IQVIA
Indexed for the AI platform and agent portfolio rather than for the wider clinical research services, data, and consulting business, which is context under this index's product scoping rule. IQVIA (NYSE: IQV) launched IQVIA.ai in March 2026, a unified agentic platform and agent marketplace spanning clinical, commercial, and real world operations, built on the company's proprietary health data and Healthcare grade AI together with NVIDIA Nemotron, NeMo Agent Toolkit, Dynamo, and LangChain, following a collaboration begun over a year earlier.
Disclosed agent use cases include target identification, clinical data review, literature review, market assessment, and healthcare professional engagement. The company reports filing more than 100 AI related patents and deploying more than 150 intelligent agents across internal teams and client environments, with 19 of the top 20 pharmaceutical companies having begun incorporating IQVIA agents into their workflows. IQVIA AI Assistant is a generative interface over the company's existing solutions and data products.
The commercial side of the portfolio includes healthcare professional targeting and engagement, which sits closer to pharmaceutical marketing than to clinical operations and should be evaluated separately from the research and clinical agents.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The fifth product scoped platform vendor here. IQVIA's durable assets are its health data holdings, clinical research services, and domain expertise; IQVIA.ai is an agentic layer over those assets launched in March 2026. The company's own framing, that the platform combines its data and expertise with NVIDIA infrastructure, correctly identifies the data as the foundation. A pharmaceutical company does not select IQVIA for its agents.
The company writes about oversight more than most vendors in this index and does not state what any specific agent may do without a person.
The published material is real. Experts in the loop are described as guiding development, trust is framed around transparency, explainability and auditability, and a published methodology sets out risk tiering with defined responsibilities as the basis for governing AI. Risk tiering is genuinely the right structure, because it accepts that a literature review agent and an agent touching safety data warrant different controls.
What is missing is the application. Nothing located states the tier any particular agent sits in, what it may do unattended at that tier, what a reviewer is shown before approving, whether any step can be configured to run without confirmation, or what recourse exists when an agent is wrong. That gap matters in proportion to the number involved: the company reports more than one hundred and fifty agents deployed across internal teams and client environments, spanning uses as different as literature review, clinical data review and healthcare professional engagement. A buyer cannot infer the oversight design of the agent they are adopting from a description of the framework that governs the portfolio.
Some of the published material also reads as advisory guidance about how organisations should govern AI rather than as a statement of this company's own runtime practice, and the two should not be conflated.
Ask which tier the specific agents under consideration occupy, what that tier permits, and how an agent action is distinguished from a person's in the record.
The infrastructure stack is named with unusual specificity for a company this size: NVIDIA Nemotron, NeMo Agent Toolkit, NeMo Customizer for fine tuning, NeMo Guardrails for deployment safety, Dynamo, and LangChain. Naming the guardrail layer explicitly is worth noting.
Held back from A because Healthcare grade AI is a trademarked positioning term rather than a described methodology, and no model cards, benchmarks, or validation results were retrieved to substantiate what distinguishes it beyond data quality and domain tuning.
The infrastructure stack is named with unusual specificity for a company of this size, covering a named model family, an agent toolkit, a fine tuning component, a guardrail layer, a serving framework and an orchestration library. That is more than nearly any platform vendor in this index provides, and two of the named components do particular work.
Naming the fine tuning component tells a buyer that domain adaptation happens on top of a third party base rather than from scratch, which is the honest architecture for a business of this kind and is usually left implicit. Naming the guardrail layer explicitly identifies where output constraints are enforced, so a buyer knows a control exists and can ask what it is configured to catch rather than guessing whether one is present at all.
Held below the top grade on the questions that matter most given the underlying holdings. No sub processor list, de identification standard, consent framework or independent privacy audit was located, and this organisation holds health data at a scale that makes those disclosures more consequential than for a typical vendor: the same gap in a small company covers thousands of records, and here it covers a far larger set.
Nothing states whether customer data contributes to the domain tuning. Ask for the de identification standard, the consent basis for the underlying holdings, a sub processor list, and whether client data informs the tuned models.
Adoption breadth is exceptional and specific: more than 150 intelligent agents deployed across internal teams and client environments, and 19 of the top 20 pharmaceutical companies reported to have begun incorporating IQVIA agents into workflows. More than 100 AI related patents filed.
Held back from A because begun incorporating is a low bar that spans pilot through production, no outcome figures were retrieved for any agent, and the platform launched in March 2026, so deployment depth is unproven relative to breadth.
The company states it uses a range of privacy enhancing technologies and safeguards to protect individual privacy while analyzing health data at scale, and cites NeMo Guardrails in the agent deployment stack, which is a named technical control rather than a general assurance.
