FDAAIcGMPwarning-letterquality-unitdata-integrity

Can You Use AI to Write GMP Documents? FDA Just Answered

Valiqa Team|August 24, 2026|10 min read|
Can You Use AI to Write GMP Documents? FDA Just Answered

Yes, you can use AI to write GMP documents. The FDA said so in writing, in what appears to be its first warning letter with a dedicated section on artificial intelligence in pharmaceutical manufacturing, issued to Purolea Cosmetics Lab on April 2, 2026. What you cannot do is release AI-generated documents without review and approval by an authorized member of your quality unit. The agency's words: "If you use AI as an aid in document creation, you must review the AI generated documents to ensure they were accurate and actually compliant with CGMP. Your failure to do so is a violation of 21 CFR 211.22(c)." No new rule, no AI-specific regulation. The FDA reached for a requirement that has been on the books for decades and applied it to a technology that did not exist when the rule was written. AI-assisted documentation is acceptable. AI-generated-and-unreviewed documentation is a citation.

That one-paragraph answer deserves unpacking, because the letter contains a second AI finding that much of the commentary has skipped, and because the letter is a preview of how inspectors will treat AI-generated validation documents, batch records, and procedures from now on. This article walks through what actually happened, the two regulatory hooks the FDA used, what the letter does not say, and what a defensible AI documentation workflow looks like in practice.

What actually happened

The FDA inspected Purolea Cosmetics Lab, a manufacturer in Livonia, Michigan, from October 28 to 30, 2025. The firm made homeopathic drug products alongside cosmetics. The resulting warning letter, issued April 2, 2026, is long and mostly conventional: insanitary conditions, missing microbiological testing, components used without identity testing, unapproved new drug claims. This was not a sophisticated AI deployment that went subtly wrong. It was a firm with a broken quality system that had outsourced parts of that system to an AI agent.

But then comes a section heading with no precedent in published drug CGMP warning letters: "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing." During the inspection, the firm told investigators it had used AI agents to help comply with FDA regulations. Specifically, it used AI to create drug product specifications, procedures, and master production or control records. Those documents went into use without adequate review and approval by the quality unit.

The FDA's response established two things. First, using AI as a document-creation aid is not itself a violation. The letter's conditional phrasing, "if you use AI as an aid in document creation," treats the practice as permissible. Second, the human review obligation is absolute. The firm's failure to review the AI output before use violated 21 CFR 211.22(c), the provision that makes the quality unit responsible for approving or rejecting all procedures and specifications that impact product identity, strength, quality, and purity.

The letter closes the AI section with the requirement stated as a forward-looking rule: if the firm resumes production and uses AI for CGMP activities, "any output or recommendations from an AI agent must be reviewed and cleared by an authorized human representative of your firm's QU."

The rule the FDA applied is older than the technology

There is no AI regulation in 21 CFR Part 211, and the FDA did not need one. The quality unit's approval responsibility under 211.22(c) does not care who or what drafted a document. A specification written by a consultant, copied from a template, or generated by a language model arrives at the same gate: an authorized person in the quality unit reviews it, understands it, and approves or rejects it. The document becomes a controlled record through that act of approval, not through the act of drafting.

This is the same logic the agency has long applied to other delegated work. Contract manufacturers, outside laboratories, and consultants have never diluted the manufacturer's own responsibility, and the letter's owner-responsibility section repeats the standing position that contractors are extensions of the manufacturer. The AI section extends the same principle to a new kind of contractor, one that produces confident, well-formatted output with no understanding of your process and no accountability for the result.

For anyone who writes or reviews validation documents, this framing should feel familiar. It is the same reason what auditors actually look for is evidence of review and approval, not evidence of authorship. Auditors have never asked who typed a protocol. They ask who approved it, on what basis, and whether the approver was qualified to judge it.

The finding everyone missed: "the AI never told us"

The AI section contains a second violation that got less attention than the document-review finding, and for a validation audience it is the more instructive one. Investigators found the firm had not conducted process validation before distributing its drug products, as 21 CFR 211.100 requires. Told of the requirement, the firm replied that it was not aware of the legal requirement, because the AI agent it relied on never told them it was required.

