Clinical Trials AI
M

Medable

Clinical trial technology platform combining decentralized trial execution and electronic clinical outcome assessment with an agentic AI layer added in 2026. Agent Studio is a no code agent builder the company describes as the first agentic AI platform purpose built for clinical development, letting sponsor teams configure agents for protocol development, trial planning, and data workflows, with human in the loop validation and integration across life sciences systems. Shipped agents include TMF Agent for trial master file document management, announced January 2026, and a Digital Data Flow Agent that converts trial protocols into machine readable data.

The underlying platform is reported deployed in nearly 400 trials across 70 countries and 120 languages, serving more than one million patients, and was named a Leader in eCOA by Everest Group. Founded 2014; CEO and cofounder Dr Michelle Longmire.

AI Health Index verifiedJuly 28, 2026
Compare Medable with other vendors
Founded
2014
Headquarters
Palo Alto, California
Website
www.medable.com
Categories
clinical-trials-ai
Indexed Products
Agent Studio, TMF Agent, Digital Data Flow Agent, eCOA
Buyer Segments
Pharma / Life Sciences
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
CC on AI CentralityArtificial intelligence is a feature layer on a product whose value stands without it.
Vendor Published

The established product is a decentralized trial and eCOA platform, and the agentic layer arrived in 2026. Agent Studio and the shipped TMF and Digital Data Flow agents are substantive rather than cosmetic, and the no code agent builder is a real capability. Graded C because a buyer purchasing Medable today is primarily purchasing trial execution infrastructure onto which agents are configured, not a model.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Human in the loop validation is stated as a design principle of Agent Studio, alongside conformance to life sciences standard operating procedures, regulatory and validation requirements, and benchmarking against trusted sources. That regulated context imposes real audit discipline. Held back from A because escalation thresholds and failure handling for individual agents are not documented publicly.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Capabilities are named and described. The technology under them is not.

What is public: a no code agent builder, a trial master file agent, an agent converting protocols into machine readable data, AI powered translation, and agent connectivity to trial systems through a named open protocol. A buyer can tell what each does and roughly how it fits a workflow, and the protocol reference is a real technical detail rather than a marketing one.

What is not public: which models underlie any of it, whether they are the company's own or licensed from a third party, where they run, how they were adapted for this domain, how versions are managed, or what evaluation exists. For a platform operating in a validated environment the version question is not incidental, because a change in an underlying model is a change to a system a sponsor may be relying on for regulated work.

The published figures follow the pattern this index sees repeatedly: translation timelines halved, build timelines reduced from sixteen to twenty weeks to under eight. Both are operational improvements and neither speaks to correctness. A faster build that produces the same instrument is a gain; a faster build that produces a subtly different instrument is a measurement problem.

For contrast within the same pass, another platform vendor in this lane names its model providers and its hosting arrangement explicitly, which lets a buyer reason about model risk directly. Ask the same questions here: which models, whose, where, and how changes are notified.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies any party in the chain: no model or model family, no foundation model provider, no hosting arrangement and no sub processor list was located in two passes, and no participant data lifecycle was found. The collection point is what makes this different from the rest of the lane and it should be stated plainly.

This platform collects outcome data directly from participants rather than receiving it from a sponsor's systems, across a reported million or more people, through a patient application, a web interface, connected sensors capturing physiological measures and electronic consent, with some participants using provisioned devices and some their own.

Whichever it is, the collection point is the person rather than an institution, which puts this closer to a consumer health application in its data handling profile than to enterprise trial software, and consumer data handling questions apply accordingly.

Nothing states what is retained on the device, what is transmitted and when, what happens to locally cached responses if a participant withdraws, what sensor data is kept beyond the derived measure, how long participant data is held after a study closes, or who inside the company can reach participant level records.

The agentic layer adds a second question, since agents act across connected systems on normalised customer data and nothing states whether normalisation for one study touches another's. Ask for the participant lifecycle end to end, including withdrawal and study close.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Platform scale is substantial and consistently reported: nearly 400 trials across 70 countries and 120 languages serving more than one million patients, with independent recognition as a Leader in eCOA by Everest Group. Held back from A because that evidence supports the trial platform rather than the 2026 agentic layer, for which no outcome data was retrieved. Agent performance and platform track record are separate claims.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

The data surface is unusually broad and nothing published describes how it is governed.

