The Most Dangerous Revenue Stream Is the One You Don’t Control

No pharmaceutical brand team sets a quarterly target for off-label prescriptions. Nobody puts “unauthorized use growth” on a slide for the board. And yet off-label use has generated real revenue for drug makers for decades — revenue that has also generated some of the largest fraud settlements in U.S. corporate history.

What has changed is where that demand comes from. For most of the industry’s history, off-label conversations happened in exam rooms, at medical conferences, or through a sales rep who knew exactly how far the science could be stretched. Today, a patient can ask ChatGPT whether a GLP-1 drug approved for diabetes will help them lose weight, get an answer with no regulatory review behind it, and act on it before their physician ever weighs in. A company has no seat at that table, no red-line process, and often no idea the conversation happened.

That is the argument at the center of this piece: off-label demand a company did not create is not a bonus. It is the same liability the industry has been paying billions of dollars to settle since the 1990s, now running through channels — AI chatbots, Reddit threads, influencer posts — that no compliance department drafted and no legal team reviewed before publication.

Why Off-Label Promotion Has Always Cost Pharma More Than It Earned

The Food, Drug, and Cosmetic Act draws a clear line that catches a lot of people off guard. Physicians can prescribe an approved drug for almost any use they judge appropriate, including one the FDA never evaluated. Manufacturers cannot promote that use. The moment a company’s sales force, marketing materials, or paid messaging point a prescriber toward an unapproved indication, the drug becomes “misbranded” under the FDCA — a label that sounds bureaucratic but carries criminal exposure.

The legal theory that turned this into a financial catastrophe for drug makers came from a whistleblower case, not a regulator. Franklin v. Parke-Davis, built around the marketing of the epilepsy drug Neurontin for unapproved uses like bipolar disorder and migraines, was the first federal case to treat off-label promotion as a False Claims Act violation. It settled for $430 million (DOJ, 2004), and it handed every plaintiff’s attorney and whistleblower in the country a template.

The following two decades produced a run of settlements that make Neurontin look like a warm-up:

YearCompanySettlementProduct(s)Off-Label Conduct
2009Pfizer$2.3 billionBextra, Geodon, Zyvox, LyricaOff-label promotion, kickbacks
2009Eli Lilly$1.4 billionZyprexaOff-label promotion
2012GlaxoSmithKline$3 billionPaxil, Wellbutrin, AvandiaOff-label promotion, failure to report safety data
2012Abbott Laboratories$1.5 billionDepakoteOff-label marketing to nursing homes
2012Amgen$762 millionAranespOff-label promotion, kickbacks
2013Johnson & Johnson$2.2 billionRisperdal, Invega, NatrecorOff-label promotion, kickbacks

GlaxoSmithKline’s $3 billion resolution in 2012 remains the largest health care fraud settlement in U.S. history, combining a criminal fine tied to unapproved marketing of Paxil and Wellbutrin with a failure to disclose safety data on the diabetes drug Avandia (Department of Justice, 2012).

Every one of those cases shares a structural feature worth sitting with: the company controlled the channel. A sales rep who tells a physician a drug works for an unapproved use is an employee the company hired, trained, and could discipline. A reprint a rep hands out is a document legal reviewed. The liability was real, but it attached to conduct the company chose.

That control is exactly what is disappearing. When a patient forum, a Reddit thread, or an AI assistant answers a question about a drug’s unapproved use, the company did not write the message, did not train the source, and frequently does not know the conversation exists until a regulator, a plaintiff’s attorney, or a journalist finds it first. The revenue that use might generate flows to the company anyway. So, increasingly, does the risk.

How AI Chatbots Are Becoming a New Off-Label Demand Channel

A sales rep who talks up an unapproved use leaves a record: a call note, an expense report, a training deck legal can subpoena. A chatbot leaves nothing of the kind. It answers a question, the conversation disappears into a session log the company will never see, and the patient walks into an appointment already convinced a drug will help with something the label never mentioned.

Researchers have started measuring how often that answer is wrong. A 2024 study out of the University of Washington School of Pharmacy put ChatGPT through 18 open-ended drug-therapy questions posed the way a clinician or patient actually asks them. The model got roughly two-thirds of straightforward “what” questions right, but accuracy fell off sharply on “why” and “how” questions — the ones that require reasoning about dosing, mechanism, or protocol rather than recall (Shiferaw et al., BMC Medical Informatics and Decision Making, 2024). The same study found the model citing references that did not exist in the published literature.

That citation problem is not an isolated glitch. A 2025 systematic review and meta-analysis of ChatGPT’s performance as a drug-counseling tool found a consistent pattern across the literature: the model’s tendency to generate fabricated citations alongside plausible-sounding clinical claims, a combination the reviewers flagged as particularly risky in a pharmaceutical counseling context, where a wrong answer can shape a real dosing decision (medRxiv, 2025).

