The FDA Didn’t Warn Against AI. It Warned Against Undefended AI

Table of Contents

Author

Omer Cimen

CEO & Co-Founder

Share

Artificial intelligence has become the easiest villain in regulated industries. Every time a warning letter mentions AI, the internet lights up like a pinball machine and the same conclusion appears on cue: the FDA is against AI.

That is not what happened.

The April 2, 2026 warning letter to Purolea Cosmetics Lab did mention AI, but the letter’s deeper message was not that AI is forbidden in regulated operations. The message was that AI cannot stand in for scientific judgment, quality oversight, required testing, or CGMP knowledge. In the same letter, FDA cited failures such as releasing products without required microbiological testing, relying on supplier certificates of analysis without establishing their reliability, failing to adequately test incoming components for identity and other attributes, and failing to conduct process validation before distribution. In the AI-specific section, FDA said that if AI is used to help create documents, those AI-generated documents still must be reviewed to ensure they are accurate and actually compliant, and that any output or recommendations from an AI agent must be reviewed and cleared by an authorized human representative of the quality unit. (U.S. Food and Drug Administration)

That distinction matters because it changes the real lesson for life sciences teams. The lesson is not “do not use AI.” The lesson is “do not use AI without defensibility.”

What the Warning Letter Actually Says

The warning letter is worth reading carefully because it has already been flattened into a slogan that misses the point. FDA did not issue a broad policy statement banning AI in pharmaceutical manufacturing. Instead, it documented serious CGMP failures and then addressed the company’s stated reliance on AI as part of that larger compliance problem. FDA wrote that the firm had used AI to create drug product specifications, procedures, and master production or control records. FDA then stated that if AI is used as an aid in document creation, the firm must review those AI-generated documents to ensure they are accurate and actually compliant with CGMP. The letter also says that any AI output or recommendation used in CGMP activities must be reviewed and cleared by an authorized quality unit representative. (U.S. Food and Drug Administration)

That is not an anti-AI position. It is a regulator reminding industry of something that should have been obvious from the start: assisted generation is not the same as justified control. A machine can propose. It cannot assume accountability.

Why This Matters Beyond One Company

It would be a mistake to treat the Purolea letter as a weird one-off curiosity. It is more useful to see it as an early marker of how regulators are likely to approach AI in practice.

FDA is already openly acknowledging growing AI use across the drug product life cycle. On its current AI for Drug Development page, CDER says it has seen a significant increase in drug application submissions using AI components over the past few years, across nonclinical, clinical, postmarketing, and manufacturing phases. FDA also notes that its January 2025 draft guidance on AI for regulatory decision-making provides a risk-based credibility assessment framework for evaluating an AI model in a particular context of use. In January 2026, FDA and CBER, working with EMA, also published 10 guiding principles that emphasize issues such as human-centric design, a risk-based approach, clear context of use, data governance, performance assessment, lifecycle management, and clear essential information. (U.S. Food and Drug Administration)

The agency’s own operational posture makes the point even clearer. In 2025, FDA announced an agency-wide rollout of generative AI capabilities for scientific review, then launched Elsa, an internal AI tool built in a high-security GovCloud environment to support agency staff with reading, writing, summarizing, scientific evaluations, label comparisons, and inspection targeting. FDA described this as part of its broader AI journey, not as an experiment it regretted touching. (U.S. Food and Drug Administration)

So the real signal from the regulator is consistent: AI is here, AI use is increasing, and AI can be useful. What matters is whether its use is controlled, reviewable, risk-based, and appropriate for its context.

The Real Compliance Standard Is Defensibility

This is where many companies still stumble. They frame the question as “Are we allowed to use AI?” That question is too shallow to be useful.

A stronger question is this: “Can we defend how we used AI?”

Defensibility is the standard that actually travels into audits, inspections, deviations, investigations, and quality reviews. A team that uses AI to help draft a procedure may be fine if it can show who reviewed it, how it was checked, whether the output matched applicable requirements, and whether the approved record entered the controlled workflow properly. A team that copies AI output directly into a regulated record without subject-matter review is building its own trapdoor.

That is exactly why the warning letter matters. FDA did not describe AI itself as the violation. The problem was overreliance, lack of review, lack of required knowledge, and lack of evidence that the resulting records and decisions were scientifically and procedurally sound. (U.S. Food and Drug Administration)

In other words, the issue was not intelligence. It was unsupported trust.

What “Undefended AI” Looks Like in Practice

Undefended AI usually does not announce itself dramatically. It often arrives wearing productivity lipstick.

It looks like AI-generated SOPs that no one with real process ownership reviewed closely enough. It looks like requirements drafted by a model and approved because they sounded polished. It looks like risk assessments produced faster than they were challenged. It looks like test content generated without strong linkage to intended use. It looks like quality units being treated as the clean-up crew after automation has already been allowed to make the mess.

The common thread is not the presence of AI. It is the absence of a reliable chain of justification.

