AI in Biopharma Manufacturing: Are We There Yet?

Transcript — Convergence: Where Is This Going — and Are We There Yet?

This is the script the AI voices read, so it matches the audio word for word; times are from the render. Researched, scripted and voiced by AI systems under Jack Prior's direction. Sam and Sarah are AI characters; nothing in the episode is Jack speaking, and none of it is a statement of his views or his employer's. Generative AI can be confidently wrong — check the sources. Corrections: jack@jackprior.ai.

00:00 Narrator This is Are We There Yet — a podcast on the evolution of AI in biopharma manufacturing, directed by Jack Prior. A word about how it's made. This episode was researched, scripted and voiced by AI systems. Jack sets the questions and the frames; the AI reads the documents and writes the conversation you're about to hear, between two AI characters: Sam, who plays a manufacturing-science practitioner, and Sarah, who has read the documents. Nothing you hear is Jack speaking, and none of it is a statement of his views or his employer's. Like any generative AI output, it can be wrong — confidently wrong, or missing a nuance — which are exactly the risks this industry is working to mitigate, and exactly what this season is about. Check the sources before you rely on anything. Corrections are welcome at jackprior dot A I. Now, the episode.

00:53 Sam A quality council, late this year. The site head has one slide on the screen: four rows, three columns. The rows are the four systems this season has followed: the bioreactor soft sensor, the batch monitoring model, the fill-volume vision system, and the assistant that drafts deviation investigations. The columns say: do now, wait for, do anyway. The slide title is the name of this podcast.

01:20 Sarah Are we there yet.

01:21 Sam The head of manufacturing science has to fill it in by Friday. Behind the slide sit a draft annex with thirteen hundred comments, an FDA draft that hasn't moved in twenty months, a reflection paper from ICH, two pages of principles signed by both agencies, and a vendor roadmap that changes every quarter. Every cell on that slide is a bet on which document lands first.

01:45 Sarah Tonight's frame, Sam, and the last of the season. Convergence: where is this going, and are we there yet? The joint principles, ICH's reflection paper, the CDER agenda and the sandboxes, and what they tell us about the next three years.

02:02 Sam Let's fill in the slide.

Convergence: the question and the map

02:03 Sam Sarah, the question and the documents.

02:05 Sarah Are the rulebooks converging, on what, and by when; and what does a site do while it waits. Nine documents, four layers, two anchors. From the regulator layer, jointly: the Guiding Principles of Good AI Practice in Drug Development, issued by the European Medicines Agency and the US Food and Drug Administration together in January twenty twenty-six. From the harmonisation layer: the International Council for Harmonisation's reflection paper on proposed guideline work for advanced pharmaceutical manufacturing, endorsed by the ICH Assembly on the eighth of October twenty twenty-five and published the following March.

02:47 Sam Provenance and maturity.

02:48 Sarah The joint principles are final: two pages, ten numbered principles, and they say of themselves that they are intended to lay the foundation for developing good practice. They are not guidance; they are the two agencies' shared statement of what good practice will be measured against. The ICH paper is final as a reflection paper, and a reflection paper is ICH thinking aloud about what to harmonise next. Neither is a guideline. Both tell you where the guidelines are heading.

03:20 Sam And the voices.

03:21 Sarah From the law layer, the EU AI Act, for its sandbox article and its dates. From the regulator layer, the UK's Medicines and Healthcare products Regulatory Agency, the MHRA, and its policy paper of April twenty twenty-four, for the AI Airlock. From Europe's institutional machinery: the European medicines agencies network strategy to twenty twenty-eight; the Network Data Steering Group's workplan, updated February twenty twenty-six; and the Quality Innovation Group's workplan for twenty twenty-six to twenty twenty-eight. From industry, BioPhorum's June twenty twenty-six risk guidance, for how it frames harmonisation. And the landscape's own watchlist and open questions.

04:05 Sam Why this question now, because episode one said why the season exists. The classical three have had twenty years of rulebook. What changed is that the agent arrived in the plant in the time it took Annex Twenty-two to get from draft to workshop, and the rulebook is being rewritten while the agent is already reading batch records. I said in episode one that agentic AI is the thing that finally makes the data work real, and that coding and data engineering are heading into the rear-view mirror. Convergence is the question of whether the rulebook arrives before the agent does, or after. That's the practitioner's stake in a document about harmonisation.

