An order has not been fulfilled. A supplier proposes a substitute, but it is unclear whether the product meets the contractual requirements. Another wholesaler declares that the medicine is available without confirming a delivery date.
In these situations, the problem is not limited to medicine availability. Communication itself becomes fragmented across inboxes, phone calls, documents and the knowledge of individual employees.
The Pharma Flow project will investigate how artificial intelligence can help organise this process. The objective is not simply to write messages more quickly. It is to move from disconnected correspondence to a workflow that can be monitored, measured, audited and safely transferred between employees.
For a broader introduction to the project and the use of AI in medication management, read Before a Medicine Runs Out: How We Plan to Use AI in Hospital Medicines Management.
Communication begins with the contract and the order
A hospital pharmacy works with multiple suppliers, and every delivery forms part of a wider process involving:
- the contract and its conditions;
- a specific order;
- confirmation of availability;
- the required quantity;
- price;
- delivery time and location;
- a possible substitute;
- explanatory correspondence;
- receipt and settlement documents.
When everything proceeds as expected, supplier communication may appear to be a routine administrative activity. The situation changes when a contractor reports that a product is unavailable, delivers only part of an order, proposes an alternative medicine or fails to respond on time.
Pharmacy staff must then establish:
- what the contract requires;
- whether a discrepancy needs to be investigated;
- whether the proposed substitute may be accepted;
- how urgent it is to replenish the stock;
- which alternative suppliers may be contacted;
- how differently formatted replies should be compared;
- which procurement procedure may lawfully be used;
- who must authorise the next step.
A large proportion of this work is currently performed manually. Pharma Flow will investigate which elements can be safely assigned to an intelligent agent and which must remain under human control.
An inbox is not a process-management system
Email is convenient and widely used, but it does not create a structured process by itself.
Information concerning one order may be distributed across several threads. A reply may reach an employee who is no longer on duty. A supplier may state the delivery time in the message, include the price in an attachment and provide information about partial availability by telephone.
Suppliers also respond in different ways. One may say that a product is “immediately available”, another may specify the number of packs and a third may propose an equivalent without clearly describing all relevant parameters.
As a result, a pharmacist must do more than communicate with suppliers. Staff also need to:
- monitor deadlines;
- connect messages to the correct contract and order;
- extract the most important information;
- compare replies expressed in different formats;
- request missing data;
- document the basis for a decision;
- transfer the case to another employee without losing context.
Automation should therefore do more than increase the number of emails sent. Its purpose should be to convert correspondence into a controlled, measurable and auditable workflow.
From detecting a problem to preparing a message
The planned Pharma Flow concept connects communication with other medicines-management processes. A workflow may be triggered by:
- missing order confirmation;
- an approaching or exceeded delivery deadline;
- partial fulfilment;
- an unavailability notice;
- a proposed substitute;
- a discrepancy between a contract price and a delivery document;
- a projected fall below a defined stock level;
- the absence of a valid contract covering the required product.
The agent should not begin by generating an arbitrary message. It first needs to reconstruct the context: the medicine, order, supplier, relevant contractual provisions, required deadline and previous communication.
It may then prepare the appropriate draft, for example:
- a request to confirm the delivery date;
- an enquiry concerning the missing quantity;
- a request to explain a delay;
- a request for the parameters of a proposed substitute;
- an availability enquiry to alternative suppliers;
- a request to complete an incomplete quotation.
The Pharma Flow funding application describes R&D into natural-language processing methods for contract analysis, correspondence generation and standard supplier interactions. The planned solution will also investigate the collection of quotations in intervention scenarios and their presentation to pharmacy staff. These are research and development objectives, not capabilities of an existing finished product.
A possible workflow
Suppose a pharmacy orders a medicine under an existing contract. The supplier has not provided the required confirmation and the delivery deadline is approaching.
The planned agent could:
- detect the missing confirmation;
- identify the order and related contract;
- determine the relevant deadline;
- draft a delivery-confirmation request;
- submit the draft for approval or — in a predefined low-risk scenario — send a routine technical reminder;
- monitor the reply;
- extract the declared quantity and delivery date;
- classify the response as complete, incomplete or ambiguous;
- record the full sequence of events.
If the supplier cannot fulfil the order, the system could propose another preconfigured workflow:
- identify suppliers authorised for contact;
- prepare a standardised availability request;
- send it after approval;
- collect replies;
- extract prices, quantities and delivery times;
- flag incomplete or ambiguous offers;
- provide staff with a structured comparison.
A qualified professional would decide whether an offer could be accepted and which procurement procedure was appropriate.
A standard question produces a more comparable answer
One of the most important benefits of automation may be communication standardisation.
A system-generated enquiry should clearly define:
- the product or acceptable range of equivalents;
- pharmaceutical form, strength and pack size;
- required quantity;
- required delivery time;
- delivery location;
- response deadline;
- information required in the offer;
- a case identifier for automatic response matching.
The agent does not merely send a message. It establishes the structure against which the response can later be assessed.
If a supplier omits the delivery time, the system may prepare a clarification request. If it provides a price but no available quantity, the response can be marked as incomplete. If another product is offered, the case can be transferred to a separate substitute-verification workflow.
NLP must interpret meaning, not merely find words
A simple mechanism can detect words such as “available”, “unavailable” or “substitute”. This is not enough.
Consider three replies:
The product is available.
Twenty packs are available and can be dispatched within two working days.
The product is temporarily unavailable. We can offer a different pack if you confirm before 12:00.
All concern availability, but their operational meaning is very different.
The model should attempt to determine:
- which product the response concerns;
- the available quantity;
- whether the price is net or gross;
- the delivery time;
- how long the quotation remains valid;
- whether the product matches the enquiry;
- whether additional conditions apply;
- which information is still missing.
NIST identifies false, unsupported or deceptively plausible output among the risks of generative AI and recommends governance, documentation, testing and human oversight.[2]
Pharma Flow should therefore never infer a missing price, quantity or date. Missing information must remain missing and ambiguous content must be referred for clarification.
Automation does not select the legal procurement basis
Emergency or single-source procurement requires particular caution.
A hospital’s urgent need for a medicine does not automatically permit a non-competitive procedure. Guidance published by Poland’s Public Procurement Office states that use of Article 214(1)(5) of the Public Procurement Law depends on cumulative statutory conditions. The event must be exceptional, not caused by the contracting authority, unforeseeable and so urgent that the deadlines of other procedures cannot be observed.[1]
An agent may therefore:
- assemble information about the need;
- identify non-performance by a contracted supplier;
- prepare a chronology;
- gather availability information;
- organise possible offers;
- produce working material or a draft document.
It should not independently determine that the conditions for a legal procedure have been met or authorise a purchase on behalf of the responsible person.
AI can prepare the evidence for a decision. It cannot assume legal responsibility for that decision.
Human approval at consequential points
Not every message necessarily requires manual approval. A technical receipt confirmation or routine deadline reminder may be sent automatically if the organisation has previously approved a precisely defined scenario.
Human approval is more important when a message:
- alleges a contractual breach;
- interprets contract provisions;
- initiates negotiations;
- accepts a substitute;
- confirms supplier selection;
- creates a financial commitment;
- places an order;
- changes delivery conditions.
In these cases, a human-in-the-loop model is appropriate: the agent prepares the draft, organises the data and identifies possible action, while an authorised person approves, corrects or rejects it.
The EU AI Act introduces obligations that depend on the system’s use and risk classification. Official Commission materials emphasise transparency, logging, human oversight, accuracy, robustness and cybersecurity.[3][4] The precise obligations for Pharma Flow will depend on its final architecture and a legal assessment of each use case.
The design should also provide clear information to suppliers when they interact directly with an AI agent. The form and scope of that information require a separate legal assessment.
Every message should leave an audit trail
In a process involving medicines, contracts and financial commitments, it is not enough to know the supplier’s latest answer.
The organisation needs a record showing:
- which event triggered the communication;
- which contract was used;
- which data were made available to the agent;
- which message it prepared;
- who approved it;
- when it was sent;
- which response was received;
- which facts were extracted;
- what the user corrected;
- who approved the next action.
This record supports internal control, audit, complaints handling, security and model-quality assessment.
It also explains the basis for a recommendation. The cheapest quotation is not necessarily the best when it cannot provide the required quantity or delivery time. The agent should show comparison criteria rather than merely presenting a winning supplier.
An automated mailbox becomes security-sensitive infrastructure
An agent that reads external correspondence and can prepare messages or initiate procurement workflows requires strong safeguards.
ENISA emphasises cyber hygiene and resilience across healthcare organisations.[5] NIST’s generative-AI profile also addresses information-integrity risks, unreliable output and use outside the intended operational boundaries.[2]
External messages and attachments may contain content intended to influence the model, such as instructions to ignore rules, disclose information or send data to another address.
The architecture should therefore include:
- treatment of all external correspondence as untrusted;
- separation of message content from system instructions;
- a strictly limited list of permitted actions;
- verification of senders, domains and recipients;
- attachment scanning and isolation;
- no autonomous change of bank details, delivery locations or recipients;
- separate permissions for drafting, sending and approving an order;
- message and transaction limits;
- activity logging without exposing secrets;
- an immediate automation stop mechanism;
- a safe manual mode for failures.
