The moment that stayed with me came out of one of my own training programmes. A regulatory affairs professional built her own agents and designed a three-layer approach for comparing certificates of analysis against release specifications, then presented it back to the room. Genuinely excellent work, in one of the least forgiving corners of this industry. Then the predictable thing happened: everyone wanted her to do it for them, on top of a full-time job that already had a submission due Friday. And when she asked how she could get the others to learn it when there was no more AI training scheduled, I had no answer.
The obvious answer is to capture what she knows and put it in the L&D system. It doesn’t work, for three reasons. She’s doing this on top of a full-time job, so there’s no time to build it. She’s an enthusiast rather than an AI specialist, and expert in regulatory rather than in medical affairs, safety and market access, so what she builds can’t serve the functions that need it most. And whatever she does build starts going out of date the moment a model updates, with nobody whose job it is to notice.
So I’m not here to tell you AI training doesn’t work. It works. I watch it work. I’m here about what happens next — because ninety days later, what a company typically has is one person who can do something remarkable, and a function that still works exactly the way it worked before.
That’s the problem. Not absence of capability. Capability the organisation never manages to hold. There are two reasons it doesn’t hold. One this industry has spent three years fixing. One almost nobody has named.
Failure one: it fades
Ninety days after an excellent session, you can no longer assume the capability is there.
Two meta-analyses cover different halves of why. On the procedural side – knowing how to run a workflow – a 2025 meta-analysis in Psychological Bulletin pooled 1,344 effect sizes from 457 reports and found a clean gradient rather than a cliff: half the initial gain in accuracy-dependent procedural skill lost at around six and a half months of non-use, roughly thirteen months for speed-based skill. Medical and dental procedures sit in the coded task categories, so this is not undergraduates memorising word lists. On the judgement side, an earlier review of 189 effect sizes across 53 studies found that below ninety days the evidence is mixed, beyond ninety days decay appears consistently, and that cognitive, accuracy-dependent work erodes around three times faster than physical or speed-based work.
Now split what your people do with AI. Running the workflow – supplying the right source material, structuring the request, working a draft into shape – is procedural, and decays on the gentler curve. Deciding whether a generated summary faithfully represents its source, whether a drafted response is defensible, whether an output can go in front of a regulator: that is cognitive, accuracy-dependent judgement, and it sits in the fastest-eroding category either paper identifies.
So you lose the half that carries the regulatory consequence faster than the half that produces the visible productivity. And nearly every measurement system in this industry is pointed at the wrong half. Usage dashboards, licence utilisation, satisfaction scores which are all of them watch the procedural side, which is the side that holds.
There is a second force on top of the ordinary curve, and it has no published literature because nothing has moved this fast before. Ordinary decay assumes the object of the capability holds still. Aseptic technique does not change while you forget it. AI does. Models change, features evolve, governance expectations shift. Which produces a failure mode ordinary decay cannot: a team that retained its training perfectly can still be wrong, because what they retained is no longer true. They have carefully preserved a technique the platform retired two updates ago.
Failure two: it never fitted
That’s failure one, and if you’ve moved to an ongoing company-wide programme, you have largely solved it. Content doesn’t age on a shelf. New joiners get enrolled. There’s a record. Measured against the workshop model, real progress — and most of your peers haven’t made it.
Failure two is the one nobody has named, and it is now the more common of the two.
A company-wide curriculum is, by construction, the same curriculum for everybody. It teaches what AI is, what it does well, where it fails, what the policy says. All worth knowing, and all identical for a medical writer and a supply chain analyst. What is not identical is the work. The judgement a regulatory writer needs to decide whether a generated summary faithfully represents its source has almost nothing in common with the judgement a brand manager needs to decide whether a generated claim is substantiated. Different failure modes, different evidence standards, different consequences, different reader at the other end.
The large horizontal platforms scale that problem rather than solving it. A Coursera library is enormous, current, cheap per head and genuinely well made — and built for everybody on earth, which means built for nobody in your building. There is no module on whether a generated summary is faithful to its source in a submission. No course on where AI use must be disclosed in promotional review, what in-silico evidence justifies wet-lab spend, or how a safety narrative changes when a model drafted part of it. That isn’t a criticism of the content. It’s a category point. General platforms teach the tool. What your people need taught is the judgement.