This platform collects outcome data directly from participants rather than receiving it from a sponsor's systems, across a reported million or more people, through a patient application, a web interface, connected sensors capturing physiological measures, and electronic consent. Some participants use provisioned devices and some use their own. Whichever it is, the collection point is the person rather than an institution, which makes this closer to a consumer health application in its data handling profile than to enterprise trial software.

Nothing located states what is retained on the device, what is transmitted and when, what happens to locally cached responses if a participant withdraws, what sensor data is kept beyond the derived measure, how long the company holds participant data after a study closes, or who inside the company can access participant level records.

The agentic layer adds a second question. Agents are described as surfacing insights and taking action across connected systems, and the company states it normalises customer data so agents can act on it. Nothing states whether participant level data is used to develop or tune models, or whether normalisation for one study's agents touches another study's data.

Ask for the participant data lifecycle end to end, including withdrawal and study close, and for a written position on whether participant data trains or tunes anything.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Vendor Published

Not a clean scoping determination, and that is the finding. This vendor sits across more frameworks than most in this category and publishes a position on none of them.

The data is collected under a trial protocol from consented participants, which points toward good clinical practice and the sponsor's own obligations rather than the United States health privacy rule. But the collection happens directly with the participant, often on their own device, frequently through a site that is itself a covered entity, and across seventy countries. Depending on the configuration, this company can be a service provider to a sponsor, a business associate of a site, and a processor of personal data under several national regimes, simultaneously and within one study.

Nothing published resolves which applies. No business associate agreement availability statement, no role characterisation, no identification of the contracting entity, and no data processing terms were located. The company's knowledge centre states that eCOA systems must comply with the health privacy rule alongside other regulations, which is guidance about the category rather than a statement about this platform, and should not be read as the latter.

Electronic consent deserves separate attention. Where a platform administers consent as well as collecting the data consented to, the consent record is both the legal basis and an artefact the platform holds. Ask who controls that record, how it is produced for an inspection, and what happens to data collected before a participant withdraws.

Establish in writing which role the company takes in your configuration, and get the agreement that matches it.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

No SOC 2, ISO 27001 or equivalent attestation was located and there is no trust centre.

The same reading caution applies here as elsewhere on this record. The company's knowledge centre states that robust encryption and access controls are essential for protecting patient data in eCOA systems, and that platforms must meet stringent security requirements. Those are descriptions of what the category demands, published as guidance for buyers, and they are not assertions that this platform has been examined against them by anyone.

The exposure behind the gap is larger than for a sponsor side data tool. This platform collects outcome data directly from patients, across a reported four hundred trials in seventy countries serving more than a million participants, through an application distributed on consumer app stores that runs either on provisioned devices or on the participant's own phone. That last configuration is the one to press on: a study application on a personal device sits alongside everything else on that device, is subject to the participant's own security posture, and persists after the study unless something removes it.

Ask for an attestation and its scope, whether the agentic layer added in 2026 is inside that scope, what is stored on the participant device and for how long, how data is protected if a device is lost or shared, and what happens to the local data and the application at study close.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No device pathway applies and none is claimed. The framework that does apply is acknowledged rather than documented, which places this between the two ends of this axis rather than at either.

The products collect patient reported and clinician reported outcome data and manage trial documentation. Outcome data of that kind is endpoint data, so it enters the submission directly, and the trial master file is the record set an inspector examines. Electronic records and data integrity expectations therefore apply squarely: attributable and contemporaneous records, secure computer generated audit trails, changes that do not obscure prior entries, and validation for intended use.

The company states that the platform incorporates security controls, audit trails and compliance safeguards supporting requirements such as the United States electronic records rule and European data protection law. That is an acknowledgement, and it is more than silence. It is hedged, product level rather than instrument level, and unaccompanied by any of the artefacts a sponsor actually needs.

A distinction matters when reading this vendor's site. Its knowledge centre publishes extensive guidance stating that eCOA systems must comply with the electronic records rule, must maintain audit trails and must undergo system validation. Those are statements about what the category requires, not claims about what this platform holds, and on the vendor's own domain the two are easily conflated.

For calibration, two vendors assessed in the same pass publish either documented compliance positions per instrument and jurisdiction, or performed qualification per release with a validation summary available on request. Ask for the validation package, the qualification documentation, and specifically how the agentic layer added in 2026 is validated.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No governance framework, model documentation, evaluation methodology or applicability statement was located. The domain relevant question here is unusually specific, and the company has already told its readers why it matters.

