Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

A

AI literacy (Art. 4 EU AI Act)

AI literacy is defined in Art. 3(56) of the EU AI Act as the skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations, to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause. Art. 4, applicable since 2 February 2025, requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context in which the systems are used, and the persons or groups on whom they are used.

The obligation applies to every organisation that uses any AI system in a professional context, not only to those with high-risk systems, and therefore to virtually every life sciences company using generative AI tools, analytics platforms or AI-enabled devices. The Commission's Q&A and the AI Office's living repository of practices indicate that there is no prescribed curriculum or certification; measures should be proportionate and differentiated (general awareness for all staff, deeper technical and legal training for those developing, procuring or overseeing systems, and specific instruction for those exercising human oversight), and organisations should be able to document what they did. National market surveillance authorities may enforce Art. 4 from August 2026, and lack of literacy measures will weigh in the assessment of other breaches.

For pharmaceutical, MedTech and HealthTech organisations, AI literacy programmes typically cover: what AI is and how the organisation uses it; the AI Act's risk categories and the company's role for each system; the interaction with the GDPR (no patient data in public tools, DPIAs for new uses); hallucination, bias and automation bias; sector rules such as EMA and FDA expectations and GxP validation; and the internal policy, approved-tool list and escalation routes. Training records, attendance logs and role-based curricula form the evidence file, and the topic sits naturally within the mandate of an AI Officer alongside the DPO's data protection training. iliomad delivers AI and data protection training as part of its training services.