Guest Column | August 28, 2026

Implementing AI Solutions In GMP While Managing Risk

A conversation between Arif Azad at Pfizer and Life Science Connect's Jon O'Connell

digital research, biotech, scientific innovation-GettyImages-2223712673

As pharmaceutical manufacturers move AI from pilot projects into regulated operations, the pressure is building to prove they can stand up to GMP expectations for control, accountability, and data integrity.

Arif Azad will explore practical ways to move out of pilot mode and put AI to meaningful use at the 2026 ISPE Annual Meeting & Expo in October. The director of engineering validation at Pfizer agreed to give us a preview of his upcoming talk and discusses how AI-driven tools can be introduced into quality and manufacturing workflows without outpacing the controls that make them trustworthy. He takes a practical approach focusing on where real-time AI may help, how companies should move from pilots to routine use, and why risk management must extend well beyond initial validation.

Azad points to value-building use cases such as batch record review, documentation generation, and maintenance signal detection, but he also emphasizes the boundaries around them. Keeping the models honest through human oversight and robust governance — all while guidance for industry plays catchup — remain critically important and challenging imperatives.

For manufacturers beginning to evaluate AI-assisted compliance work, his conclusions offer a grounded look at where to start, what to avoid, and how to build confidence responsibly.

Can you start by describing real-time AI-driven solutions? What does it mean to leverage AI in real time compared to asynchronous or offline functionality?

Azad: Real-time AI-driven solutions use live or near-live data to support a decision while the process is still happening. In manufacturing, that could mean detecting equipment drift, flagging an unusual batch record entry, identifying a documentation gap, or pointing a reviewer to areas that need attention before a delay becomes a deviation. Offline AI is different. It looks at historical data after the fact, such as monthly trend reviews, periodic quality reviews, or completed investigation records.

Both approaches can add value, but real-time use carries higher expectations because the output may influence immediate quality decisions. For cGMP, the key is control. The intended use, data source, model version, human review, audit trail, and monitoring process must be clear. Real time should not mean autonomous or undocumented decision-making.

What does the path from pilot to routine use look like for the applications you describe, including AI-enabled periodic reviews, automated GxP documentation generation, and intelligent batch record review?

Azad: The path from pilot to routine use should be disciplined and, frankly, a little boring. First, define the intended use, the process needs, the GxP impact, and the acceptance criteria. Then test the model against representative records before placing it under change control and periodic review.

For periodic reviews, documentation generation, and batch record review, the starting point is human-in-the-loop assistance rather than autonomous decisions. The system may draft, summarize, flag, or prioritize, but a qualified person should review and make the final decision.

Routine use begins only when the data sources, model version, review process, exception handling, monitoring, and retirement plan are defined. A successful pilot proves feasibility. A routine GxP implementation proves that the organization can control the tool over its full life cycle.

You note that risk management for AI is often underestimated during implementation and ongoing monitoring. What are the most common pitfalls? For example, do you often see technical or governance gaps or global mindset problems?

Azad: The biggest pitfall is treating AI like a clever software feature instead of a life cycle-controlled GxP capability. Teams often focus on whether the model “works” and underestimate data quality, model drift, supplier responsibilities, cybersecurity, validation strategy, and human accountability. I also see a mindset gap. Some people over-trust the model because it looks sophisticated, while others reject it completely because it is unfamiliar. Both positions are risky. AI needs neither blind confidence nor fear. Rather, it needs appropriate control.

ICH Q9 thinking is useful here. The level of control and documentation should match the risk to patient safety and product quality. If an AI tool only organizes information, the controls may be lighter. If it influences quality decisions, the governance, verification, and monitoring need to be much stronger.

Model bias and lack of transparency are flagged as key risks in your session. In a cGMP context, what does verification look like in practice, and how do you test for bias in a model that makes decisions about batch records or periodic reviews?

