Home / Insights / What you may and may not put into an LLM in medical publishing
Compliance

What you may and may not put into an LLM in medical publishing

Summarize with AI Prompt copied — paste it into the chat

Ask five people in medical publications whether you can run a draft through an LLM and you will get five answers, because four different regimes apply and almost nobody separates them. They have different sources, different timelines and very different consequences. This is the map.

Regime 1 — publisher and journal policy (bites first)

Not law. Contract and reputation — which is exactly why it is the one that catches people, because it applies the moment you submit, with no enforcement lag.

Wiley, Wolters Kluwer (Lippincott) and Elsevier all explicitly warn against uploading unpublished manuscripts or patient data into general-purpose LLMs. Science, Springer Nature and The Lancet go further on imagery, generally prohibiting AI-generated or AI-altered figures to prevent data manipulation.

The practical test is not "is this tool good?" It is "where does my content go, who can see it, and is it used for training?" A vendor who cannot answer that plainly is disqualified for unpublished work no matter how well it writes. The same tool may be perfectly fine for published material, congress logistics or an internal note containing nothing confidential — the distinction is the content, not the software.

Regime 2 — ICMJE and GPP 2022 (disclosure and authorship)

Since May 2023, ICMJE has required authors to disclose the use of AI-assisted technologies in manuscript preparation, and prohibits listing AI as an author or co-author. The reasoning is that authorship carries accountability for the integrity of the work, which a model cannot hold.

GPP 2022 extends comparable transparency to company-sponsored research: medical-writing support must be declared, and the scope now explicitly covers manuscripts, abstracts, posters, congress presentations, plain language summaries and preprints.

Two practical consequences that get missed. First, disclosure is required even where the AI use feels trivial — language polish counts. Second, because the obligation attaches to preparation rather than to output, you need a record of what was used and where, kept as you go. Reconstructing it at submission is unpleasant and unreliable.

Regime 3 — the EU AI Act (and what moved in July 2026)

This is where most published advice is now simply out of date.

  • Article 4, AI literacy. In force since 2 February 2025. Applies to every organisation using AI, of any size. See the text of Article 4.
  • Transparency obligations. Applied from 2 August 2026 — disclosure where people interact with AI or see generated content.
  • Annex III high-risk regime. Was due 2 August 2026. The Digital Omnibus, in force since 27 July 2026, moved it to 2 December 2027.

So the position for most publishing and MedComms work is: you are a deployer of limited-risk AI. The literacy duty and transparency obligations apply; the heavy conformity regime largely does not, and in any case has moved out by sixteen months. In the Netherlands the Autoriteit Persoonsgegevens coordinates supervision, with sectoral supervisors including DNB, AFM, IGJ and the Nederlandse Arbeidsinspectie in their own domains.

If a consultant is still selling urgency on an August 2026 high-risk deadline, their material predates the Omnibus. That is a useful, fast credibility test to apply to anyone quoting you for compliance work.

Regime 4 — GxP and data integrity

Only engages where work touches regulatory submissions — clinical study reports, protocols, anything heading into a dossier. Then validated-system expectations and ALCOA+ data-integrity principles apply, and an AI step inside that workflow needs the same audit trail as any other step: what was generated, what a human changed, who approved it, when.

Most MedComms work never reaches this regime. Regulatory writing teams live in it permanently. Confusing the two is how publications teams end up buying far more governance than they need, and how regulatory teams end up buying far too little.

The map, on one page

If you take one thing from this article, take this ordering — because it is the opposite of how the regimes are usually presented.

  • Publisher policy — contractual, immediate, no lag. Check first, always.
  • ICMJE / GPP 2022 — disclosure and authorship. Requires a running record, not a retrospective one.
  • EU AI Act — literacy since Feb 2025, transparency since Aug 2026, high-risk deferred to Dec 2027.
  • GxP / ALCOA+ — only if the output enters a regulatory dossier, and then fully.

What to do about it this month

None of this requires a project. It requires four artefacts, and a competent person can assemble them in a week.

  • An AI register. Which AI systems are in use, what each does, who owns it. A spreadsheet is a legitimate start.
  • A usage policy. Which categories of content may go into which tools. This is also your best data-protection control.
  • A disclosure habit. Recorded as work happens, not reconstructed at submission.
  • A written risk classification. Usually "limited-risk deployer", with the reasoning. One page.

We have set out where the hours actually are in AI for medical publishing, and compared the tooling by job — including which vendors state their data handling plainly — in AI tools for medical publishing.

Frequently asked questions

Can I put a manuscript into ChatGPT?

Not an unpublished one. Wiley, Wolters Kluwer and Elsevier all explicitly warn against uploading unpublished manuscripts or patient data into general-purpose LLMs. This is publisher policy rather than law, which makes it faster to bite than any statute — it applies the moment you submit. Published material, congress logistics and non-confidential internal notes are a different matter.

Did the EU AI Act high-risk deadline change?

Yes. The Digital Omnibus, in force since 27 July 2026, moved the Annex III high-risk application date from 2 August 2026 to 2 December 2027. The transparency obligations still began on 2 August 2026, and the Article 4 AI-literacy duty has applied since 2 February 2025. Advice still built on an August 2026 high-risk deadline predates the Omnibus.

Do I need to disclose AI use for language editing?

Under ICMJE, yes — the requirement attaches to the use of AI-assisted technologies in manuscript preparation, and language polish falls within that. Because the obligation attaches to preparation rather than output, keep a running record of what was used and where as you work, rather than reconstructing it at submission.

Which regime applies to my MedComms work?

Usually the first three. Publisher policy applies the moment you submit; ICMJE and GPP 2022 govern disclosure and authorship; and the EU AI Act makes you a deployer of limited-risk AI, meaning the literacy duty and transparency obligations. GxP and ALCOA+ only engage where output enters a regulatory dossier — which most MedComms work never does.

What is the minimum we should have in place?

Four artefacts, assemblable in about a week: an AI register listing systems in use and their owners; a usage policy stating which content categories may enter which tools; a disclosure habit recorded as work happens; and a one-page written risk classification with its reasoning, usually "limited-risk deployer". None of this needs a project.
Our AI services Hire an AI consultant AI automation AI agents AI implementation Pricing

Want any of this applied to your business?

We turn these concepts into working tools — grounded, safe and measurable. Start with a free consultation.

Book a free consultation →