Four Approaches to AI in Regulatory Publishing

The AI regulatory publishing landscape is dividing into four approaches, each with genuine strengths and real limitations. This article attempts an honest assessment of all four — including our own.

We are a vendor in this space, so we have a perspective. We have tried to be fair. Where we do not know a competitor’s internal details, we say so rather than guessing.

Approach 1: Established RIM Vendors (Veeva, IQVIA)

Strengths

  • A very large installed base. Veeva RIM is used by most of the top 20 pharmaceutical companies. When an authority changes a requirement, Veeva has the direct relationships to understand and implement it.
  • Deep regulatory data. Decades of submission history and agency interaction built into their platforms.
  • A proven enterprise track record. Hundreds of enterprise customers, validated environments, established support.
  • A connected suite. Veeva Vault links regulatory to clinical, quality and safety — one vendor, fewer connections to build and maintain.

How they approach AI

Adding AI to what already exists: assistants for drafting, help with regulatory intelligence, prediction of submission timelines. AI extends the existing product rather than reshaping it.

Limitations

  • Design constraints. These platforms were designed in the 2010s, before AI was a consideration. AI is added rather than built in, which can mean audit trails for AI actions have to be retrofitted.
  • Closed ecosystems. Limited scope for customers to bring their own AI or connect their own assistants.
  • Cost. Enterprise pricing that can run to six or seven figures annually, plus significant consulting costs for configuration.

Fair acknowledgment: Veeva’s data advantage is real and hard to replicate. A smaller vendor with a better design but less data may not deliver better results.

Approach 2: Kivo (Headless GxP)

Strengths

  • A clean design. Built for AI from the start, using an open standard for how AI connects.
  • A simple proposition. “Connect your existing AI to our compliance layer” is easier to adopt than “replace your regulatory platform”.
  • Works with any AI. No lock-in on the AI side.
  • A clear pattern. “AI researches and recommends, a person acts, the system records both” is intuitive and easy for an auditor to follow.

How they approach AI

Compliance as a service that other things connect to, with the system enforcing access controls and audit recording around whatever AI is used.

Limitations

  • Early stage. Three features announced for private beta in July 2026, with limited public detail about the compliance foundations underneath.
  • Scope. Based on what is public, focused on compliance record-keeping rather than full regulatory publishing — eCTD assembly, validation, multi-region submission.
  • Market presence. A newer company with fewer published case studies or enterprise references.

Fair acknowledgment: we do not have full visibility into Kivo’s product. Their actual capabilities may be broader than what is publicly visible. We are comparing on public announcements.

Approach 3: DnXT (Open GxP)

Strengths

  • A full regulatory platform in production. eCTD publishing, validation, document management, workflow, and support for the US, EU, Japan, Canada and Australia.
  • Built for AI from the start. Audit records created by the platform as information is written, four independent layers keeping customers separate, and electronic signatures designed for Part 11.
  • Limits that are absolute. AI cannot sign, cannot publish, and cannot reach another customer’s information — not by policy, but because those capabilities do not exist for it.
  • Real experience already. Thirty internal AI tools in daily production use, with established patterns for keeping them safe.

How we approach AI

A platform where compliance is part of the structure rather than a layer on top. We are extending the platform’s existing capabilities to customers’ own AI assistants, with proper sign-in, strict separation between customers, and permission checks throughout.

Limitations

  • A small company. We are a startup-scale team competing with organisations of thousands of people and hundreds of enterprise customers.
  • Fewer enterprise references. Less published evidence than Veeva or IQVIA, which means a prospective customer has less third-party validation to rely on.
  • The customer-facing AI connection is not live. The internal tools and the platform behind them are in production; the customer-facing layer is in design.
  • A workflow engine we built ourselves. More control over regulatory specifics, more to maintain for a small team.

Fair acknowledgment: our design advantages are real, but design does not close deals — references, support and market trust do. We are earlier in that journey than our competitors.

Approach 4: Using AI Directly (Claude, GPT, Gemini)

Strengths

  • Genuinely capable. Able to draft regulatory documents, analyse submission information and answer regulatory questions.
  • No lock-in. Use whichever model suits the task.
  • Low cost. A fraction of an enterprise platform subscription.
  • Flexible. Can be fitted into almost any way of working.

Limitations

  • No regulatory enforcement. A general-purpose model does not know that a 505(b)(2) submission requires different eCTD sections than an ANDA. It can be told, but it cannot enforce.
  • No compliance foundations. No audit trail, no electronic signatures, no separation between clients, no validation rules.
  • No accountability. When it gets something wrong in a regulatory context, there is no built-in process for putting it right.

Fair acknowledgment: for ad-hoc research, drafting and analysis, general-purpose AI is genuinely useful and cost-effective. Not every regulatory task needs a full compliance platform.

Comparison

Based on publicly available information as of May 2026:

Capability Veeva/IQVIA Kivo DnXT General-purpose AI
Open standard for AI connection Not announced Yes (beta July) Yes (internal live, customer planned) Varies
21 CFR Part 11 audit trail Yes (established) Announced Yes (built in, ALCOA+) No
Electronic signatures Yes Unknown Yes (Part 11 compliant) No
Separation between customers Yes Announced Yes (four independent layers) No
eCTD publishing Yes (market leader) Not announced Yes (multi-region) No
Validation Yes Not announced Yes (multi-region) No
Enterprise references Hundreds Early stage Growing N/A
Choice of AI provider Limited Any Any (planned) Any

The right choice depends on where your organisation is today: an established Veeva customer adding AI, a company wanting a compliance layer to connect to, an organisation ready for a platform built around AI, or a team using AI for ad-hoc work. There is no universal best answer.

This article was written by the DnXT Solutions team. We’ve made every effort to represent competitors fairly based on public information. If we’ve gotten something wrong, we welcome corrections at se******@***********ns.com.