What You’re Not Told by AI—and the Consequences
First-ever US Food and Drug Administration (US FDA) Current Good Manufacturing Practice (cGMP) Warning Letter Citing Inappropriate Use of Artificial Intelligence (AI) in Pharmaceutical Manufacturing
An April 2026 enforcement action against a Michigan (USA) drug manufacturer marks the moment the US FDA moved from guidance to enforcement on AI in pharmaceutical manufacturing and reaffirmed that the Quality Unit’s accountability cannot be delegated to an algorithm.
“The AI never told us it was required.”
That was the explanation a drug manufacturer gave US FDA investigators when asked why process validation, one of the most foundational requirements in cGMP, had not been performed before product distribution. Not a missing record. Not a training lapse.
The firm told the agency it did not know the legal requirement existed because the AI agent it relied on had never flagged it.
On 2 April 2026, the US FDA issued a Warning Letter to a Michigan-based manufacturer of homeopathic drug products1. In many respects, the letter is routine: it cites insanitary conditions, inadequate microbial testing, and a Quality Unit that failed to ensure batch records were reviewed before release. But buried in the findings is a section (Section 3) without precedent in US FDA enforcement history: “Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing”. With it, a clear signal that the agency’s expectations on AI in cGMP have moved from the guidance phase into the enforcement phase.
What the Inspection Found
The Warning Letter followed a three-day inspection of the company’s facility in late October 2025. Investigators documented insects, dirt, leaves, and clutter throughout the manufacturing areas, and observed a docking bay door that, when opened, exposed the manufacturing space directly to the outdoor environment. The firm had not conducted appropriate laboratory testing to confirm products were free of objectionable microorganisms.
During the inspection, the firm’s owner told investigators she had used AI agents to create the company’s drug product specifications, standard operating procedures, and master production and control records, specifically with the stated aim of helping the firm comply with US FDA regulations.
Product specifications, standard operating procedures, and master production and control records all directly link into manufacturing. The Quality Unit, however, did not independently review or verify those AI-generated outputs before they were incorporated into the company’s manufacturing operations.
Two Citations, One Underlying Failure
The US FDA cited two distinct violations. The first, under 21 CFR 211.22(c)2, concerns the Quality Unit’s responsibility to review and approve documents that affect drug product quality. The agency wrote that if a manufacturer uses AI as an aid in document creation, it “must review the AI generated documents to ensure they were accurate and actually compliant with cGMP,” and that failure to do so is a violation in itself.
The second, under 21 CFR 211.1003, concerns process validation, a foundational requirement that the firm had simply skipped before distributing product. When investigators raised it, the firm’s response was that the AI agent had not informed them validation was required. The US FDA’s position in the letter was unambiguous: an AI knowledge gap is not a defense. Any output or recommendation from an AI agent used in cGMP activities must be reviewed and cleared by an authorized human representative of the respective Quality Unit before entering the quality system.
“The FDA is not creating a new standard for AI. It is applying the existing standard, expressing that over-reliance and/or blind-reliance on AI violates it.”
The Deeper Issue: Automation Bias
What makes the case uncomfortable is not that something failed. It is the way it failed.
The US FDA is not opposed to AI in document drafting. The problem is that no one reviewed the outputs, no one had enough cGMP fluency to recognize the errors, and the firm appears to have used a commercial off-the-shelf tool rather than a closed system with controlled inputs.
This is the well-documented pattern of automation bias: when a system produces output that looks complete, structured, and authoritative, reviewers apply less scrutiny. Not because they are careless, but because the surface signals of error are absent. AI generates patterns but it does not validate obligations. A clean, professional procedure can quietly omit something fundamental like process validation and give no indication that anything is missing. In a regulated environment, that is precisely where failure starts and patients get impacted.
This Did Not Come Out of Nowhere
The enforcement action follows a multi-year regulatory build-up. CDER’s March 2023 discussion paper on AI in drug manufacturing4 established the conceptual framework. The January 2025 draft guidance introduced a seven-step credibility assessment for AI used in regulatory decision-making5. A February 2025 Warning Letter to another company6 addressed AI-based devices marketed without the proper pathway. And in January 2026, the FDA and the European Medicines Agency jointly published the Guiding Principles of Good AI Practice in Drug Development7
The trajectory follows the agency’s familiar playbook: educate, set expectations, then enforce. The first two phases are now complete.
Implications Beyond One Manufacturer
For contract development and manufacturing organizations (CDMOs), contract testing laboratories, and contract packagers, the implications run deeper than a single Michigan facility. Under US FDA’s framework, the product owner remains responsible for drug quality regardless of any agreement with a contract facility. A principle the Warning Letter restates directly. AI governance gaps at a contractor therefore translate into compliance exposure for the sponsor.
Quality Agreements that are silent on AI use, permitted applications, human oversight requirements, and audit rights are now, as a matter of practice, incomplete. The questions sponsors should be asking right now their partners (not limited):
- Where in your quality and manufacturing workflows is which kind of AI in use today, and for what purpose?
- What are the sources, and is the system closed or open to general internet content?
- How is human review evidenced in the quality record before AI outputs enter the quality management system?
- What change controls and revalidation triggers apply when the model or its prompts change?
The Bottomline:
The letter does not say AI cannot be used in regulated drug manufacturing. It says human accountability cannot be delegated to it. AI can draft a specification, propose a procedure, or surface a precedent but it cannot be the entity that releases a batch, validates a process, or owns a regulatory obligation. Outputs from any AI are outputs. The human remains making the decision.
For an industry that is rapidly piloting (generative) AI across documentation, deviation handling, and specification authoring, the practical message is simple. Inventory the tools. Map them to GxP impact. Codify a human-review-and-release control with traceable Quality Unit sign-off. Update Quality Agreements with contract partners. Train reviewers to remain sceptical in the presence of convincing output.
And remember that an AI that does not know what it does not know will not share what it missed.