PiVily Quarterly Report · Q3 2026
The State of the Pharmacovigilance Ecosystem
Current edition · through 11 August 2026
The period was not defined by one rule or one technology. It was defined by the increasing connection between standards, evidence, infrastructure, governance, and professional judgment.
Executive signal
Pharmacovigilance is becoming a more connected intelligence system.
Reporting obligations remain foundational. The differentiating capability is increasingly what happens around them: translating standards across jurisdictions, selecting evidence that is fit for a decision, governing technology, preserving traceability, and enabling qualified people to intervene when the system is uncertain.
PiVily's reading
From 2025 through August 2026, the field moved further away from a model in which safety information could be managed as a chain of largely separate activities. The operating reality is now more interdependent—and more exposed at its interfaces.
Global standards advanced while regional implementation remained specific. Regulators expanded real-world evidence capacity while insisting on credible methods. AI moved from general possibility into formal workplans, principles, and risk-based governance. Safety data became easier to access, without becoming easier to interpret. And quality expectations continued to follow the work beyond the walls of the marketing authorisation holder.
Taken together, these are not six independent trends. They describe a system transition: more data, more connectivity, more visible decisions, and a greater need for accountable judgment.
Selected verified milestones
The period in sequence
UK pharmacovigilance entered the Windsor Framework operating model.
The MHRA became the licensing authority for medicines across the UK, with pharmacovigilance requirements differentiated by product category.
FDA proposed a risk-based credibility framework for regulatory AI.
The draft guidance addressed AI models used to generate information or data supporting regulatory decisions about safety, effectiveness, or quality.
The European Health Data Space entered its transition phase.
The regulation created a future framework for primary and secondary use of health data. Most provisions apply later; the immediate signal is directional.
ICH M14 and E2D(R1) reached Step 4.
One advanced global principles for non-interventional safety studies using real-world data; the other revised post-approval ICSR standards and case-management practices.
EMA and FDA published joint principles for good AI practice.
The ten principles cover evidence generation and monitoring across the medicines lifecycle, including safety monitoring.
FDA launched the Adverse Event Monitoring System.
AEMS began consolidating adverse-event reporting and public access across product categories, with real-time publication and broader analytics planned.
The system-level analysis
Six connected shifts
Harmonisation advanced. Execution remained local.
In September 2025, ICH completed two consequential Step 4 milestones. M14 established principles for planning, designing, analysing, and reporting non-interventional studies using real-world data for medicine-safety assessment. E2D(R1)updated definitions, standards, and good case-management practices for post-approval ICSRs.
Yet Step 4 is not uniform operational adoption. ICH guidelines move into regional implementation, and the UK framework effective from January 2025shows how product categorisation, reporting routes, referrals, and local responsibilities can still require jurisdiction-specific control.
Global consistency now depends less on one universal procedure and more on controlled translation: one scientific position, clear regional expressions, and no ambiguity about which rule governs the action.
Real-world evidence became operating infrastructure.
EMA reported that DARWIN EU had 33 data partners covering more than 180 million people across 16 European countries in 2025. Fifty-two studies were initiated and forty completed during the year. This is evidence of operational scale, not merely strategic intent.
The importance of ICH M14 is therefore practical. Access to large datasets does not resolve questions of provenance, relevance, comparability, confounding, or study design. The regulatory value of real-world evidence still depends on whether the data and method are fit for the question.
The competitive question is no longer whether an organisation can access real-world data. It is whether safety, epidemiology, statistics, medical, regulatory, and data teams can frame and govern a decision-ready study together.
AI moved from experimentation toward governed use.
In January 2025, FDA issued draft guidance proposing a risk-based credibility assessmentfor AI models used to generate information or data supporting regulatory decisions. EMA and HMA placed guidance, tools, organisational readiness, and structured experimentation in a multi-year data and AI workplan. In January 2026, EMA and FDA jointly published ten principles for good AI practice across the medicines lifecycle, including safety monitoring.
The boundaries matter. FDA's draft is not an all-purpose validation standard for every internal automation. Nor does a regulator workplan prove that a particular tool is reliable. Together, however, these actions show where credible adoption is heading: defined context of use, risk-based evidence, data governance, performance monitoring, human oversight, and records that make the result explainable.
“Human in the loop” is not a control by itself. A defensible model specifies which human, with what competence, at which decision point, using what evidence, and with what authority to stop or override the system.
Safety data became more visible—not self-interpreting.
FDA's March 2026 launch of AEMSbegan consolidating adverse-event data that had sat across multiple legacy systems. FDA described real-time publication, historical migration, APIs, and enhanced analytics as part of the transition.
