Written and maintained by CASRAI Editorial Board
Last updated
Last verified: September 20, 2026. The Common Rule body that is supposed to tell IRBs how to weigh AI-specific risk against benefit has never issued that guidance — and the paper trail showing why is not speculation, it is five of OHRP’s own Federal Register notices. The Secretary’s Advisory Committee on Human Research Protections (SACHRP), OHRP’s statutory advisory body, began studying AI’s effect on IRB risk-benefit review in mid-2021, developed draft recommendations across three subsequent meetings, and had formally approved them by fall 2022. As of this writing, four years after that work began, no public OHRP guidance document has followed. IRBs evaluating AI-touching protocols today are doing so without the regulator-level guidance OHRP’s own advisory committee told it, in writing, was needed.
What SACHRP Is, and Why Its Meeting Notices Are a Verifiable Record
SACHRP is not an outside critic. It is the federal advisory committee Congress and HHS built specifically to advise OHRP — the HHS office that administers the Common Rule (45 CFR 46) and oversees Institutional Review Boards nationally. Under the Federal Advisory Committee Act (FACA), every SACHRP meeting requires a public notice in the Federal Register, and those notices routinely state the meeting’s agenda topics in the notice text itself. That makes SACHRP’s own institutional history on any given topic unusually easy to verify independently of any single participant’s account: the Federal Register is a primary government record, not a press release or a secondhand summary, and each notice below is independently checkable at its own permanent URL.
The Federal Register Paper Trail: 2021 to 2022
Five SACHRP meeting notices, read in sequence, document a clear progression from “the committee is looking into this” to “the committee has approved recommendations on this.” Every document number below resolves at federalregister.gov/d/<number>.
| Federal Register Document | Notice / Meeting Dates | Agenda Language (quoted from the notice) |
|---|---|---|
| 2021-13362 | Published June 24, 2021; meeting July 21-22, 2021 | “Expert panel discussion on the impact of artificial intelligence algorithms on Institutional Review Board considerations for human subjects protections” |
| 2021-22351 | Published October 14, 2021; meeting October 26-27, 2021 | “Discussion of draft recommendations on ethical and regulatory considerations for the use of artificial intelligence in human subjects research” |
| 2022-03370 | Published February 16, 2022; meeting March 10-11, 2022 | “Discussion of new draft recommendations on ethical and regulatory considerations for the use of artificial intelligence in human subjects research” |
| 2022-14102 | Published July 1, 2022; meeting July 20-21, 2022 | “Final review of draft recommendations on the ethical and regulatory considerations for the use of artificial intelligence in human subjects research” |
| 2022-21163 | Published September 29, 2022; meeting October 19-20, 2022 | “Review and potential amendment of previously approved SACHRP recommendations on the ethical and regulatory considerations for the use of artificial intelligence in human subjects research” |
Read as a sequence, the language itself tracks the committee’s own progress: “draft recommendations” (October 2021) becomes “new draft recommendations” (March 2022), then “final review of draft recommendations” (July 2022). By the time of the September 2022 notice, the recommendations are no longer described as draft at all — they are “previously approved SACHRP recommendations,” with the October 2022 meeting agenda covering their potential amendment, not their adoption. That phrase is the load-bearing evidence here: a federal advisory committee does not describe its own prior work as “previously approved” unless a vote or formal sign-off actually happened, and the only body positioned to make that determination about SACHRP’s own recommendations is SACHRP’s own Federal Register notice.
Atomic Facts
- Committee: Secretary’s Advisory Committee on Human Research Protections (SACHRP), a Federal Advisory Committee Act body that advises OHRP.
- Start of AI-specific work: July 2021 meeting, per Federal Register notice 2021-13362 (published June 24, 2021).
- Draft recommendations first discussed: October 2021 meeting, per notice 2021-22351.
- Revised draft discussed: March 2022 meeting, per notice 2022-03370.
- Final review of the draft: July 2022 meeting, per notice 2022-14102.
- Recommendations confirmed as approved: By the September 29, 2022 notice (2022-21163), which refers to them as “previously approved” — meaning approval occurred between the July 2022 final-review meeting and the September 2022 notice, at the latest.
