntactic correctness. The paper is non-binding.
- The syntactic half has a published specification: the QRD convention, EMA/62470/2007 rev. 8, 12 April 2011 — Times New Roman 11, fixed margins, non-breaking space before units, no automatic numbering, cross-references by section number. All of it is testable in code.
- The pressure point is the post-opinion translation window. Under EMEA/5542/02 rev. 6 of 10 February 2025, all 24 other EU/EEA language versions are due 5 days after the CHMP opinion at Day 215, with Member State review to Day 229.
- For Type IA variations and minimal-change Article 61(3) notifications there is no linguistic review at all — the holder alone is responsible for translation correctness. That is where automated drafting carries the most unmanaged risk.
- ePI is what makes any of this diffable. EMA's draft roadmap of March 2026 shows voluntary go-live from Q4 2026 for vaccines, and the FHIR implementation guide validates Composition resources against the QRD templates.
Which instrument says what, and whether it binds
Getting this table wrong in a steering committee is how a regulatory operations programme loses its sponsor. As of 30 August 2026:
| Instrument | Covers | Status |
|---|---|---|
| EMA reflection paper EMA/CHMP/CVMP/83833/2023, s. 2.3.5 | AI drafting, translating, reviewing product information | Final, adopted 9 Sep 2024. Non-binding |
| QRD convention EMA/62470/2007 rev. 8, 12 Apr 2011 | Format, layout, typography of the annexes | Procedural. Strict compliance required by EMA's linguistic review guideline |
| QRD product information template v10.4, 29 Feb 2024 | Section structure and standard statements | Current. A draft v11 went to consultation 14 Apr – 31 Aug 2025 and had not been finalised |
| Linguistic review guideline EMEA/5542/02 rev. 6, 10 Feb 2025 | Day 215 timetable, translation quality, QRD forms | Procedural, operative |
| Regulation (EC) No 1234/2008 | Variation classification driving whether linguistic review happens | Binding |
| EudraLex Vol. 4 Annex 11 (revision January 2011) | Computerised systems in GMP | Binding. The draft revision published 7 Jul 2025 closed consultation 7 Oct 2025 and is not law |
| Draft Annex 22, artificial intelligence | AI in GMP, not product information | Draft. It does not appear among the published annexes in EudraLex Volume 4 |
| Regulation (EU) 2026/1744, Digital Omnibus on AI | Amends the AI Act, defers Annex III high-risk to 2 Dec 2027 | Published in the OJ 24 Jul 2026, in force 27 Jul 2026 |
| New EU pharmaceutical legislation | Would introduce the ePI legal basis | Provisional agreement 11 Dec 2025, Coreper endorsement 6 Mar 2026, SANT committee 18 Mar 2026. Not adopted |
Two entries deserve emphasis. Draft Annex 22 is a GMP annex, frequently quoted at labelling teams as though it governed them; it does not, and it is not law in any case. And the ePI mandate that vendor material describes as arriving is contingent on legislation that had cleared committee but neither plenary nor Council on 30 August 2026, with an indicative plenary date in November 2026 on the Parliament's own legislative train.
Why "syntactically" is the load-bearing word
Read the QRD convention and the reason for EMA's word choice becomes obvious. It is three pages of mechanical rules: orientation portrait; section breaks avoided; margins of 2.0 cm top and bottom and 2.5 cm left and right; Times New Roman, size 11, regular, black, including in figures, tables and pictograms; left alignment except centred title pages; first indent 1.0 cm.
Then the rules that matter for generated text. A non-breaking space between a figure and its unit, so that "10 mg" cannot split across a line. A non-breaking hyphen in ranges, so that "100-200" holds together. Scientific symbols inserted from the symbol window rather than by AutoCorrect, "to ensure that the symbols are always readable". No automatic numbering insertion. Table borders single line, colour automatic, width half a point, no shading. Cross-references written as the section number alone and never the heading, as in "(see section 5.1)". Boxed headings in the labelling annex created with outside borders rather than by inserting a table, kept through the whole procedure and absent from the printed carton.
Every one of those is a deterministic assertion over a .docx file. A model that has produced substantively correct text will still, routinely, emit an ordinary space before "mg", a soft hyphen in a dose range, an autocorrected micro sign that renders as a box in a Greek annex, and a cross-reference that helpfully names the section. The syntactic checks are the cheap half of the quality review mechanism and the half a machine does better than a reviewer at Day 233. Build them first, as a gate a document cannot pass, and reserve human attention for the factual half: is this contraindication supported by the assessment, does this posology match the clinical section, has the safety statement been carried across from the core data sheet with its qualifiers intact.
This is the same architectural move that the seven-step credibility assessment FDA proposed for AI models supporting regulatory decisions makes for models generally: fix the context of use, then decide how much evidence the risk of that context demands. Product information drafting is a narrow context of use with an unusually well-specified output format, which is why it is a good first target and a bad place to be sloppy.
