←
AI for Pharma & Life Sciences
Capable · M4 · lesson 4 of 35 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI-Assisted Cover Letter and Module 1 Disclosure of AI Involvement
📖
now learning

AI-Assisted Cover Letter and Module 1 Disclosure of AI Involvement

15 min

Two weeks before the NDA locks, the RA director sends the Module 2.5 lead a one-line email that stops the room: "Legal wants to know what we are saying in the cover letter about the AI." No one has written it. The submission used Certara CoAuthor to draft Module 2 sub-summaries, an enterprise LLM to draft three Module 1 administrative documents, and an AI-assisted granularity check on the eCTD backbone. The question is not whether AI was used; it was, extensively, and that is now ordinary. The question is what, if anything, the cover letter should say about it, in what words, with what level of detail, and whether saying too much invites scrutiny while saying too little fails the FDA-EMA transparency principle that took effect on 14 January 2026. This lesson is about that paragraph: the emerging-practice cover-letter disclosure of AI involvement, what the transparency and accountability principles actually imply for it, what sponsors are putting in submissions in 2026, and how to draft a disclosure that is accurate, defensible, and not a liability. It is the paragraph the agency reads first and the one that is hardest to get right, because there is no template, only principles and a fast-moving practice.

Why This Paragraph Exists Now

For most of regulatory history there was nothing to disclose, because the tools that drafted submissions were word processors and reference managers, and no one expected a cover letter to say "this document was typed in Microsoft Word." The forcing function changed that. On 14 January 2026, FDA's CDER and EMA jointly released the Guiding Principles of Good AI Practice in Drug Development, ten principles spanning nonclinical, clinical, post-marketing, and manufacturing AI use, with explicit applicability to the AI used to generate, review, or support regulatory content. Two of those ten principles bear directly on the cover letter: transparency, which asks that the use of AI be visible and understandable to those who rely on the output, and accountability, which insists that a named human and the sponsor, not the tool, remain responsible for the content.

Neither principle says "write a paragraph in the cover letter." The principles are outcome statements, not formatting instructions, and that is precisely the difficulty. Transparency can be satisfied in more than one place: in the cover letter, in a Module 1 administrative document, in an AI use log retained and producible on request, or in some combination. What the principles do is shift the default. Before January 2026, silence about AI was normal and defensible. After it, silence is a position that may need defending, because a reviewer who later learns that AI drafted a Module 2.5 the sponsor never disclosed may read the omission as an attempt to obscure how the document was produced, which is a worse posture than a clean, factual disclosure would have been. The paragraph exists because the floor moved, and the practice is now catching up to the principle.

What the Transparency Principle Actually Requires, and What It Does Not

The transparency principle is widely misread in both directions, so it is worth stating precisely. It does not require disclosing every prompt, every model version, or every keystroke of AI assistance in the cover letter. It does not require the sponsor to characterize the AI as a co-author or to apportion percentages of human versus machine contribution. And it emphatically does not transfer accountability to the vendor or the model: the accountability principle is explicit that the sponsor and the named author own the content regardless of how it was produced. What transparency requires is that those who rely on the submission can understand, at an appropriate level, that AI was used and that human verification governed the output, so that the reviewer is not misled about the provenance of the content.

"At an appropriate level" is the load-bearing phrase, and the appropriate level is higher and cleaner than most first drafts assume. A defensible 2026 cover-letter disclosure typically states three things and no more: that AI tools were used to assist in the preparation of certain submission content, that all AI-assisted content was reviewed and verified by qualified personnel who are responsible for its accuracy, and that the sponsor retains records of the AI use available upon request. It does not enumerate which sections, which tools, or which models, because that detail belongs in the retained AI use log, not in the cover letter, where it would be both unnecessary and a hostage to error. The cover letter makes the attestation; the log holds the evidence. Conflating the two, by trying to put log-level detail into the cover letter, is the single most common drafting mistake, and it produces a paragraph that is longer, more brittle, and more likely to contain a claim that does not match the record.