- Public OHRP guidance document responding to these recommendations, identified as of September 2026: None found. No Federal Register search for OHRP guidance, rules, or notices referencing these SACHRP AI recommendations returned a responsive guidance document (searched via the Federal Register’s own document API, agency-filtered to HHS, through September 2026).
- Time elapsed since approval: Approximately four years, as of September 2026.
What We Did Not Verify, and Why
This guide deliberately does not describe the content, title, or specific recommendations inside SACHRP’s AI document itself. hhs.gov/ohrp, where SACHRP posts its recommendation letters and where OHRP would post any resulting guidance, returned an HTTP 403 on every access attempt for this guide — site-wide, not on one page — so we could not read the recommendations document directly, confirm its exact title, or rule out that OHRP has posted something to that domain that simply is not indexed or mirrored anywhere we could reach. What we can verify, independently of hhs.gov, is the Federal Register record above: that SACHRP’s own notices describe the recommendations as approved by fall 2022, and that no subsequent Federal Register document — the channel OHRP would normally use for a formal guidance notice or rule — shows OHRP acting on them. That is a narrower and more defensible claim than “OHRP has done nothing,” and it is the one this guide makes: no publicly identified OHRP guidance document has followed, in the channel where such a document would normally appear, as of September 2026. If OHRP has published guidance directly to its own website without a Federal Register notice, this guide’s sourcing would not catch it, and we are saying so rather than papering over the gap.
Why the Source Matters More Than a Generic “No Guidance Exists” Claim
It would be easy to write a version of this piece that just asserts “OHRP hasn’t issued AI guidance for IRBs,” sourced to nothing in particular. That claim is weaker than what the record actually supports. The stronger, more credible version is this: OHRP’s own statutory advisory committee flagged this gap first. SACHRP is not an outside advocacy group or a journalist’s anonymous source — it is the body HHS built to advise OHRP, and its own Federal Register notices show it treating AI’s effect on IRB risk-benefit review as a priority worth four consecutive meetings, then approving formal recommendations, all in the space of about fourteen months (July 2021 to fall 2022). The four-year silence that has followed is not an inference about what OHRP should have done; it is the absence of a formal response to work OHRP’s own committee already finished and handed over.
What This Means for IRBs Right Now
An IRB conducting risk-benefit review under 45 CFR 46.111 on a protocol that uses an AI system — as a study intervention, a data-analysis tool, or a recruitment or eligibility-screening mechanism — has the general Common Rule risk-benefit framework to apply, but not the AI-specific interpretive guidance that SACHRP’s own recommendations were meant to provide. In practice, that means individual IRBs and institutions are each making their own judgment calls about how AI-specific risks (algorithmic bias in eligibility screening, model behavior drift, black-box decision processes affecting subject risk) map onto the Common Rule’s existing risk-benefit language, with no OHRP interpretation to align against and no indication of when one might arrive. That is the gap this guide’s title describes: IRBs are, at least for now, on their own.
NIKOLAI: A Structured Vocabulary for the Gap, Not a Substitute for OHRP Guidance
CASRAI’s own NIKOLAI project — an independent, unendorsed reference dictionary of 64 elements across ten tracks (N1-N10) describing frontier-AI-safety practice — is not a regulatory body and makes no claim to fill the role OHRP has not yet filled. It is offered here as exactly what it is: a structured vocabulary an IRB or research-ethics office could use internally, while formal OHRP guidance remains unactioned, to describe what an AI-touching protocol is actually claiming about its own risk.
