Artificial intelligence is changing the way organizations work.
At DocXellent, we use AI tools internally to work more efficiently, accelerate research, assist with content drafting, create mockups, and improve responsiveness. The governing principle is straightforward:
AI is an assistant, not a decision-maker.
Customer data is never used to train AI models, passed to third-party AI services, or exposed to generative AI tools under any circumstance. Customer records, quality documents, and system data remain inside the product environment.
Organizations operating in regulated industries trust us with sensitive information. Protecting that information is fundamental to maintaining data integrity, confidentiality, and customer trust.
Read on to learn more about AI use, the risks it presents in regulated industries, and what you can do to implement strong AI governance in your organization.
Why human oversight still matters
As AI adoption accelerates, regulatory agencies are beginning to define what responsible AI use looks like in practice.
On April 2, 2026, the FDA issued its first warning letter explicitly citing AI misuse as a compliance violation:
-
21 CFR 211.22(c): Quality control unit responsibility. FDA found that using AI-generated documents without review was a violation of the quality unit's core obligations––a regulation written decades before AI existed.
-
21 CFR 211.100: Process validation. The firm failed to conduct required validation before distribution; the AI agent had not flagged the requirement.
The recipient of the warning letter was Purolea Cosmetics Lab, a small contract drug manufacturer in Livonia, Michigan. Multiple legal and regulatory sources—RAPS, DLA Piper, Morgan Lewis, BioSpace, and Pharmaceutical Technology—covered the action.
Investigators found that Purolea Cosmetic Labs had used AI to generate quality documentation without appropriate human review or quality unit validation. When asked why required process validation had not been completed, company personnel stated that the AI had never identified the requirement. The company has since ceased drug production.
Key takeaways from this situation include:
- The FDA is not anti-AI: RAPS reports that regulatory attorneys confirmed the action does not mean FDA is against AI in manufacturing.
- Human accountability is non-negotiable: Per Morgan Lewis: reliance on AI is not a defense against regulatory violations. The regulated entity remains fully responsible for every AI-generated output, including errors and omissions.
- No new AI-specific rule was needed: FDA applied existing cGMP regulations. The agency did not write new laws to make this finding, which means every company already subject to these regulations is already subject to this standard.
The Purolea letter is the line of demarcation, highlighting the fact that today’s regulatory question is no longer: "Will the FDA eventually enforce AI governance?"
It already has.
Rather, the question for businesses in regulated industries today is:
"If an FDA inspector asked us today to show every AI-generated document and every human review that followed it, could we?"
At DocXellent, AI-assisted output is reviewed by a qualified person before it is acted upon. AI generates; experts review and make final decisions.
The EU AI Act and AI Governance
The FDA is not the only regulatory body paying closer attention to AI. The European Union has also established a formal legal framework for AI governance through the EU AI Act.
Beginning August 2, 2026, enforcement expands for high-risk AI systems, giving national authorities the ability to investigate violations and issue penalties.
Key enforcement dates are as follows:
- February 2, 2025: Prohibited AI practices enforceable. AI literacy requirements (Article 4) in effect.
- August 2, 2025: General-purpose AI (GPAI) model obligations apply to providers (OpenAI, Google, Anthropic, Meta, etc.).
- August 2, 2026: Full enforcement activates for high-risk AI systems. National market surveillance authorities gain full investigatory authority. Fines become issuable.
- August 2, 2027: Full application for AI in medical devices (Article 6(1) / Annex I). Legacy GPAI models placed on market before August 2025 must now comply.
Note that a pending EU proposal (the "Digital Omnibus") would delay some high-risk AI obligations from August 2026 to late 2027. As of this writing, the European Commission has rejected blanket delays, and current dates remain operative.
As far as penalties, the EU AI Act fines exceed GDPR maximums for the most serious violations:
|
Violation Type |
Maximum Fine |
|
Prohibited AI practices (Article 5) |
€35M or 7% of global annual turnover |
|
High-risk AI system violations |
€15M or 3% of global annual turnover |
|
Incorrect or misleading information |
€7.5M or 1% of global annual turnover |
What “high risk” means in regulated industries
AI used in any of the following contexts is likely to trigger high-risk classification:
• AI embedded in or acting as a safety component of products regulated under EU MDR or IVDR—automatic classification, no separate analysis needed
• AI used in manufacturing controls, quality decisions, or compliance automation affecting product safety
• AI used in regulated records, clinical decision support, or patient-facing workflows
High-risk classification requires:
- Documented risk management
- Human oversight by design (Article 14)
- Full technical documentation
- Comprehensive audit trails
- Post-market monitoring
- Vendor compliance verification
Common Themes Across FDA and EU AI Regulation
Although the FDA warning letter and the EU AI Act come from different regulatory frameworks, they reinforce many of the same key AI governance principles:
Human accountability cannot be delegated to AI
The FDA applied a quality unit accountability rule written decades before AI existed. The EU AI Act codifies human oversight as a mandatory design requirement. Both frameworks reach the same conclusion: the regulated entity is fully responsible for every AI output.