04:44 Sarah And last episode ended on the sentence: we know what changes and who to tell. Tonight asks whether the people we tell are going to agree with each other.

04:54 Sam Start with the two pages.

Joint principles: the shared vocabulary

04:55 Sarah Guiding Principles of Good AI Practice in Drug Development. EMA and FDA, January twenty twenty-six; the landscape has the fourteenth. Per the landscape, the first joint EU and US statement on AI. It defines its subject in one sentence: AI, for this purpose, refers to system-level technologies used to generate or analyse evidence across the drug product life cycle, and it lists the phases: nonclinical, clinical, post-marketing, and manufacturing. Manufacturing is in the first paragraph, not a footnote.

05:30 Sam What does it say it's for?

05:32 Sarah Its own words: the ten principles are intended to lay the foundation for developing good practice, and they identify areas where international regulators, standards organisations and other collaborative bodies could work to advance it: research, educational tools, international harmonisation, and consensus standards, which may help inform regulatory policies and regulatory guidelines in different jurisdictions. So it is a charter for the next round of documents, written by the two agencies whose documents diverge most.

06:06 Sam Read the ten. Briefly; we've met most of them.

06:09 Sarah One, human-centric by design. Two, a risk-based approach: proportionate validation, risk mitigation and oversight based on the context of use and determined model risk. Three, adherence to standards, and it names Good Practices, GxP, in so many words. Four, a clear context of use, defined in a parenthesis as role and scope for why it is being used. Five, multidisciplinary expertise covering both the AI technology and its context of use, integrated throughout the life cycle.

06:46 Sam That's episode two in the first four, and Annex Twenty-two's cast list in the fifth.

06:51 Sarah Six, data governance and documentation: data source provenance, processing steps and analytical decisions documented in a detailed, traceable and verifiable manner, in line with GxP requirements. Seven, model design and development practices, leveraging data that are fit-for-use, considering interpretability, explainability and predictive performance. Eight, risk-based performance assessment, which I'll read in full because it is the one episode seven turned on: risk-based performance assessments evaluate the complete system including human-AI interactions, using fit-for-use data and metrics appropriate for the intended context of use.

07:34 Sam Both agencies, one sentence: the human is part of what gets assessed.

07:38 Sarah Nine, life cycle management: risk-based quality management systems throughout the life cycle, with scheduled monitoring and periodic re-evaluation, its example being data drift. Ten, clear, essential information: plain language about the technology's context of use, performance, limitations, underlying data, updates, and interpretability or explainability.

08:03 Sam Here's what I take from the two pages, and it's the character's reading. Count the words we've spent the season on: context of use, model risk, fit for use, lifecycle, human-AI team, GxP. All six are in there, and they are in there under both logos, which until January had never happened. The vocabulary has converged. What hasn't is the sentence after the vocabulary: how much evidence, which model types, which reporting category. The principles don't say, and they are honest that they don't. They say good practice and consensus standards must evolve as the use of AI evolves, and they name harmonisation as the work still to be done.

08:43 Sarah One quieter thing the document has already done. BioPhorum's June twenty twenty-six risk guidance says of itself that it aligns with the EMA and FDA Guiding Principles, and its executive summary describes the frameworks it surveyed as, quoting, robust individually but fragmented collectively. Industry has picked the joint principles as the thing to align to. That is what a shared vocabulary is for.

ICH: the likely destination

09:10 Sam Now the harmonisers. Provenance, maturity, and what it actually proposes.

09:15 Sarah Reflection Paper on Proposed ICH Guideline Work to Facilitate the Adoption of Advanced Pharmaceutical Manufacturing. Endorsed by the ICH Assembly on the eighth of October twenty twenty-five; published the following March. A reflection paper, not a guideline. Its own last paragraph says ICH should consider these topics during the annual new topic selection process, and as of the landscape's last check in August no topic had been adopted.

09:42 Sam Why did ICH write it?

