Overview
You may already know where AI could improve a process in your organization. Turning that idea into a tool people can use in a GxP setting depends on how well the validation work is framed from the beginning.
FDA and EMA have now agreed broad principles for AI in medicine development, while detailed validation expectations for drugs, devices, and GMP manufacturing continue to take shape through draft guidance and consultation.
Across these different scopes, the same questions keep appearing: which decision will the tool influence, who remains accountable, what evidence supports its use, and who will manage change after approval.
This gives promising use cases a clearer route into practice, with defined responsibilities and evidence people can trust.
Start with the work that changes
Consider three uses of the same general technology. One system drafts an investigation summary, one ranks batches for further review, and one supplies evidence for a release decision. Each changes the work and the consequence of a wrong output.
First record how the current process reaches the decision: who decides, which evidence they use, where errors appear, and how uncertainty escalates. The proposed AI role can then sit beside a documented process.
Like any thorough research approach, a measurement becomes useful once the researcher defines its meaning, test conditions, and comparison baseline. An AI accuracy score carries the same requirement.
HTO working framework
From decision to lifecycle control
- 01DecisionName the regulated choice or work product.
- 02BoundaryDefine users, conditions, failures, models, data, and versions.
- 03EvidenceSet the tests and acceptance criteria for that use.
- 04ReviewName the accountable reviewer, escalation route, and fallback.
- 05MonitoringDefine performance signals and change or revalidation triggers.
The boundary determines what counts as evidence
Regulators call this boundary the context of use, meaning the specific role a model performs and the decision its output supports. FDA and EMA place it inside their January Good AI Practice principles. FDA's draft drug framework also connects the required credibility work to the consequence of a wrong decision.
FDA's 18 August discussion paper brings the same issue into GenAI-enabled medical devices through questions about risk, benchmarking, clinical confirmation, and postmarket monitoring. The paper remains open for comment through 19 October. Its questions show why a general claim that a model “works” gives validation too little to assess.
Researchers at Gilead Sciences tested AI for classifying particles in injectable medicines. The model performed better when its training images covered the particle types and appearances it could encounter. Missing examples led to more mistakes, especially for clear or faint particles.
Further studies must test performance across sites, instruments, and production conditions. A validation plan would need to cover those conditions before relying on the model in a regulated process.
Approval creates ongoing work
The proposed EU GMP Annex 22 turns intended use into a manufacturing control structure. Its draft covers training and test data, performance measures, validation, human review, monitoring, and change control. The consultation closed in October 2025, and the annex remains draft material.
The process owner defines the decision and baseline. The technical owner shows how the data and model support that use. The validation owner tests the consequential failures, and the quality unit approves the controlled route and its changes.
Responsibility continues after release. Suppliers can change model behavior, data can move, and users can extend a tool beyond its approved boundary. Monitoring and change control therefore belong in the original definition.
Keep each rule in its own scope
The current documents carry different legal weight. FDA's GenAI device paper is a consultation. FDA's drug framework and EU GMP Annex 22 are drafts. The FDA and EMA document provides joint principles. The FDA warning letter applies existing cGMP requirements in one case.
EU AI Act Article 50 adds a separate legal obligation. Its transparency duties became applicable on 2 August 2026 for covered AI interactions and generated or manipulated content. The same system may therefore require an AI Act transparency assessment and a GxP validation assessment. Each assessment answers its own question.
Four scopes, four different questions
Read the material and its legal status before selecting controls.
| Scope | Material | Status | Control question |
|---|---|---|---|
| Medical devices | FDA GenAI-enabled device discussion | Consultation | Risk, benchmarking, clinical confirmation, and postmarket monitoring |
| Medicines development | FDA–EMA principles and FDA drug framework | Principles + draft | Context of use, evidence credibility, and lifecycle practice |
| GMP manufacturing | Proposed EU GMP Annex 22 and existing FDA cGMP duties | Draft + existing duties | Manufacturing controls, technical review, approval, and change control |
| AI transparency | EU AI Act Article 50 | Applicable law | Disclosure for covered interactions and generated or manipulated content |
The practical starting point remains the same across these scopes. I would ask seven questions before anyone writes the validation plan:
- Name the work. Which decision or regulated work product can the AI influence?
- Name the owner. Who owns and approves the final decision?
- Define failure. What happens when the output is wrong, late, or unavailable?
- Set the boundary. Which users, products, processes, data, models, and versions define permitted use?
- Set the evidence standard. Which evidence demonstrates fitness for that use?
- Define change triggers. Which changes or performance signals trigger review or revalidation?
- Retain the trace. Which record must remain for an audit, deviation, or investigation?
Those answers support classification, requirements, evidence, procedures, and supplier discussions. They also expose a weak use case while its design can still change cheaply. That is the point where scientific caution becomes useful operational work.
Takeaways
- Decision
Define the AI-supported decision before selecting the validation method.
- Evidence
Match evidence to the users, process conditions, and failures inside the approved boundary.
- Scope
Keep medical-device, medicines, GMP, and general AI-law requirements separated by scope and legal status.
- Accountability
Name the human owner and retain evidence of review, approval, monitoring, and change.
- Lifecycle
Treat the decision definition as a lifecycle artifact that changes with the system and its use.
Bring the decision into the room
The Applied AI for Life Sciences community gives quality, regulatory, process, and technical practitioners a place to compare these decisions before an organization commits to a system design.
Notes and references
- U.S. Food and Drug Administration, GenAI-enabled medical-device discussion, 18 August 2026. FDA opened a consultation on possible risk, premarket-evidence, and postmarket-monitoring approaches.
- FDA and EMA, Guiding Principles of Good AI Practice in Drug Development, 14 January 2026.
- FDA, Considerations for the Use of AI To Support Regulatory Decision-Making for Drug and Biological Products, draft guidance, January 2025.
- European Commission consultation on revised Chapter 4, Annex 11, and proposed Annex 22, 2025.
- MHRA Inspectorate, Use of AI for GxP inspection responses, 29 June 2026. This records current inspectorate thinking and is not formal guidance.
- FDA Warning Letter 320-26-58, 2 April 2026. The letter applies existing cGMP review and quality-unit responsibilities in one enforcement case with wider deficiencies.
- European Commission, Guidelines on AI Act Article 50 transparency obligations, 20 July 2026.
- Mohan et al., Developing machine learning models with pharmaceutically relevant microscopy images, International Journal of Pharmaceutics, August 2026. The article uses only claims available in the published abstract.