The 5-day window where this actually bites
The reason labelling teams reach for generative drafting is arithmetic. EMA's linguistic review guideline sets out what happens after a positive CHMP opinion at Day 215: the applicant provides translations of the final adopted English product information in all other EU languages — the 24 other EU/EEA languages, which include Icelandic and Norwegian — "to the Agency at the latest 5 days after the CHMP opinion". Member States, coordinated by national QRD members, perform a detailed review of all translations from Day 215 to Day 229 and send comments by Day 229. The applicant returns final tracked-change and clean versions plus QRD form 2 by Day 235. The Agency checks implementation of Member State comments at Day 235 to 237, then the Commission opens a 22-day Standing Committee consultation that addresses only legal and public health matters, "which means in principle no further linguistic review".
The guideline is candid that the schedule is tight, advising applicants to start translating "well in advance of the opinion (e.g. after Day 180)" — that is, to translate text still being negotiated. It also states the consequence of getting it wrong: "Poor quality translations, poor implementation of Member States' comments, or absence of a completed QRD form 2 may lead to a delay in transmission to EC." Where a translation is judged unacceptably poor, the Member State informs the applicant and the Agency within 3 days and transmission is delayed until an amended version arrives. The Agency tracks translation quality as a key performance indicator.
Post-authorisation the same shape recurs on a compressed clock. For Type II variations affecting the product information, only the English version is filed at submission; translations go to Member State contact points by Day +5, comments come back by Day +19, finals are due Day +25, and with no Standing Committee procedure there is no revision after Day +27.
Now the part that should change how you scope an automation project. For Type IA variations, no linguistic review of the other EU languages is performed at all, and the holder is responsible for ensuring the correctness of the translations. The same applies to Article 61(3) notifications with minimal changes — minor editorial changes, alignment to QRD statements — which is precisely the category of change a drafting model is most likely to be handed. Type IB and extensive Article 61(3) changes do attract a review, running in parallel with assessment on the Type II pattern.
So the regulatory safety net is thinnest exactly where the automation is most attractive. If your pilot targets high-volume editorial variations because they are low risk, you have selected the workstream where nobody outside your company will read the output before it becomes the authorised text in 25 languages. That is the risk assessment to write down, and it is an argument for tightening rather than relaxing the internal gate on those procedures.
CCDS to local label: what automation is genuinely good at
The company core data sheet fixes a holder's position on core safety, indications, posology, contraindications and warnings, and every local label derives from it. Divergence is normal and often required: national wording, local legal categories, market-specific regulatory decisions. Divergence nobody decided on is drift, and it is what inspectors and partners find when they compare the two.
The reconciliation artefact is a label comparison chart, core sheet section against local text with each difference stated and justified. Producing one manually across a mature portfolio is large, repetitive and mostly mechanical, which suits section-aligned automated comparison — provided the comparison is a proposal and the classification of each difference into justified, obsolete or drift is made by an accountable regulatory professional and recorded as their decision. That division survives contact with 2.3.5's "close human supervision" and with the expectation that an AI output entering a regulated process is itself a record: attributable, reviewed, audit-trailed.
What automation cannot fix is the input format. Diffing two Word files whose section boundaries exist only as bold text produces noise. Which is the argument for structure.
Why ePI changes the economics rather than the rules
The EU ePI common standard expresses the authorised product information — SmPC, package leaflet and labelling — as FHIR resources. The European Medicines Regulatory Network ePI implementation guide is at version 1.0.0, active as of 2 May 2025, built on FHIR R5, and it validates Bundle resources for compliance and Composition resources against the QRD templates. That last detail is the point of this article in one line: the structure a diffing tool needs and the structure a conformance checker needs are the same structure, and it is now published.
EMA's draft ePI implementation roadmap, made available in March 2026 and labelled DRAFT on its face, sequences centrally authorised products as industry user acceptance testing through 2026, voluntary go-live for vaccines under ATC code J07 from Q4 2026, voluntary go-live for oncology under L01 and L04 in the first half of 2027, and voluntary go-live for all centrally authorised products in the second half of 2027, then hypercare and a transition period. Several published summaries place the vaccine go-live in Q3 2026; the roadmap graphic and its accompanying slide both say phased go-live "from Q4 2026", and the Q3 column carries user acceptance testing. For nationally authorised products it shows a June 2026 competent authority workshop, a survey and readiness assessment, and national roll-out timelines still to come, "to be defined, following readiness assessment".
Three operational facts from the same roadmap deserve to be in your plan. Initial implementation "will not interfere with the assessment": applicants author or upload ePI at the PLM portal as an extra step alongside the current Word and PDF submission, so this is additional work before it is replacement work. Once a product's information exists in electronic format it remains electronic in all subsequent variations, so the first product you convert is a permanent commitment. And initial implementation for centrally authorised products is English only, with all other languages optional and full multilingual delivery later — meaning the translation problem described above is not solved by ePI in this phase, only made tractable later.
Does the EU AI Act reach AI-drafted labelling?
Probably not through the high-risk regime. Annex III lists employment, education, credit scoring, biometrics, law enforcement, migration and essential services; drafting regulatory documentation is not among them. In any event, obligations for Annex III standalone systems were deferred from 2 August 2026 to 2 December 2027, and for AI embedded in Annex I regulated products to 2 August 2028, by the Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Prohibited practices, the Article 4 AI literacy duty and the general-purpose model obligations are already live and are not affected by that deferral.