09:44 Sarah Its first paragraph: through external engagements, international manufacturers have noted the lack of global regulatory alignment as one reason for not pursuing and adopting advanced manufacturing technologies. And its first example of such a technology is process modelling, including AI-based models. So the paper's premise is tonight's question: divergence is costing adoption.

10:11 Sam Three topics.

10:12 Sarah Process modelling, continuous process verification, and decentralised or distributed manufacturing, in that order, stepwise, with a phased approach that it says might mean three separate guidelines. On process models it says they might be considered digital representations of physical manufacturing processes; that they are increasingly used for process design, scale-up, site transfer, monitoring and control; and that they can become a critical element of the control strategy.

10:43 Sam And its verdict on the twenty eleven Points to Consider, which episode three called the spine.

10:48 Sarah It credits it first: the Points to Consider established the principle that a model's impact, its contribution to assuring product quality, guides the extent of regulatory oversight. Then three gaps, each in its own words. There is currently a need for global harmonisation on multiple aspects, and its examples are terminology, model risk framework, basis for regulatory oversight, and data requirements. Manufacturers require guidance on regulatory notification of model updates considering model risk and maturity of a site's quality system. And the Points to Consider does not address the scientific and regulatory considerations for linking model risk to model validation and lifecycle management activities.

11:34 Sam Terminology, risk framework, notification, and the link from risk to evidence. That's episodes three, eight and five, written down by ICH as unfinished.

11:44 Sarah And the AI sentences. New types of AI models might further challenge the regulatory frameworks for process models; and where it says regulators are actively developing regional guidelines, its footnotes point to the EU's consultation on Annex Twenty-two and to FDA's January twenty twenty-five draft. Then: a new ICH guideline on process models could provide a comprehensive framework with principles that might be applicable to AI models, recognising that the Points to Consider did not explicitly foresee these new types of AI models.

12:19 Sam Does it see the divergence from episode four?

12:21 Sarah On page seven, yes. The Points to Consider approach may not be best suited for AI models used as part of a dynamic control strategy and in continuous manufacturing; regulators and industry are recognising the need for a modern risk-based classification of models and lifecycle management approach; and AI or continuous learning models can pose a significant challenge for regulators, because post-approval model verification activities need to be balanced with the ongoing changes to the model as new information is generated. It names the problem. It does not take a side.

12:58 Sam So ICH has seen the split and called it a topic. What does it propose to do first?

13:02 Sarah Section C. A new ICH guideline on process models would be a preferred first step. It would clarify the Points to Consider on the regulatory expectations for implementing and using process models, including, quoting, documentation required in dossiers related to models and model updates over the lifecycle; and it would revise the Points to Consider based on scientific and regulatory considerations for linking model risk to intended use and decision consequence.

13:31 Sam Intended use and decision consequence. That's FDA's step three and M fifteen's model risk, adopted as the revision principle for the manufacturing document. If that guideline gets written, the grading crosswalk from episode three stops being a crosswalk and becomes one column.

13:49 Sarah It also lists the questions it wants answered, and three are ours. What are the expectations for in-process material testing and release testing when a model is employed for process control. What are the expectations for risk-based validation of pharmaceutical manufacturing models. And what are the expectations for a lifecycle maintenance approach over a model's lifespan, especially, quoting, for frequently updating process models, e.g., AI models that learn and self-adjust.

14:19 Sam And the second topic, continuous process verification. Why does it matter as much as the modelling one?

14:26 Sarah Because the paper says continuous process verification, as defined in Q eight, is briefly addressed in the Points to Consider, represents an advanced approach to process validation, and has not been widely adopted; and that there is a need for further clarification on the expected level of product and process understanding, the process monitoring and control strategy, and the information and data needed in the dossier. Its second question on the topic is whether regional approaches can be aligned. The batch monitoring model is a continuous process verification tool. Every multivariate model that trends every batch is waiting on this topic, not the modelling one.

15:06 Sam Hold the practitioner's reading for a moment, because that sentence, not widely adopted, is one people will misread. Every site head who hears it will think of the trending programme their quality unit already runs on every commercial batch, and object that they adopted it years ago. That programme is not what the paper means. There are two terms here, one letter apart, and they are not the same thing.

15:31 Sarah Continuous, and continued. Continuous process verification is Q eight's term, and its glossary definition is one sentence: an alternative approach to process validation in which manufacturing process performance is continuously monitored and evaluated. An alternative, that is, to qualifying the process on a fixed number of batches before launch. Continued process verification is FDA's term, stage three of the twenty eleven process validation guidance: ongoing assurance, gained during routine production, that the process remains in a state of control. Stage three is not an alternative to anything. It is what every validated process owes after qualification, whichever way it was qualified, and the guidance ties it to the record-evaluation requirement in part two eleven.

16:22 Sam And Europe has a third phrase for the second thing.

16:25 Sarah Annex Fifteen calls it ongoing process verification, and its glossary says, in so many words, also known as continued process verification. Clause five twenty-eight says the ongoing-verification paragraphs apply to all three approaches to validation, traditional, continuous and hybrid. So continued, or ongoing, is the floor: every commercial process, both regions, since twenty eleven. Continuous is something else: using that same stream of monitoring to validate the process in the first place, in place of the pre-launch batches.

17:04 Sam So when the paper says continuous has not been widely adopted, it is saying almost nobody has replaced the validation batches with the monitoring. It is not saying nobody watches the process. Nearly every site does the first and has never attempted the second, and a batch monitoring model is, today, a stage-three tool. Now the practitioner's reading. Continuous verification was the promise of Q eight: validate the process by watching every batch instead of three. It never took, because nobody could say what watching had to look like on paper. If ICH writes that down, the batch model stops being a continued-verification chart on the MSAT wall and becomes the thing the dossier cites. For this show's audience that is a bigger prize than the modelling guideline.

17:52 Sarah One caution on timing. The paper says the timing to initiate this effort may be influenced by external factors, including regional legislation or policy development, and that topic prioritisation will be informed by regulatory experience. Read plainly: ICH will wait to see what Annex Twenty-two and the FDA texts settle into before it harmonises them.

The calendar: what is actually dated

18:16 Sam Checkpoint, a third in. Two pages of principles that converge the vocabulary and admit the rest is unfinished. An ICH reflection paper that names three topics, three gaps and a preferred first guideline, with no topic adopted. Now the calendar. Sarah, only the dates the landscape verified; hedge the rest.

18:36 Sarah Seven items. One: the twenty twenty-six guidance agenda of CDER, FDA's Center for Drug Evaluation and Research, lists a planned draft titled AI and ML Quality Considerations in Pharmaceutical Manufacturing; the agenda came out early this year, in February as I understand it. Not yet published. It would be the first FDA text specifically about AI in CMC, the successor to the twenty twenty-three discussion paper, and the natural home for the reporting categories for model changes that episode eight found missing. Whether it appears this year is a guidance agenda's promise, and those slip.

19:18 Sam Two.

19:19 Sarah Two, three and four are the EU GMP trio: Annex Twenty-two on artificial intelligence, the Annex Eleven revision on computerised systems, and the Chapter Four revision on documentation. Consulted together from the seventh of July to the seventh of October twenty twenty-five; around thirteen hundred comments on Annex Twenty-two; the EMA workshop of the thirtieth of June and first of July this year explored adaptive and generative models; no amended draft has been published, and EMA's own minutes say the draft is under revision. The final texts are targeted to reach the Commission around the end of this year, with effect around twenty twenty-seven. Both are estimates, as I understand it, not published dates.

20:07 Sam Five.

20:08 Sarah Five: FDA's January twenty twenty-five draft on AI to support regulatory decision-making, the credibility framework, still a draft as of August, with no date for a final. Six: a possible EMA follow-up on adaptive and generative AI after the workshop, as separate guidance or a second phase of the annex; the landscape lists it as possible and I can't say more than that.

20:34 Sam Seven.

20:35 Sarah The AI Act. In force since the first of August twenty twenty-four. Its high-risk obligations were deferred this summer by an amending regulation, in force since late July, that the landscape calls the Digital Omnibus on AI: to the second of December twenty twenty-seven for the Annex Three use cases, and the second of August twenty twenty-eight for AI embedded in products under Annex One. The landscape's section on EU law has the new dates, and I'm following that. And as episode three said, almost nothing in a pharma plant is high-risk under the Act unless it is a safety component of a regulated product, a medical device or a machine, that needs third-party conformity assessment.