Azad: In practice, verification starts with a precise intended use and a locked test strategy. For a batch record or periodic review model, I would test against independent representative records, including edge cases, different sites, product types, formats, and known failure modes. Bias testing means checking whether performance changes across meaningful subgroups, not just reporting one overall accuracy number. A model might perform well for one product family or site but poorly for another if the training data was not balanced. That matters in cGMP because inconsistent performance can affect review quality and decision confidence.

We also need false positive and false negative analysis, explainability review, confidence thresholds, and documented human adjudication. Rather than aiming to prove perfection, we want to prove controlled, understood performance for the specific use case.

AI introduces new questions about integrity and where decisions come from. How are you adapting existing data integrity frameworks like ALCOA+ to account for AI-generated or AI-assisted records?

Azad: I would extend ALCOA+ by treating AI interaction itself as part of the record life cycle. That means capturing the source data, prompt, or query where relevant, model version, configuration, output, timestamp, reviewer, and final human decision. AI-generated text should be treated as a draft or recommendation until a qualified person verifies it. The final record still needs to be attributable, legible, contemporaneous, original or a true copy, accurate, complete, consistent, enduring, and available. AI does not reduce those expectations. In fact, it makes traceability more important. If an inspector asks where a conclusion came from, the organization should be able to show what the AI produced, what the human accepted or changed, and why. Accountability cannot disappear inside the model.

Where do current regulatory expectations for AI in GxP environments still fall short of giving manufacturers confidence to move forward? Are you seeing agencies get ahead of the technology in any specific areas?

Azad: Regulators are giving useful principles, but manufacturers still need more practical clarity on dynamic models, generative AI in GMP workflows, model drift, cloud-hosted tools, supplier oversight, and what types of AI changes require regulatory notification.

FDA has acknowledged that AI in manufacturing raises questions around data management, validation, explainability, and continuous learning systems. EMA and FDA are ahead in setting shared principles, and the EU draft Annex 22 is more direct for GMP, but global harmonization is still developing. That uncertainty matters. Companies do not want to wait forever, but they also do not want to build systems that later fail inspection expectations. More alignment on risk classification, validation evidence, human oversight, and life cycle monitoring would help manufacturers move forward with confidence.

For a midsize manufacturer, what's a realistic first step into AI-assisted compliance work? On the other hand, what should such a company deliberately avoid trying to do first?

Azad: A realistic first step is a low- to moderate risk use case with strong human review. Examples include deviation trending support, periodic review draft summaries, batch record exception triage, missing field detection, or maintenance signal detection. The first project should have good data, a clear benefit, and no autonomous product quality decision. It should also teach the organization how to govern AI. This includes, for example, who owns the tool, how outputs are reviewed, how changes are controlled, and how performance is monitored.

I would avoid starting with any kind of AI controlled batch release, self-learning process control, or unrestricted generative AI writing GMP records. Those use cases may become possible in mature organizations, but they are poor first steps. A midsize manufacturer should build confidence through controlled, explainable applications before expanding into higher risk areas.

Two years from now, what does responsible AI adoption in cGMP manufacturing look like if the industry gets this right? Going a step further, what are the implications if we get it wrong?

Azad: If the industry gets this right, AI will be part of normal validation and quality practice. Tools will be inventoried, risk-ranked, validated for intended use, monitored for drift and bias, and governed with clear human accountability. Batch review and periodic review should become faster and more consistent, but final quality decisions will remain explainable and auditable. AI should help people see patterns earlier, reduce manual burden, and improve documentation discipline without weakening GxP expectations.

If we get it wrong, the risk is weak data integrity, hidden decision logic, overreliance by users, inspection findings, and loss of trust in digital transformation. Responsible adoption means using AI with discipline, because patient safety and product quality remain the foundation. We need to understand that AI adoption is inevitable, so resource allocation is required to stay future-ready.

About The Expert:

Arif Azad is director of engineering validation at Pfizer where he leads strategic and operational direction for validation functions. Previously, he served as head of technical operations-validation. Past posts include roles at ICU Medical, Decypher Corporation, and Ispahani Alliance Pharmaceuticals Limited. He was also an adjunct professor at the Temple University School of Pharmacy. He received his doctorate with a focus on risk management and technology adoption from California Southern University.