Which Life Sciences Companies Are Actually Getting AI Governance Right?

Aug 27, 2026 | 6 min read

  • CI Life
  • The companies making real progress on AI governance aren't the ones with the thickest policy binder. They're the ones that folded AI governance into a structure they already had, and then built oversight around what they actually found. AstraZeneca and Novartis are both proof of that, and neither one built AI governance as a brand-new department.

    Most articles about AI governance show you a framework: a diagram with boxes, a list of principles, a chart with arrows pointing at each other. What they don't show you is what happened after a real company built one. AstraZeneca and Novartis both have public, verifiable answers to that question.

    Here's the pattern worth paying attention to. Neither company treated AI governance as a separate function bolted onto the business. Both folded it into something that already had real authority: an existing data office, an existing code of ethics. That's the difference between a framework that works and one that just exists on paper.

    What does it actually look like when a life sciences company gets AI governance right?

    Not a slide deck. A real governance program needs three things: a framework that says what's allowed, a way to catch it when something goes wrong, and someone with the authority to actually act once it does. Most companies manage the first part. Fewer manage the second. Even fewer have the third figured out, which is usually where a governance program quietly stops being real.

    The gap between the first part and the third part is exactly where most AI governance efforts fail. Writing down what's allowed takes an afternoon. Building a way to actually notice when the rule gets broken takes months, and giving someone real authority to act on what they find, authority that can override a project timeline or a department head, takes a level of organizational buy-in most governance documents never get. AstraZeneca and Novartis both got there by attaching AI governance to a function that already had that authority, instead of asking a brand-new committee to earn it from zero.

    What did AstraZeneca's R&D Data Office actually build?

    AstraZeneca didn't stand up a separate AI governance team from scratch. It built an AI Governance Framework, a Risk Framework, and a Playbook, all inside its existing R&D Data Office, the same group already responsible for data governance across research and development. Brian Dummann, VP of Insights & Technology and Chief Data Officer at AstraZeneca, explained the reasoning to CDO Magazine: asked whether AI governance is something separate from data governance, his answer was that it falls under data governance for risk, with AI governance capability and talent sitting inside the enterprise data office rather than off on its own.

    That's a specific, deliberate choice, not an accident. Dummann described it as a decision to avoid making AI governance "another group or committee." Instead, AstraZeneca operates a federated model, data offices embedded across business units, aligned to one central enterprise data office that sets standards, tools, and policy. The questions AI raises, who has access to a model, what happens with its output, how a decision traces back to its source, are largely the same questions data governance was already built to answer. AstraZeneca didn't need a new department to ask them. It needed to extend the one it had, and the company had the scale to make that extension count: AstraZeneca reported more than $45 billion in revenue in 2024, with a target of $80 billion by 2030, so the data and AI structure underneath that growth carries real weight.

    How is Novartis governing AI differently?

    Novartis took a similar approach from a different starting point. In 2023, the company introduced an AI Risk & Compliance Management Framework, sitting under a broader Ethical Use of Data & Technology Policy it expanded through 2024. The framework applies to AI Novartis builds internally, AI it co-develops with partners, and AI it simply buys from a vendor, a detail that matters because most companies only think to govern the AI they built themselves. Novartis frames it as covering transparency, explainability, and human oversight together, not as three separate checklists someone fills out once and files away.

    Novartis also created a dedicated AI Handbook that lays out its guiding principles in one place, instead of scattering the rules across memos and slide decks. None of this appeared overnight. It's an update to a Code of Ethics the company already had, expanded specifically to cover AI as the technology showed up in more parts of the business. That timing matters. Novartis didn't wait for a finished, perfect AI policy before doing anything. It updated what it had in 2023, then kept building through 2024 as it learned more about where the actual risk was.

    Register for the September 24 webinar

    What do these companies have in common?

    Neither one waited for a perfect framework before acting, and neither treated AI governance as its own island. Fierce Pharma reported on a 2025 Define Ventures survey of pharma leaders that found 80% already have some kind of dedicated AI governance structure in place, with ethics and safety as the main focus for most of them. AstraZeneca and Novartis aren't outliers. They're early, well-documented examples of where most of the industry is already heading.

    What sets them apart isn't that they moved first. It's that they built governance into something that already had real authority: an existing data office, an existing code of ethics. That's the same argument we made in the first post of this series about visibility coming before framework, and the same one behind why simply blocking tools doesn't work. Governance sticks when it's attached to a real function with real authority. It doesn't stick when it floats on its own as a document nobody owns, which is exactly how AI mistakes turn into real consequences in the first place.

    None of this means either company has finished the job. AstraZeneca and Novartis are both still expanding these frameworks as AI use grows inside their organizations, and neither would claim to have a perfect system. What they've proven is narrower and more useful than perfection: governance built on top of an existing function survives contact with reality better than governance built from nothing. That's a repeatable model, not a one-time success story, and it's available to any life sciences company willing to look at what it already governs well and extend that authority to AI, instead of starting a new committee and hoping it sticks.

    Frequently asked questions

    What does good AI governance actually look like in a life sciences company?

    It has three parts: a framework that defines what's allowed, a way to catch problems when they happen, and someone with real authority to act on what's found. Most programs are missing at least one.

    How did AstraZeneca approach AI governance?

    AstraZeneca built an AI Governance Framework, a Risk Framework, and a Playbook inside its existing R&D Data Office, treating AI governance as an extension of data governance rather than a separate function.

    What is Novartis's AI Risk & Compliance Management Framework?

    It's a framework Novartis introduced in 2023 and expanded through 2024, covering AI the company builds internally, co-develops with partners, or purchases from vendors, all under its broader Ethical Use of Data & Technology Policy.

    Do most pharma companies already have an AI governance structure?

    According to a 2025 Define Ventures survey reported by Fierce Pharma, 80% of pharma leaders say their company already has a dedicated AI governance structure, with ethics and safety as the main focus for most of them.

    Save your seat for "AI Adoption Is Accelerating, But Where Is the Oversight?"

    Author
    Headshot of Craig Taylor, Practice Lead at CI Digital
    Craig Taylor

    Share this article

    Subject Matter Expert
    Claudia Beqaj Photo
    Claudia Beqaj

    Managing Partner - Health and Life Sciences

    Driving impact across the pharmaceutical landscape with over two decades of cross-functional leadership.

    Speak With Our Team

    Share this article

    Let’s Work Together

    [email protected]