Head-to-head comparisons don’t offer much reassurance about picking a “safer” platform. A cross-sectional study testing ChatGPT-4o, Google Gemini, and Microsoft Copilot against 76 real drug-information questions pulled from medical sites and social platforms like Reddit found no statistically significant difference between the three models in correctness, completeness, or the rate of high-risk answers (Journal of Medical Internet Research, 2025). A more recent comparison in the British Journal of Clinical Pharmacology found human physicians still outperforming ChatGPT on real-world pharmacotherapy counseling questions (Krichevsky et al., 2026) — evidence the gap hasn’t closed, not evidence any one chatbot has solved it.

Across three major AI platforms tested against real patient and physician drug questions, researchers found no statistically significant difference in how often the models produced high-risk or incorrect answers — meaning the risk isn’t concentrated in one product a brand team could simply flag and move on from (JMIR, 2025).

None of this requires a chatbot to say something dramatically wrong to create off-label exposure. Plenty of off-label uses are well established in clinical practice and easy for a model to surface accurately: gabapentin for anxiety, propranolol for performance anxiety, low-dose naltrexone for chronic pain. An AI system that correctly describes these uses, without flagging that they fall outside the approved label, is functionally doing what a sales rep is legally barred from doing — just without a rep, a call note, or a company in the loop at all.

The FDA’s promotional oversight apparatus, run through the Office of Prescription Drug Promotion, was built around a company’s own advertising and sales materials — content a manufacturer files, submits, or controls. It has no comparable mechanism for a chatbot’s live-generated answer. That gap doesn’t mean the company is safe. It means the exposure has moved somewhere the existing compliance workflow was never built to see, which is precisely why monitoring platforms built for AI-generated pharmaceutical content — DrugChatter among them — have become part of how medical affairs and regulatory teams try to close that gap rather than discover it after a warning letter arrives.

What the FDA’s 2025 SIUU Final Guidance Actually Allows

The FDA did not ignore off-label communication. It built an entire regulatory pathway for it — one aimed squarely at company-controlled channels, which makes the absence of any equivalent pathway for AI-generated conversations more conspicuous, not less.

That pathway has a name most brand teams outside regulatory affairs have never heard: SIUU, short for “Scientific Information on Unapproved Uses.” The FDA issued its first version of this guidance in 2014, covering how firms could distribute reprints of published studies on off-label uses to health care providers without triggering a misbranding claim. On October 24, 2023, the agency replaced it with a revised draft that expanded the scope considerably, reaching beyond reprints to cover independent clinical practice resources and firm-generated presentations built around a published study (Jones Day, 2023). On January 6, 2025, FDA finalized that guidance.

The final version backed off one of the more contested elements of the 2023 draft. That draft had required source publications to be both “scientifically sound” and “clinically relevant” — a two-part standard industry commenters argued was too subjective to apply consistently. The Final SIUU Guidance dropped “clinically relevant” and kept only “scientifically sound” (King & Spalding, 2025), a narrower bar that gives medical affairs teams more room to work with legitimate published evidence.

What survived, largely unchanged, are the guardrails that make SIUU communications defensible rather than promotional: the information has to be truthful, non-misleading, and factual, and it has to give the health care provider enough context — strengths, weaknesses, validity, clinical utility — to evaluate the evidence rather than just accept a conclusion (Arnold & Porter, 2023). FDA frames the whole guidance as an enforcement discretion policy. Communications that follow it won’t, on their own, be treated as proof the company created a new intended use for the product (Ropes & Gray, 2025).

FDA’s Final SIUU Guidance offers firms a specific reassurance: scientific communications about unapproved uses that follow the agency’s recommended standards will not, by themselves, be used as evidence that a company intended a new, off-label use for its product — a protection that applies only to firm-initiated communications to health care providers (Ropes & Gray, 2025).

Read that reassurance closely and its limits become the more important part of the story. SIUU protection covers information a company originates and sends to prescribers. It says nothing about a patient typing a drug name into a chatbot and getting back a plausible-sounding answer about an unapproved use, sourced from the same published literature a medical affairs team might legitimately cite in an SIUU communication — but stripped of the balance, context, and evidentiary caveats the guidance requires. The underlying science can be identical. The compliance status is not, because the FDA’s entire enforcement discretion framework was built around who initiates the message and where it goes, not around whether the medical claim happens to be accurate.

That distinction matters more now than it did even two years ago, because the FDA’s willingness to act on off-label and misleading promotional content — in any channel — has changed sharply, which is the subject of the next section.

Inside the FDA’s 2025 Advertising Enforcement Reversal

For most of the last decade, FDA’s Office of Prescription Drug Promotion was, by its own numbers, one of the quietest enforcement bodies in the federal government. Warning letters for misleading drug advertising, which used to run well over 100 a year, fell to a single letter in 2023 and zero in 2024 (AJMC, 2026). Then the agency reversed course almost overnight.

