Pharma IT

Building the Knowledge Foundations for AI-Ready Pharmaceutical Quality Systems

How pharmaceutical quality systems can build the knowledge foundations needed for trustworthy AI across CMC and CGMP.

Dr. Ajaz Hussain
By Dr. Ajaz Hussain
Former Deputy Director - U.S. FDA
Sep 03, 202621 min read
Building the Knowledge Foundations for AI-Ready Pharmaceutical Quality Systems

The title promises foundations, not models. Those foundations are the knowledge duties a quality system must already hold — scope, reconstructability, assumption-break detection, and the authority to stop — before any model, predictive or generative, is fit to sit in a control strategy or to write a GxP record.

A model that cannot detect its own broken assumptions is not a control strategy.

That sentence is not a comment on algorithms. It is a knowledge-management test that now has to be applied on both sides of a seam the industry still treats as two different conversations: Chemistry, Manufacturing and Controls in the file, and current good manufacturing practice in the plant. If a quality system fails the test, every later discussion — who is accountable when AI decides, what validation teams do on Monday, who watches the watcher — will decorate a system that was not ready to be decorated.

The binding constraint is not model capability

Industry already knows how to fit a residence-time-distribution (RTD) model, how to train a chemometric model on a Raman or near-infrared probe, and how to prompt a general-purpose model to draft a procedure or a deviation. What it does not reliably know is whether the knowledge underneath those systems is current, complete enough for the job they have been given, and able to announce when it is no longer either.

ICH Q10 already named the duty: product and process knowledge, maintained over the lifecycle, and used in the control strategy (ICH, 2008). Most systems treat that heading as a compliance checkbox. The operational test is harsher. Can the system tell that an assumption frozen at approval — or frozen in a standard operating procedure — has died while the old alerts, or the old template language, stay green?

Regulators are moving toward that second question. In January 2025, FDA issued draft guidance on the use of artificial intelligence to produce information or data intended to support regulatory decisions on safety, effectiveness or quality. The unit of review is not “the algorithm.” It is the context of use: the specific role and scope of the model in addressing a question of interest (U.S. FDA, 2025a). Credibility, in that document, is trust — established through credibility evidence — in the model’s performance for that context of use. Because credibility is defined for a particular context, a change in role or scope (a new supplier, a new site, a wrapper that turns a predictor into a recommender) is a change in the job for which evidence was collected. The assessment has to be opened again.

The same month, draft considerations for 21 CFR 211.110 made the manufacturing implication explicit. Process models may be incorporated into commercial control strategies. They may not, on present science, be used alone to satisfy in-process control. FDA states that it has not been made aware of process models that demonstrate both that underlying assumptions remain valid during routine manufacture and that the manufacturer can detect when an assumption is no longer valid. Current process models “cannot ensure the continued validity of all of the model’s underlying assumptions at all times, particularly during certain unplanned disturbances.” Control strategies that rely solely on such models would be insufficient for §211.110 (U.S. FDA, 2025b; Fisher et al., 2026). That is not hostility to models. It is a precise description of the knowledge foundation that is still missing.

Regulatory admissibility in the file is becoming clearer. Readiness in the plant is not.

Two FDA-authored papers now have to be read together, and then placed against the plant.

In 2024, O’Connor, Fisher and European colleagues set out why process models are a growing instrument for design and control — and why the binding problem is model risk across the commercial lifecycle, not permission to file a model (O’Connor et al., 2024). They classified mechanistic, empirical/chemometric and hybrid models, and they treated RTD models as tools already used for material traceability, feeder limits and diversion of nonconforming material on continuous solid-oral lines.

In 2026, Fisher, Chatterjee, Madurawe, Tian, Tran and Lee published the first public account of models that had actually supported approved U.S. applications (Fisher et al., 2026). Across 2012–2025 they identified at least fifteen approved NDAs, BLAs — including biosimilars — originals and supplements, from eight companies, covering drug substance and drug product. Eleven of those model-supported applications involved continuous manufacturing. FDA encountered mechanistic models (for example mass balance), empirical models (NIR and Raman chemometrics) and hybrid models (RTD). Models appeared at high risk or impact (release decisions, parametric control), medium (in-process controls, diversion of nonconforming material) and low (design-space definition, investigations and monitoring). Documentation in the file generally scaled with that determination. On some files, Agency modelers built in-house models calibrated to the applicant’s experimental data and used them to test the proposed control strategy (Fisher et al., 2026).