21:18 Sam And the two you can't talk about.

21:20 Sarah A pharmacopeial standard on digital twins is expected; that is all I can say. And an industry proposal is circulating. Nothing on the content of either.

21:29 Sam Seven rows: one date that's law, six that are targets. Here's how I'd read a calendar like that, and it's the character's reading. The only certain thing on it is the thing that touches the plant least. Everything that touches the plant directly is a draft or a promise. That is not a reason to wait; episode one said a draft is what the inspector asks about the day it's published. It is a reason to plan for the shape of the documents rather than their dates, because the shape is already visible and the dates aren't.

Europe's machinery: EMANS, NDSG, QIG

21:57 Sarah The dates come from somewhere, so, briefly, the machinery behind the EU texts. The European medicines agencies network strategy to twenty twenty-eight, EMANS twenty twenty-eight, adopted in twenty twenty-five by the Heads of Medicines Agencies and EMA together. Six themes, the second of which, after accessibility, is leveraging data, digitalisation and artificial intelligence.

22:21 Sam What does it say about manufacturing?

22:23 Sarah Two objectives. Under regulatory science, three point one point three: facilitate the development and implementation of novel manufacturing technologies and analytical techniques. And under availability and supply, five point two point four: keep good manufacturing practice requirements updated in light of technological progress in manufacturing, with digital and AI as its examples. That second one is the strategic sentence Annex Twenty-two answers to. And goal two point three is to realise the network's vision on AI across all of its focus areas.

22:59 Sam The steering group.

23:00 Sarah The joint HMA and EMA Network Data Steering Group, the NDSG, and its workplan to twenty twenty-eight. Its first-quarter deliverable this year was publishing the Guiding Principles for Good AI Practice, so the joint principles are a line item of this plan. Then: a coordinated roadmap of further AI guidance in the second quarter; an AI glossary in the fourth; exploring additional opportunities for international harmonisation from late this year through twenty twenty-eight; and, in the second quarter of twenty twenty-seven, what it calls a regulatory sandbox simulation hackathon, on hypothetical AI use-case scenarios. Most of the plan is the network's own use of AI; the harmonisation and glossary lines are the ones that reach a plant.

23:52 Sam And the quality group.

23:54 Sarah The Quality Innovation Group, the QIG: EMA's advanced-manufacturing group and the nearest EU counterpart to FDA's Emerging Technology Program. Its rolling workplan, dated the fifth of December twenty twenty-five, puts pharmaceutical process models including AI considerations first among its priority areas. Its guidance list for twenty twenty-five and twenty twenty-six: its own preliminary considerations on pharmaceutical process models, which the ICH paper cites; and specialised input to Annex Eleven and Annex Twenty-two. Internationally: collaborate with FDA on areas of common interest, and, quoting, voice the EU's position in international fora such as ICH. It offers a point of entry for developers and yearly listen-and-learn meetings with industry.

24:45 Sam So the same group that gave specialist input to the annex sits behind the EU's voice at ICH and runs the door industry knocks on. Which means the annex's position on model type is the position the EU carries into any ICH topic, unless the comments move it first. Worth knowing when you decide where to spend a comment.

Sandboxes: the Airlock and Article 57

25:04 Sam Sandboxes. Industry has asked for one for years. What exists?

25:07 Sarah One running, in medical products. The MHRA's policy paper of April twenty twenty-four, Impact of AI on the regulation of medical products, describes the AI Airlock as a regulatory sandbox for AI as a medical device, launching in pilot form in spring twenty twenty-four, funded by the health department's AI lab, bringing together the UK approved bodies, the health service and other regulators, to identify and address the novel regulatory challenges for AI devices and, in its words, answer previously unanswered questions. The landscape confirms it launched, that its second phase is complete, and that it is funded through twenty twenty-nine.

25:50 Sam Devices, though.