Held back from A because no specific de identification standard, consent framework, or independent privacy audit was retrieved, and the scale of the underlying data holdings makes that disclosure more consequential here than for most vendors in this index.
This company stands in at least two quite different relationships to health data, and nothing published states which applies to the platform indexed here. That is the finding.
In its research and services work it handles identifiable information on behalf of sponsors and sites, where business associate arrangements and trial frameworks apply in the ordinary way. Separately, and this is the larger part of the business, it holds and licenses health data at enormous scale, sourced from across the care and payment system. That second activity rests on a determination that the data is de identified, because de identified information sits outside the health privacy rule altogether.
That determination is therefore the load bearing legal step in the whole arrangement, and it is not published. The rule offers two routes: a documented determination by a qualified expert that re identification risk is very small, or removal of the enumerated identifier set. Which method is relied on, who performs it, how often it is revisited as linkage becomes easier, and whether the standard is applied uniformly across sources are the questions that matter, and none was located.
The agents make it live rather than academic. Agents reasoning over a linked national scale dataset can surface associations that a single de identified record could not, and re identification risk is a property of the linked whole rather than of any one source.
Ask which entity contracts and under what agreement, whether a business associate agreement is available for the agent platform, which de identification method underpins the data the agents draw on, and when that determination was last refreshed.
No attestation scoped to the agent platform and no trust centre were located.
One architectural control is disclosed and it is genuine. For the pharmacovigilance assistant the company describes the underlying model running in a secure enclave, with the security framework stated to prevent customer information from reaching commercial models. A named isolation architecture attached to a named product is more useful than a general assurance, and it is credited on the governance axis. It is not an attestation, it covers one product, and it says nothing about the company's own environment, its development practices or the access its staff hold.
A route exists here that was not exhausted in this pass and should be recorded rather than assumed. The company is listed on a United States exchange, so its annual report must carry the cybersecurity governance item describing processes for assessing and managing cybersecurity risk, board oversight and accountable management. That item is the source of graded disclosures elsewhere in this index. It was not retrieved here, so this row does not rely on it, and it should be read before anyone does.
The scale of what sits behind this platform makes the gap consequential. The company holds health data at national scale and reports agents deployed across client environments at nineteen of the twenty largest pharmaceutical companies. Ask for an attestation and its scope, whether the agent platform and the data estate are inside the same boundary or different ones, and whether the enclave architecture described for one product applies to the others.
No device pathway applies and none is claimed. The framework that does apply is unaddressed for the platform indexed here, which is what holds this at C.
Disclosed agent use cases include clinical data review, and the platform is described as spanning clinical, commercial and real world operations from target identification through submission adjacent work. Where output contributes to a regulatory filing, the operative expectations are electronic records and data integrity requirements and the validation of computerised systems for their intended use, not device clearance.
The company's wider research services business necessarily operates inside that regime, and has done for decades. That is not the same as a published position for the agent platform, and this record is scoped to the platform. Nothing located states whether the agents sit inside a validated boundary, how a non deterministic component is qualified, whether agent behaviour is re tested when an underlying model changes, or how an action taken by an agent is attributed in an audit trail.
That last question has particular force here. The platform is built partly on third party model and agent infrastructure from a named external provider. A model version change originating outside the company's own release cycle is a change to a system a customer may be relying on for regulated work, made by a party that is not accountable to the customer's quality system.
For calibration, two vendors assessed in the same pass publish either documented compliance positions per instrument and jurisdiction, or performed and documented qualification per release with a validation summary available on request. Both are the standard this axis measures against. Ask for the equivalent here, scoped to the agents.
The most developed governance apparatus in this category, and the strongest single element is a concrete architectural disclosure rather than a principle.
What exists. A dedicated governance page setting out a standardised ethical framework said to guide development and deployment across the portfolio, built on five stated principles and naming bias, transparency, accountability and ethics as the concerns it addresses. A published methodology applying quality management system thinking to AI with risk tiering, threat modelling and defined responsibilities, framed around verifying and documenting that systems perform reliably in real world conditions. A published white paper on regulatory frameworks for AI. External policy engagement through international bodies, adherence to recognised data stewardship principles, and a reported body of more than two hundred AI scientific publications, which is a substantial record by any measure in this index.
The most useful disclosure is narrower and more specific than any of that. For its pharmacovigilance assistant the company describes the underlying model running in a secure enclave with a stated guarantee that no customer data trains the model, and describes the security framework as preventing customer information from reaching commercial models. That is a named architecture attached to a named product with an explicit training exclusion, which is worth more than a page of principles and which most vendors in this lane do not offer at all.
