To content

AI in the Life Sciences

The problem isn't the law, but how it should be applied

AI is already part of everyday life in the life sciences, from research and development to production and quality assurance. For Swedish companies, this is a matter of both competitiveness and the ability to deliver safe Pharma and medical devices globally. At the same time, the EU’s AI Act is often described as a new challenge. But that is not where the real challenge lies.

In an industry that is already heavily regulated, the problem is rather that there are many sets of regulations that overlap and sometimes point in different directions. This creates paralysis within organizations. The uncertainty surrounding what is permitted—and how AI may be used—leads many to err on the side of caution—and do nothing.

This paralysis is exacerbated by the need to protect business-critical data. The fear that sensitive information might be leaked through AI models limits the ability to experiment.

Regulation Is Lagging Behind Technology

AI is currently being implemented faster than organizations can figure out how to control it. A new survey of stakeholders in the life sciences industry shows that about 60 percent use AI daily and over 90 percent use it weekly.

At the same time, the level of maturity is low. Over 70 percent describe their AI usage as limited or in the early stages, and few say they are at the forefront. In practice, AI is currently used primarily in the form of standalone chatbots, rather than as integrated agents or dedicated systems—that is, the more advanced AI solutions that could fundamentally transform compliance work.

Sweden is in a strong position and is often cited as innovative and digitally mature. At the same time, many are lagging behind in the practical application of AI, particularly in regulated industries. Strict requirements for control and quality make the leap from experimentation to full-scale deployment a significant one. After all, it is not the technology that the industry finds most difficult to manage. It is the governance, and it is developing more slowly than the technology it is supposed to control.

When AI is integrated into mission-critical systems, new questions arise. How do you validate a model that changes over time? And how do you review decisions that aren't entirely predictable?

The key issue, therefore, is not whether AI may be used, but how its quality should be ensured, how it should be validated, and how it should be monitored over time.

The regulations point in different directions

The EU’s AI Act is often cited as a solution. But for many companies, the law does not entail any major changes in practice. The requirements for oversight, documentation, and validation already exist. What is new is the uncertainty surrounding how they should be applied to AI.

Furthermore, regulatory frameworks are constantly changing. Updates and clarifications are underway in both the EU and the U.S. At the same time, frameworks such as GAMP have begun to address AI, including through the guide published last year.

For companies, this means they must navigate a landscape where both regulations and practices are evolving in parallel. In addition to legal requirements, companies are expected to live up to the industry’s “gold standard,” which, in practice, applies regardless of whether it is formally mandated by law or not.

Companies must determine what applies and which set of regulations takes precedence. But an increasingly common consequence is that they choose not to act. This uncertainty leads to AI initiatives being postponed or never really gaining momentum. This creates paralysis, putting companies at risk of falling behind.

Policies exist, but not the procedures

A majority have AI policies, but only slightly more than one-third use AI in their compliance work. Questions regarding validation, monitoring, and change management remain unanswered. In part, there is a lack of established procedures; in part, the boundaries are unclear.

Those who act now will have the head start

The question is not whether clarity will come, but when. In the meantime, companies must make decisions without having the full picture. Those who wait risk being forced to adapt after the fact. Those who are already building structures for governance, validation, and control are gaining a head start.

Sweden is well-positioned to become a test bed for AI in regulated environments. But we risk falling behind in practical application—and that is precisely why the potential is so great.

Ultimately, it’s less of a legal issue and more a matter of making the technology work in a regulated environment—before the regulations have had time to catch up. The question is who is taking action now—and who will be forced to adapt afterward.

Subject matter expert

Cecilia Fällman
Cecilia Fällman
Business Area Manager Compliance

Subject matter expert

Cecilia Fällman
Cecilia Fällman
Business Area Manager Compliance

In this article

Related content

AI in Life Sciences
EUDAMED agent
AI in Life Sciences
Regulatory Insights for Life Sciences 2026
Read more
AI in Life Sciences
The Use of AI in Life Sciences
Read more
AI in Life Sciences
EUDAMED agent
Read more
AI in Life Sciences
Regulatory Insights for Life Sciences 2026
Read more
AI in Life Sciences
The Use of AI in Life Sciences
Read more
Stay up to date

SUBSCRIBE to our newsletter