Artificial intelligence was no longer treated as a peripheral technology topic at the 2026 PDA/FDA Joint Regulatory Conference.
The conference, held in Washington, D.C. from 14 to 16 September 2026, included dedicated discussions on AI in regulatory oversight, inspection readiness, manufacturing data and validation of digital tools in a CGMP environment.
One message stands out:
AI does not remove existing CGMP responsibilities. The level of validation and control should reflect how the AI is actually used and the impact of its output.
The official PDA/FDA programme explicitly states that appropriate controls, human oversight and validation remain foundational requirements when digital tools are introduced into CGMP processes.
This is an important direction for pharmaceutical companies because it moves the discussion beyond the simplistic question:
“Does every AI tool require the same validation?”
towards:
“What evidence and controls are necessary for this particular AI use case?”
AI-Ready Manufacturing Starts with AI-Ready Data
One session, Advancing Digital Tools and Data Utilization in a CGMP Environment, brought together FDA and industry representatives.
Sanofi presented a practical framework for assessing whether manufacturing data are sufficiently mature to support advanced analytics and AI.
The concept evaluates not only which data exist, but also how those data are made available.
Relevant considerations include:
- coverage of critical quality attributes;
- process and yield data;
- batch and sensor information;
- equipment and material genealogy;
- derived process values;
- data freshness;
- accessibility;
- authenticity;
- standardisation;
- structure.
This is an important point for AI implementation.
An organisation may have very large quantities of manufacturing data without actually having data that are suitable for regulated AI use.
AI readiness therefore cannot be measured simply by:
How much data do we have?
A more relevant question is:
Are the data complete, contextualised, reliable, accessible and sufficiently controlled to support the intended AI decision?
CGMP Principles Still Apply
FDA participation in the session focused on the relationship between digital transformation and established pharmaceutical quality requirements.
The underlying message was not that AI requires abandonment of traditional CGMP principles.
Quite the opposite.
AI-enabled processes still need to operate within established expectations relating to:
- Quality Unit oversight;
- data integrity;
- documented procedures;
- validation;
- record governance;
- Quality Risk Management;
- appropriate human control.
This reinforces an important principle for pharmaceutical AI:
The technology may be new, but accountability remains within the Pharmaceutical Quality System.
An algorithm cannot assume responsibility that CGMP assigns to the Quality Unit, system owner, process owner or qualified personnel.
A Risk-Proportionate Validation Model Is Emerging
One of the most interesting discussions concerned the level of validation appropriate for different digital and AI applications.
Conference reporting described a distinction between tools that contribute directly to final regulated decisions and tools used primarily for investigation, exploration or information support.
This suggests a potentially useful continuum.
Higher-impact application
AI directly influences or supports a final GxP decision.
Examples might include:
- product-quality decisions;
- critical process decisions;
- batch disposition support;
- critical specification or release assessments.
Such uses may require extensive CGMP validation and strong evidence demonstrating fitness for intended use.
Lower-impact or exploratory application
AI helps users investigate information or identify possible signals while a qualified person independently evaluates the evidence.
Examples might include:
- investigation support;
- regulatory intelligence;
- trend identification;
- searching quality records;
- exploring historical inspection findings.
For these applications, a different level of evidence may be appropriate, provided that the use is clearly bounded and the output cannot bypass the responsible human decision-maker.
The important point is not that lower-risk AI requires “no validation”.
Rather:
The depth of assurance should be proportionate to intended use, GxP impact and the consequence of an incorrect output.
This Is Different from a One-Size-Fits-All AI Validation SOP
Pharmaceutical companies may be tempted to create one standard validation package for every AI application.
The conference discussion suggests that this could be unnecessarily rigid.
AI applications can perform fundamentally different functions.
Compare:
- AI that searches historical deviations;
- AI that drafts an investigation summary;
- AI that recommends a possible root cause;
- AI that predicts a critical process parameter;
- AI that influences a final batch disposition decision.
Calling all of these simply “AI systems” hides important differences in risk.
A more mature approach could therefore start with:
Intended Use → GxP Impact → Decision Impact → Failure Consequence → Required Assurance
Only after those questions are answered should the validation strategy be defined.
Inspection-Ready AI Regulatory Intelligence
A separate conference session provided an interesting practical example.
