There is a lot of rightful discussion about AI in pharmaceutical and medical device companies right now. Vendors selling generative tools as compliance solutions. User groups with good intentions, but limited time and understanding. Compliance teams blocking pilots that pose no real regulatory risk. An environment evolving at unprecedented speed, with a lot of uncertainty about how to apply and extend existing regulatory frameworks to new technology.

This section is for the work that happens in between.

I am in no way arguing that AI is harmless in regulated settings. It is not. Models drift. Outputs are non-deterministic. Training data is opaque. Validation strategies designed for deterministic software do not transfer cleanly to systems that produce different results from the same inputs. These are real problems. Pretending they are not is dishonest.

I am also not arguing that AI is special enough to require an entirely new regulatory framework. The principles in GAMP 5 SE, in the FDA’s predicate rules, and in the EU AI Act’s risk-based structure already cover most of what is needed. Industry guidance is evolving, e.g., in ISPE’s Digital Validation Good Practice Guide. The hard work is in applying those principles to the specific challenges of AI, and in identifying where the gaps are and how to fill them.

The pieces that will appear in this section are working through specific cases:

  • AI in pharmacovigilance signal management: what a validation approach looks like, and how it is complemented by continuous monitoring and human oversight
  • Generative tools as an element in document drafting: how it augments existing determinitstic tools, where the audit trail lives, and what GxP compliance requires in practice
  • Breaking down the black box, at process and model levels: what explainability means in practice, and how to get there
  • The EU AI Act in practice for Life Sciences — high-risk classification and what it changes

The thesis throughout: validated AI is method, not magic. The companies that adopt it well will be the ones that bring regulatory rigor to the AI side, not the ones that lower the rigor on the regulatory side to make AI fit.

More to follow.