Held at B rather than A for three reasons. No model documentation or performance evaluation was located for any individual agent, so the framework is visible at the level of process rather than result. Bias and hallucination mitigation are described as ongoing work rather than measured. And the training exclusion, which is the disclosure a buyer would most want, attaches to one product rather than to the platform. Ask whether it holds across all agents and get it in writing.
Two passes located no model cards, no benchmarks, no validation results, no published limitations and no warranty, indemnity or remediation commitment. The quality claim standing in for all of that deserves a specific comment, because it is a construction this index has not recorded before. The positioning term used to describe the standard of the artificial intelligence is a trademark rather than a described methodology.
A trademark is protected as a brand, which is close to the opposite of a specification: it identifies who is making the claim and gives them exclusive rights to the phrase, while defining nothing a buyer could test against and nothing a competitor could meet. A published standard invites others to comply with it; a trademarked one prevents them from using the words.
So the term that appears where a methodology should be is legally strong and epistemically empty, and a buyer reading it learns the vendor's marketing position rather than anything about the software. What would fill the gap is ordinary: model cards for the tuned models, benchmark results against a named baseline, and an error characteristic for whichever capability the buyer is licensing. Ask what the positioning term actually requires, what evidence supports it, and for validation results on the specific capability you are buying.
A partial scoping determination with the domain equivalent unanswered, which is why this does not sit higher.
The agents serve sponsor side and commercial functions rather than clinical care, so the clinical interoperability question this axis normally asks does not reach them directly, and no electronic health record integration is claimed for the platform.
The equivalent question has two halves here and neither is documented. On the inbound side, the company's foundational asset is health data assembled from across the care and payment system, which necessarily involves large scale ingestion from record systems, pharmacies and claims processors. That is a substantial interoperability capability, and nothing published describes the standards, formats or refresh cadence behind it, which matters because the currency and completeness of that pipeline determines what any agent reasoning over it can actually see.
On the outbound side, agents are described as deployed into client environments, which implies integration with each customer's systems. No interface documentation, named integration or supported format specification was located, and the platform is presented as a marketplace of agents rather than as a documented integration surface.
Ask what standards the data pipeline uses and how current the data is at the point an agent reads it, and separately what interfaces exist for deploying an agent into a customer's own stack and what it can read and write there.
Nothing was located on hosting location, region availability, residency options, tenancy separation, retention or subprocessors for the agent platform.
What can be said about the architecture points in two directions at once and the tension is worth naming. The company describes agents deployed both across its own internal teams and inside client environments, which implies at least two deployment models with materially different exposure: an agent running in a customer's estate is a different proposition from one running in the vendor's, and the answers to residency, tenancy and access differ accordingly. Separately, the platform is described as built on third party model and agent infrastructure from a named external provider, which introduces a further environment into the path.
The one specific disclosure located is the secure enclave described for the pharmacovigilance assistant, which is an isolation claim rather than a residency one and covers a single product.
The residency question is not theoretical for this customer base. Nineteen of the twenty largest pharmaceutical companies are reported to be adopting these agents, all of them running trials and commercial operations across jurisdictions with their own transfer rules, and the underlying data estate spans many countries.
Ask which deployment model a proposal covers, where inference runs and in which region, how one client's environment is isolated from another's, and what the position is where an agent operates on a customer's own infrastructure rather than the vendor's.
No public pricing. Contact the vendor. Enterprise agreements with life sciences organizations, typically bundled with existing data and services relationships. Third party analysis notes the platform is structured as a multi year commitment rather than a discrete product, which increases switching costs once agents are embedded in clinical and commercial processes; that lock in dynamic is worth weighing against a specialist alternative.
Coverage spans clinical, commercial, and real world evidence operations across the asset lifecycle, with named use cases including target identification, clinical data review, literature review, market assessment, and healthcare professional engagement. Held back from A because that range is very broad and mixes research functions with commercial targeting; a buyer should scope which agents are production ready for their specific function rather than assuming uniform maturity.
What Changed
Material product, regulatory, evidence and commercial changes at IQVIA, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
IQVIA launched Predictive Clinical Development, a suite covering site selection and study design, an automated start up path it calls Push Button Start-Up, and real time data cleaning aimed at shortening the gap to database lock.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor
|
Enterprise life sciences agreements, typically bundled with data and services | — | — | Third Party Estimated |
No rate card published. Enterprise agreements with life sciences organizations, typically bundled into existing data, services, and clinical research relationships rather than sold standalone. Third party analysis characterizes IQVIA.ai as a multi year platform commitment rather than a discrete product, and notes this increases switching costs once agents are embedded in clinical and commercial processes. Buyers should weigh that lock in against specialist alternatives, and should separate what is genuinely incremental cost from what is repackaging of an existing relationship.