Excluding three submissions whose delays were unrelated to modeling, the model-supported files were approved a mean of 20.3 days before their goal date, some under accelerated review (Fisher et al., 2026). That is a Chemistry, Manufacturing and Controls result. It is evidence that models can survive quality assessment. It is not evidence that a model can announce the death of its own context of use after commercial launch, and it says almost nothing about generative systems already drafting procedures, deviations and investigation text inside the current good manufacturing practice ecosystem.

Fifteen files from eight companies over thirteen years is progress. It is not current practice. If predictive competence remains an eight-firm boutique, and generative use remains an unlisted plant habit, neither will move the public-health arithmetic that matters in this room: shortage resilience, credible advanced manufacturing at scale, and the quality of the products that fill most prescriptions.

From process-model governance to generative use

The 2025 artificial-intelligence draft and the 211.110 draft are not two unrelated documents. Both make the same demand in different vocabularies: state the job, score the influence of the output and the consequence of being wrong, and keep a way to know when the assumptions that made the job legitimate have failed. A process model used for diversion already has that grammar in the file (Fisher et al., 2026; O’Connor et al., 2024). A generative system used to write a master production record, a specification or a deviation does the same kind of work — it produces text that can govern a batch — usually without that grammar at all.

The difference is not “predictive versus generative.” It is whether the quality system treats the output as a decision-support artefact with a context of use, or as prose that happens to have come from a model. Once an output can change what the plant does, or what the record says the plant did, the knowledge duties are the same. That is the bridge. The four patterns below are what happen when it is missing.

Four ways the seam fails

The fifteen files live in Module 3. Current good manufacturing practice lives in §§211.100, 211.110 and 211.192, in change control, training and data integrity. Predictive models fail the test of the title if they are credible in the file and mute in the plant. Generative systems fail the test of the title when they are used to write GxP documents without a stated context of use.

First, CMC-credible, CGMP-mute. An RTD or NIR model is approved with a verification plan. After launch it is not asked the antithesis questions. Corrective and preventive action cannot investigate what the approval never put in scope.

Second, CGMP-generative, CMC-absent. A team uses a general-purpose model to write specifications, master production records or investigation text. There is no stated context of use, no influence × consequence score, no reconstructable prompt-and-source package.

Third, a predictive model plus a generative wrapper, no new context of use. An agent is placed on a validated RTD or on a batch record. The wrapper changes the job — from “predict residence time” to “recommend diversion and draft the justification.” Under the 2025 draft, that is a new context of use (U.S. FDA, 2025a). Treating it as a user-interface upgrade is how high-influence decisions arrive without a credibility plan.

Fourth, ontology recycling. Generative systems trained on a site’s deviations, investigations and procedure library will reproduce “root cause unknown,” confirmatory language and whatever the pharmaceutical quality system already cannot see. Faster confirmation of a frozen plant ontology is not intelligence.

RTD as the first proxy — then the rest of the ecosystem

Fisher and colleagues describe a supplement that proposed continuous tablet manufacture as an alternative to an approved batch process. An RTD model tracked material and predicted assay so that nonconforming segments could be diverted in real time. Near-infrared models supported development and were proposed for identity and assay. FDA judged the RTD model medium risk: it decided diversion, not release. The process still combined predictive modeling with validated analytical testing. Approval required argument over acceptance criteria, validation completeness, parameter documentation, robustness in equipment failure, and lifecycle management — including which events would force revalidation (Fisher et al., 2026).

That case is the right first object. Influence is high. Consequence is high. The Agency’s own 211.110 draft says current models do not keep all of their assumptions valid through unplanned disturbance, and do not, by themselves, detect that an assumption has failed. Once those duties are visible on an RTD file, they apply to a Raman feed controller, a release model, a specification drafted by a generator, and an agent wrapped around any of the above.

Table 1. Knowledge duties across the CMC–CGMP seam. Residence-time-distribution diversion is row one because FDA has already assessed it. The remaining rows are the applications the rest of a quality agenda will assume are AI-ready.