In regulated environments, outputs need lineage. Teams need to know what the model was used for, what inputs shaped the result, what context of use applied, what human review took place, what evidence supports acceptance, and how that artifact or recommendation moved into a controlled state. FDA’s own draft guidance and guiding principles align tightly with that logic through their focus on credibility, context of use, data governance, performance assessment, lifecycle management, and clear information. (U.S. Food and Drug Administration)

What Defended AI Looks Like Instead

Defended AI is much less glamorous in a demo and much more valuable in real life.

It starts with narrow, explicit intended use. The organization knows whether AI is being used to draft, summarize, classify, propose, compare, or assist. It does not pretend that “the AI helps with validation” is a meaningful control statement. It is specific.

Then it adds human ownership in the right place. Review is not a ceremonial click. It is a real check performed by someone qualified to catch technical, procedural, and regulatory issues. FDA’s warning letter could hardly be clearer here: AI outputs used in CGMP activities must be reviewed and cleared by an authorized human representative of the quality unit. (U.S. Food and Drug Administration)

Then comes traceability. Teams should be able to connect AI-assisted artifacts to requirements, risks, tests, approvals, changes, and evidence. If the logic vanishes the moment someone asks “why was this accepted?”, the process is already wobbling.

Then comes governance across time. Models, prompts, workflows, data sources, and approval paths all change. A defended AI process assumes that change will happen and controls it rather than hoping no one notices.

This is why “defensibility, not hype” is a better north star for regulated AI programs. The shine wears off quickly. The audit trail does not.

Why This Is Also a Validation Design Problem

Many organizations are still trying to solve AI governance as a policy problem alone. Policy matters, but policy without operational design is just a framed poster.

The harder and more useful work is building environments where AI-assisted work can be created, reviewed, approved, traced, and monitored in the same controlled ecosystem as the rest of validation activity. That means connecting requirements, designs, tests, deviations, changes, approvals, and evidence so that AI use does not become a side alley with its own shadow rules.

This is one reason the market is moving beyond simplistic document automation conversations. The more AI participates in regulated workflows, the more organizations need infrastructure that supports attribution, review, traceability, and lifecycle control by design. FDA’s public materials point in the same direction through their emphasis on risk-based credibility, clear context of use, governance, performance, and lifecycle management. (U.S. Food and Drug Administration)

For life sciences teams, that means the conversation should not stop at whether AI can save time. It should move toward whether the operating environment can preserve control.

What Life Sciences Teams Should Do Now

The immediate takeaway from this warning letter is not panic. It is cleanup.

Teams using AI in validation, quality, manufacturing, or compliance workflows should review where AI is already being used, what intended use has actually been defined, where quality unit or subject-matter review happens, what evidence exists for acceptance decisions, and whether AI-assisted records are entering controlled workflows with the same rigor as manually authored ones.

They should also ask a sharper question about readiness: if an inspector picked one AI-assisted artifact at random, could the organization explain why it is trustworthy?

If the answer is fuzzy, that is the work.

FDA has already shown that it is willing to promote AI use, build internal AI capabilities, and engage industry on risk-based frameworks for AI in drug development. At the same time, it has also shown that AI will not be allowed to function as a decorative shield for missing process validation, missing testing, weak quality oversight, or unreviewed CGMP content. (U.S. Food and Drug Administration)

Conclusion

The FDA did not warn against AI. It warned against using AI like a substitute for responsibility, evidence, and review.

That distinction is the whole story.

AI can help draft faster, summarize better, compare more broadly, and reduce administrative drag. FDA itself is using AI internally and is actively developing frameworks for its appropriate use in drug development and regulatory decision-making. But none of that lowers the bar for compliance. If anything, it raises the importance of being able to explain how AI was used, why the output was acceptable, who reviewed it, and how the validated state remained under control. (U.S. Food and Drug Administration)

In regulated environments, the winning question is not whether AI was involved.

It is whether its use was defensible.

Visual representing software validation processes

Computerized System Validation: What It Is and How to Validate a System

Computerized system validation is the backbone of safe,..

Data Integrity in Pharmaceutical Industry

Understanding Data Integrity in the Pharmaceutical Industry

Data Integrity Policy for Pharmaceutical Industry is a set..

Visual representing data integrity and compliance

The Importance of ALCOA Principles in Pharma

ALCOA principles are the five pillars, Attributable, Legible, Contemporaneous,..

Enter your email to get the Handbook

Learn about the industry

Get tailored templates

Discover Validfor

Before you go...

Verify your e-mail

We will send you the final “21 CFR Part 11 Readiness Checker ” report to your email address. Please enter a valid email address and verify your email address to access the tool.

Check your inbox!
We've sent an access link to


Click the link in the email to start your 21 CFR Part 11 assessment.

Verify your e-mail

We will send you the final “Annex 11 Readiness Checker” report to your email address. Please enter a valid email address and verify your email address to access the tool.

You’re all set!

We’ll reach out shortly to schedule a time