

三大启示
1. 按后果治理,而非按工具数量治理结语视角
过去四个月的核心教训,并非“加强控制”,而是“正确控制”。薄弱的治理会在规模化时暴露无遗,但若治理机制连“会议纪要”和“批放行决策”都无法区分,它终将因自身重量而崩塌,并拖垮团队对整个质量体系的信任。The Other AI Risk: Controlling It Like It's All the Same
For three months, I have argued that AI in GMP fails on control, not adoption. In March, I made the case. In April, I showed it in an FDA warning letter. In May, I landed it on a single sentence: the model will not carry quality unit responsibility; the company will.
This month, I want to turn the argument around, because a second failure mode is quietly becoming more common.
Look at the last 30 days of regulatory output: USP standards and a shortages report; FDA guidance on cell and gene therapy alongside approvals, labelling changes, and warning letters; an MHRA–FDA liaison program; an MHRA evidence base on AI in healthcare; and FDA’s first in-silico tool into the ISTAND program. That is not an unusual month.
No quality organization can apply maximum ceremony to it all. Yet, that is exactly what many organizations now do reflexively with AI, treating every AI touchpoint—a GMP meeting summary, a first-draft SOP, a batch-release input—with the same heavy validation, the same exhaustive documentation, and the same sign-off chain. The instinct feels safe. It is not governance. It is friction that does not track risk, and it trains people to treat controls as theatre.
Here is the uncomfortable part: under-control and over-control are the same disease. Both come from failing to anchor on intended use and risk. The Purolea warning letter (April) was risk under-applied—AI output entering records with no review. The over-control reflex is the opposite: risk undifferentiated and every output treated as if it were a release decision. ICH Q9 is the cure for both, and it has been sitting in the toolbox the whole time.
Notably, regulators are modelling the proportionate approach better than many manufacturers. When FDA accepted the AI-driven digital liver model into the Innovative Science and Technology Approaches for New Drugs (ISTAND) pilot, it did not bless "AI for toxicology." It accepted a letter of intent, the first of a three-step qualification, for a narrowly defined context of use. The tool has to earn its place against a specific purpose, not a general capability. That is risk-proportionate governance, written into the pathway itself.
Three Implications
Govern by consequence, not by tool count. An AI that drafts a meeting note and an AI that supports batch release sit under the same pharmaceutical quality system (PQS) umbrella and demand radically different control depth. Effort should track consequence or it is wasted twice: once in cost, once in credibility.
Undifferentiated control has a body count of its own. Heavy ceremony applied everywhere crowds out attention from the touchpoints that actually carry GMP risk, and it conditions reviewers to sign reflexively. A control everyone performs but no one believes is worse than no control, because it looks defensible and isn’t.
Proportionality is what scales across jurisdictions. Regulatory output is accelerating across USP, FDA, EMA, and MHRA simultaneously, and it is not neatly harmonized. You cannot maintain a separate maximal posture for every agency. Risk-based, intended use-anchored governance inside the PQS is the only way to stay coherent when the requirements multiply faster than they converge.
Closing Perspective
The lesson across four months is not "control more." It is "control right." Weak governance gets exposed at scale, but governance that cannot distinguish a summary from a release decision collapses under its own weight and takes the team's trust in the quality system with it.
So, before asking how tightly to control an AI, ask what the AI decides and what it would cost if it were wrong? The answer sets the rigor. Everything else is theatre or neglect. The defensible middle is the only place worth standing.

夜雨聆风