The platform delivers outcome instruments to patients in around 120 languages, and the company advertises AI powered translation that halves time to go live and cuts build timelines from sixteen to twenty weeks down to under eight. Its own published guidance states that linguistic validation is crucial for multilingual studies, that translation must be culturally appropriate as well as accurate, and that instruments must be adapted so patients in different populations comprehend them the same way.

That is the right standard, and it is the company's own. An outcome instrument is a measuring device. If a translated item shifts meaning even slightly, responses from that language group are not comparable with the rest of the study, and the effect does not appear as an error. It appears as variance, or as a real difference between populations, in an endpoint a regulator will assess. Speeding translation is valuable; preserving equivalence is what makes the data usable.

Nothing located describes how linguistic validation is maintained when translation is machine generated: whether a qualified reviewer confirms each item, whether cognitive debriefing with patients is still performed, what the process is for instruments already validated in a source language, or what evidence a sponsor receives that an AI translated instrument measures what the original measured.

Ask for the linguistic validation workflow around the translation capability, and for the evidence pack a sponsor can put in front of a regulator that asks.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no model named for any capability, no evaluation methodology, no accuracy measure and no warranty, indemnity or remediation commitment. The published figures measure speed rather than correctness, covering translation timelines halved and build timelines reduced from sixteen to twenty weeks to under eight, and for this product type that distinction is not academic.

These capabilities produce trial instruments, so a faster build that produces the same instrument is a gain, while a faster build that produces a subtly different instrument is a measurement problem: a translated or reconstructed patient reported outcome measure that shifts wording changes what is being measured, and the endpoint moves without anyone intending it.

The same applies to a protocol converted into machine readable form, where a misconstrued criterion propagates into every downstream system that consumes it. The version question is also not incidental here. This operates in a validated environment, so a change in an underlying model is a change to a system a sponsor may be relying on for regulated work, and nothing describes how versions are managed or how changes are notified.

A sponsor who validated a configuration cannot tell whether they are still running it. Ask which models underlie each capability, how versions are locked and change is notified, and what evidence exists that a generated instrument is equivalent to the source.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

A scoping determination on the clinical question, and the domain equivalent is answered specifically and well.

This is sponsor side trial software. It does not sit in clinical care, does not read or write a patient chart, and no electronic health record integration is claimed. Grading it against clinical interoperability would misdescribe it.

The equivalent question is whether the platform connects to the systems a trial actually runs on, and here the company names them. It describes connectors to electronic data capture, the trial master file, interactive response technology and collaboration tools, using a named open protocol for connecting model driven systems, so that agents can surface insights and act across those workflows. It describes standardised integrations for sensors capturing physiological measures, a library of more than four hundred reusable pre validated instruments, and a data normalisation layer beneath the agents. Naming the specific system categories and the protocol is more useful than a general claim to integrate, and few vendors in this lane do it.

Held at B rather than A because no interface documentation, supported object specification or named partner system was located, and because a connector to a category is not the same as a tested integration with a particular vendor's product. Ask which specific systems have been integrated in production, and what an agent is permitted to read and write in each.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

The residency question is live for this vendor in a way it is not for most, and it is unanswered.

The platform operates across a reported seventy countries in around a hundred and twenty languages, collecting data directly from participants on provisioned devices and on their own phones. That means personal data of identifiable individuals is being collected inside many jurisdictions at once, several of which impose localisation requirements on health or personal data rather than merely governing transfer.

The company's own published guidance names this precisely, advising that implementers must understand data privacy laws, security regulations and data localisation requirements in each participating country. It does not state its own position on any of them. No hosting region, residency option, tenancy model, retention period or subprocessor list was located.

A second layer sits underneath. Agents are described as connecting to external systems through a named protocol and taking action across them, which means the deployment surface extends beyond the platform to wherever those connected systems run, and the data path multiplies accordingly.

Ask where participant data is held for a given study and whether region can be elected, how localisation requirements are met in countries that impose them, how one sponsor's environment is separated from another's, and where agent inference executes relative to the data it reasons over.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No public pricing. Contact the vendor. Enterprise agreements with pharmaceutical sponsors and CROs; no published rate card.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Precisely bounded: sponsor side clinical development, spanning decentralized and hybrid trial execution, eCOA, eConsent, and trial document operations. No clinical care claims are made, which is appropriate to the buyer.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Sponsor and CRO agreements, scoped per study or program Vendor Published

Enterprise agreements with pharmaceutical sponsors and CROs, typically scoped per study or per program. No rate card published.