It depends entirely on where the document is going. Scientific venues and health technology assessment agencies increasingly require you to declare AI use: NICE (August 2024), Canada's Drug Agency (April 2025), Quebec's INESSS (June 2026) and the EU's HTA Coordination Group (July 2026) all require a declaration, an explanation of the method and a report of the human input, with the submitter remaining accountable. Journals and societies — ICMJE, ISPOR, ASCO, ESMO and every major publisher — require disclosure and prohibit AI authorship outright. Meanwhile the FDA's draft guidance expressly excludes drafting a submission from its scope, and ICER, AMCP's current Format, US state law and commercial payers require nothing at all.
The question people ask, and the question that matters
The question is usually asked as "am I allowed to use AI for this?" Outside regulated work, the answer is generally yes. Inside it, the honest answer is that most people are already not allowed — not because a rule forbids AI, but because the conditions that would make it permissible have not been met. Sending confidential material to a model typically engages an NDA or a privacy law, and the lawful routes through that require things almost nobody does: disclosing the processing, completing a privacy-impact or risk assessment, or obtaining permission from the patients and individuals whose information is in the file. Those steps are rarely taken. The use happens anyway.
So the permission question is usually settled before it is asked, and settled badly. The question that determines what you actually have to do is narrower: who is going to read this document, and what does that particular body require you to say about how it was made?
There is no general answer, because the rules did not arrive from one place. They were written separately by journals, by scientific societies, by HTA agencies and by regulators, at different times, for different reasons. The result is that the same piece of work — the same author, the same tool, the same paragraph — carries a different obligation depending on where you send it.
What regulatory bodies and health technology assessment agencies require
This is the fastest-moving part of the landscape, and the part most likely to have changed since a reader last checked. Four bodies now impose a declaration duty; the wording is strikingly consistent, because each borrowed from the one before.
| Body | Duty to declare AI use | Source |
|---|---|---|
| NICE (UK) | Yes — declare use, explain the method, report human input; the submitting organisation stays accountable. | Position statement ECD11, 15 August 2024, plus a mandatory AI block inside the company submission templates. |
| CDA-AMC (Canada) | Yes — same wording, adapted from NICE. Augmentation, not replacement, with a human in the loop. | Position statement, April 2025; RWE guidance, August 2026. |
| INESSS (Quebec) | Yes — a mandatory yes/no question covering the submission, the economic model and the evidence. Translation is expressly excluded. | “Description sommaire” submission form, June 2026. Not in the submission guide. |
| EU HTA Coordination Group | Yes — document every AI-assisted step, identify AI-generated output, and record all prompts, available on request. | General principles for Joint Clinical Assessment dossiers, adopted 15 July 2026. |
| HAS (France) | No duty to declare. States that manufacturers using AI remain solely responsible for the final content. | “Numérique et intelligence artificielle à la HAS”, updated 30 January 2026. |
| FDA (US) | No. Drafting a submission is named in the guidance's own scope exclusion; no disclosure duty appears anywhere in it. | Draft guidance, January 2025 — still draft, explicitly non-binding. |
| Health Canada | No policy for drug submissions. A July 2026 device notice requires accuracy, but no declaration. | Full guidance text searched; zero occurrences. |
| ICER (US) | No — the current value framework does not mention AI in any form. | 2023 Value Assessment Framework, in force to 2026. |
| AMCP (US) | Not in Format 5.0. The draft Format 6.0 permits AI as a writing assistant and recommends a qualified individual validate the dossier — with no disclosure duty. | Format 5.0, April 2024; Format 6.0 draft, March 2026, publication due October 2026. |
| pCPA, all Canadian provinces, every US state, US commercial payers | Nothing found requiring a submitter to declare that AI wrote a document. | Sitemaps and submission guidance searched in full; payer dossier templates are not public. |
NICE set the template in August 2024: when AI is used, the submitting organisation and authors should clearly declare its use, explain the choice of method and report how it was used including the human input — and the submitting organisation remains accountable for the content of the submission. Canada's Drug Agency adopted substantially the same language in April 2025, adding that AI use "should be based on the principle of augmentation, not replacement, of human involvement." The EU's HTA Coordination Group went furthest in July 2026, requiring that AI-assisted steps be specified, AI-generated output identified, and all prompts recorded and made available if requested.
Submission forms: the rule is often not in the guidance, it is in the form
This is the single most practical warning on this page, and it is not hypothetical: two independent research passes for this guide searched INESSS's published guidance and concluded there was no policy. Both were wrong, and both were wrong for the same reason. The Guide de soumission — the sixty-five-page document a submitter actually reads — contains no occurrence of intelligence artificielle at all. The duty lives in the Word form attached to the submission.
That form asks, in terms: does this submission, or any part of it, rest on the use of an artificial intelligence system? It requires a plain-language description of the systems used, the content generated, and the mitigations applied. It covers the submission, the economic model and the generation of the evidence. Translation is expressly excluded. NICE does the same thing from the other direction: the position statement is the document everyone cites, but the mandatory four-part AI block sits inside the company submission template.
Open the form before you read the guidance.
Some agencies run your dossier through AI themselves
The published rules point at the submitter. The more interesting movement is in the other direction. INESSS's submission form states that Microsoft 365 Copilot may be used by the agency to accelerate parts of the evaluation — unless the manufacturer files a reasoned objection in the form itself. It is opt-out, not opt-in, and the place to opt out is a box on a document that, as above, many submitters do not read closely.
France's HAS has stated since 2023 that it applies AI across its missions, including dossier analysis. The FDA has publicly deployed its own internal AI system into application review, with the stated safeguard that it is not trained on submitted data. Neither offers the sponsor a choice.
INESSS, for all that the placement of its clause is easy to miss, is doing this the right way. Asking is the correct default. What arrives in a submission form is not ordinary correspondence: it is industrial and commercial secrets — pricing assumptions, unpublished trial data, competitive positioning — handed to a public body because the process requires it. Running that through an AI system carries a real risk of leakage if it is done carelessly, and most acutely when the data reaches the model uncloaked. A sponsor who can see the question can weigh it. A sponsor who cannot is simply not part of the decision.
There is a reasonable version of this: these are careful institutions using enterprise tooling under their own governance rules. But it does reframe the question. A sponsor spending months deciding whether it is permissible to draft a section with AI may be submitting into a process that will itself be read by one — inside a framework that asks everyone to trust AI handling, in years when the number of leaks, and the size of them, has grown with every month rather than every decade.
What the regulator most people worry about actually says
Ask a regulatory affairs team which body they are most concerned about and the answer is the FDA. Its January 2025 draft guidance on AI supporting regulatory decision-making is the document usually invoked. It is worth reading its scope section closely, because it says something people do not expect. The guidance does not address AI used for "operational efficiencies (e.g., internal workflows, resource allocation, drafting/writing a regulatory submission)" that do not impact patient safety, drug quality, or the reliability of results from a nonclinical or clinical study.
Of all the examples available, FDA reached for writing a submission to illustrate what it was not regulating. Nowhere in the document does it ask a sponsor to disclose, declare, attest to or certify any use of AI. And the whole thing is still a draft: Level 1, non-binding by its own terms, unfinalised more than a year and a half after it was issued.
Silence is not permission.
Where we think the real exposure sits — our reading, not FDA's rule
What follows is our argument rather than a requirement, and we mark it as such. The interesting risk is not that AI writes a weaker sentence. It is that AI which touches, transforms or analyses study data introduces a factor into study quality that nobody has accounted for. A single unverified extraction, a quietly invented figure, a transposed subgroup — none of these is visible in the prose, and all of them survive into a document that reads perfectly well. The exposure grows sharply with self-hosted deployments and small models, which several institutions have signalled they intend to use: reasoning and self-validation are weak at that scale, and a smaller model is likelier both to make the error and to state it confidently.
