Launch webinar · AI in Pharma · 30 Aug, 12:00 PM IST
Home / Knowledge Hub / Article
Knowledge Hub

Before you paste that into an AI tool…

By Sachin Bhandari, Honorary Dean · 25+ years in pharma Quality IT · 10-minute read

AI is already in your building. Somebody in QA drafted a deviation summary with it last week, somebody in RA summarised a guidance document, and most of it happened on personal accounts nobody assessed. I write this as someone who has spent years bringing new technology into GxP environments: the answer is not to ban the tools, and it is not to look away. It is to give people four questions they can run in their heads in thirty seconds.

The thirty-second gate

1 · Is the data allowed to leave? patient, unreleased product, supplier-confidential safe to share STOP 2 · Is this a GxP decision? release, disposition, approval, patient impact drafting only A HUMAN DECIDES 3 · Can you verify the output? against source data, guidance or your own expertise yes, and I will STOP 4 · Would you show the prompt to an inspector? prompts are records of how work got done STOP Go ahead verify, then own the result
Four questions, thirty seconds. Any red exit means stop and rethink, not "try a different tool".

1 · Is the data allowed to leave?

No patient data, no unreleased product data, no supplier-confidential material into public tools. Ever. Not anonymised-by-hand, not "just this once", not partially redacted. Public AI tools may log, retain and train on what you type, and once it leaves, you cannot call it back.

What good looks like in practice: your organisation names which tools are approved for which data classes. An enterprise deployment with a data processing agreement and retention controls is a different animal from a free consumer account. If your company has not classified this yet, the honest default is that only public-domain information goes in. And remember the law sits behind the policy: patient data carries GDPR and, in India, DPDP obligations that do not care how convenient the tool was.

2 · Is this a GxP decision?

AI can draft the deviation summary. It cannot decide whether the batch ships. A qualified human makes the GxP decision and signs it, and that line has to stay bright, because accountability is not transferable to a language model.

The subtle trap is not the obvious decision, it is the drafted recommendation nobody re-examined. If AI drafts an impact assessment and the reviewer waves it through, the human signature is real but the human judgement is not. My rule for teams: AI output enters the record only after a named person has done to it what they would do to a junior colleague's draft, challenged it line by line, then owned it.

3 · Can you verify the output?

If you cannot check it, you cannot use it. AI output you cannot verify is a rumour with good formatting. These tools produce confident, fluent, wrong answers, and in our industry a fabricated regulatory citation in a submitted document is not an embarrassment, it is a finding.

Verification means checking against something the AI did not produce: the source data, the actual guidance text, your own domain knowledge. A practical habit that works: ask the tool for its sources, then open them. If a cited guidance section does not exist, and sometimes it will not, you have just seen a hallucination up close and learned why this question exists.

4 · Would you show the prompt to an inspector?

If the answer is no, stop. Your prompts are records of how work got done. If AI meaningfully contributed to a GxP-relevant document, expect a future inspector to ask how, and expect your answer to need evidence, not memory.

A defensible prompt record is lighter than people fear. It looks like this:

Example · AI use record

Task: first draft of deviation trend summary, Q2 data
Tool: [approved enterprise tool, version]
Input: anonymised deviation categories and counts (no batch or patient identifiers)
Prompt: "Summarise these deviation trends by category and flag any category rising for 3 consecutive months."
Verification: counts cross-checked against QMS export by A. Reviewer, 14 Jul
Human owner: A. Reviewer, Senior QA. Draft rewritten in sections 2 and 4 before approval.

Six lines. If writing them feels disproportionate, the task probably did not need AI. If writing them feels impossible, because you would have to admit what went into the tool, that is the answer to question one arriving late.

The regulatory weather

The rules are moving, but the direction is readable. The FDA has signalled risk-based expectations for AI use in regulated work, with draft guidance on AI in drug and biological product decisions. The EU AI Act entered into force in 2024 and phases in obligations by risk class. GAMP has published practical thinking on AI within the quality framework we already know. None of it says do not use AI. All of it says know your data, keep a human accountable, verify outputs and be ready to show your work, which is exactly what the four questions above operationalise.

Go deeper: this checklist is one small piece of AI Fundamentals for Pharma. In two hours you will practise prompting on regulated work, learn where AI fails in pharma, and leave with a 90-day plan you wrote yourself. It launches live with the AI in Pharma webinar on 30 Aug, free.
One practical article at a time.

We publish when we have something worth your inbox, and not before.

Read next: CSV vs CSA: what actually changed?