What NICE, CDA-AMC and the new EU JCA principles now expect the moment AI touches your evidence, and the questions nobody has answered yet
On 15 July 2026, the EU HTA Coordination Group (HTACG) adopted its general principles on the use of artificial intelligence in Joint Clinical Assessment dossier preparation. It is a short document, three pages long. It is easy to skim, file and forget.
That would be a mistake.
Those three pages join NICE’s position statement on AI in evidence generation from August 2024 and CDA-AMC’s adaptation of it from April 2025. Read together, the three texts send one message to every HEOR, market access, evidence synthesis and regulatory team in the industry: you may use AI, but you now answer for every part of how you used it.
The timing makes this pressing. JCA has covered oncology medicines and ATMPs since January 2025. Orphan medicines come into scope from 13 January 2028, and all centrally authorised medicines from 13 January 2030. Within a few years, almost every new medicine heading for the European market will pass through a process with explicit expectations about AI. And unlike most of the documentation your team produces, the JCA dossier is published. Every AI declaration you make will be public.
This article is taken from our full practitioner course on HTA expectations for AI-generated evidence: close to three hours of material, including a hands-on workshop. That course has already had to be updated more than once since it was first recorded, because the ground keeps moving under it. July 2026 alone brought the HTACG principles and the EU AI Act’s Digital Omnibus within twelve days of each other. Anything written on this subject has a short shelf life, which is part of the point.
What follows is the shape of the problem: what has changed, where the bodies agree, where they quietly differ, and where the gaps are. The detailed answers are in the course.
Three documents, one posture
The headline is convergence. HTACG, NICE and CDA-AMC wrote their texts at different times, for different systems and under different legal frameworks, yet they share a common core. All three hold that:
- the sponsor is accountable for the content of the submission, whatever tools were used to produce it;
- there must be a human in the loop;
- AI use must be declared, along with how it was used;
- the use must comply with copyright and data-protection law.
None of the three bans AI. All three make you answerable for it.
The differences are where teams get caught. One body is far more prescriptive than the others about exactly what must be reported and what must be kept. Another asks a question most sponsors never think to answer: should you have used AI at all? The third adds its own ethical principles and anchors its definitions in Canadian legislation that, as it turns out, never made it onto the statute books.
Even small details diverge. Only one of the three texts explicitly exempts spelling and grammar tools from disclosure. If you take one body’s exemptions and assume they apply everywhere, you may under-declare without realising it.
It is also worth knowing where the wording comes from.
The HTACG accountability language closely follows the RAISE recommendations on responsible AI in evidence synthesis, which underpin the 2025 joint position statement from Cochrane, Campbell, JBI and the Collaboration for Environmental Evidence. Norms that began in the evidence-synthesis community are hardening into regulatory expectations, and they will not soften again.
The HTACG principles rest on four pillars: accountability, human oversight, transparency and reporting. Each has consequences most organisations have not yet worked through.
Accountability: the decision to use AI is itself a method choice
The HTACG text makes the health technology developer accountable for the content, methods and findings of the evidence synthesis. That includes whether and how AI is used, its impact on the synthesis, and the validity of any AI output. NICE and CDA-AMC say the same: the submitting organisation remains accountable for everything in the submission.
The implication is uncomfortable. “The vendor’s tool did it” is not a defence, in any jurisdiction.
Consider how evidence actually gets produced. A systematic literature review is often run by a CRO. The CRO may use a screening platform with AI prioritisation built in. That platform may run on a third-party model the vendor updates without notice. Somewhere along the chain, a “smart” feature may have been switched on by default without anyone deciding to use it. Under the new principles, all of that is yours.
So here is one of the questions we put to participants in the course:
Could you name, today, every AI tool, version number, and underlying foundation model and number, that your vendors used on your last submission, and who approved each use?
Most teams can’t.
That isn’t negligence. Until recently nobody asked. Now someone does.
NICE adds a further layer: AI should be used only where it brings demonstrable value given its risks, and where more explainable methods are potentially robust, those should come first. The decision to use AI now has to be justified and documented like any other methodological choice.
Most existing CRO and vendor agreements say nothing about any of this. The course sets out how accountability should be divided across the evidence chain and what those contracts now need to contain. It is far cheaper to fix before a submission than during one.
Human oversight: answerable, not nearby
HTACG states that no step of dossier preparation or analysis should be fully automated without a human ultimately responsible for its quality and accuracy. NICE frames AI as augmentation, not replacement. The EMA–FDA guiding principles published in January 2026 take the same human-centric position.
Read closely, the bar is responsibility and verifiability, not necessarily re-doing every item by hand. But how much verification is “enough” is not defined anywhere. That is one of the most consequential open questions in this area, and you need a defensible position on it before an assessor asks for one.
The right answer is not the same at every stage of the pipeline, and the stakes vary sharply. HTA bodies have historically expected very high sensitivity for study identification. Meanwhile, one 2026 sponsor case study found mean LLM data-extraction accuracy of around 73%. A single oversight policy applied uniformly will either waste a great deal of effort or leave gaps an assessor can find.
There is also a quieter risk, and it is about people rather than technology.
The danger isn’t that AI makes mistakes. It’s that people stop looking for them.
Automation bias is well documented: scrutiny drops, plausible outputs go unchecked, and responsibility drifts onto the tool. One indicator is worth checking in your own team tomorrow. If your reviewers never override the AI, that isn’t evidence the AI is excellent. A 0% override rate is a warning sign.
Then there is a question none of the HTA texts answer: who actually signs off the AI-use declaration, and what does their signature attest to? No HTA body names that role. It is an operating-model decision your organisation has to make, and it is much better made before the dossier is due than during it.
For the AI step you rely on most, what exactly does the human do, and how would an assessor know they did it?
Transparency and reporting: if it isn’t written down, it didn’t happen
This is where the HTACG principles are most specific. If AI is used, it must be clearly documented in the dossier, with every AI-assisted step specified. Any AI-generated or AI-informed output or judgement must be identified as such.
For each tool, HTACG sets out minimum reporting fields: tool name, version, date, developer and specific purpose. Think of it as a nutrition label for every AI tool in your evidence. That is the minimum. Good practice goes further, and NICE and CDA-AMC expect more again.
Then there is the line that should get every evidence team’s attention: all prompts should be recorded and made available if requested during the JCA. All of them, not just the final version that worked. And because the same prompt does not reliably give the same answer twice, the prompts alone are not enough.
JCA runs in parallel with the EMA procedure, on tight timelines. You cannot reconstruct an audit trail after the fact, and certainly not in days.
If an assessor asked tomorrow for every prompt behind your extraction tables, how long would it take you to produce them?
There is a distinction in the HTACG text that sounds simple and isn’t: the difference between an AI-generated output and an AI-informed judgement. Both must be identified. What the text does not say is at what level of detail: per data point, per table or per section. Get it wrong one way and the dossier becomes unreadable. Get it wrong the other way and it becomes unverifiable.
The approach we teach is to build one declaration that satisfies HTACG, NICE and CDA-AMC at once, so the same document travels between Brussels, London and Ottawa. Doing that well means knowing which body asks for what, where the expectations stack, and which established reporting standards assessors will recognise. In the workshop, teams build exactly that declaration for a real submission.
Publication changes the risk
This is the part legal and compliance teams tend to notice last, and it should come first.
The JCA dossier is published, in a version without confidential information. After receiving the revised draft reports, you have seven days, and in some scenarios only five, to flag factual errors and confidential information. You must show that anything you want redacted is commercially sensitive. The Commission may refuse.