Application

Typical posture in the file

Typical posture in the plant

What the quality system must hold before the application is AI-ready

RTD / hybrid model for diversion (proxy)

Medium-risk model; paired with testing; verification and revalidation triggers (Fisher et al., 2026)

Runs on the line; disturbance handling still depends on testing and human response (U.S. FDA, 2025b)

Scope of the development plan; reconstructable residuals; antithesis queries every campaign; named stop-authority

Chemometric / process-analytical model for in-process control or real-time release

Often in the control strategy; lifecycle via comparability protocol

Probe drift, reference-method mismatch, library ageing

Same duties plus spectral-library and reference-method surveillance

Predictive model for feed, bioreactor or impurity

Design-space or monitoring claim

Set-point recommendations during manufacture

Context of use restated when the model starts recommending, not only predicting

Generative drafting of procedures, master records or specifications

Usually absent from the file

Already happening

Context of use, source package, reconstructable prompt, qualified corpus, prohibition on silent model updates

Generative drafting of deviations, investigations or inspection responses

Absent

High-frequency temptation

Antithesis retrieval against the site’s own failure modes; a human accountable for the investigation, not for clicking accept

Agent wrapping a validated predictive model

Treated as interface

Changes the decision

New context of use. Influence × consequence scored again (U.S. FDA, 2025a)

The left-hand column is what a competent dossier already knows how to show: protocols, fits, signatures, sometimes a comparability protocol that sends an algorithm change to a prior-approval supplement and lesser changes into the site quality system (Fisher et al., 2026). The right-hand column is the foundation. Provenance is the boundary of the development plan — what was asked and what was excluded because the filing clock, or the investigation template, closed (Hussain, Gurvich, & Morris, 2019). Verifiability is reconstructability: Fisher et al. (2026) report that FDA scientists have built digital twins of proposed commercial processes and calibrated them with submitted data. The site must be able to do the analogue for a model and for a generated record. Detection is assumption-break, not a limit alert and not a fluent paragraph. Surveillance is every campaign, not the annual review (O’Connor et al., 2024). Accountability is a named owner in manufacturing time. Reversibility is the authority to stop a model or a drafting tool without waiting for a new regulatory clock.

That two-column difference is the gap between a validated system and a trustworthy one. Validation asks whether the artefact met its protocol for the stated use at the time of testing. Trustworthiness asks whether the knowledge is still fit for the job the organization is giving it today, and whether anyone is authorized to stop it if it is not. Process-validation guidance has required demonstration of process and product capability for more than a decade (U.S. FDA, 2011). Layering a model, or a generator, on a system that cannot make that demonstration does not close the gap. It shortens the cycle time of confirmation.

Fisher et al. (2026) also record a shift inside FDA reviews: older assessments speak of model impact in the ICH Q8/Q9/Q10 sense; newer assessments speak of model risk as influence × decision consequence in a stated context of use (U.S. FDA, 2025a; ICH, 2012). A chemometric model that looks “medium impact” as an in-process monitor can become high risk if the same model is the homogeneity control for a low-dose product (O’Connor et al., 2024; Fisher et al., 2026). Context of use is not paperwork. It is how knowledge is allowed to decide.

Challenges the current good manufacturing practice ecosystem has to cover

Before artificial intelligence is layered onto the plant, the pharmaceutical quality system has to hold eight practical duties.

Context of use must be written across Part 211, not only across the dossier. Diversion is one context. Drafting the deviation that explains the diversion is another.

Assumption surveillance must live inside the pharmaceutical quality system. Section 211.110 is explicit that current models do not guarantee assumption validity under unplanned disturbance, and do not by themselves detect that an assumption has failed (U.S. FDA, 2025b). The antithesis queries — material change, residual drift inside alert limits, complaint codes, “root cause unknown” — have to run on a campaign cadence.

Change control must treat model version, retrieval corpus, system prompt and fine-tune as master data. A silent vendor update is an uncontrolled change.

Reconstructability must serve inspectors, not only assessors. If the site cannot reconstruct generation the way it reconstructs an assay, the record is not legible under §211.

Someone must be able to stop the model or the drafting tool in plant time.

  • “Human in the loop” is not a foundation if the human cannot see the excluded questions or the sources.

  • The corpus a generator can see must include negative knowledge — what failed, what was out of scope — or the system will industrialize the site’s blind spots.