In 2025, framed by the Trump administration and HHS Secretary Robert F. Kennedy Jr. as an effort to restore transparency and curb what they called overmedicalization, FDA issued thousands of template letters instructing pharmaceutical companies to bring advertising into compliance, alongside roughly 100 formal cease-and-desist letters — a volume with no recent precedent (National Law Review, 2025; Juris Law Group, 2025). The agency’s own release pointed to direct-to-consumer advertising spend of $10.8 billion in 2024 (MediaRadar, cited in National Law Review, 2025) as context for why it considers the category worth this level of scrutiny.

Social and digital media took a disproportionate share of the criticism. FDA’s public messaging specifically called out undisclosed paid influencer promotion as having blurred the line between editorial content, user-generated posts, and pharmaceutical advertising to the point that patients can no longer reliably tell them apart (Loeb & Loeb, 2025). The agency cited a 2024 Journal of Pharmaceutical Health Services Research finding that the majority of social posts advertising top-selling drugs are published by individuals rather than by the companies that manufacture them — a structural feature of influencer marketing that makes it harder for a compliance team to review content before it goes live, because so much of it was never theirs to review in the first place.

That last point is the one worth sitting with. Warning letters in this wave have gone after content companies paid for and, in some technical sense, authorized — Sprout Pharmaceuticals over an Instagram post from its own CEO promoting Addyi without risk information (Sheppard Mullin, 2025); kaléo over a paid-partnership influencer post that omitted risk information entirely; Merz Pharmaceuticals over a video that raced through required safety disclosures too quickly to meet FDA’s “prominence and readability” standard (Global Relay, 2026). Every one of those was, at minimum, a paid arrangement the company entered into. AI-generated content circulating with no commercial relationship to the manufacturer at all sits a step further out — outside the paid-partnership structure these letters have targeted so far, but not obviously outside the “deceptive advertising” framing FDA has now shown it’s willing to invoke broadly.

FDA has stated it will deploy artificial intelligence and other technology-enabled tools for proactive surveillance and review of drug advertising going forward, rather than relying primarily on complaints or manual review to identify violations (AJMC, 2026).

That detail deserves more attention from brand and compliance teams than it has gotten. An agency that is building AI-powered surveillance of advertising content is, almost by definition, going to start surfacing AI-generated and AI-amplified content in its review process — chatbot answers that get screenshotted and shared, influencer posts optimized to perform well in AI-driven search results, forum threads an AI system might cite as a source. A regulator using AI to monitor promotion is a regulator whose search radius now includes exactly the channels this piece has been describing. Companies still relying on manual monitoring of their own sanctioned content are, in effect, using yesterday’s surveillance method against tomorrow’s enforcement posture.

Case Studies: Warning Letters for Content Companies Didn’t Fully Control

The 2025 enforcement wave described above isn’t abstract. The individual letters behind it show exactly how much distance the FDA is now willing to accept between a company’s compliance department and the content that gets it in trouble — and that distance is instructive for anyone trying to figure out where an AI-driven exposure might land next.

Start with Sprout Pharmaceuticals. The Instagram post that triggered its May 29, 2025 warning letter had been live for nearly a year — CEO Cindy Eckert posted it on July 1, 2024, sharing a screenshot of a People magazine article alongside her own commentary calling Addyi “the sex pill for women” (FDA OPDP, 2025). Addyi is approved for one specific population: premenopausal women with acquired, generalized hypoactive sexual desire disorder. The post said nothing about that limitation, nothing about safety, and nothing distinguishing HSDD from general low libido. FDA’s letter made a point of stating that it treats a screenshot plus original commentary as a single “post” for regulatory purposes — a framing that matters because it means curating someone else’s content, even loosely, can carry the same promotional weight as writing it from scratch. FDA gave Sprout 15 days to either fix its promotional materials or stop distributing the drug, and demanded a corrective-communication plan reaching everyone who saw the post (FiercePharma, 2025). It was not Sprout’s first letter over Addyi promotion; OPDP had already cited the company in 2020 over a radio ad.

Merz Pharmaceuticals’ case shows what happens when the paid relationship is explicit and disclosed and the company still gets cited. In October 2024, OPDP sent an untitled letter over an Instagram reel from designer Nate Berkus, posted in a labeled “paid partnership” with the Xeomin Aesthetics account, promoting the wrinkle treatment Xeomin. The letter alleged the post misrepresented the drug’s risks and effectiveness, and it noted something brand teams should sit with: OPDP had already sent Merz two prior advisory comments about similar concerns before issuing this formal letter (Covington & Burling, 2025). Xeomin carries a boxed warning for distant spread of toxin effect — the FDA’s highest safety-labeling category — and a contraindication for patients with a botulinum toxin hypersensitivity. None of that made it into the reel.

kaléo’s letter follows the same shape: an Instagram post made in paid partnership presented efficacy claims for the company’s product while including no risk information at all, a direct violation of the FDA’s fair-balance regulation at 21 CFR 202 (Global Relay, 2026).

