From The Editor | October 1, 2026

AI Governance Is Becoming A Competitive Edge In Trials

John Oncea Profile Photo

By John Oncea, Chief Editor, Clinical Tech Leader

AI governance, compliance, security, legal policy, ethical oversight-GettyImages-2285523466

AI adoption in clinical research is no longer optional or experimental. It’s ambient. “You can’t go on the internet and do a search and not be using AI,” said Nick Spittal, Chief Operations Officer of Velocity Clinical Research. “You can’t open up Microsoft Word and not be using AI. You can’t write an email without being prompted by a Copilot coach.”

For Spittal and Raghu Punnamraju, Velocity’s Chief Technology Officer, that ambient presence is precisely why governance has become a strategic priority rather than a compliance afterthought. Their answer wasn’t to restrict AI use; it was to build a formal structure for evaluating it.

Data Hygiene Comes First

Before any discussion of models or use cases, Punnamraju pointed to something less exciting but foundational: data hygiene. As Velocity has moved from disparate systems toward predictive analytics and AI-driven decision support, the reliability of those tools has become directly tied to the consistency and cleanliness of the underlying data. “That data posture, that data hygiene really becomes even more critical,” Spittal said, describing it as the kind of infrastructure work organizations are often tempted to defer and can no longer afford to.

Building The Governance Council

Velocity formalized its approach through a governance council with representation from operations, legal, quality, HR, and IT security, alongside Punnamraju’s technology team. Every proposed AI use case runs through the council, starting with an initial automated assessment before human reviewers weigh in and issue guidance to the business unit requesting the tool, typically a conditional approval with defined parameters, occasionally a rejection.

“There is always a human in the loop,” Punnamraju said. “We haven’t really seen an automatic pass yet.”

The framework itself borrows from established models rather than reinventing the wheel. Gartner has popularized the concept of AI TRiSM – AI trust, risk, and security management – as a way for organizations to balance innovation against responsible oversight. Velocity built its own version, modeled from Gartner’s TRISM, by combining elements of that framework with Microsoft's approach. Punnamraju described it as covering five core functions the council evaluates for every tool: Is the organization using AI with transparency and fairness, is the data kept private, is the model risk understood and managed, and is the data and model access secured?

That level of scrutiny isn't optional in a regulated environment. Unlike industries where AI experimentation carries mostly reputational risk, clinical research operates under GCP and 21 CFR Part 11 requirements that demand data provenance, validation, and auditability for anything that touches a study record, which is part of why every AI use case, however small, runs through the same council rather than getting adopted informally by individual teams.

Governance Has To Keep Up With The Technology

One clear lesson from standing up the council: the pace of AI development means governance decisions can’t be treated as permanent. Spittal described reviewing an application just a week before the interview that the council had rejected six months earlier. The second review reached a different conclusion, with new parameters attached for how it could be used.

“If we have to do that with every application we might use, we’re going to just spend all our time all day long doing governance, and that’s not really what we’re in the business to do,” Spittal said. The challenge isn’t just evaluating new tools; it’s revisiting old decisions as the underlying technology, and the risk profile that comes with it keeps shifting underneath them.

That challenge is compounded by how deeply AI is now embedded in existing enterprise software. It’s not always possible to simply decline the AI features in a platform an organization already relies on. Increasingly, those capabilities are built into the product itself, which raises new questions about how data is used and trained on by the software vendor. “Frankly, I don’t think we’ve got it figured out either,” Spittal admitted. “It’s a real challenge.”

Human-In-The-Loop Is Non-Negotiable

Both leaders were clear that clinical and financial decisions remain human decisions. Clinical judgment calls stay with the clinician; AI can inform that judgment but doesn’t get a vote. Financial decisions get the same treatment; Punnamraju described the process as “100% human in the loop,” with AI serving as an assistant rather than a decision-maker even at the operational level: scheduling, outreach, and patient experience workflows all route through a human manager.

Neither Spittal nor Punnamraju believes the industry has tipped into over-reliance on AI. If anything, both see the opposite risk as more immediate: people trusting AI output without checking it.

Spittal offered a specific example. Someone asks a large language model a question, pastes the output directly into an email, and sends it along without noticing that the numbers are off by orders of magnitude, or that a computational conclusion doesn’t hold up. “You’ve got to be the thinking layer on top of it,” he said of his own team’s approach. “You’ve got to actually look at what it’s doing and saying.” He described watching someone generate a polished-looking presentation slide that, on inspection, didn’t actually say anything substantive: technically correct, functionally empty.

Some of that gap is a training problem, not a technology problem, in his view. Velocity has started running cohorts of staff through structured training with its technology team specifically to build better prompting and evaluation habits, on the theory that the tools will keep improving faster than most users’ skill in questioning what they produce.

Governance As A Strategic Asset

Punnamraju was equally direct that over-governing carries its own cost. A council that treats every request as a risk to be minimized rather than a capability to be enabled will slow an organization down without necessarily making it safer. “Do we really want to constrain it? AI is everywhere. How do we make sure of its efficient use?” he said, framing responsible governance as something the council actively has to fight complacency toward, not just laxity.

That balance – enabling adoption while keeping a human accountable for every consequential decision – is what both executives see as the real differentiator going forward. Organizations that get it wrong either move too slowly to benefit from the technology or move fast enough to create problems they can’t see coming. Velocity bets that clean data, a standing governance structure, and a persistent human layer of judgment are what let an organization do both: adopt AI quickly and still trust what it produces.