Greater access can improve surveillance, external research, and public scrutiny. It can also amplify familiar errors: treating reporting counts as incidence, overlooking duplicates and stimulated reporting, or inferring causality from an unadjusted pattern. FDA itself states that spontaneous reports have limitations and can help identify potential signals—not prove that a product caused an event.
Transparency increases the communication burden around the data. Organisations need scientific literacy and public-facing explanation to mature at the same pace as access.
Accountability continued to follow the work across organisational boundaries.
FDA's postmarketing adverse-event reporting compliance programmestates that inspections may include entities contracted to process adverse event information. The underlying expectation is not new: complete, accurate, and timely reporting remains required. What deserves renewed attention is where work is performed and how evidence of control travels across sponsors, affiliates, vendors, distributors, technology providers, and other partners.
Outsourcing an activity does not outsource the need to understand the process. Dashboards, service levels, and contracts are useful, but they do not replace clear ownership, traceable decisions, reconciled data flows, meaningful deviation review, and tested escalation routes.
Third-party oversight should be designed around patient-safety and regulatory risk, not around the convenience of the organisational chart.
Professional capability became more visibly part of system control.
Every other shift in this report increases the value of people who can move between specialist depth and system context. Implementing E2D(R1) requires more than reading a revised document. Using real-world evidence requires more than procuring a dataset. Governing AI requires more than approving a tool. Interpreting public safety data requires more than generating a chart.
This does not mean every PV professional must become a regulator, epidemiologist, technologist, auditor, and communicator. It means teams need explicit capability at the interfaces—and leaders need to know where judgment, challenge, and escalation reside.
Training completion is a weak proxy for readiness. Better questions test whether a person can recognise a changing assumption, explain the consequence, and involve the right expertise before the issue becomes a failure.
Compliance remains the floor. Connected, evidence-literate, and explainable decision-making is becoming the capability that separates a functioning PV system from a resilient one.
For PV leaders
Six questions for the operating agenda
- Translation: Can the organisation show how one global safety position becomes correct, timely action in each jurisdiction?
- Evidence: Is the data source selected because it is available, or because it is fit for the regulatory and scientific question?
- Technology: Is every material AI or automation use tied to a defined context, risk, owner, performance measure, and intervention route?
- Transparency: Can scientific and communications teams explain what public safety data can—and cannot—support?
- Partners: Can the end-to-end safety record be reconstructed across affiliates, vendors, systems, and contractual boundaries?
- Capability: Does development prepare people to make and challenge decisions, or only to complete assigned steps?
PiVily watchlist
What deserves attention next
These are evidence-informed watchpoints, not predictions and not a substitute for jurisdiction-specific regulatory intelligence.
Regional implementation
How ICH M14 and E2D(R1) move from global consensus into local requirements, procedures, systems, and inspection expectations.
AI assurance
Whether high-level principles become more specific expectations for validation, change control, monitoring, explainability, and human accountability in PV use cases.
Evidence operations
How mature real-world evidence networks influence signal assessment, risk characterisation, risk minimisation, and benefit–risk decisions.
Data-space implementation
The implementing acts and transition milestones that will determine how the European Health Data Space supports secondary use for research and regulatory activity.
Public-data interpretation
How researchers, organizations, media, and the public use more timely adverse-event data—and whether communication standards keep pace.
Workforce design
Whether organisations build multidisciplinary capability deliberately or continue relying on informal bridges between safety, quality, regulatory, data, and technology teams.
Method & source register
How this analysis was built
PiVily reviewed official materials published or materially applicable from 1 January 2025 through 11 August 2026. Selection was based on system-level relevance to human pharmacovigilance: standards, regulatory operating models, evidence generation, safety-data infrastructure, governance, and professional capability. The report is selective rather than an exhaustive jurisdictional change log.
Facts are attributed to the publishing authority. Statements labelled “PiVily interpretation” connect those facts into an editorial point of view. Watchpoints identify questions to monitor; they are not claims that a future outcome will occur.
- ICHE2D(R1) reaches Step 4
- ICHM14 reaches Step 4
- MHRAPharmacovigilance following the Windsor Framework
- EMAAnnual report 2025: DARWIN EU
- EMAReal-world evidence
- FDADraft guidance on AI supporting regulatory decisions
- EMAArtificial intelligence in medicines regulation
- FDAFDA Adverse Event Monitoring System launch
- FDAPostmarketing adverse-event reporting compliance program
- European CommissionEuropean Health Data Space Regulation