All three of these 2025-era letters — Sprout, Merz, and kaléo — involved content the company either created, paid for, or had prior warning about, and FDA cited each one anyway for omitting risk information required under 21 CFR 202’s fair-balance standard.

None of this started in 2025. FDA sent women’s health company Duchesnay a warning letter in 2015 over Kim Kardashian’s paid Instagram and Twitter posts promoting its morning-sickness drug Diclegis, faulting the posts for omitting risk information and understating the clinical evidence behind the product (MM+M, 2026). A decade of precedent existed before this year’s enforcement wave, and companies still got caught by the same gap.

What should concern a compliance team more than any single letter is what these cases have in common: a documented, paid, disclosed relationship between the company and the person posting. Sprout knew Eckert would post about Addyi — she’s the CEO. Merz and kaléo had contracts, disclosure requirements, and presumably some review process, and still missed required risk language. If that level of control still produces warning letters, a chatbot conversation or a Reddit thread with zero commercial relationship to the company represents a materially larger blind spot, not a smaller one. Pharmaceutical companies are already telling investors this in writing — Tarsus Pharmaceuticals’ most recent 10-K discloses the September 2025 enforcement wave as a named risk factor, warning that increased FDA scrutiny could force it to modify, pause, or withdraw advertising and could adversely affect product demand (SEC, 2025). That’s a public company putting a regulatory risk most brand teams still treat as a marketing-department problem into a financial risk disclosure.

Can AI-Generated Content Create a False Claims Act Exposure?

No reported case has yet held a pharmaceutical company liable under the False Claims Act for something a chatbot said about its drug. That silence is not the same as safety, and attorneys who track FCA enforcement are already writing about why.

The FCA remains the government’s primary weapon against pharmaceutical fraud for a reason: it works. The Department of Justice recovered more than $6.8 billion through False Claims Act settlements and judgments in fiscal year 2025, with over $5.7 billion of that coming from the health care industry alone (DOJ, cited in LegalClarity, 2026). Off-label promotion sits squarely inside that enforcement category, and the legal test for triggering it has always turned on causation: did the company do something — through a rep, a sales incentive, marketing materials — that caused a false claim to be submitted to Medicare or Medicaid. That causation requirement is exactly what makes AI-generated content a harder fit for prosecutors than a sales call, and exactly what makes it dangerous to assume the theory can’t reach that far.

Two threads in current FCA practice point toward how it might. The first: courts have not required promotional content to be false to create liability. A federal court in Massachusetts held that even truthful off-label promotion can support an FCA claim if the manufacturer knew its conduct would cause the submission of false claims (Greene LLP, 2026). Read against AI-generated content, that holding removes the defense a company might reach for instinctively — “the chatbot’s answer was accurate” doesn’t resolve the exposure if the company knew patients were being steered toward an unapproved use through a channel it could have addressed and didn’t.

The second thread runs through the Anti-Kickback Statute rather than misbranding directly, and it has an unusually close AI parallel already on the books. In 2020, DOJ resolved criminal and civil charges against the electronic health records vendor Practice Fusion over clinical decision-support alerts it had allowed an opioid manufacturer to help design — including letting the company select the clinical guidelines behind the alert and, in some instances, draft the alert’s language, in exchange for payment (Mintz, 2024; Morrison Foerster, 2024). DOJ’s language was blunt, calling the arrangement a scheme that let the opioid company insert itself into the doctor-patient relationship to increase prescribing. Attorneys tracking AI enforcement risk now cite Practice Fusion explicitly as the template regulators are likely to reach for: not “did the company promote off-label,” but “did the company pay to shape what a technology intermediary tells a prescriber or patient” (Morrison Foerster, 2024).

Legal analysts tracking AI-related False Claims Act exposure point to the 2020 Practice Fusion prosecution — where DOJ penalized an EHR vendor for letting a pharmaceutical company help design the clinical alerts shown to prescribers — as the closest existing template for how kickback theory could reach a company that pays to influence what an AI system tells a health care provider or patient (Morrison Foerster, 2024).

That template requires the company to have paid for or shaped the outcome. A general-purpose chatbot answering a question about a drug’s established off-label uses, with no commercial relationship to the manufacturer, sits outside it — nobody has brought that theory, and it’s a meaningfully weaker fit for causation than a paid EHR alert or a sales rep’s pitch. Where the exposure gets less theoretical is the moment a company engages with that content at all: correcting it, amplifying it, quoting it in its own materials, or entering any commercial arrangement with the platform surfacing it.

The other shift worth naming is who is doing the monitoring. DOJ and plaintiffs’ firms are already using AI tools to comb through public records, court filings, and online sources to build False Claims Act complaints faster and more cheaply than manual review ever allowed (Mintz, 2024). Some of those AI-assisted complaints have already run into a genuinely novel procedural fight — whether information an AI tool pulled from public sources counts as “publicly disclosed” for purposes of the FCA’s jurisdictional bar, a question Wiley Rein attorneys flagged as unresolved as early as 2023 (Law360, 2023). None of that requires an AI chatbot to have generated the off-label claim in the first place. It only requires that the conversation happened somewhere public, and that someone — a regulator, a relator’s attorney, an AI tool built for exactly this kind of search — went looking.