So here is the frame I’d like to leave you with, because I think it’s the most useful thing in this article. There are two axes, not one. Episodic to maintained. Generic to role-specific.
The workshop is episodic and generic. Custom consulting is episodic and role-specific: excellent, expensive, gone the day the consultant leaves. The company-wide platform is maintained and generic, and that is where most of this industry has arrived and stopped. Only the fourth box – maintained and role-specific – produces capability that both persists and applies.
Most organisations made one of the two moves and treated it as the destination. Going from episodic to maintained solves availability. It does not, on its own, change what anybody does on a Tuesday. Enrolment is high, completion is high, the dashboards are lovely, and the submission gets written exactly the way it was written before.
Why pharma pays more for this
Every industry has this decay. Pharma pays more when it happens.
Your people don’t work in a sandbox. Medical information, pharmacovigilance, submissions, medical-legal review, content going out under your company’s name to a prescriber or a payer. When someone in another sector half-remembers how to use an AI tool, the cost is a clumsy email. When your regulatory team half-remembers, the cost is a confidently wrong output inside a regulated workflow. And a fifty-person biotech carries the same exposure per document as a global company, with none of the review depth to catch it first.
But here is what actually concerns me. Training with no follow-through can leave you more exposed, not less. You have raised several hundred people’s willingness to use these tools without embedding the judgement to use them safely. Usage rises faster than control. That’s a risk you funded, with a certificate of attendance stapled to it.
There is a better version of that argument than my abstract one. Dr Myriam Cherif spent fourteen years in large pharma, latterly running regional medical affairs for oncology across GSK’s emerging markets. She describes her own path with these tools as five stages.
1. Dislike – too generic to be worth the effort.
2. Learning – better prompts, better outputs, then a plateau.
3. Daily use it clicks, she loves it.
4. Then stage four: over-reliance, loving it so much that without noticing she began outsourcing her thinking to it.
5. Then stage five: sparring partner, knowing what to keep and what to ignore.
Two things about that. Stage one is a finding about training design, not about her: generic content gives a specialist no reason to persist past the first disappointment. And stage four is this whole argument, reported from the inside. Over-reliance didn’t arrive through neglect. It arrived through enthusiasm, at peak confidence and peak usage, and it was invisible while it happened. She names it only in retrospect.
Which tells you something no abstract version can. A person in that stage does not feel uncertain. They feel excellent. On your post-session survey they report high satisfaction, high usage and high confidence — the three things most organisations read as success. There is no question on your feedback form that catches this. None.
And now it’s a regulatory question
Until recently all of that was a management argument. As of July, part of it isn’t.
Article 4 of the EU AI Act — the AI literacy duty – was rewritten in full by the Digital Omnibus, in force from 27 July. The old wording was a duty to ensure a sufficient level of literacy. The new wording is a duty to take measures supporting its development.
That reads like a relaxation, and plenty of people have filed it that way. I’d read it as a change of kind. What it lightens is the result. What it leaves is the effort. An obligation to ensure a level is oriented to a result, and a result can in principle be discharged by one intervention that demonstrably raised capability. An obligation to take measures supporting development is an obligation of effort — and effort is not a state you arrive at. It is demonstrated continuously.
Three features matter more than the headline.
Scope. Most obligations under the Act attach to high-risk systems. Article 4 doesn’t; it applies at any risk level. So it covers the general-purpose AI already in daily use across every function, not a narrow set of validated tools. And note that the same Omnibus which softened the literacy wording deferred the high-risk obligations beside it, out to 2027 and 2028. Article 4 was not deferred.
Reach. Non-EU organisations are in scope where the output of their AI systems is used inside the EU. So if you are in New Jersey or Basel filing this as a European problem, I’d check.
What satisfies it. Measures must account for people’s skills, experience and the context in which systems are used. Which is where role enters, because context is not separable from the job someone does. A generic awareness session is a measure. So is a company-wide fluency programme with a completion record. Against a standard framed around context, both are thin — because a completion record for a generic programme documents, precisely, that a generic programme was completed.
Regulatory note: this describes the position as at late August 2026 and is general information only, not legal advice or a compliance assessment. The EU AI Act, the guidance under it, and the FDA and EMA positions all continue to develop, and how any of them applies depends on your own systems, jurisdictions and circumstances. Confirm your obligations with your own legal, regulatory and compliance functions. No capability programme, including ours, can of itself make an organisation compliant with Article 4.