FDA's guidance supports this for data, in its own terms: data used must be "accurate, complete, and traceable"; code quality assurance must resolve "errors or anomalies"; and model risk is defined as "the possibility that the AI model output may lead to an incorrect decision that could result in an adverse outcome." Those are statements about data handling, not about drafting — and we are not going to pretend otherwise. But they describe precisely the failure mode that matters, and they are the reason a serious answer to "did you use AI?" has to cover the analysis steps, not just the writing.
One word in that FDA sentence is worth dwelling on: traceable. It is the requirement that shadow use and casual tooling can never satisfy, because nothing was recorded at the time and nothing can be reconstructed afterwards. It is also the half of the problem people forget, having solved only the first half. Our own position is that both halves have to hold at once: the model should not be able to see your data or your identity, and you should still hold a stronger audit record of its use than an unaided human process would ever produce — with certification and breach testing to demonstrate that the AI never received a real value. Confidentiality without traceability is unprovable. Traceability without confidentiality is a log of everything you should not have sent.
What journals and societies require
Here the picture is settled on principle and chaotic on practice. Every body we examined — ICMJE, COPE, WAME, ISPOR, ASCO, ESMO, and all six major medical publishers — prohibits listing AI as an author, and every one gives the same reason: authorship implies accountability, and accountability cannot be delegated to a tool. ISPOR adds that AI may not be cited as a reference either.
On where you declare it, there is no consensus at all. Research-process AI goes in the Methods section nearly everywhere; that is the one dependable rule. Writing assistance goes in five different places.
| Venue | AI used in writing | AI used in research |
|---|---|---|
| Elsevier journals | Declaration section at the end, immediately before the references | Methods |
| The Lancet | Declaration at the end; prompts may be requested by editors | Methods |
| Wiley | Acknowledgments | Methods, plus figure captions for visuals |
| JAMA Network | Acknowledgment | Methods |
| BMJ | Contributor statement | Methods |
| Springer Nature | AI Declaration, placement set by risk tier | Methods |
| JCO (ASCO) | Acknowledgments | Methods |
| ASCO abstracts | In the abstract body — it counts against the word limit | Methods |
| ESMO congress abstracts | No statement required for writing assistance | Methods of the abstract |
| ISPOR conferences | On the poster or slides, visible to the audience, and on the submission form | — |
| Value in Health | A “Use of AI” statement — expected even when AI was not used | Methods |
Two asymmetries are worth noticing, because they catch experienced authors. First, a society's congress rules and its journal rules can differ. ASCO wants writing assistance in the Acknowledgments for a JCO manuscript but in the abstract body for a meeting abstract — where it consumes your word count. ESMO requires no statement at all for writing assistance at congress, while its journal requires a named declaration section. Second, the null case is not uniform: Value in Health supplies a model statement for authors who did not use AI, implying one is expected; ESMO says in as many words that no statement is needed if there is nothing to disclose.
ISPOR is the strictest on reach. Disclosure must be made to ISPOR on the submission form and to the audience in the delivered material — the poster, the slides, the paper. It states that failure to disclose may result in withdrawal, and that it may use AI-detection software. Several publishers now also require the specific tool, version number and date of access, and The Lancet reserves the right to ask authors for their prompts.
- Check the venue, not the field. The rule that applies is the one published by the journal or society you are submitting to, in its current version — several of these pages carry no version number at all and change silently.
- Grammar and spell-checking are exempt everywhere. This is the one exemption common to every policy we read.
- Opinion content is increasingly off-limits. JAMA bars AI drafting for Viewpoints and Correspondence; ASCO for editorials and reviews; Value in Health for Letters to the Editor; The Lancet restricts Comments and Correspondence to grammar and spelling only.