Where Off-Label Conversations Are Actually Happening

Ask where off-label drug demand originates today and the honest answer for a growing share of it is: wherever patients already are, in enormous volume, with no promotional oversight of any kind. Reddit has become the largest of these venues, and researchers have started treating it as a legitimate data source rather than internet noise.

The clearest illustration is semaglutide. A 2024 topic-modeling study analyzed 46,491 Reddit posts across r/ozempic, r/ozempicforweightloss, and r/semaglutide, spanning April 2019 through December 2023 (Emerging Trends in Drugs, Addictions, and Health, 2024). The dominant theme across those posts wasn’t diabetes management, the drug’s original approved indication — it was off-label weight loss, along with dosing strategies, insurance denials tied to lacking a diabetes diagnosis, and progress tracking. The same study flagged a gap that should concern anyone thinking about patient safety rather than just promotional compliance: discussion of the health risks tied to unsupervised, off-label use as a cosmetic aid appeared far less often than the enthusiasm driving people toward it.

That community didn’t need a pharmaceutical company’s marketing budget to generate hundreds of thousands of posts and, by extension, an enormous volume of off-label prescription requests walking into physicians’ offices. Novo Nordisk did not build r/ozempicforweightloss. It didn’t need to. The demand generated itself, at a scale no sales force could match, entirely outside any channel a compliance team could review before it reached a patient.

Researchers who scanned Reddit posts about Ozempic found the site’s dominant conversation centered on off-label use for weight loss, while discussion of the risks specific to using the drug without medical supervision for that purpose appeared comparatively rarely (Emerging Trends in Drugs, Addictions, and Health, 2024).

The same phenomenon shows up at even larger scale in more recent research. A University of Pennsylvania team analyzed 410,198 Reddit posts mentioning semaglutide or tirzepatide, posted between May 2019 and June 2025, and identified 67,008 users who self-reported actually using the drugs. Of those, 43.5% described at least one side effect — mostly the gastrointestinal symptoms already on the label, but the researchers also surfaced reproductive and temperature-related complaints they say aren’t well captured in current labeling or clinical trial data (Nature Health, 2026). The study’s authors frame this explicitly as pharmacovigilance: a way of detecting safety signals faster than the slower, smaller mechanism of formal clinical trials allows.

That framing matters more than it might first appear. Academic researchers now treat these forums as a real pharmacovigilance data source, worth publishing in a peer-reviewed Nature Portfolio journal. If a university team can mine 400,000-plus Reddit posts with AI tools to surface safety signals a drug’s own label doesn’t mention, an AI chatbot trained on overlapping data pools is drawing from the same unfiltered well when a patient asks it a direct question — minus the peer review, minus the methodological caveats, and minus any of the balance requirements FDA imposes on a company’s own promotional speech.

Reddit is the most heavily studied version of this, but it isn’t the only one. Physician-only networks like Sermo and Doximity host their own off-label discussion threads among prescribers comparing notes on drugs used outside their approved indications — a channel with real clinical value and just as little promotional oversight, because none of it originates from the manufacturer. Patient-run forums built around specific conditions function the same way, often with more clinical specificity than a general subreddit and just as little visibility into how AI systems might be summarizing or citing them.

None of these channels are new. What’s new is the intermediary standing between them and the next patient who asks a question. A decade ago, someone curious about off-label Ozempic use had to go find r/ozempicforweightloss and read it themselves, forming their own judgment about how much to trust an anonymous post. Today, they can ask an AI system the same question and receive a synthesized answer that sounds authoritative — built, in part, from exactly the same unmoderated source material, with none of the “this is one person’s anecdote” framing a human reader would apply instinctively while scrolling.

Why Pharmacovigilance Teams Can’t Treat AI Platforms as Out of Scope

FDA’s existing framework for adverse event monitoring online was built around a boundary that made sense in 2014 and looks increasingly outdated now: companies are expected to review internet sites they sponsor, and they are not expected to review sites they don’t (Pharmaceutical Commerce, 2026). A chatbot conversation between a stranger and a general-purpose AI platform sits well outside anything a manufacturer sponsors. Under the letter of current guidance, that puts it outside the monitoring obligation too — which is exactly why treating it as genuinely out of scope is a mistake, not a defensible reading of the rules.

Start with why the boundary exists in the first place. FDA requires four elements before a report counts as a reportable adverse event: an identifiable patient, an identifiable reporter, a specific drug or biologic, and an adverse event (Pharmaceutical Commerce, 2026). One widely cited industry analysis found that only about 1 in 500 social media posts contain enough information to satisfy all four criteria — and extrapolated across nearly 1,400 health-related sites tracked at the time, that worked out to roughly 166 reportable events a day across the entire pharmaceutical industry, a volume regulators and companies both judged too diffuse to build a mandatory monitoring regime around (Pharmaceutical Commerce, 2026).