Six requirements to hold against any supplier
The answer is not a longer event. A two-day session decays exactly like a one-day session; you have front-loaded more material into a sitting people will still forget.
Better to go back to that regulatory affairs professional, because she is a better test than any principle I could offer. What would have had to exist for her three-layer approach to become how her function operates, rather than something one capable person did once? Not a better session – the session is what produced the approach. Somewhere to take the next version when the model changed underneath it. Colleagues in her own discipline working the same problem, so it wasn’t hers alone to carry. A record her head of function could see, so it registered as a departmental capability rather than a thing she does. And a route for the other fourteen people in regulatory to get there without her personally teaching each one.
Answer that honestly and you have written the specification. Here it is as six requirements. Hold it against your internal programme, your existing supplier, or the proposal on your desk this afternoon.
PHARMA AI TRAINING MEETING REQUIREMENTS CHECKLIST
1. Routed by function. Everyone starts with foundations. After that, medical affairs does medical affairs, regulatory does regulatory, supply chain does supply chain. Routed by function, not by an AI knowledge assessment — you don’t need an assessment to work out what job somebody does.
2. A foundation that’s common because the work is common, not because it’s introductory. GxP validation applies wherever AI touches a qualified process. Security, confidentiality and who owns AI-generated output don’t vary by department. The test isn’t how much sits in the foundation; it’s whether what’s there is common because the regulatory reality is common, or common because it was cheaper to write once.
3. A standing route for live questions. The gap between understanding a technique and using it on the submission in front of you is where most training quietly dies. There has to be somewhere to take the real thing to a real pharma AI specialist.
4. Content kept close to the reality it describes. Recorded material that ages is the same problem as a workshop that fades, in a format that hides it better. Prompt guidance tuned to a previous generation of model can produce materially worse results on the current one, silently.
5. A per-person record the functional sponsor can act on. Not an organisation-wide completion percentage. Who has done what, in which role, how recently, visible to the person accountable for that team. Most organisations discover they don’t have this at the exact moment somebody asks.
6. Governance running alongside the skills, not after them. Otherwise you get the sophisticated version of confidence without competence: a team that knows how to use the tools and isn’t current on what’s expected of that use.
None of that is exotic. It is what you already do for every capability you take seriously. You don’t validate a system once and walk away. You don’t run one pharmacovigilance check and call the function covered. The only new idea is applying that logic to the fastest-moving capability in your business — which is, precisely backwards, the one you have assigned your lightest maintenance model.
Every licence starts with Foundations — common because the regulated reality is common, not because it’s introductory. Just a few examples from many of the content in this part. ‘How to evaluate an AI vendor properly: what to ask, which claims collapse under a specific question, what a demo is designed to hide’. ‘How to judge AI output effectively, with working checklists your team can apply to a real draft — faithfulness to source, defensibility, what has to be verified before anything goes near a reviewer’. ‘GxP validation wherever AI touches a qualified process’. ‘Security, confidentiality, and who owns AI-generated output.’ Shadow AI and How to Ensure Safety with Prompt Poisoning and other unseen AI Dangers’
Then the tracks split by function. Regulatory teams train on how to leverage AI within specific regulatory workflows. e.g. AI for CMC & Module 3 Authoring’, Medical affairs topics for medical affairs workflows e.g. ‘AI in Evidence Generation: Integrated Planning, Gap Analysis and Study Support’. ‘Publication Integrity in the AI Era: Authorship, Disclosure and Journal Policy’, Market Access topics for Market Access functions e.g. ‘AI, RWE and Unstructured Data for Payer-Relevant Evidence’ , Quality and Compliance e.g. ‘Annex 22 and the Validated State: AI Models in GMP-Critical Applications’, R&D e.g. ‘High-Throughput Screening & Lab Automation with AI’, Manufacturing e.g. Electronic Batch Record Review & Release’, Commercial e.g. ‘AI for hyper-personalisation of HCP marketing’, ‘AI for HCP segmentation and targeting’ and so on – each highly relevant to a functional role and each growing topics constantly. Hit a challenge, find the video solution. AI-enabled video search! Of course.