The FDA documented that answer in the warning letter, describing it as overreliance on artificial intelligence. The defense failed completely, and it was always going to fail. A regulated manufacturer's obligations come from the regulations, not from whatever subset of the regulations an AI tool happens to surface. An AI assistant that drafts a procedure on request will do exactly that, and nothing more. It will not volunteer that the process the procedure supports also needs process validation, that the equipment needs qualification before the process runs on it, or that a change last month triggered revalidation. If nobody at the firm knows the requirement exists, the gap ships.

This is the deeper lesson of the letter. The document-review finding is about checking AI output. The overreliance finding is about the scope of what you ask AI in the first place. A tool that answers questions cannot compensate for not knowing which questions to ask. That knowledge has to live in your people or in a system built by people who hold it, which is one reason choosing validation software is partly a question of how much regulatory context is built into the tool rather than left to the operator's prompt.

What the letter does not say

A news-pegged enforcement action attracts commentary, and some of it stretches the letter past what it holds. Three clarifications are worth making.

The letter does not prohibit or discourage AI. The conditional framing runs through the entire AI section. The corrective path the FDA lays out is about review, approval, and a functioning quality unit, not about removing AI from the building.

The letter does not cite 21 CFR Part 11 or 21 CFR 211.68. Some commentary has connected the letter to the computerized-systems requirements of 211.68 and to Part 11's electronic records controls. Those connections are reasonable analysis of where enforcement may go, but they are not in the letter. The AI section's citations are 211.22 and 211.100. If your review and approval of AI-generated documents happens electronically, Part 11's controls apply to those records and signatures the same way they apply to any other electronic record, but that is a consequence of the records being electronic, not of the documents being AI-generated.

The letter does not require you to validate the AI model itself. Nothing in the letter treats the AI agent as a computerized system requiring qualification, and the violation was located entirely in the missing human review. Whether an AI tool in your operation needs formal assessment is a separate, risk-based question. A drafting aid whose every output passes through qualified human review sits at the low-risk end of the GAMP 5 and CSA spectrum precisely because the human gate is the control. Remove the gate and the tool's risk profile changes, which is exactly the situation the letter describes.

The line: assisted versus unreviewed

Put the two findings together and the compliance line is easy to state. AI that accelerates drafting, with a qualified human approving every output before it becomes a controlled document, is a productivity gain the FDA has now implicitly accepted in writing. AI whose output enters use without that review is an unapproved procedure, whoever ran the prompt.

The compliance line FDA drew: AI-assisted drafting with quality unit review is acceptable, AI-generated documents released unreviewed draw a 211.22(c) citation

The line does not move based on how good the AI is. A generated specification that happens to be perfectly accurate is still a 211.22(c) violation if the quality unit never reviewed it, because the violation is the missing review, not the content error. This matters for teams tempted to sample-check AI output or to skip review on "routine" documents. The regulation makes approval a per-document obligation, and the letter enforces it that way.

It is worth being precise about what review means here, because a signature is not a review. The FDA's phrasing is that the firm "must review the AI generated documents to ensure they were accurate and actually compliant with CGMP." That is a technical evaluation: are the specifications right for this product, do the procedures reflect the actual process, are the acceptance criteria traceable to requirements rather than invented by the model. A reviewer who cannot make that judgment is not an authorized reviewer in any sense that survives an inspection, no matter what their signature block says.

What this means outside pharma

The Purolea letter is a drug CGMP action under 21 CFR Part 211, so its citations do not apply directly to medical device manufacturers. The principle transfers intact. The FDA Quality Management System Regulation, in effect since February 2, 2026, incorporates ISO 13485:2016, which requires documents to be reviewed and approved for adequacy prior to issue, and requires process validation where output is not fully verified. A device manufacturer that released AI-generated procedures without review, or skipped process validation because an AI tool never mentioned it, would face the same findings under different clause numbers.

The same is true one level down, for the validation documents themselves. An AI-generated IQ, OQ, or PQ protocol is a controlled quality document. It carries specifications and acceptance criteria that will be used to judge equipment fitness. Under either framework, it needs qualified review and documented approval before execution, and the executed record needs the same data-integrity discipline as any other GMP record. If your team is generating protocols with AI, the Purolea letter is the enforcement-grade argument for treating generation as the start of the document lifecycle, never the end.

What a defensible AI documentation workflow looks like

The letter defines the floor: human review by an authorized quality representative before any AI output becomes a controlled record. A workflow that will hold up under inspection needs a few more properties, all of them derivable from existing expectations rather than speculation about future AI rules.

A defensible AI documentation workflow: AI draft, qualified human review, e-signed approval, locked controlled record, with an audit trail spanning every stage

A structural review gate, not a procedural one. The difference between "our SOP says we review AI output" and "our system will not let an unreviewed document advance" is the difference between a control an inspector must take on faith and one they can test. AI-generated drafts should enter the same review and approval workflow as human-authored documents, with no path around it.

Named, qualified approvers with recorded signatures. Approval must be attributable to a specific authorized person, dated, and preserved. Electronic signatures need to meet Part 11 requirements if the records are electronic.

Locked records after approval. Once approved, the document is immutable except through controlled revision. An approved protocol that can be silently edited is not a controlled record, whoever authored it.

An audit trail across the lifecycle. Generation, edits, review, approval, and any later changes should be reconstructable. When an inspector asks how a document came to exist, "the AI made it and someone cleaned it up" is not an answer. A timestamped trail from draft through approval is.

Recorded provenance. Knowing which tool and which version generated a document turns "we use AI" from a vague admission into a controlled fact. If the tool changes materially, you want to know which documents it produced under which configuration.

None of this is exotic. It is the ordinary machinery of document control, pointed at a new class of author.

Where Valiqa stands on this

Valiqa generates validation protocols with AI, so the Purolea letter is about our category, and we would rather be plain about the line it draws than pretend the letter is about someone else. A protocol generated in Valiqa enters the lifecycle as a draft. It cannot advance without review, and it cannot be approved without an electronic signature from an authorized person, with separation of duties enforced so an author cannot approve their own work. Approval locks the document, lifecycle actions land in a hash-chained, tamper-evident audit trail, and each generated protocol records the model version that produced it under formal change control. The generation step saves the drafting time. The review step is deliberately impossible to skip, because the review is what the FDA just confirmed it will cite you for missing. Details are on our security and compliance page.

That design choice predates this warning letter, and the letter is confirmation of why it exists. AI in a regulated quality system is only as defensible as the human accountability wrapped around it.

What to do now

If your organization uses AI anywhere near GMP documentation, a short self-assessment covers the letter's blast radius. Do you know, concretely, which documents in your quality system had AI involvement in their drafting? Does every one of them carry a documented review and approval by someone qualified to judge its technical content? Could you show an inspector the workflow that guarantees the next AI-assisted document gets that review? And is your regulatory scope, the list of what validation and documentation your operation actually requires, owned by qualified people rather than assembled from AI answers?

If any answer is no, the fix is the ordinary discipline of document control applied without exception to AI output. The Purolea letter is not a reason to stop using AI in validation and quality work. It is the clearest statement yet that the FDA will treat AI-generated documents exactly like every other document: judged by whether a qualified human stood behind them before they went into use.

---

Valiqa is an AI-powered validation lifecycle platform for regulated manufacturing. Learn more at valiqa.io

Frequently Asked Questions

Ready to automate your validation documentation?

Generate audit-ready IQ/OQ/PQ protocols in minutes, not weeks.

Get Started

We use essential cookies for authentication and security. With your consent, we also use Microsoft Clarity, Google Analytics, and the LinkedIn Insight Tag on our marketing pages to understand how visitors navigate the site and to measure our advertising. Learn more.