The safest agent should not have unrestricted access to every mailbox, contract and purchasing function.
Email may be the beginning, but it should not be the end
Email can reach suppliers that provide no API or integration platform. It may therefore be a practical initial channel.
Over time, some communication may move to more structured mechanisms:
- supplier forms;
- contractor portals;
- EDI messages;
- APIs;
- structured confirmations;
- electronic invoices and delivery documents.
European public procurement uses mechanisms such as eForms, TED and eInvoicing. Their shared value lies in greater structure and improved machine processing of information.[6]
Pharma Flow can follow a similar principle: an email may remain the source, but its contents are converted into a structured business event.
From local correspondence to an availability picture
Communication automation may also generate data about repeated patterns:
- suppliers that frequently deliver late;
- products regularly reported as unavailable;
- common reasons for non-fulfilment;
- average response time;
- frequency of proposed substitutes;
- differences in price and delivery time;
- seasonal changes in availability.
At European level, the European Medicines Agency uses the European Shortages Monitoring Platform to collect availability, supply and demand information in support of shortage prevention, detection and management.[7]
Pharma Flow is not intended to replace regulatory systems. It may, however, help a hospital use its own operational data more effectively and identify when isolated incidents begin to form a pattern.
Measuring useful automation
The number of automatically generated messages is not a meaningful measure of success. A system could send hundreds of emails while increasing operational chaos.
More useful indicators include:
- time from problem detection to first contact;
- time required to obtain a complete response;
- percentage of drafts corrected by staff;
- accuracy of matching replies to cases;
- accuracy of price, quantity and delivery-date extraction;
- missing data detected automatically;
- unnecessary enquiries;
- time required to prepare a comparison;
- recommendations accepted by professionals;
- security incidents and attempts to manipulate the agent;
- staff time before and after implementation.
The Pharma Flow application defines automation of at least 80% of specified intervention-order activities as a target. This is a research objective that still requires precise definition and validation, not a result achieved by an operating system.
The objective is not to write more messages
The key value of an intelligent agent will not be the ability to generate professionally worded emails. That function is relatively easy to demonstrate.
The more difficult task is to create a system that:
- understands why communication is required;
- knows the contract and order context;
- interprets ambiguous replies;
- recognises missing information;
- respects its authorisation limits;
- preserves a complete activity history;
- transfers the decision to a human at the correct moment.
This is the problem that Pharma Flow will investigate.
We are at the beginning of the journey. We do not yet know how much supplier correspondence will prove sufficiently repetitive for safe automation, how suppliers will respond or how many human interventions will remain necessary.
The future should not be an inbox in which every problem must be reconstructed from a dozen disconnected messages.
It may be a process in which technology organises information, monitors the next steps and prepares possible actions, while pharmacists retain professional knowledge, control and accountability for the final decision.
About the project
- Communication name: Pharma Flow
- Project number: FENG.01.01-IP.02-0638/25
- Official title: “Development of the Pharma Flow intelligent agent using artificial intelligence and federated machine learning to optimise medicines management and take over routine, time-consuming tasks performed by hospital pharmacy staff”
- Beneficiary: Infotower Business Solutions sp. z o.o.
- Project period: 1 March 2026 – 29 February 2028
- Planned implementation period for the results: 1 March 2028 – 31 August 2028
- Total project value: PLN 22,137,373.39
- Funding: PLN 16,146,083.00
- Programme: European Funds for a Modern Economy — SMART Path
- Current stage: early implementation of research and development work
The project is co-funded by the European Union.
Sources and further reading
- Poland’s Public Procurement Office, guidance on Article 214(1)(5) and urgent medicine procurement: gov.pl
- NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile”, NIST AI 600-1: nist.gov
- European Commission, “AI Act”: digital-strategy.ec.europa.eu
- European Commission, “Understanding the standardisation of the AI Act”: digital-strategy.ec.europa.eu
- ENISA, “A good practice guide for a robust and resilient EU health sector”: enisa.europa.eu
- European Commission, “Digital procurement”: single-market-economy.ec.europa.eu
- European Medicines Agency, “European Shortages Monitoring Platform”: European Medicines Agency
- Pharma Flow funding application, FENG.01.01-IP.02-0638/25 — internal source for objectives, timetable, budget and planned features.
This article describes the objectives and hypotheses of an R&D project at an early stage of implementation. Planned features and indicators are not achieved results of a finished product. The article does not constitute legal, procurement or medical advice.