Defensible, Scalable, Fast: A Practical AI Framework for Regulatory Submissions in Medical Devices

by | Sep 8, 2026

Defensible, Scalable, Fast: A Practical AI Framework for Regulatory Submissions in Medical Devices
Michael Konings (Head of Regulatory Affairs IGT Systems, Philips) and Sepanta Fazaeli (Head of AI Solutions, TransPerfect) sat down with moderator Gert Bos (CSO, Qserve Group) at the MedTech Regulatory Intelligence Conference in Arnhem to work through the questions most teams are facing when adopting AI in regulatory submission. Their answers had less to do with the technology than with the state of the data and processes sitting underneath it. The full Q&A is below.

Q1: Why is AI in regulatory submissions such an important topic for you personally?

Michael Konings (Philips)

What I see in regulatory affairs is AI coming into play rapidly, but the conversation is not just about the technology itself, it is about where and how you use it. I do not believe anybody has written the definitive book on how AI will help us. Many of us are understandably cautious. But this is part of the journey, and it is about learning together, connecting with peers, and helping solution providers build tools that actually answer our needs.

Sepanta Fazaeli (TransPerfect)

There is a collective sense of being overwhelmed across the industry. People are worried about how AI will affect their roles. I came from Stryker, where I spent several years on intelligent process improvement and represented the company at the EU AI Act Task Force. My goal now is to move past the hype: AI is not going away, and it is not magic. It is yet another tool and like any other tool, it comes with obligations and requirements. The conversation should be about how to use it safely and smartly.

Q2: What is the biggest misconception regulatory teams walk in with when they hear ‘AI-enabled submissions’?

Sepanta Fazaeli (TransPerfect)

There are several, and they are connected. The first is believing AI automatically qualifies as a medical device and triggers the highest level of regulatory scrutiny. That is not always the case it depends on the intended purpose and the risk classification. But regardless of the regulatory category, if you are deploying AI within a GXP environment, you need to validate your process end-to-end. That is not an AI Act obligation, it is just good practice for any tool in a regulated workflow.

The second misconception is that you need AI for everything. More often than not, straightforward automation will do the job with far less validation burden. Ask yourself: Does this genuinely require the probabilistic capability of a large language model, or can a deterministic rule handle it?

Third, people assume AI has to be perfect. It does not. There are measured, proportionate ways to integrate AI into workflows without eliminating every uncertainty as long as you have the right guardrails, documentation, and oversight in place.

Michael Konings (Philips)

The most persistent misconception is that the tool will solve everything on its own. I have not seen an AI tool that will write your technical file for you. The second is failing to start with a clear problem statement. Ask: What are you trying to solve? Build a strategy first. Then, and this is important, AI amplifies what is already there. If your data is bad, it will reveal that very quickly. If your process is broken, it will iterate rapidly on a broken process. Fix the foundations first.

Q3: Out of ‘defensible, scalable, and fast’ — which is hardest to achieve and why?

Michael Konings (Philips)

Defensible is by far the hardest, and the reason is trust. How can you defend something you do not fully understand? Many AI tools remain a black box. And in our field, it is not just the output that needs to be defensible, it is every step of the process. Notified bodies, patients, and regulators all need to be convinced that the chain of decisions is sound. There is always a human accountant somewhere, most likely in this room, and that person needs to be able to put their signature on the output with confidence. That requires trusting each step completely.

Sepanta Fazaeli (TransPerfect)

I agree. And I would add a dynamic risk: in our drive to make things scalable and fast, we often inadvertently eliminate the very thing that made the output defensible, genuine human critical engagement in the decision-making process. This is what automation bias is about. The EU AI Act addresses it. FDA draft guidance addresses it. Once you introduce AI into a process, it changes how humans interact with that process, what they notice, and how they judge. The influence on judgment is the common thread across all risk levels.

Q4: What did getting your data house in order actually require at Philips?

Michael Konings (Philips)

A concrete example: we implemented a tool to manage access enablement and disabling. Almost immediately, clearance times ballooned from hours to days and weeks. Nothing was wrong with the tool. But when we looked deeper, we found there was no well-documented process governing what data went in and what came out. The tool simply exposed the gap.
The solution had three layers. First, make sure the right data is in the right place, accessible to the right people. Second, transform tacit, craftsmanship-based processes into transparent, tool-readable workflows. Third, bring the people along, build AI literacy across the team. In short: data, process, and people ownership. In that order.

Q5: What separates organisations ready to scale AI from those that only think they are?