The gap nobody has written a rule for yet
Every policy described on this page was written for one shape of AI use: a person types a prompt into a chat window and reads what comes back. That is no longer the only shape. Tool-using systems can now read a filesystem, query a database, open a shared drive or call an internal service — which moves the question from what did you paste to what could it reach.
There is no rulebook for this. ESMO's clinical guidance explicitly scopes out agentic systems that act autonomously and says future guidance will be needed. Elsevier's June 2026 policy names AI agents only to fold them into the same disclosure regime written for chatbots. NICE's position statement asks submitters to evidence measures against prompt injection and data poisoning — the closest any HTA text comes to naming the new attack surface, without naming agents. That is the entire body of guidance.
The exposure is not theoretical, and it is worst exactly where this audience works: an agent with filesystem access, pointed at a working directory that also contains identifiable patient data, an unredacted CSR appendix or an NDA-bound dataset. The disclosure question — did you use AI? — is not the interesting one there. The interesting one is what the tool was able to see, and the honest answer is often everything: every file in the directory, every row in the connected table. That is a question about guardrails, and it needs answering before the disclosure question is worth asking.
It is worth being precise about why this is worse than the problem everyone has been worrying about. The pasting problem is bounded by intent: whatever you deliberately put in the box is what leaves. An agent with reach is bounded by scope, and scope is set once, loosely, at configuration time. The failure does not require anyone to behave badly. A well-intentioned agent asked to pull background for a submission will range across a working drive doing exactly what it was told — and the machines this work happens on are not clean. A consultant's laptop holds years of accumulated engagements: pricing models, unpublished trial data, competitive strategy, patient-level files, correspondence. Not one confidential item, but hundreds, belonging to several clients who have never met.
What makes that a disclosure event rather than an untidy filesystem is the next step: whatever the agent gathers is sent to a model, usually across a border, and unless something specifically prevented it, with the real values intact. No paste to remember, no moment of decision to point at, and usually no record of which files were opened. That is a larger subject than this page, and we will treat it separately — but it belongs here for one reason: it is the question nobody in the rulebook above has written a single line about.
Why a protocol-grade record turns disclosure into paperwork
The direction of travel is not subtle. NICE in August 2024, Canada's Drug Agency in April 2025, INESSS's forms in June 2026, the EU's Joint Clinical Assessment principles in July 2026, AMCP's Format 6.0 due in October 2026 — the trend line runs one way, and the requirements have become more specific at each step, from "declare it" to "name the tool and version" to "produce your prompts." We would expect the bodies currently silent to acquire a position rather than keep the absence, though that is our expectation and not a fact we can cite.
What that makes valuable is not a policy but a record. A declaration you can substantiate — which tool, which version, which sections, what a human checked — is a form-filling exercise. The same declaration reconstructed from memory months later is a risk, and if the venue asks for prompts, it may not be answerable at all. Should a leak follow, it stops being a paperwork problem altogether: an unanswerable question about what a model was given, in a file full of patient or commercial secrets, is the kind of fault that ends careers.
There is a demonstration of this worth borrowing. Canada's Drug Agency, in the same August 2026 document where it tells submitters to declare AI use, discloses its own: naming the tool, stating that all AI-generated content was reviewed and edited by humans, that all references were verified by humans, and that the agency takes full accountability for the content. That is the entire practice, modelled in four lines by the body writing the rule.
This is also where architecture does more than policy. If the values in a document were cloaked before any model saw them, the prompt log you may one day be asked to hand over contains no confidential value to begin with — and the honest answer to "what could the tool see?" is labels — or cloaks, as we call them. That is the design behind cloaking, and the reason the Untraceable Protocol records labels and run identifiers rather than text.
Related reading
- AI watermarking and your deliverables — what changed when model output began carrying statistical marks, and why a contemporaneous record turns a detected mark into corroboration rather than a finding.
- AI for HEOR and market access — what can and cannot go into a prompt in health economics work.
- The HEOR AI writing benchmark — measured writing quality of frontier models, scored by an independent AI-Delphi panel.