25:52 Sarah Devices. On medicines the same paper says that the questions the regulator needs to ask to determine whether a product is safe do not change when the nature of the evidence changes, and it points to its own scientific advice and accelerated pathways. The ICH paper lists an MHRA consultation among the avenues for advanced manufacturing, alongside FDA's FRAME initiative and Emerging Technology Program, the biologics centre's advanced technologies team, EMA's QIG, and Japan's innovative manufacturing team. Those are front doors, not sandboxes.

26:31 Sam And the AI Act's.

26:32 Sarah Article fifty-seven. Every member state must have at least one AI regulatory sandbox operational by the second of August twenty twenty-six. Its definition: a controlled environment that facilitates the development, training, testing and validation of innovative AI systems for a limited time before they are placed on the market, under a sandbox plan agreed between the provider and the competent authority; and it may include, quoting, testing in real world conditions supervised therein. The provider leaves with an exit report that market surveillance authorities and notified bodies must take positively into account, and one stated objective is evidence-based regulatory learning.

27:16 Sam But.

27:17 Sarah But the competent authority is the AI Act authority, the compliance in question is compliance with the AI Act, and the Act mostly does not reach a GMP plant. Horizontal, not GMP. That is the landscape's phrase and the article supports it.

27:33 Sam So the sandbox that exists is for devices, and the sandbox the law mandates is for a law that mostly doesn't reach the plant. What industry keeps asking for is a third thing: a supervised deployment, in a GMP facility, with the GMP regulator in the room, where a soft sensor or an agent runs for real under an agreed plan and the exit report counts for something. Nobody has built it. The nearest things in the corpus are FDA's early engagement, which episode two noted reaches before implementing, and the QIG's one-to-one meetings. Those are conversations. A sandbox is an experiment. The device world has one; the drug world has meetings.

28:18 Sarah What the documents support in that: the Act's article gives the template, the Airlock gives the precedent, and the ICH paper says the lack of harmonisation across regulators' initiatives may discourage manufacturers. What no document says is that a GMP sandbox is coming.

The open questions, in one list

28:36 Sam Second checkpoint, two-thirds. Vocabulary converged; ICH's topic named, not adopted; a calendar with one law and six targets; the EU machinery behind it; sandboxes for devices and for the Act, none for GMP. Now the list. Sarah, the open questions as the season found them, and which episode found each.

28:57 Sarah Six. One: adaptive and continuously learning models in critical GMP use. Annex Twenty-two says they should not be used; FDA's draft anticipates them under lifecycle maintenance; nobody harmonises, and ICH has named it as a challenge without a topic. Episode four. Two: generative AI and agents in GxP documentation. Annex Twenty-two says not in critical use, and human-in-the-loop elsewhere; FDA's draft never uses the words; and whether a documentation use is critical is, in the landscape's phrase, the key question. Episodes four and seven.

29:41 Sam Three.

29:42 Sarah Three: third-party and foundation-model dependency, a vendor changing the model outside your change control. Under-addressed everywhere; episode eight's fourth kind of change, with no instrument. Four: a predetermined change control plan for CMC. No mechanism; Q twelve's protocol is the closest, and episode eight found the sentence that lets it repeat and nobody who has written one for a retrain. Five: which human, with which competence, for human-in-the-loop. No document says; episode seven. Six: the pipeline from plant data to fit-for-use data. Assumed by every framework, specified by none; episode six.

30:30 Sam Notice what the six have in common. Four of them are the agent. Self-learning, generative, vendor-dependent, human-supervised: that is a description of the deviation assistant, and the rulebook's four biggest holes are its four defining properties. Each classical model falls into one hole. The agent falls into all of them. That isn't an accident, and it's why the season exists.

30:55 Sarah And the other two are the rulebook's oldest questions in new clothes: notification of model updates, which FDA asked in twenty twenty-three and ICH repeated in twenty twenty-five; and data fit for use, which is the twenty eighteen data integrity guidance with the word relevance added.

Scorecard: four systems, three columns

31:13 Sam The slide. Four rows, three columns: what a site can do today with confidence, what it must wait for, by name, and what it should do anyway. Soft sensor.