Sepanta Fazaeli (TransPerfect)

The pattern is brutally consistent: organisations that have an easier journey with AI adoption are the ones that were also doing well before AI. The technology is not the bottleneck, it is advancing faster than anyone can keep up with. The bottlenecks are siloed systems, disconnected data, and a lack of standardised procedures.

AI can find a misaligned hazard ID in your risk management file in 30 seconds. But if your systems are siloed, it will take three weeks to act on it because nothing talks to anything else. The concept of FAIR data, Findable, Accessible, Interoperable, Reusable — is the foundation. Without it, you will remain in what people call the ‘decel valley’: impressive demos that never scale into production. Standardisation is equally critical. If your adverse event data is labelled differently across PMS, clinical, and real-world evidence, your risk management file has a basket-of-fruit problem, you are either overcounting or undercounting, and AI will not fix that; it will just do it faster.

Q6: How do you prevent — or escape — the AI pilot ‘valley of death’?

Sepanta Fazaeli (TransPerfect)

Start small and pick low-hanging fruit that demonstrates impact quickly, because organisational interest evaporates fast without visible results. Invest in the right people: you need an analytical translator, someone with both technical fluency and deep domain knowledge who can bridge IT and medical/regulatory teams. These hybrid roles are undervalued and underfunded in most organisations.

Define KPIs before you start. What does success look like? For automation bias specifically, consider metrics like time-to-review for article screening: if a reviewer is processing items below a minimum time threshold, the scrutiny is insufficient, regardless of how many items were handled. Most importantly, build your first pilot as a reusable asset. Every pilot should be a template for the next use case, not a one-off.

Q7: How do you integrate AI into existing QMS infrastructure without disrupting validated processes?

Michael Konings (Philips)

AI cannot be a separate activity. It must be embedded in the QMS just like any other tool — with a defined process, consistency, traceability, and compliance. That means having a documented strategy for how AI is permitted to be used, including its intended use and explicit boundaries. Notified bodies will look for this.

Start with small, incremental steps in areas where you already have confidence. Earlier-phase activities, market access regulation tracking, standards assessment, are good candidates because they are more deterministic. Do not attempt to automate the most critical compliance decisions until you have established a strong track record of trustworthy outputs.

Q8: How should regulatory teams approach the risk of automation bias versus non-negotiable human oversight?

Michael Konings (Philips)

It is proportionate to risk and consequence. For internal use cases, translation, drafting, document organisation, lower oversight may be acceptable as trust is established. For anything that directly affects a patient-facing label, a warning, or a submission that will be scrutinised by a regulator, human expertise must be central. The concern I have is human fatigue: if you review the same type of AI output hundreds of times, scrutiny naturally decreases. The QMS needs to build in structural checkpoints that prevent that drift.

Sepanta Fazaeli (TransPerfect)

With today’s large language models, because of their probabilistic and inherently non-deterministic nature, a final human check is not optional. You can earn your way toward lighter oversight over time: start with 100% line-by-line review, collect performance data, and only move from ‘human-in-the-loop’ to ‘human-on-the-loop’ once the evidence supports it. The manufacturer is always the liable party. The AI does not sign the document, you do.

Q9: What first action should people take when they get back to the office?

Michael Konings (Philips)

Look at your strategy. Where can AI or automation add value in your workflows, and where should it not be used? Break down one process end-to-end. Pick one small, repetitive task, even something as simple as extracting action points from meeting notes and automate it. Create a small win. Build trust through experience.

Sepanta Fazaeli (TransPerfect)

Find what is repeatable and tedious. Then ask: can I draw this process as a logical flowchart? If you cannot decompose it into modular, sequential steps, the process itself needs fixing before AI can help. Use the AI implementation exercise as a diagnostic: process disintegration will surface every ambiguity and weakness that your team has been working around for years. That is not a problem, it is the starting point.

“Eat the elephant one bite at a time, but with a strategy. — Gert Bos, Moderator”

DistillerSR
  • Vivian MacAdden, DistillerSR

    Vivian MacAdden is DistillerSR's Senior Manager, Industry Marketing - Medical Devices. Throughout her career, she has accumulated 20 years of strategic marketing experience in various industries in Canada and international markets such as Brazil, China, Singapore, Jordan and Japan. A problem solver at heart and forever an optimist (and karaoke lover), she is passionate about telling great stories that make a positive impact on the world.

    View all posts

Stay in Touch with Our Quarterly Newsletter

Recent Posts

What is Regulatory-Grade AI?

What is Regulatory-Grade AI?

We keep getting asked the same question: if we use general-purpose AI tools to support a regulatory submission, will the output stand up to a regulator, a payer, or a notified body? Every day, medical affairs, HEOR, and regulatory teams conduct literature reviews that...