  • Shadow use on personal devices writing GxP text is an ecosystem fact. The foundation is an inventory and a ban-or-qualify rule, not a slide about responsible AI.

  • GAMP 5 Edition 2 and draft Annex 22 sit downstream of this list. Validation of computerized systems cannot repair a quality system that has no context of use and no authority to stop.

What fails when the order is inverted

The inversion is now familiar. Buy a platform. Stand up a use case. Fit a model to the data on hand, or point a generator at the site library. Write a validation package. Call the organization AI-ready. Then discover that the data were collected for a different question, that the development plan never included the failure mode that matters, that the only people who understand the residual plot have left, and that an investigation cannot examine what approval never authorized anyone to know.

That pattern is not new. In 1991 a back-propagation network was used to map hydrophilic-matrix formulation variables to in vitro release (Hussain, Yu, & Johnson, 1991). In 2002, with colleagues then at FDA, neural networks were applied to a Phase 2 pharmacokinetic and pharmacodynamic data set for repaglinide (Haidar, Johnson, Fossler, & Hussain, 2002). Those models were confirmatory pattern machines. Their honesty was hold-out error and a refusal to over-claim clinical significance. They could not close a lifecycle loop, because the knowledge base they queried contained almost no curated failures. Larger models have not repealed that limitation. They have scaled it.


Detection is not actuation — and knowledge supply is not a quality system

A quality system can surface a residual pattern, a complaint or a generated paragraph that contradicts the certified claim and still fail to change the decision. Certification freezes an incomplete ontology; later contradiction then has no obligated path to revision (Valerio & Hussain, in press). Forced-contradiction retrieval is one way to stop knowledge systems — predictive or generative — from retrieving only what confirms the file (Hussain, 2026). Neither mechanism substitutes for an institution that can curate failure-mode knowledge the sponsor has no incentive to keep; that is the public-interest knowledge layer sketched in the NIPTE 2030 agenda (Hussain, Morris, & Gurvich, 2026). For this audience the operational test remains simpler. If the site cannot state a context of use, reconstruct the model or the prompt, detect an assumption that died while alerts stayed green, and stop the tool in plant time, the system is model-equipped. It is not AI-ready.

Where this room sits

A view from outside India should be specific, and it should not treat the sector as one firm.

The Indian pharmaceutical manufacturing sector is unevenly distributed across this maturity curve. Part of it still struggles with the left-hand column of Table 1: a reconstructable report, a signed control strategy, a method that remains valid after the people who wrote it have left. Those are not advanced-manufacturing problems. They are knowledge-management problems that inspections already know how to find.

Another part of the sector can produce that left-hand column — and some of it is already in the kind of continuous-manufacturing and process-model work Fisher and colleagues described for eight companies. That capability is real. It is also not the same as readiness.

Across both parts, the right-hand column is thin: assumption surveillance while old alerts stay green, a named person who may stop a model in plant time, reversibility that does not wait for a supplement, and an inventory of generative use that never entered a file. Cost pressure on mature generics widens both gaps at once. It narrows the development plan, which starves the left-hand column of scope, and it rewards confirmatory speed, which starves the right-hand column of antithesis (Hussain et al., 2019). That is not a national character. It is an incentive.

So the risk from outside is not “India cannot file.” It is that excellence, where it exists, concentrates on the column that gets applications approved, while the column that keeps a model or a generated record trustworthy after approval remains the scarce resource. Process models will not protect the generic supply if they remain the property of a handful of well-staffed sites. Generative tools will not raise maturity if they only accelerate the ontology a site already has. The public-health payoff of Process Analytical Technology-era logic was always at scale (U.S. FDA, 2004; Arden et al., 2021). A risk-based lifecycle frame used only where modelers already sit still leaves that hole (O’Connor et al., 2024; Fisher et al., 2026).


What a chief quality officer should ask on Monday

Not “what AI use cases are we running.” Ask these.

  1. Inventory every predictive model and every generative use that touches a batch, a procedure or an investigation. One context-of-use sentence each (U.S. FDA, 2025a; Fisher et al., 2026).

  2. Which of those uses exist only in the plant and have never been in a file? Those are the unassessed contexts of use.

  3. For each predictive model, what would falsify it while alerts stay green? For each generative use, can the site reconstruct sources and prompt (U.S. FDA, 2025b)?