The provision worth putting in front of counsel is Article 50(4). Its second subparagraph requires deployers of an AI system that generates or manipulates text "published with the purpose of informing the public on matters of public interest" to disclose that the text was artificially generated, then exempts content that "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication". A package leaflet on a public medicines portal is not an obvious fit for either reading, and Article 50 was itself amended by the Digital Omnibus, so run the analysis against the consolidated text rather than the 2024 original. The practical observation is that the exemption and section 2.3.5's condition describe the same control.
Note the asymmetry while you are there. EMA's own LLM guiding principles tell network staff that if an output is mostly the result of an LLM they should "consider disclosing the output as the outcome of an LLM". No equivalent disclosure expectation is placed on applicants by section 2.3.5.
What this means in practice
Write the context of use down in one paragraph and refuse to widen it: which document types, which procedure types, which languages, which model version, what the model may not touch. Section 2.3.5 covers six verbs carrying very different risk. Translating an approved English sentence into Portuguese is not the same act as tailoring a warning.
Then build the syntactic gate as code, before the model. Non-breaking space between figure and unit, non-breaking hyphen in ranges, font and margin conformance, no automatic numbering, table border specification, cross-reference format, boxed headings present in the labelling annex, section numbering matching QRD template v10.4. A document that fails any assertion does not reach a reviewer. Publish the pass rate: it is the evidence that a quality review mechanism exists, and it is the artefact you hand an assessor who asks how you satisfied section 2.3.5.
Keep the factual review human and visible in the record: a qualified regulatory or labelling professional, with the record showing what the model proposed, what the human changed and who approved. Treat the model output as a record rather than a draft that evaporates, and pin the model version, treating a version change as a change requiring assessment.
Sequence the portfolio against the linguistic review map, not against volume. Procedures that get a Member State review have an external check; Type IA variations and minimal-change Article 61(3) notifications do not, so those need a heavier internal gate, not a lighter one. If you are choosing a first ePI conversion candidate, remember the choice is irreversible for that product and the current phase adds a submission step rather than removing one.
Two things go wrong most often. The first is a pilot scoped as "AI writes the SmPC", which collides with the fact that the assessed English text is negotiated with a rapporteur and is not a greenfield writing task at all; the tractable work sits in translation quality control, format conformance, core sheet reconciliation and change impact analysis. The second is a quality review mechanism that exists as a paragraph in an SOP rather than as a gate in a system, which survives exactly as long as nobody asks to see the evidence. The word EMA used was "mechanisms". A mechanism has outputs you can show, and the same risk-based validation logic that applies to any non-deterministic system in a regulated process applies here: define the claim narrowly, test against it, monitor it, and keep the human decision on the record.
Questions people ask about this
- Does EMA allow AI to write the SmPC and package leaflet?
- Section 2.3.5 of the EMA reflection paper on AI in the medicinal product lifecycle, adopted by CHMP on 9 September 2024, says AI/ML applications used for drafting, compiling, editing, translating, tailoring or reviewing product information should be used under close human supervision, with quality review mechanisms ensuring model-generated text is factually and syntactically correct before submission for regulatory review. It permits the use and attaches two conditions. A reflection paper is not legally binding.
- Is the EMA reflection paper on artificial intelligence legally binding?
- No. EMA reflection papers set out the Agency's current thinking where formal guidance does not yet exist; they create no legal obligation in themselves. The binding instruments around AI-drafted product information are elsewhere: Regulation (EC) No 1234/2008 for variations, Regulation (EC) No 726/2004 for the centralised decision process, and the applicant's own pharmacovigilance and quality system obligations. Assessors nonetheless read the reflection paper, and so do inspectors.
- What does syntactically correct mean for a Summary of Product Characteristics?
- It means compliance with the mechanical conventions the annexes must follow, not grammar in the ordinary sense. The QRD convention, EMA/62470/2007 rev. 8 of 12 April 2011, prescribes Times New Roman 11 point, page margins of 2.0 cm top and bottom and 2.5 cm left and right, a non-breaking space between a figure and its unit as in 10 mg, a non-breaking hyphen in ranges such as 100-200, no automatic numbering, and cross-references given as section numbers only.
- When does electronic product information become mandatory in the EU?
- It has not been made mandatory. The draft ePI implementation roadmap EMA published in March 2026 shows voluntary go-live for centrally authorised products, starting with vaccines under ATC code J07 from Q4 2026, oncology products under L01 and L04 in the first half of 2027 and all centrally authorised products in the second half of 2027. National procedures follow a plan still to be defined after a readiness assessment. Any mandate would come with the new pharmaceutical legislation, which was not yet formally adopted on 30 August 2026.
- Does the EU AI Act classify AI-drafted labelling as high risk?
- Not on the face of Annex III, whose categories cover employment, education, credit, biometrics, law enforcement, migration and essential services rather than medicines documentation. Annex III obligations were in any case deferred to 2 December 2027 by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force from 27 July 2026. The transparency, prohibited practice, AI literacy and general-purpose model obligations are already live and should be assessed separately.