What Protects Pharma's Data When It Partners With an AI Company
- 5 days ago
- 3 min read
Behind every billion-dollar AI partnership sits a promise that pharma's data stays private. Every layer enforcing that promise, from encryption to blockchain, still depends on a person getting it right.
Prepared by Richstorm.co

Key Takeaways
Pharma's AI partnerships split into three types — hardware and infrastructure, general AI platforms, and AI-native discovery specialists — each solving a different layer of the problem.
Enterprise AI deals promise data ownership and no-training guarantees, enforced through a private training copy, automatic forgetting after each use, a separate locked-off space per customer, and pharma holding its own encryption key.
Real-world AI security failures trace overwhelmingly to misconfiguration and stolen credentials, not broken cryptography.
Blockchain-based audit trails make tampering provable after the fact; they do not prevent unauthorized access in the first place.
The same divide shows up everywhere: published research gets leveled by AI, but pharma's own private archives — failed trials, manufacturing know-how — keep compounding for whoever already holds them.
One Technology, Three Kinds of Partners
Pharma's AI dealmaking reads like one trend. It is really three separate relationships, each solving a different problem, often bundled under the same headline.
Table: Three distinct AI-pharma relationship types and representative 2025-2026 deals.
A company can buy the factory, rent the general intelligence, and hire the specialist scientist all at once — and increasingly does.
The Promise Behind Every Deal
Merck stated publicly that it "retains full ownership and control" of its data under its Google Cloud partnership, with all AI applications running in governed environments. Novo Nordisk's OpenAI deal carries the same structure. That promise rests on six specific technical layers, not just a press release.
Table: Six layers behind enterprise AI's data-privacy promise, in plain terms.
Of everything in that table, who holds the key matters most.
When pharma keeps the lock's key itself, a breach on the AI company's side mostly can't reach the data — the AI company never had the ability to unlock it, breach or not. That is a real, meaningful reduction in risk, not a technicality. It just doesn't answer everything: the AI still needs to actually read the data to do its job, and someone still has to manage that key on pharma's own side. Both of those are covered next.
Where It Actually Breaks
None of these failures involve anyone actually cracking a lock. They involve a person, on one side or the other, getting something wrong.
Table: The three most common ways enterprise AI's data protections actually fail in practice.
The contract and the audit exist because the architecture alone can't be verified from outside — they compensate for the same human dependency they can't remove.
Where Blockchain Fits, and Where It Doesn't
Pharma has begun applying blockchain to its own compliance problem, anchoring audit trails so a modified data record can't quietly be edited later, building on the same approach already used in pharma supply-chain tracking.
Blockchain narrows the trust problem to fewer, more accountable people. It doesn't remove people from the loop.
The Same Divide Shows Up in the Moat
This isn't only a security story. The same public-versus-proprietary split shows up inside drug discovery itself, not just between discovery and manufacturing. Published literature and patents are genuinely public, which is why small AI-native teams can compete with giants there. But an estimated 85-95% of preclinical failures never get published at all — they sit locked in each company's own archive of terminated programs and failed experiments. A large, established pharma company can train its AI on decades of that failure history. A new entrant working from public data alone cannot.
Table: What's shared gets leveled by AI; what stays locked in one company's archive keeps compounding.
The same rule shows up everywhere in this piece: data that's shared publicly gets leveled out by AI, and data that stays locked inside one company's walls keeps compounding for whoever holds it — whether that's an AI vendor holding pharma's data, or pharma holding its own decades of failed experiments and manufacturing know-how.
Bottom Line
A companion piece on RichStorm covers why AI can out-invent Big Pharma but still can't out-build it, the manufacturing side of this same divide in full.