  4. Who may stop the model or the drafting tool today, without a supplement?

  5. What excluded questions and failed investigations are in the corpus the generator can see? If the answer is “none,” it will confirm the ontology already in place.

  6. Is this capability being built on the stock-keeping units and sites that would cause a shortage if the assumption died quietly — or only where modelers already sit?

If those six questions make a leadership team uncomfortable, that discomfort is the knowledge foundation. Artificial intelligence can be layered on it. It cannot substitute for it.

The rest of GPACTS may ask who is accountable when a model decides, and who watches the watcher. Those questions are downstream of a prior one: does the knowledge system know when its own certificate has expired?


References

Arden, N. S., Fisher, A. C., Tyner, K., Yu, L. X., Lee, S. L., & Kopcha, M. (2021). Industry 4.0 for pharmaceutical manufacturing: Preparing for the smart factories of the future. International Journal of Pharmaceutics, 602, 120554. https://doi.org/10.1016/j.ijpharm.2021.120554

Fisher, A. C., Chatterjee, S., Madurawe, R., Tian, G., Tran, R., & Lee, S. L. (2026). FDA regulatory experience with drug manufacturing process models in approved applications. International Journal of Pharmaceutics, 702, 127249. https://doi.org/10.1016/j.ijpharm.2026.127249

Haidar, S. H., Johnson, S. B., Fossler, M. J., & Hussain, A. S. (2002). Modeling the pharmacokinetics and pharmacodynamics of a unique oral hypoglycemic agent using neural networks. Pharmaceutical Research, 19(1), 87–91. https://doi.org/10.1023/a:1013611617787

Hussain, A. S. (2026). Engineering epistemic resilience: Overcoming ontological fragmentation in pharmaceutical AI. Journal of Artificial Intelligence and Knowledge Engineering. Advance online publication.

Hussain, A. S., Gurvich, V. J., & Morris, K. (2019). Pharmaceutical “New Prior Knowledge”: Twenty-first century assurance of therapeutic equivalence. AAPS PharmSciTech, 20, 140. https://doi.org/10.1208/s12249-019-1347-6

Hussain, A. S., Morris, K., & Gurvich, V. J. (2026). NIPTE 2030: The nation’s digital trust anchor for Pharma 5.0. Pharmaceutical Research. https://doi.org/10.1007/s11095-026-04118-z

Hussain, A. S., Yu, X., & Johnson, R. D. (1991). Application of neural computing in pharmaceutical product development. Pharmaceutical Research, 8(10), 1248–1252. https://doi.org/10.1023/A:1015843527138

International Council for Harmonisation. (2008). Q10: Pharmaceutical quality system.

International Council for Harmonisation. (2012). Quality Implementation Working Group points to consider for ICH Q8/Q9/Q10 guidelines.

O’Connor, T. F., Chatterjee, S., Lam, J., Hernán Pérez de la Ossa, D., Martinez-Peyrat, L., Hoefnagel, M. H. N., & Fisher, A. C. (2024). An examination of process models and model risk frameworks for pharmaceutical manufacturing. International Journal of Pharmaceutics: X, 8, 100274. https://doi.org/10.1016/j.ijpx.2024.100274

U.S. Food and Drug Administration. (2004). Innovation and continuous improvement in pharmaceutical manufacturing (Pharmaceutical CGMPs for the 21st Century — A risk-based approach, final report). https://www.fda.gov/media/77391/download

U.S. Food and Drug Administration. (2011). Process validation: General principles and practices (Guidance for industry).

U.S. Food and Drug Administration. (2025a). Considerations for the use of artificial intelligence to support regulatory decision-making for drug and biological products (Draft guidance for industry and other interested parties). Docket No. FDA-2024-D-4689.

U.S. Food and Drug Administration. (2025b). Considerations for complying with 21 CFR 211.110 (Draft guidance for industry). Docket No. FDA-2024-D-5374.

Valerio, N. G., & Hussain, A. S. (in press). Trust as a distributed function: Accountability outside epistemically sealed systems. Blockchain in Healthcare Today.

TopicsPharma IT
Dr. Ajaz Hussain
Written by
Dr. Ajaz Hussain
Former Deputy Director - U.S. FDA

Reporting on the science, business and regulation shaping the pharmaceutical industry.

Discussion

Loading discussion…

More in Pharma IT

All articles →