Eli Lilly described an AI-supported regulatory intelligence system connecting information that historically sits in different quality repositories, including:
- regulatory inspection findings;
- internal audit observations;
- deviation information;
- responses to observations;
- after-action reviews.
The architecture combines retrieval-augmented generation for unstructured documents with structured-data exploration.
The objective is not simply to ask a chatbot a compliance question.
It is to allow users to trace quality signals across:
time → site → health authority → observation → response → organisational learning
while retaining connection to the underlying evidence.
This represents a potentially important model for pharmaceutical Quality Systems.
AI may provide the greatest value not by replacing Quality experts, but by connecting information that humans currently review in isolated systems.
Source Grounding Becomes a Critical Control
For regulatory or compliance applications, an AI answer is only useful when the user can determine where it came from.
This makes source grounding particularly important.
A useful architecture may therefore require:
- controlled source repositories;
- retrieval of relevant source documents;
- citations linked to the generated answer;
- traceability to the original record;
- defined document versions;
- human verification of the cited evidence.
This can substantially change the validation question.
Instead of asking only:
“Is the generated answer correct?”
the organisation can also ask:
“Can the user reconstruct the evidence on which the answer was based?”
For GMP applications, that second question may be equally important.
Hallucination Risk Does Not Disappear with Better Models
The conference discussion also highlighted the continuing risk of hallucination and model variability.
General-purpose AI models can differ substantially in their behaviour, and performance can deteriorate depending on question framing, context length and the information supplied to the model.
For pharmaceutical compliance use, this means that selecting a more powerful model does not eliminate the need for controls.
A robust architecture should assume that:
the AI can sometimes be wrong.
The control strategy should therefore determine:
- how incorrect outputs are detected;
- when source verification is mandatory;
- when the AI must defer;
- what requires independent human review;
- what decisions AI is not authorised to make.
Human Oversight Must Be Real, Not Formal
The official conference programme explicitly identifies human oversight as a foundational requirement.
However, simply inserting a human approval step into a workflow may not provide meaningful control.
Effective human oversight requires that the reviewer:
- understands the intended use of the AI;
- understands its known limitations;
- has access to source information;
- can challenge the AI result;
- has sufficient expertise to identify an implausible output;
- has authority to reject the recommendation;
- remains accountable for the final decision.
This distinction may become increasingly important as AI becomes embedded inside routine quality-system software.
From AI Validation to AI Assurance
The conference discussions point toward a broader model than traditional one-time software validation.
A possible lifecycle could be:
Intended Use
↓
Risk Classification
↓
Data Readiness
↓
Validation / Fitness-for-Use Evidence
↓
Controlled Deployment
↓
Human Oversight
↓
Performance Monitoring
↓
Change Control
↓
Periodic Reassessment
The exact depth of each element should depend on risk.
This is increasingly consistent with the broader concept of maintaining an AI-enabled system in a demonstrable state of control rather than merely declaring the system “validated” at implementation.
Why This Is Important
The 2026 PDA/FDA conference is significant because AI is now being discussed within mainstream CGMP topics such as:
- inspection readiness;
- data governance;
- manufacturing data;
- validation;
- quality systems;
- regulatory oversight.
AI is therefore moving from an innovation discussion into normal pharmaceutical quality-system governance.
The emerging direction appears to be:
do not validate AI because it is AI; validate and control the regulated function according to intended use, risk and decision impact.
This may ultimately provide a more practical approach than attempting to apply one universal validation standard to every AI technology.
Regulatory Status Note
The observations described above originate from presentations and panel discussions at the 2026 PDA/FDA Joint Regulatory Conference.
The conference includes FDA participation, but individual presentations, panel discussions and interpretations should not be treated as new FDA guidance or formal regulatory policy.
In particular, the concept of proportional levels of AI validation discussed during the conference should be understood as emerging regulatory and industry thinking rather than a newly issued CGMP requirement.
Sources
FDA – 2026 PDA/FDA Joint Regulatory Conference:
https://www.fda.gov/ … -conference-09142026
PDA – PDA/FDA Joint Regulatory Conference 2026, programme and session details:
https://www.pda.org/ … tory-conference-2026
BioPharm International – FDA, Sanofi, Gilead Weigh AI Readiness and Validation Risk at PDA/FDA Conference:
https://www.biopharm … k-pda-fda-conference
Pharmaceutical Technology – Lessons For AI Governance in Quality Systems: