Hristos Bilis

Hristos Bilis

What pharma is really doing with AI, and how to do it right.

I'm a pharma-systems consultant specializing in AI solutions and validation. I track what the industry is actually doing with AI in the Pharma AI Tracker, a sourced record of public disclosures from the 49 largest pharma companies by market cap. After 15 years in regulated pharma systems, I help regulated teams design AI solutions that hold up under validation, and I share what works in my writing and teaching.

Industry

Pharma AI Tracker

Publicly disclosed pharma AI initiatives. Sourced, quoted, archived.

274 of 349 entries · 45 of 49 companies

Last updated:

Leaderboard

Disclosed AI use cases since January 2023

Top 10 companies by disclosed AI use cases since January 2023. Research partnerships are excluded.
Rank Company Disclosed use cases
1 Sanofi 28
2 Novo Nordisk 18
3 Takeda 15
4 Merck & Co. 11
4 Moderna 11
6 Amgen 9
6 Johnson & Johnson 9
8 Astellas Pharma 8
8 Daiichi Sankyo 8
8 Merck KGaA 8
See the leaderboard
Writing

Notes from the field & Industry Info.

Shorter pieces on where regulated-pharma AI actually is, what the regulators are signaling, and the controls the industry keeps skipping. Based on real contracts and interactions (sanitized).

Note

The most valuable AI call you'll make is often 'not this one'

When a pharma AI idea is first proposed: write the value case, sort it into four buckets, and use generative AI only when a rule will not do. Three sourced cases and one illustrative workflow, with the GxP points for each.

Readout

The GenAI routing layer is the least-documented part of the pharma stack

When a company assistant sends a question to a model, the public record rarely says who picks that model. In the Pharma AI Tracker, a search of 349 entries across 49 companies for gateway and routing terms returns nothing. That is a gap in what companies say in public, not a finding about what they run.

Note

Security is now a GMP requirement

The 2025 Annex 11 rewrite puts pen-testing, MFA, and audit trails into GMP text — so for AI systems, the security controls and the validation controls are now the same controls.

Note

How much validation does your AI actually need? Start with Context of Use

Before you validate a GxP AI system, classify it. A practical, cross-regime procedure — Context of Use, influence x consequence, Annex 22, GAMP 5, EU AI Act — that tells you how much evidence you actually owe.

Note

What a CSV validator should look for in an LLM gateway

A pilot went well and the business wants it in production. The CSV team opens the architecture diagram and sees 'LLM gateway' in the middle. Here's what that means for validation — and the three failures to reproduce before signoff.

Teaching

Here live the core runnable gmp ai project artifacts. Enjoy!

Everything here is a curated teaching artifact. The reason is simple: the clearest way to communicate the way to have secure, validated AI is to build the smallest honest version of it and explain every part.

The Zero to Validated sequence

Read them in order — each artifact builds on the last, simplest to most complete.

The "Zero to Validated" sequence

The flagship repos above build on each other, from the simplest possible gateway up to a vendor-comparison harness that can be used as validation evidence.