Before you paste that into an AI tool…
By Sachin Bhandari, Honorary Dean · 25+ years in pharma Quality IT · 10-minute read
AI is already in your building. Somebody in QA drafted a deviation summary with it last week, somebody in RA summarised a guidance document, and most of it happened on personal accounts nobody assessed. I write this as someone who has spent years bringing new technology into GxP environments: the answer is not to ban the tools, and it is not to look away. It is to give people four questions they can run in their heads in thirty seconds.
The thirty-second gate
1 · Is the data allowed to leave?
No patient data, no unreleased product data, no supplier-confidential material into public tools. Ever. Not anonymised-by-hand, not "just this once", not partially redacted. Public AI tools may log, retain and train on what you type, and once it leaves, you cannot call it back.
What good looks like in practice: your organisation names which tools are approved for which data classes. An enterprise deployment with a data processing agreement and retention controls is a different animal from a free consumer account. If your company has not classified this yet, the honest default is that only public-domain information goes in. And remember the law sits behind the policy: patient data carries GDPR and, in India, DPDP obligations that do not care how convenient the tool was.
2 · Is this a GxP decision?
AI can draft the deviation summary. It cannot decide whether the batch ships. A qualified human makes the GxP decision and signs it, and that line has to stay bright, because accountability is not transferable to a language model.
The subtle trap is not the obvious decision, it is the drafted recommendation nobody re-examined. If AI drafts an impact assessment and the reviewer waves it through, the human signature is real but the human judgement is not. My rule for teams: AI output enters the record only after a named person has done to it what they would do to a junior colleague's draft, challenged it line by line, then owned it.
3 · Can you verify the output?
If you cannot check it, you cannot use it. AI output you cannot verify is a rumour with good formatting. These tools produce confident, fluent, wrong answers, and in our industry a fabricated regulatory citation in a submitted document is not an embarrassment, it is a finding.
Verification means checking against something the AI did not produce: the source data, the actual guidance text, your own domain knowledge. A practical habit that works: ask the tool for its sources, then open them. If a cited guidance section does not exist, and sometimes it will not, you have just seen a hallucination up close and learned why this question exists.
4 · Would you show the prompt to an inspector?
If the answer is no, stop. Your prompts are records of how work got done. If AI meaningfully contributed to a GxP-relevant document, expect a future inspector to ask how, and expect your answer to need evidence, not memory.
A defensible prompt record is lighter than people fear. It looks like this:
Example · AI use record
Task: first draft of deviation trend summary, Q2 data
Tool: [approved enterprise tool, version]
Input: anonymised deviation categories and counts (no batch or patient identifiers)
Prompt: "Summarise these deviation trends by category and flag any category rising for 3 consecutive months."
Verification: counts cross-checked against QMS export by A. Reviewer, 14 Jul
Human owner: A. Reviewer, Senior QA. Draft rewritten in sections 2 and 4 before approval.
Six lines. If writing them feels disproportionate, the task probably did not need AI. If writing them feels impossible, because you would have to admit what went into the tool, that is the answer to question one arriving late.
The regulatory weather
The rules are moving, but the direction is readable. The FDA has signalled risk-based expectations for AI use in regulated work, with draft guidance on AI in drug and biological product decisions. The EU AI Act entered into force in 2024 and phases in obligations by risk class. GAMP has published practical thinking on AI within the quality framework we already know. None of it says do not use AI. All of it says know your data, keep a human accountable, verify outputs and be ready to show your work, which is exactly what the four questions above operationalise.
We publish when we have something worth your inbox, and not before.
Read next: CSV vs CSA: what actually changed?