31:24 Sarah Do today: a static, versioned soft sensor as an operator advisory or a contributing control is inside every framework: FDA's credibility steps, the Points to Consider's medium impact, Annex Twenty-two's scope. Wait for: the reporting category for a retrain, which is CDER's promised manufacturing guidance or the ICH process-models guideline, whichever lands first. Do anyway: write the intended-use document with the input sample space, per Annex Twenty-two clause three point one, and the lifecycle plan with metrics and retest triggers, per FDA's draft. They are the same artefact under two names, and every future document will ask for them.

32:08 Sam Batch model.

32:09 Sarah Do today: multivariate batch monitoring as a trending and alerting tool is mature under the Points to Consider, and its contribution plots are the explainability Annex Twenty-two clause eight asks for. Wait for: the ICH continuous process verification topic, which is what would let a dossier lean on it; and, if it ever replaces a release test, the tier-three treatment with parallel testing. Do anyway: hold out whole campaigns as the independent test set and document every golden-batch exclusion, per episodes five and six; the monitoring data are the one evidence base for both the retest and the reporting decision.

32:48 Sam Vision system.

32:49 Sarah Do today: this is FDA's own example. A fill-volume vision system with the release-sample test kept as the orthogonal control is medium model risk in FDA's draft and squarely inside Annex Twenty-two's scope as a static, deterministic model. Wait for: nothing on the model itself; on the vendor, the instrument for a pushed update, which no document on the calendar promises. Do anyway: pin the version, contract for notice, keep a physical regression set of vials and run it on every vendor release, per episode eight; and build the confidence threshold that sends borderline vials to undecided, per clause nine.

33:30 Sam And the agent. Take your time.

33:32 Sarah Do today, with confidence: nothing in critical use in an EU-inspected plant. Draft Annex Twenty-two says generative models should not be used in critical GMP applications. No revised text has changed that yet — but EMA's consultation summary reports support for enabling them under controls, and the workshop was built to define those controls, so that line is the one most likely to move. FDA's draft has no text on it beyond the operational-efficiency carve-out, which holds only until the output shapes a quality decision. What a site can do today is deploy it in uses it is prepared to argue are non-critical, with a human in the loop, and with the audit trail and access controls the Annex Eleven revision asks of any computerised system.

34:20 Sam Wait for.

34:21 Sarah Three things, none dated. A definition of critical for a documentation use, which only the annex's final text or an EMA follow-up could give. Any FDA text at all on generative AI in manufacturing, which the CDER agenda item might be. And an instrument for a vendor deprecating the model you validated, which nothing on the calendar promises. The joint principles cover the agent in the sense that they cover everything; they do not mention it.

34:48 Sam Do anyway.

34:49 Sarah Start where the classical models start. The data discipline the agent needs, provenance and version control of what it reads, access control, an audit trail of what it read to reach a conclusion, is the Annex Eleven discipline the soft sensor and the vision system already need. The human it needs is the one episode seven specified: which human, which competence, which inputs, measured how, with the signature kept human. And the test set it needs is the adjudicated set of historical deviations episode five described. None of that waits on a document.

35:25 Sam And the line I'd write on the slide under the agent, as the character. The non-critical line is the site's to draw and defend, and it will be inspected before any document defines it. So draw it narrow, write down why, and instrument the human. The plant that can show an inspector what the agent read, what it drafted, who changed what and why, is ahead of the rulebook. The plant that can't is behind it, whatever the rulebook ends up saying.

Are we there yet? Sam's verdict

35:52 Sarah The season's question, then. Sam, are we there yet? I've given you what the documents support. The verdict is yours.

35:59 Sam Three answers, and they're the character's synthesis, offered for the listener to test. On vocabulary, nearly. Context of use, model risk, fit for use, lifecycle, the human-AI team: shared by FDA, EMA, ICH and industry, and signed by two agencies on one page in January. A site that writes its AI documents in those words will be understood in every region. That was not true when the classical models were validated.

36:27 Sarah On instruments.

36:29 Sam No. The binding text is a draft. The FDA framework is a draft. The ICH topic is a reflection paper. The change-control instrument for a model that retrains is a sentence in Q twelve nobody has used, and for a model that learns, or a vendor that pushes, there is nothing. The two agencies that signed the principles disagree in writing on whether a self-updating model belongs in a critical step. Convergence on words, divergence on mechanisms, and the mechanisms are what a site has to file.