What Sponsors Are Actually Submitting in 2026

Practice in 2026 is not uniform, and it is worth being honest about the spread rather than pretending there is a settled standard. At one end, some sponsors include no AI disclosure at all, on the view that AI-assisted drafting with full human verification is no more disclosable than spell-check, and that the verified content stands on its own. This is a defensible legal position and is still common, but it is becoming the minority posture for submissions with substantial generative-AI involvement, because the transparency principle creates a presumption that meaningful AI use should be visible. The distinction that matters is between AI as a productivity utility and AI as a content generator: few would argue that grammar-checking or formatting assistance is disclosable, but generating substantive Module 2 summary text is a different category, and the line between the two is exactly where the transparency judgment lives. At the other end, a small number of sponsors over-disclose, naming tools, models, and sections, which creates a paragraph that must be re-verified every time the tool stack changes and that hands a reviewer a detailed map of where to probe.

The center of gravity in 2026 is a short, principle-aligned attestation: a few sentences in the cover letter affirming AI-assisted preparation with human verification and retained records, paired with a more detailed AI use log kept outside the cover letter and produced on request. The use log is where the specifics live: the tools and versions, the sections assisted, the nature of the assistance, the verification steps, and the named verifiers. This pairing satisfies transparency through the attestation and satisfies accountability through the named human verification and retained evidence, without turning the cover letter into a brittle technical document. It is also the posture most consistent with how FDA has signaled it thinks about AI in regulated content: the agency's concern, made concrete in its first AI-related Warning Letter, is not that AI was used but that AI-generated content reached a regulated record without the human review and verification that 21 CFR obligations require. A disclosure that foregrounds verification speaks directly to that concern.

The Cover Letter Versus the Use Log: A Division of Labor

The cleanest way to think about the disclosure is as a two-tier record with a deliberate division of labor, because each tier answers a different question. The cover letter answers the reviewer's first-glance question, "was AI used and did a human own the result," with a brief, durable attestation that does not change submission to submission. The AI use log answers the auditor's deeper question, "show me exactly what the AI did and what the human did about it," with the granular, run-level detail that an Information Request might demand. Keeping these separate is not bureaucratic neatness; it is risk management. The cover letter is a public-facing legal document that ships with the submission and is hard to amend; the use log is an internal record under change control that can be as detailed as the workflow requires.

This division also resolves the tension that paralyzes the drafting room. The fear of saying too little, that silence fails transparency, is answered by the cover-letter attestation. The fear of saying too much, that detail invites scrutiny and ages badly, is answered by moving the detail to the log. The attestation is short because it is the principle-level statement; the log is detailed because it is the evidence. A sponsor that builds both is not choosing between candor and caution; it is putting each at the tier where it belongs. And critically, the two must be consistent: a cover letter that attests to human verification must be backed by a log that actually documents that verification on the specific content, because a disclosure the evidence does not support is worse than no disclosure, in the same way a fabricated cross-reference is worse than a missing one.

How to Draft the Paragraph the AI Itself Should Not Finalize

There is an obvious irony in using an LLM to draft the very paragraph that discloses LLM use, and it is instructive. You can absolutely use the model to draft candidate disclosure language, and it will produce fluent, plausible options quickly. But this paragraph is the one place in the submission where the model's characteristic failure, confident generation of plausible-but-unverified claims, is most dangerous, because the claims are about the sponsor's own conduct and compliance posture. A model asked to draft an AI disclosure will happily generate a sentence asserting that "all content was generated in accordance with 21 CFR Part 11 and the FDA-EMA Guiding Principles," which sounds authoritative and may not be true of the actual workflow, and which a sponsor must never sign unless it is verifiably accurate.

So the drafting discipline inverts the usual ratio: the model contributes the least here and the human contributes the most. Use the model to surface candidate phrasings and to check the draft against the principles' language. Then strip every claim that the sponsor cannot substantiate from its own records. The disclosure should assert only what is documented: that AI assisted preparation, that named qualified personnel verified the content, that records are retained. It should avoid characterizing the degree of compliance ("fully compliant," "validated") unless a validation actually exists to point to, because those are legal conclusions, not descriptions. It should be reviewed by regulatory and by legal, because it is the paragraph most likely to be read against the sponsor in a dispute. And it should be written so that it remains true even if the tool stack changes, which is another reason to keep tool names out of it. The paragraph is short by design, accurate by obligation, and human-owned without exception, because it is the sponsor attesting, in writing, to how it produced the dossier the agency is about to review.