Validation still applies
AI-generated documents do not bypass the validation requirements that would apply to human-generated documents of the same type. The FDA January 2025 draft guidance introduced a risk-based credibility framework for AI validation that mirrors IQ/OQ/PQ approaches regulated manufacturers already know.
Audit trails matter
Organizations should be able to demonstrate what AI generated, who reviewed it, and what decisions were made before it was used. The right question for any AI vendor or QMS platform: "Can you show a complete audit trail of every AI-assisted action and the human decision that followed it?"
Vendor accountability remains important
DLA Piper advises reviewing written agreements with AI vendors to address regulatory compliance responsibilities. The EU AI Act makes this a legal obligation. The inability to verify a vendor's compliance is itself a violation. Companies cannot assume their AI vendor has handled this on their behalf.
The regulatory landscape is evolving
The FDA has moved from publishing guidance to issuing warning letters. The EU AI Act has moved from discussion to enforcement. For regulated companies that have been treating AI governance as a future problem, the Purolea action and the August 2026 EU deadline confirm that the future is now.
Building a Strong Foundation for AI Governance
As AI becomes more deeply integrated into regulated operations, organizations need processes and systems that support human oversight, traceability, validation, and accountability throughout the document lifecycle. Those same principles have long been the foundation of effective quality management and document control.
For organizations operating under strict requirements, that means maintaining controlled documentation, complete audit trails, version control, training traceability, and documented approval workflows.
These capabilities not only support day-to-day quality processes but also help organizations demonstrate compliance as expectations around AI governance continue to evolve.
ENSUR is designed with these requirements in mind.
It centralizes controlled documentation, approvals, training, and quality workflows in a single system while embedding audit trails, electronic signatures, version control, and training traceability into everyday processes.
The result is a compliance-first foundation that helps regulated organizations maintain audit readiness without adding unnecessary complexity.
Learn more about ENSUR can help with audit trails and document control here.
Sources:
FDA Warning Letter — RAPS: https://www.raps.org/resource/fda-warns-firm-for-inappropriate-use-of-ai-in-drug-manufacturing.html
FDA Warning Letter — DLA Piper analysis: https://www.dlapiper.com/en-us/insights/publications/2026/04/fda-warning-letter-highlights-risks-of-using-ai-in-drug-manufacturing
FDA Warning Letter — Morgan Lewis analysis: https://www.morganlewis.com/blogs/asprescribed/2026/04/fdas-warning-letter-suggests-growing-scrutiny-of-ai-overreliance
FDA Warning Letter — BioSpace: https://www.biospace.com/policy/fdas-first-ai-focused-cgmp-warning-letter-signals-new-scrutiny-for-manufacturers
FDA Warning Letter — Pharmaceutical Technology: https://www.pharmtech.com/view/what-fda-s-ai-warning-letter-tells-us-about-gmp-accountability
FDA Warning Letter — Greenlight Guru medtech analysis: https://www.greenlight.guru/blog/purolea-warning-letter-ai
FDA Warning Letter — ECA Academy: https://www.gmp-compliance.org/gmp-news/use-of-ai-agents-leads-to-the-first-fda-warning-letter-relating-to-ai
FDA January 2025 Draft Guidance — IntuitionLabs: https://intuitionlabs.ai/articles/fda-draft-guidance-ai-drug-development
EU AI Act Article 99 — Penalty Structure (primary source): https://artificialintelligenceact.eu/article/99/
EU AI Act Fines — Legalithm: https://www.legalithm.com/en/blog/eu-ai-act-penalties-fines-explained
EU AI Act GPAI Enforcement August 2026 — Beam AI: https://beam.ai/agentic-insights/eu-ai-act-enforcement-august-2-2026-gpai-fines
EU AI Act 2026 Timeline — Axis Intelligence: https://axis-intelligence.com/eu-ai-act-news-2026/
EU AI Act Pharma & Medical Device — IntuitionLabs: https://intuitionlabs.ai/articles/eu-ai-act-pharma-medical-device-compliance
EU AI Act Life Sciences Compliance — USDM: https://www.usdm.com/resources/blogs/the-eu-ai-act
EU AI Act August 2026 Manufacturer Guide — Certivo: https://www.certivo.com/blog-details/eu-ai-act-august-2026-compliance-guide-for-manufacturers-integrating-ai-into-products




























