RegulatoryGlobal2025-05
WHO adopts pandemic agreement to strengthen global preparedness, surveillance, and equitable access
WHO member states adopted a pandemic agreement aimed at improving prevention, preparedness, pathogen access, data sharing, and more equitable access to health products. Implementation details, financing, and national adoption steps will determine practical compliance obligations for governments and manufacturers.
Source: World Health Organization
ComplianceEU2025
EU AI Act begins phased application with major implications for medical AI and digital health compliance
The EU AI Act’s staged obligations are moving from text to implementation, affecting providers and deployers of high-risk AI, including certain medical and clinical decision systems. Companies must align governance, transparency, risk management, and post-market monitoring with existing MDR, IVDR, and GDPR requirements.
Source: European Union
ComplianceUS2025
FDA continues oversight focus on AI-enabled medical devices through lifecycle and change-control expectations
US regulators continue emphasizing total product lifecycle oversight for AI-enabled devices, including documentation, validation, cybersecurity, and management of post-deployment model changes. Developers should expect scrutiny around safety, effectiveness, data quality, and quality-system controls when introducing adaptive or software-based functions.
Source: U.S. Food and Drug Administration
RegulatoryEU2025
EMA and HMA advance coordinated shortages, supply resilience, and critical medicines work
European regulators are maintaining pressure on medicine shortages and supply-chain resilience through coordinated monitoring and critical-medicines policy work. Manufacturers and marketing authorization holders face continued expectations around shortage notification, manufacturing continuity, and risk-based supply planning across the EU.
Source: European Medicines Agency / Heads of Medicines Agencies
RegulatoryUK2025
MHRA expands attention on software and AI as medical devices under UK reform pathway
The UK’s device reform program continues to shape requirements for software and AI medical devices, including classification, evidence, post-market surveillance, and cybersecurity. Developers targeting the UK market should monitor evolving guidance and transitional arrangements alongside broader medical device regulatory modernization.
Source: Medicines and Healthcare products Regulatory Agency
ComplianceUS2025
FDA warning letters and inspections keep data integrity and 21 CFR Part 11 compliance in focus
Recent enforcement trends continue to highlight failures in audit trails, electronic records controls, validation, deviation handling, and investigation practices. Drug, device, and biologics manufacturers should reassess data governance, training, supplier oversight, and computerized system validation under cGMP and Part 11 expectations.
Source: U.S. Food and Drug Administration
RegulatoryIndia2025
CDSCO maintains tighter oversight of quality, licensing, and risk-based regulation for drugs and devices
India’s regulator continues strengthening oversight through quality surveillance, licensing controls, and updated expectations for manufacturers and importers. Companies operating in India should track evolving device rules, testing, labeling, and post-market obligations as CDSCO pushes more consistent compliance and enforcement.
Source: Central Drugs Standard Control Organisation
ComplianceEU2025
GDPR enforcement remains a major risk for health data processing, especially in AI and secondary use cases
European privacy regulators continue treating health data as a high-risk area, especially for cross-border transfers, AI training, research, and secondary data use. Life-science and digital-health organizations must align lawful basis, transparency, minimization, retention, and security with sector-specific regulatory obligations.
Source: European Data Protection Board / national DPAs
ComplianceUS2025
HIPAA privacy and cybersecurity enforcement continues to target breaches, access controls, and risk analysis failures
US health privacy enforcement remains focused on inadequate safeguards, impermissible disclosures, ransomware preparedness, and incomplete risk analysis. Covered entities and business associates should review encryption, authentication, vendor management, incident response, and minimum-necessary controls as OCR scrutiny persists.
Source: U.S. Department of Health and Human Services OCR
ComplianceEU2025
IVDR and MDR transition pressures continue as EU seeks capacity relief without weakening compliance
Implementation challenges under the EU’s device and diagnostics frameworks remain significant, particularly around notified-body capacity, legacy product transitions, clinical evidence, and post-market requirements. Manufacturers should maintain remediation plans and documentation readiness as regulators balance continuity of supply with stricter oversight.
Source: European Commission / European Medicines Agency
SafetyGlobal2025
Global regulators keep cybersecurity high on agenda for connected medical devices and hospital systems
Authorities across the US, EU, and UK continue emphasizing secure design, vulnerability management, software bill of materials, patching, and coordinated disclosure for connected products. Cybersecurity is increasingly treated as a patient-safety and quality-system issue rather than solely an IT concern.
Source: FDA / EMA-related EU bodies / MHRA
SafetyGlobal2025
WHO and global health agencies continue monitoring H5N1 and other emerging infectious disease risks
Public-health authorities remain alert to zoonotic influenza and other outbreak threats, with ongoing surveillance, laboratory coordination, and preparedness planning. Manufacturers, laboratories, and healthcare systems should expect continued attention to reporting, biosafety, emergency readiness, and supply continuity for critical countermeasures.
Source: World Health Organization
ComplianceGlobal2025
FDA and international inspectors continue emphasizing sterility assurance and contamination control
Enforcement activity in sterile manufacturing continues to spotlight environmental monitoring, aseptic processing, CAPA effectiveness, and facility design. Drug and biologics manufacturers should review contamination control strategies, investigation quality, and training records in line with cGMP and global GMP expectations.
Source: U.S. Food and Drug Administration / PIC/S-related GMP frameworks
ComplianceUS2025
Payers and hospitals face continued compliance pressure on price transparency, billing, and information blocking
US healthcare providers and plans remain under scrutiny for hospital price transparency, billing practices, and interoperability-related information blocking requirements. Compliance teams should monitor enforcement signals, machine-readable file accuracy, patient access processes, and coordination between legal, revenue-cycle, and IT functions.
Source: CMS / HHS ONC