A private exchange with an AI chatbot fails that four-part test even more completely than a Reddit post does. There’s no username, no public thread, no way for a company to identify the “reporter” at all — the conversation exists in a session log the manufacturer will never see. If the case-level reporting framework struggled with Reddit’s pseudonymous but at least persistent and searchable posts, it has essentially no mechanism for a one-on-one AI conversation that leaves no public trace.

Existing FDA draft guidance holds that pharmaceutical companies are responsible for reviewing internet sites they sponsor and are not responsible for reviewing sites they don’t — a standard that, applied literally, places most AI chatbot conversations about a company’s own drug outside any current monitoring obligation (Pharmaceutical Commerce, 2026).

That’s the narrow, US-specific reading. It is not the global one. The European Medicines Agency’s Good Pharmacovigilance Practices Module VI takes a broader position, stating that marketing authorization holders should routinely monitor the internet and digital media for potential adverse event reports — not just channels the company owns (Amethys Insights, 2025). A global pharmacovigilance team operating under both standards is already required to look further than its US-only regulatory floor demands. Treating AI platforms as categorically out of scope because the FDA hasn’t caught up isn’t compliance with the stricter standard the same company is very likely already subject to somewhere in its portfolio.

The academic literature has moved even further ahead of both regulators. Researchers now routinely treat Reddit as a legitimate pharmacovigilance data source in its own right, building machine-learning pipelines specifically to extract adverse-event signals from it and comparing what they find against FAERS, the FDA’s own formal reporting database (medRxiv, 2024). If university researchers with no regulatory mandate at all are running that analysis and publishing it in peer-reviewed journals, a pharmacovigilance team that isn’t running comparable monitoring on its own products is choosing to know less about its drug’s real-world safety profile than outside academics already know — and finding out about a safety signal from a published paper, rather than from its own monitoring, is not a position any PV lead wants to explain to their head of Regulatory Affairs.

None of this means every AI chatbot answer triggers an individual case safety report. It means the aggregate signal — the pattern across thousands of AI conversations and forum posts, not any single unidentifiable one — is exactly the kind of pharmacovigilance data the rest of the industry is already learning to extract, and exactly the kind a company with no visibility into AI-generated conversations about its own products cannot see at all.

Building an AI Monitoring Workflow for Off-Label Signal Detection

Most brand teams that get asked “what does ChatGPT say about our drug?” answer it the way they’d answer any one-off question: someone opens a chatbot, types the product name, reads the response, and reports back. That approach catches a single snapshot on a single platform on a single day. It misses everything that matters about how AI-generated drug information actually behaves, which is that it drifts.

A workable monitoring workflow starts by treating the approved label as the benchmark, not a general sense of “does this sound right.” That means breaking the label into checkable components — approved indications, boxed warnings, contraindications, the specific patient populations a drug is and isn’t indicated for — the same categories FDA itself weighs when it evaluates whether a promotional communication is misleading. Scoring an AI-generated answer against that structure, category by category, turns “this seems a little off” into a specific, defensible finding: which claim drifted, which safety statement was missing, which population got left out of the answer entirely.

The second component is coverage across platforms, not just one. ChatGPT, Gemini, Copilot, and Perplexity don’t answer the same question the same way, and the JMIR comparison discussed earlier in this piece found no statistically significant difference in how often any of them produced high-risk or inaccurate answers — meaning a monitoring workflow that checks one platform and calls it done is, at best, sampling a quarter of the actual exposure.

The third is cadence. A single audit is a photograph; what a compliance or medical affairs team actually needs is a trend line. Underlying models get updated on schedules companies don’t control and rarely announce in advance, and an answer that was accurate and balanced last quarter can shift after a model update with no warning. Tracking findings on a rolling basis — a 30-day composite view rather than a point-in-time check — is what turns monitoring into something that catches drift instead of confirming, repeatedly, that nothing looked wrong on the day someone happened to check.

Fourth: presence and position matter as much as accuracy. A drug that never comes up when a patient asks an AI system about its therapeutic category has a different problem than a drug that comes up constantly, sits behind three competitors, or shows up with a noticeably different sentiment than its rivals. This is the same logic behind traditional share-of-voice tracking, applied to a search surface that didn’t exist five years ago — worth watching not because it’s a compliance risk in itself, but because it’s the commercial mirror of the same exposure. DrugChatter’s own brand-visibility tooling, for instance, was built around exactly this pairing — label-alignment scoring sitting next to a presence-and-sentiment view of how a brand shows up against named competitors, tracked over time rather than as a single check. It’s telling that semaglutide brands are among the more common test cases for tools like this, given how much unmoderated conversation already exists about them.