The Accountability Principle and the Name on the Page

Transparency tells the reviewer that AI was used; accountability tells the reviewer who is responsible, and the two are not interchangeable. A disclosure that satisfies transparency by mentioning AI but is vague about human ownership leaves the most important question unanswered, because the FDA-EMA accountability principle is unambiguous that responsibility for AI-assisted content does not transfer to the vendor, the model, or the platform. The named author of a Module 2.5 owns the Clinical Overview whether they wrote every word or verified a CoAuthor draft. The Qualified Person for Pharmacovigilance owns the PSUR whether or not LifeSphere NavaX drafted the narratives. The cover-letter disclosure should therefore foreground verification by named, qualified personnel, because that phrasing carries the accountability principle into the attestation: it says not merely that AI was used, but that identifiable humans reviewed the output and stand behind its accuracy.

This is why a disclosure built around the word "assisted" is stronger than one built around the word "generated." "AI assisted in the preparation of certain content, which was reviewed and verified by qualified personnel" locates the human at the center and the tool at the periphery, which is both accurate and aligned to the principle. "Content was generated by AI" inverts that, foregrounding the machine and inviting the reviewer to wonder where the human judgment entered. The grammar of the disclosure is not cosmetic; it encodes the accountability posture. A sponsor that has done the verification work should describe it in language that reflects that work, with the human as the responsible actor and the AI as the assistive tool, because that is what actually happened and what the principle requires the record to show.

Where the Disclosure Physically Lives in Module 1

The cover letter is the natural home for the attestation, and in the eCTD it lives in Module 1, the regional administrative section, typically in the cover-letter leaf where the sponsor frames the submission for the reviewing division. Placing it there has a practical logic: the cover letter is the first document the agency reads, so a disclosure there is genuinely transparent rather than buried, and it sits alongside the other framing statements about the submission's purpose and contents. Some sponsors additionally or alternatively reference the AI use in a dedicated Module 1 administrative document, but the cover letter remains the primary and most-read location in 2026 practice.

The granularity discipline from the prior lesson applies here too. The cover-letter disclosure is a summary-level statement; it points to the AI use log without reproducing it, exactly as a Module 2.3 QOS points to Module 3 detail without reproducing it. If the disclosure tries to carry the full detail of the AI workflow, it commits the same granularity error as a control narrative misplaced in a summary node: it puts detailed content where a summary belongs. The correct structure is a brief, principle-aligned attestation in the cover letter, a pointer to the retained AI use log, and the log itself held under change control and producible on request. This structure is defensible across the spread of 2026 practice, it satisfies both the transparency and accountability principles, and it positions the sponsor to answer an Information Request about AI involvement with a record rather than a scramble. There is a final discipline worth naming: the disclosure should be written once as a reusable, sponsor-approved template that regulatory and legal have blessed, not re-improvised under deadline for every submission. The whole point of keeping tool names and section lists out of the cover letter is that the attestation becomes stable, portable, and reusable, while the variable detail lives in the per-submission AI use log. A sponsor that has to re-litigate the disclosure language two weeks before every lock has put the brittleness in the wrong tier. The paragraph is small, but it is the sponsor's signature on the question the agency now asks of every modern submission: how was this made, and who stands behind it.

Key Takeaways

  • The disclosure paragraph exists because the floor moved on 14 January 2026. The FDA-EMA transparency principle made silence about meaningful AI use a position that may need defending, where before it was the unremarkable default; the question is no longer whether AI was used but what the cover letter should say about it.
  • Transparency requires an appropriate-level attestation, not full disclosure. A defensible 2026 cover-letter disclosure states three things: that AI assisted preparation of certain content, that qualified personnel verified it and are responsible for its accuracy, and that records are retained and available on request. It does not enumerate tools, models, or sections.
  • The cover letter attests; the AI use log holds the evidence. This two-tier division answers both fears at once: the attestation cures the risk of saying too little, and moving granular detail to the retained log cures the risk of saying too much and aging badly. The two must be consistent, because a disclosure the evidence does not support is worse than none.
  • This is the one paragraph the AI should not finalize. A model will fluently assert compliance claims like "fully compliant with 21 CFR Part 11" that the sponsor cannot substantiate; the drafting discipline inverts the usual ratio so the human contributes the most, asserting only what the records document and avoiding legal conclusions that no validation supports.
  • The disclosure is a summary-level statement that lives in the Module 1 cover letter. It points to the AI use log without reproducing it, exactly as a 2.3 QOS points to Module 3 detail; carrying full workflow detail in the cover letter repeats the granularity error of misplaced content and produces a brittle, scrutiny-inviting paragraph.