Around that sits the maintenance, which is the part I haven’t seen done properly anywhere:
• Monthly office hours with me, live. Questions submitted in advance and answered anonymously. A regulatory team working out how to use AI in a submission workflow. An L&D manager building the internal case. A market access team unsure whether a vendor’s claims survive contact with reality. The anonymity is the entire mechanism — it’s what lets one session serve organisations that compete with each other, without anyone describing their internal workflows in front of a peer.
• A quarterly refresh. Four times a year, the opening live session covers only what has actually moved that quarter: model capabilities, new tools worth your attention, shifts in regulatory expectation, emerging practice. Run once across the Institute, not repeated per function, and emphatically not a re-performance of introductory material. The point is that attending one saves your team the work of scanning the field themselves.
• Role-specific prompt libraries, kept under review as the models change, because guidance optimised for a retired model fails silently.
• Governance updates running alongside the skills rather than after them.
• Per-person records at a granularity each functional sponsor can act on for their own team.
• Independent vendor analyses, on the roadmap rather than at launch. When they come, we take no referral fees, no revenue share and no promotional arrangements from anyone we assess. That independence is the only thing that would make them worth reading.
On pricing, I want to be direct, because this is a design decision and not a discount. One price per business unit, banded by the size of that unit. No per-seat charges. Everyone on the licence gets the full library, all of Foundations, everything added during the term, and the live sessions.
Here’s why that matters. Per-seat pricing has a specific effect in this industry and I have watched it happen repeatedly: the fifteen-person biotech decides it can only afford to send two people. Two come back with capability, thirteen don’t, and the two who did get quietly absorbed back into how the team already works. That is precisely the failure mode this article is about, and the pricing model caused it. So the banding is there to make the entry point real for a small biotech with no L&D function and one regulatory person carrying an entire submission, and to work equally for a five-hundred-person global function. Not two products. One programme, priced so the size of your organisation decides what you pay, not whether you can take part at all.
The rest is unromantic: annual term, PO-based onboarding, no auto-renewal. Theming, private sessions and LMS delivery are add-ons.
Two questions, whether or not you ever speak to us
Next time you scope AI capability work, internally or from a supplier, ask two questions. Not “how good is the session?” A good session is easy to buy.
First: what happens in month four? If the answer is “you’d book another one,” you are being sold the expensive model in economical packaging. The right answer describes a structure.
Second, and this is the one a maintained generic programme cannot answer: what does this look like for a regulatory writer, and how is it different for a brand manager? Real role-specificity answers immediately, and differently, for each. A generic catalogue describes the same content twice and calls the difference a learning path. Ask for both curricula side by side. The gap between them is the whole answer, and it takes a minute to see.
And one thing to actually do this month: run the audit almost nobody runs. Not of what you have purchased, but of what your people are already doing without being asked. Which tools are in daily use, including the ones nobody approved. Which workflows they have quietly entered. How much of that touches regulated, confidential or patient work. How you ask decides what you get — run it as a compliance investigation and you’ll get denial, and drive the usage underground. Run it as a capability question and you’ll get a remarkably candid picture. Most people aren’t hiding anything. They are using tools that were already on their desktop, for work already on their list.
So: trained once is not a capability plan. And trained generally, forever, isn’t one either.
Pharma already knows how to build capability that lasts. You do it for pharmacovigilance. For regulatory affairs. For clinical operations. For every function where getting it wrong is consequential. The logic is identical for AI. The only thing missing was the decision to apply it.
I’ll be straight with you: I’m more excited about this than anything Eularis has built. It is because it finally gives that regulatory affairs professional somewhere the other fourteen people in her department acan learn how to do things themselves, and that doesn’t run through her calendar. They all gain capability and results that is constantly up-to-date.
If you want that structure for your function, the next step is a twenty-minute conversation about where your team actually sits — including if the honest answer is that you should build it yourself. Email training@eularis.com or contact@eularis.com and we’ll set it up.
Found this interesting?
Most training providers hand you a catalogue and ask which parts you’d like. We do it the other way round.
Book twenty minutes and I’ll show you the topic roadmap by function (including leadership) — hundreds of pharma-specific AI trainings, function by function, many already built, and more in production.
Then tell us what you want AI-ified in your own role. The workflow that consumes your week. The one you’ve assumed can’t be automated. We’ll show you how to do it, and it goes into the build queue.
For more information, contact Dr Andree Bates abates@eularis.com.