The last piece is routing, and it’s the one most workflows skip. A finding that a chatbot is describing an off-label use accurately but without balance is a medical affairs and regulatory question. A finding that patients are reporting a symptom cluster not on the label is a pharmacovigilance question. A finding that a competitor’s drug is being described inaccurately is, carefully, a legal question before it’s anything else. Building the monitoring pipeline without deciding in advance who owns each type of finding just moves the “who’s responsible for this” argument from before the finding to after it — at exactly the moment a fast response actually matters.

Measuring Off-Label Share of Voice Across LLMs and Forums

“Share of voice” is a borrowed term, and the borrowing shows. In traditional media, it means a measurable slice of paid impressions — a number a media buyer can pull from an ad platform. Applied to AI-generated content, there’s no impressions dashboard to query. A company can’t ask ChatGPT for a report on how often it mentioned a competitor’s drug last month. The only way to measure presence is to go ask, repeatedly, with a defined and repeatable set of questions, across every platform that matters.

That distinction matters more given where marketing spend is actually headed. Social media’s share of pharmaceutical marketing has grown roughly 45% year-over-year, and by 2025 nearly half of pharmaceutical digital advertising budgets were going to social channels rather than traditional DTC placements (McGuireWoods, 2025) — on top of the $10.8 billion in direct-to-consumer ad spend FDA itself cited earlier this year (National Law Review, 2025). Brand teams have built entire measurement infrastructures around that spend: impressions, click-through, sentiment tracking, share of voice against named competitors. None of that infrastructure extends to AI-generated answers, because none of it was designed to. A company can have a mature, well-instrumented view of its paid social performance and a total blind spot on how the exact same drug gets described the moment someone asks an AI system about it instead of scrolling past a sponsored post.

The channels this piece has covered differ enough in control, identifiability, and existing oversight that treating them as one undifferentiated “digital risk” category obscures more than it explains:

ChannelCompany ControlReporter IdentifiabilityDocumented ScaleExisting Oversight Framework
Company-sponsored promotional materialsFullN/ASubject to FDA submission at first use21 CFR 202/314, OPDP review
Paid influencer/social postsPartial (contracted)Usually identifiableSubject of 2025 warning letters to Sprout, Merz, kaléoSame fair-balance rules as company ads
Patient forums (e.g., Reddit)NoneRarely identifiable410,198 posts on semaglutide/tirzepatide alone (Nature Health, 2026)None formal; treated as research data
AI chatbots (ChatGPT, Gemini, Copilot)NoneEffectively never identifiableNo significant accuracy gap found between major platforms (JMIR, 2025)No dedicated framework yet
Physician forums (e.g., Sermo, Doximity)NoneSemi-identifiable (verified prescribers)Not independently quantified in cited researchNone formal

Reading down that “oversight framework” column is the argument for building a measurement practice before a regulator or a plaintiff’s firm builds one first. The two channels with real oversight — company materials and paid influencer content — are also the two channels companies already have the most visibility into, because they paid for the content or wrote it themselves. The three channels with no formal oversight are exactly the three a company has to go looking for.

A workable share-of-voice methodology for AI platforms borrows the discipline of a media audit and applies it to a set of representative prompts instead of an ad account: the same core set of questions — the drug’s primary indication, its most likely off-label use, its main safety concerns, its top two or three competitors by name — run on a recurring schedule across every major platform, with results scored for presence, position relative to competitors, sentiment, and label alignment. Run once, it’s a data point. Run monthly against the same prompt set, it becomes the trend line that catches the moment a model update shifts how a drug gets described — usually well before a warning letter or a plaintiff’s filing tells the company the same thing the hard way.

What Medical Affairs, Legal, and Commercial Should Each Own

Every case study in this piece shares a second feature beyond the “company didn’t fully control the content” pattern: in each one, the finding eventually needed an owner, and figuring out who that was after the fact cost time nobody had. A functioning response to AI-driven off-label exposure requires deciding who owns what before the first finding shows up, not during the fifteen days FDA gives a company to respond to a warning letter.

FunctionWhat It OwnsTrigger
Medical AffairsResponding to accurate-but-unbalanced AI content through approved scientific-exchange channels; keeping SIUU-compliant materials currentAI answer is factually correct but missing required context or safety framing
Regulatory AffairsDetermining whether a finding constitutes a promotional communication requiring FDA submission; tracking evolving guidanceAI or influencer content resembles company-attributable promotion
Legal / ComplianceAssessing False Claims Act and Anti-Kickback exposure, especially any paid or contracted relationship with a platform or creatorAny commercial relationship exists between the company and the content’s source
Commercial / BrandShare-of-voice and competitive-position tracking across AI platforms; monitoring the patent and exclusivity landscape shaping generic substitution riskOngoing, independent of any single finding
PharmacovigilanceAggregate signal detection across forums and AI platforms; distinguishing pattern-level safety signals from unreportable individual mentionsRecurring symptom or complaint pattern emerges across sources

The commercial row deserves a word of its own, because it’s the one most likely to get treated as pure marketing analytics rather than something connected to the rest of this framework. Off-label demand doesn’t move in isolation from the competitive and patent landscape around a drug — a company watching how it’s discussed on AI platforms without also watching when a competitor’s exclusivity lapses, or when generic entry is likely to reshape the same conversation, is tracking half the picture. That’s the kind of cross-referencing a tool like DrugPatentWatch is built to support: patent and exclusivity data sitting next to the AI-visibility data commercial teams increasingly need to interpret it.

