A quality manager asked me recently whether AI could write his deviation investigations for him. He’d been told, by someone selling a tool, that it would cut cycle time in half. Probably true. Also not the question that matters.
An AI system can draft an investigation reasonably well. It can summarize a batch record, pull related events from history, propose candidate failure modes, and produce something more organized than the average first draft written under deadline pressure at the end of a long shift. That’s a genuine capability, and I’d use it. What it cannot do, no matter how good the draft is, is be the person who signs it.
Why the signature was never administrative
It’s easy to treat a signature on an investigation as a formality, the box that has to be checked before the record can close. It isn’t. A signature on a GMP investigation is an assertion, made by a named, qualified individual, that they examined the evidence, reached this specific conclusion, and can be questioned about how they got there, in a room, by an investigator, potentially years later. That’s the entire regulatory logic underneath the requirement: accountability has to attach to a specific person who can defend the reasoning, not to a process that produced a plausible-looking output.
An AI system cannot hold that position, structurally, regardless of how accurate its draft turns out to be. It has no standing to be questioned. It has no accountability to attach a consequence to. Which means the moment a draft, AI-generated or otherwise, is signed, the entire regulatory weight of that signature depends on what the signer actually did between receiving the draft and approving it. That’s the question nobody’s answering clearly yet, at sites that are already using these tools in production, well ahead of any finalized guidance on how they should be governed.
The question that matters: what did the reviewer actually do
If a reviewer read the AI-drafted investigation, checked it against the underlying evidence, and agreed with the conclusion, that’s review. It’s defensible, the same way any reviewed and approved document is defensible, provided the reviewer can demonstrate that the review actually happened and actually engaged with the substance.
If a reviewer signed because the draft looked plausible, read fluently, and the investigation queue was already three weeks backlogged, that isn’t review. It’s automation of the exact failure mode quality systems have been fighting for decades: a conclusion that looks adequate on paper and was never actually tested against the evidence. AI doesn’t introduce this risk. It makes the risk faster and cheaper to produce at scale, because a fluent, well-organized, wrong conclusion is now something a tool can generate in under a minute, on demand, as many times as someone asks for it.
This is worth sitting with, because it inverts an intuition a lot of people bring to this topic. The concern isn’t usually that AI drafts will be obviously bad. Obviously bad drafts get caught. The concern is that they’ll be well-organized and plausible enough that a rushed reviewer has no practical friction stopping them from approving something that was never actually verified.
What a defensible review actually requires
A few concrete things separate genuine review of an AI-assisted draft from a rubber stamp, and they’re worth writing into procedure explicitly rather than leaving as an assumption about what a reviewer is supposed to do.
The reviewer has to independently trace at least the key claims in the draft back to the underlying evidence, not just read the draft’s own summary of that evidence. An AI system summarizing a batch record can misrepresent it confidently and fluently, in ways that read as entirely reasonable unless someone checks the primary source directly.
The reviewer has to be able to articulate why the conclusion is right, not just that it reads as plausible. “This makes sense” is not the same statement as “I checked this against the deviation history and the root cause is consistent with what actually happened here.” An investigator asking a reviewer to explain their reasoning six months later needs the second statement to exist, and it can only exist if the reviewer actually did that work.
The review has to leave a trace. Not necessarily an elaborate one, but something beyond a signature block, some documented indication of what was checked and against what, so that “what did the reviewer actually do” has an answer beyond “they clicked approve.”
The scope of AI involvement should be identifiable in the record, even informally. Not because AI use is inherently disqualifying, it isn’t, but because a future investigator, auditor, or inspector asking questions about how a conclusion was reached deserves an accurate account of the process that produced it.
Where regulatory guidance actually stands right now
The gap here isn’t hypothetical or distant. As of this writing, the guidance most directly on point, EU and PIC/S draft Annex 22 addressing AI within GMP operations, remains in draft form, unfinalized, and not widely read outside a fairly narrow regulatory-affairs audience in the US. Broader AI guidance that does exist tends to focus on submissions and regulatory decision-making rather than day-to-day GMP operations specifically. Which means the governance question this piece is raising, what a reviewer actually has to do to make a signature defensible, is currently being answered, if it’s being answered at all, informally and inconsistently, site by site, without a finalized external standard to anchor the practice.
That’s not a reason to wait. Sites are already using these tools. The absence of finalized guidance doesn’t pause the risk, it just means each site is currently writing its own version of the answer, whether deliberately or by default.
My position on this, stated plainly
Use AI to draft. Don’t let it narrow the set of causes a human actually considers, which is a subtler risk than an outright wrong answer, because a fluent draft that proposes one plausible cause can quietly foreclose the harder work of considering two or three others. The value of these tools is genuinely in the writing. The risk is in the thinking, specifically in letting a fluent draft substitute for the thinking a reviewer is supposed to be doing.
And if you can’t describe, specifically, what your reviewer did beyond approving a document, you don’t currently have a review step. You have a formality that happens to precede a signature.
Conclusion
AI drafting tools inside GMP investigations aren’t a future problem waiting on finalized guidance to arrive. They’re a present governance question, and the answer doesn’t depend on the tool. It depends on whether your review process can survive someone asking, specifically, what a named reviewer actually verified before they signed.
If you’re not confident your own review process could answer that question today, that’s worth a direct look, and it’s exactly the kind of gap a Rapid Diagnostic is built to find.
Key Takeaways
A signature is an assertion, not a formality. It’s a named, qualified person committing to defend a conclusion under questioning, potentially years later.
AI can draft. It cannot hold accountability. No tool can be the entity questioned about how a conclusion was reached, which means the human reviewer’s actual work is the only thing standing behind the signature.
The real risk is narrowed thinking, not obvious error. A fluent, plausible AI draft can quietly foreclose consideration of alternative causes a rushed reviewer would otherwise have had to generate themselves.
Genuine review leaves a trace. Independently checked claims against primary evidence, an articulated reason the conclusion is right, and some documented record of what was actually verified.
Finalized guidance is not the constraint here. Draft Annex 22 remains unfinalized and narrowly read. Sites using these tools today are answering this governance question themselves, whether they’ve decided to or not.