The relevant element, verified directly against its live page for this guide, is Residual Risk and Risk Acceptance Determination, on NIKOLAI’s N4 track (Claims and argument). Its current definition: “NIKOLAI proposes Residual Risk Determination as a record of the assessed risk remaining after mitigations have been applied, paired with the recorded decision (and decision-maker) that this residual risk is acceptable for a stated scope — further development, internal deployment, or external deployment.” Structurally, that is close to what an IRB does under 45 CFR 46.111 when it determines that risks to subjects are minimized and reasonable in relation to anticipated benefits: both processes require a documented determination, tied to a named accountable party, that residual risk clears an acceptability bar for a defined scope. The element’s own crosswalk table currently lists ten organizations mapped against it, every one labeled a shadow mapping — CASRAI’s own reading of published documents, not a mapping any of these organizations has reviewed or endorsed:
| Organization | Quoted Language | Match / Confidence |
|---|---|---|
| OpenAI | “If residual risks associated with the model exceed acceptable risk levels, the model is not deployed unless additional mitigation measures are implemented” (FGF §2.5) | Exact / High |
| Google DeepMind | “Residual Risk Assessments: the process of evaluating the level of risk that remains after all planned mitigation strategies have been implemented” | Exact / High |
| Meta | “Residual risk: describes the level of risk that a Frontier AI model presents after mitigations have been implemented” | Exact / High |
| Anthropic | “AAF risk report must include an assessment of residual risk that remains after accounting for the safety mitigations” (p.6) | Close / High |
| California SB 53 | “Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model” (22757.12(a)) | Close / High |
It bears repeating plainly, in this element’s own terms: NIKOLAI is CASRAI’s own project, and nothing about the Residual Risk and Risk Acceptance Determination element is an official OHRP interpretation, an IRB requirement, or an endorsed standard. No IRB, accreditor, or the organizations in the crosswalk table above has adopted it for human-subjects review. What it offers, honestly described, is a documented, independent, unendorsed structure for the same kind of question OHRP’s own advisory committee has been examining since 2021 — and that structure is available today, while formal guidance is not.
Frequently Asked Questions
Did SACHRP actually approve AI recommendations, or just discuss them?
SACHRP’s own September 29, 2022 Federal Register notice (2022-21163) refers to “previously approved SACHRP recommendations on the ethical and regulatory considerations for the use of artificial intelligence in human subjects research,” placed on the agenda for “review and potential amendment.” A federal advisory committee describing its own prior work as “previously approved” is, on its face, evidence that a formal approval occurred — most plausibly at or shortly after the July 2022 “final review” meeting documented in notice 2022-14102.
Has OHRP issued guidance on AI in human subjects research since 2022?
No OHRP guidance document responding to these recommendations was identified in the Federal Register as of September 2026. hhs.gov/ohrp, where OHRP would most likely post standalone guidance outside the Federal Register process, returned an HTTP 403 for every access attempt made in researching this guide, so a guidance document posted there without any Federal Register notice cannot be fully ruled out from this sourcing alone.
What should an IRB do in the meantime?
This guide does not offer that as regulatory advice — OHRP is the authoritative source for how 45 CFR 46 risk-benefit review should treat AI-specific risk, and no such interpretation has been published. IRBs are applying the existing Common Rule framework using their own institutional judgment until OHRP guidance, if any, follows. CASRAI’s NIKOLAI project offers an independent, unendorsed structured vocabulary (see above) that some institutions may find useful for internally documenting AI-specific risk-acceptance reasoning, but it is not a substitute for regulatory guidance and is not presented as one.
Is NIKOLAI an official OHRP or federal framework?
No. NIKOLAI is CASRAI’s own independent, unendorsed reference dictionary. It has no relationship to OHRP, SACHRP, or any federal agency, and none of the organizations in its crosswalk tables have reviewed or endorsed how NIKOLAI classifies their published material unless they have filed their own Mapping Declaration.
Related Reading
- What Is an Institutional Review Board (IRB)?
- Risk-Benefit Analysis (dictionary term)
- The Common Rule (45 CFR 46)
- NIKOLAI: Residual Risk and Risk Acceptance Determination (element page)
- NIKOLAI N4 — Claims and Argument
- What Is NIKOLAI? CASRAI’s Frontier-AI-Safety Dictionary Explained
- NIKOLAI’s Track System: A Map of the Frontier AI Safety Landscape (N1-N10)
- AI Risk Assessment Framework and Risk Register: A Practical Starting Point
- Safety Cases: The Missing Methodology in Frontier AI Governance
- Frontier AI Safety Timeline: 2023-2026