Frequently asked questions
Do I have to disclose that AI helped write my HTA submission?
It depends on the agency, and the answer is changing. NICE (August 2024) and Canada's Drug Agency (April 2025) both require the submitting organisation to declare AI use, explain the method and report the human input — and both say the submitter remains accountable for the content. Quebec's INESSS goes further: its June 2026 submission form contains a mandatory yes/no question about AI use in the submission, the economic model and the evidence. The EU's HTA Coordination Group adopted principles in July 2026 requiring that AI-assisted steps be documented and that all prompts be recorded and made available on request. The US is the outlier: neither ICER nor AMCP's Format 5.0 mentions AI at all.
Does the FDA require me to disclose AI-assisted writing?
No. FDA's January 2025 draft guidance on AI in regulatory decision-making expressly excludes AI used for "operational efficiencies (e.g., internal workflows, resource allocation, drafting/writing a regulatory submission)" that do not impact patient safety, drug quality, or the reliability of study results. A full-text search of that guidance finds no disclosure or declaration requirement anywhere in it. It also remains a draft, explicitly non-binding. FDA is silent on AI-assisted writing — which is not the same as having approved it. We would still recommend keeping a tight leash on AI use in work headed for a regulator. A detailed record of what was used, where, and what a human checked is the minimum preparation that gives your audit position a chance of surviving the next iteration of the guidance.
Can ChatGPT or Claude be listed as an author?
No, and this is the one rule on which every body agrees. ICMJE, COPE, WAME, ISPOR, ASCO, ESMO, and all six major medical publishers prohibit it, for the same stated reason: authorship carries accountability, and only a human can be accountable. ISPOR adds that AI may not be cited as a reference either.
Where in the manuscript do I declare AI use?
There is no single answer, which is the practical difficulty. Research-process AI goes in the Methods section almost everywhere — that is the one near-universal rule. Writing assistance is scattered: Elsevier and The Lancet want a declaration section at the end of the manuscript before the references; Wiley and JAMA want the Acknowledgments; BMJ wants the contributor statement; ASCO wants it in the abstract body itself, where it counts against your word limit; and ISPOR wants it disclosed to the audience on the poster or slides. Check the specific venue, not the general practice.
Do I need a statement if I did not use AI at all?
Sometimes — and the venues disagree, which is how authors get caught. Value in Health's author instructions hand you a ready-made sentence for declaring that you did not use AI, which tells you one is expected either way. ESMO's congress rules say the opposite outright: if there is nothing to disclose, no statement is needed. Read the venue's own template before assuming silence will do.
Does disclosing AI use weaken my submission?
Nothing in any of these documents penalises disclosed, human-supervised AI use. The penalties attach to concealment: ISPOR states that failure to disclose may result in withdrawal, and says it may use AI-detection software. Detection software is not proof of anything today — those tools are unreliable and widely known to be. Watermarking is a different matter: statistical marks embedded in model output at the moment of generation are a far stronger class of evidence, and they are arriving now. A denial that is merely unprovable today may be checkable tomorrow. See our guide to AI watermarking at /guides/ai-watermarking-detection. The more immediate risk is being unable to substantiate a declaration you have already made — a record-keeping problem rather than a disclosure one.
Is there any rule covering AI agents with access to my files?
No. Every policy we could find is written for chatbot-style prompting. ESMO's clinical guidance explicitly scopes out agentic systems that take action autonomously and says future guidance will be needed; Elsevier's June 2026 policy names AI agents only to fold them into the existing disclosure regime; NICE's position statement addresses prompt injection and data poisoning without naming agents. This is the widest gap in the current rulebook, and it is the one that matters most when a tool can reach a filesystem holding personal data.
This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary — review your own agreements with qualified counsel before relying on any framework described here.
Work with AI on data you can't share with it.
Untraceable cloaks confidential values on your computer before any AI model sees the text — the model never receives the secret at all.