Deploying AI in clinical research expands your attack surface in ways traditional GCP frameworks weren't built to handle. Healthcare breaches now cost an average of $9.77 million, the highest of any industry for 14 consecutive years, and trial data carries unique risks: it's irreplaceable, regulatory-consequential, and flows across sponsors, CROs, sites, labs, and vendors. AI-specific threats include data poisoning (as few as 100 tampered samples can compromise a model), adversarial attacks that fool diagnostic tools without detection, and model inversion that reconstructs patient-level data from outputs. ICH E6(R3), finalized by FDA in September 2025, now requires explicit audit trails showing who changed what, when, and why across all computerized systems. Adaptive models that shift behavior between validation cycles create a gap: 21 CFR Part 11 requires validated systems, but AI that learns continuously may change without triggering formal revalidation. FDA's January 2025 draft guidance recommends ongoing credibility assessment aligned with NIST AI RMF principles. Sites and sponsors must now define performance thresholds that trigger revalidation, secure multi-party data boundaries, and ensure every AI output feeding a regulatory submission has a complete, tamper-proof lineage.