Tool names, methods and possibly prompts may become visible to competitors and the public. HTACG explicitly links legal compliance to publication. That gives new weight to questions many teams have never asked. Were you actually licensed to put those full-text PDFs into an AI tool? Many publishers now reserve AI rights in their terms, and the legal exceptions commercial developers assume they can rely on are narrower than most people think. What do your AI tool’s terms say about retaining and training on your inputs?
Everything in the dossier will be public. Everything you fed the model may not have been yours to feed.
The course includes a pre-submission legal checklist for exactly this, along with how the EU AI Act fits in. Briefly: the Digital Omnibus that came into force on 27 July 2026 deferred the high-risk obligations, but it did not defer the AI literacy duty. That one applies now. And if the same AI component appears in your marketing authorisation application and your JCA dossier, the two descriptions had better match, because the HTA secretariat and EMA talk to each other.
The asymmetry: the assessor may be using AI to check the AI you used
Agencies are not just writing rules about AI. Many are testing and using it. NICE, CDA-AMC, HAS, IQWiG and others have run their own evaluations of AI tools, and they have not always concluded in AI’s favour. Agencies with in-house machine-learning experience know exactly where these tools fail, and they will ask pointed questions accordingly. AI-assisted assessment may also surface inconsistencies faster, which makes undeclared AI use easier to spot.
Meanwhile, how much AI is actually being declared? A 2026 ISPOR review found AI reported in only three NICE technology appraisal documents.
There are two possible explanations.
Either very little AI is being used in submissions, or much of it is going undeclared. Most people working in HEOR today know which is more likely.
There is an upside. Early, well-documented declarations will set the precedents others follow, and the agencies’ own published tool evaluations can do some of your vendor due diligence for you, if you know where to look and how to read them. That is covered in the course too.
What remains unsettled
It would be easy to present the new principles as a finished rulebook. They aren’t. HTACG says itself that further guidance will follow “as needed”. This is a first version, not the last word.
Comparing the three texts side by side reveals eight genuinely open questions. Three of them:
• Performance thresholds. There is no HTACG sensitivity or accuracy bar for AI screening or extraction.
• Proprietary tools. Vendors update models silently, which sits awkwardly with a requirement to report the exact version you used.
• Consequences. Nothing in the texts says what happens if undeclared AI use is discovered.
The other five, and the national signals from agencies across Europe that hint at how they may be answered, are where the course spends real time. Uncertainty is not a reason to wait. It is a reason to have a documented position on each question before an assessor gives you theirs.
The one-sentence test
If you take one thing from this article, take this test, and apply it to every AI-assisted step in your current live submission:
Could a stranger reconstruct what the AI did, and who checked it?
If the answer is no, the declaration isn’t ready yet.
Passing that test takes more than good intentions. It needs an inventory of every AI touchpoint, including the ones nobody consciously chose. It needs a declaration built to satisfy several bodies at once, an audit trail designed before the work starts, and a named person prepared to sign. In the course workshop, teams build all of this for a live submission and then hand it to colleagues playing the JCA assessor, whose only job is to find the weaknesses. It is far better to find them there than in a published report.
What this article left out
What this article left out
This article covers the shape of the problem.
The full course covers how to solve it, including:
- a stage-by-stage human oversight design across the evidence pipeline, from retrieval to reporting;
- a complete AI-use declaration template, field by field, mapped to HTACG, NICE and CDA-AMC;
- an audit-trail design you set up before the work starts, not after;
- an accountability and sign-off model for sponsors, CROs and tool vendors;
- all eight open questions, the national agency signals behind them, and how to raise them in early dialogue;
- a pre-submission legal checklist covering copyright, data protection, confidentiality and the AI Act;
- a red-team workshop where your declaration is challenged before an assessor sees it.
And because the course has already been updated more than once since it was first recorded, what you learn reflects the guidance as it stands now, not as it stood when I first wrote the slides.
To find out more about the Pharma AI Enablement Institute, click here, or contact us here.
Or email institute@eularis.com for a confidential call about your challenges to identify if this can help.