None of these five functions can do this work well in isolation, and that’s the structural reason so many of the warning letters in this piece look, in hindsight, avoidable. Sprout’s compliance team likely wasn’t monitoring its own CEO’s personal Instagram account. Merz’s marketing team had already received two advisory warnings from OPDP before the letter that made headlines. In both cases, the information needed to catch the problem early existed somewhere in the organization — the failure was routing, not knowledge.

The uncomfortable truth underneath all eleven sections of this piece is the one in its title. A revenue stream nobody at the company created — AI-driven awareness of an off-label use, a Reddit community that built itself around a drug’s unapproved benefits, an influencer post the company paid for but didn’t fully vet — carries the same regulatory weight as the promotional campaigns the industry has spent thirty years and tens of billions of dollars learning to manage. The demand doesn’t ask permission to exist. Whether a company finds out about it from its own monitoring or from a warning letter is still, for now, a choice.

Key Takeaways

  • Off-label promotion liability historically attached to company-controlled channels — sales reps, marketing materials, paid campaigns — and cost the industry billions of dollars in settlements. That same liability logic now extends to channels no one at the company operates, including AI chatbots and unmoderated patient forums.
  • FDA’s Final SIUU Guidance, effective January 6, 2025, only protects firm-initiated scientific communications sent directly to health care providers. It offers no equivalent protection for AI-generated content patients encounter directly, even when it draws on the same published literature.
  • FDA’s 2025 enforcement wave shows that even paid, disclosed, contractually reviewed influencer content — Sprout, Merz, and kaléo all had documented, controlled relationships with the person posting — still generated warning letters for missing risk information. Uncontrolled AI content represents a larger blind spot, not a smaller one.
  • Independent research comparing ChatGPT, Gemini, and Copilot found no statistically significant difference in accuracy or high-risk answer rates between them. There is no single “safer” AI platform to point patients toward instead.
  • The closest existing legal template for AI-related False Claims Act exposure is the 2020 Practice Fusion case, where DOJ penalized an EHR vendor for letting a pharmaceutical company help shape the clinical alerts shown to prescribers — a kickback theory, not a misbranding one.
  • US pharmacovigilance guidance currently limits monitoring obligations to company-sponsored sites, but the EU’s GVP Module VI already expects broader internet monitoring. Global PV teams are effectively already accountable to the stricter standard somewhere in their product portfolio.
  • A workable response combines label-alignment scoring, cross-platform share-of-voice tracking, and a pre-defined routing plan across medical affairs, regulatory, legal, commercial, and pharmacovigilance — built before a warning letter forces the question, not after.

Frequently Asked Questions

Can a pharmaceutical company be held liable for what an AI chatbot says about its drug?

Companies aren’t directly liable simply because a chatbot mentions an off-label use. Exposure grows if the company knew about the pattern and did nothing, or if it paid to shape the AI system’s output. The 2020 Practice Fusion case, where DOJ penalized a vendor for letting a drug company help design clinical alerts, is the closest existing legal template.

What does FDA’s SIUU guidance actually cover?

FDA’s Final SIUU Guidance, effective January 6, 2025, lets companies share scientifically sound published studies about unapproved drug uses directly with health care providers without it counting as evidence of promoting a new use. It covers firm-initiated communications to prescribers only, not AI-generated or patient-facing content.

Is off-label promotion illegal for pharmaceutical companies?

Physicians can legally prescribe an approved drug for any use they judge appropriate, including unapproved ones. Manufacturers cannot promote those unapproved uses. Doing so makes the drug “misbranded” under the FDCA and has produced some of the largest fraud settlements in U.S. history, including GSK’s $3 billion resolution in 2012.

Do pharmacovigilance teams have to monitor AI platforms for adverse events?

Current FDA guidance only requires companies to monitor internet sites they sponsor, not the wider internet. The EU’s GVP Module VI sets a broader standard, expecting marketing authorization holders to routinely monitor digital media generally. Global pharmacovigilance teams are effectively already held to the stricter standard somewhere in their portfolio.

Why did FDA warning letters for drug advertising increase in 2025?

FDA drug-advertising warning letters had fallen to one in 2023 and zero in 2024. In 2025, following a presidential memorandum and MAHA Commission report, FDA reversed course, issuing thousands of compliance letters and roughly 100 cease-and-desist letters, with a stated focus on social media and influencer promotion.

DrugChatter - Know what AI is saying about your drugs
Scroll to Top