37:00 Sarah And on the plant floor?

37:02 Sam The honest answer: the rulebook is ahead of most data readiness. Every framework tonight assumes the basement is dry: provenance, context, versions, completeness, relevance. Most plants have a historian and a good intention. The thing really deciding what can be built is not Annex Twenty-two; it's whether you can regenerate a training set from raw records and say who has seen the test set. And the agent will find that out first, because it reads everything. That's the season's refrain, and it's mine. So: there on vocabulary, not on instruments, and the floor decides.

So what for biomanufacturing

37:40 Sam So what for biomanufacturing: three habits to leave the season with, opinionated and labelled. First, a watchlist with the seven dated rows Sarah read, reviewed monthly, owned by one person in regulatory CMC, with a column for what we would change if it lands. Not a slide; a page that gets a date stamp every month.

37:58 Sarah Second?

37:59 Sam Second, a docket-comment habit, because the drafts are shaped by whoever shows up. Thirteen hundred comments moved nothing at the workshop, which tells me the arguments have to be better, not more numerous. The middle tier episode three found missing, a critical application with low model influence and strong intervening controls, is the argument worth making. When CDER's draft appears, comment on the reporting categories. When the ICH topic is proposed, the QIG holds a listen-and-learn meeting every year; that's the room.

38:28 Sarah Third.

38:30 Sam Third, a one-page what-we-do-today position per use case. The tier, from episode three. The instrument for each of the four kinds of change, from episode eight. The human, by competence, from episode seven. The data-readiness statement, from episode six. The intended use, from episode five. That page is what an inspector asks for, what FDA's summary in the application condenses, and what you update when a watchlist row lands. Four systems, four pages, done before Friday.

39:02 Sarah Who has to be in the room, from the documents. The joint principles' fifth: multidisciplinary expertise covering both the AI technology and its context of use, throughout the life cycle. Annex Twenty-two's cast: process experts, quality, data science, IT. The ICH paper puts the maturity of a site's quality system next to model risk as what notification will depend on, so the quality system's maturity is now a regulatory variable, and QA owns it. And the EU's dates come out of public workplans, so regulatory CMC owns the watchlist.

39:42 Sam And then the question turns. Nine episodes on whether the rulebook is there. It's close enough to plan for. The question I'd take into next season is the one under all of it: is the data there yet.

Recap: the season in three

39:52 Sam Three things, and then the season. Sarah.

39:55 Sarah First, the vocabulary has converged. Context of use, model risk, fit for use, lifecycle, the human-AI team: two agencies on one page in January, ICH pointing at the same words, industry aligning to them. Write in those words.

40:14 Sarah Second, the instruments haven't. The GMP annex, the FDA framework and the ICH topic are a draft, a draft and a reflection paper; the calendar has one law and six targets; the change-control instrument for AI does not exist; the sandbox industry wants has not been built. Plan for the shape, not the date.

40:36 Sam Third, mine: the six open questions are mostly one system. The agent is self-learning, generative, vendor-dependent and human-supervised, and those are the rulebook's four holes. Draw the non-critical line narrow, instrument the human, and start with the data discipline the classical models already need. Are we there yet? On words, nearly. On mechanisms, no. On the floor, the basement decides.

The reading list

41:04 Sam One more thing before we go, for whoever's about to get back from a run. We said forty documents. What did we actually read — and if someone has an evening a week, what order should they set about reading them in?

41:15 Sarah We read about twenty-five of the forty-odd in the corpus closely; the rest are strategy papers, position statements and the device-world texts we cited rather than read. In the order I'd give a colleague. One: FDA's January twenty twenty-five draft on AI to support regulatory decision-making — every episode but one leaned on it; it's the vocabulary. Two: draft Annex Twenty-two — six episodes; the text closest to what an EU inspector will ask for, and the one to keep watching while EMA weighs the thirteen hundred comments. Three: EMA's reflection paper on AI in the medicinal product lifecycle — the risk axes and the system risk management plan. Four: BioPhorum's June twenty twenty-six risk guidance — industry's synthesis, and the one with a grading built for a plant, not a filing. Five: the EU AI Act, but only Article ten on data, Article fourteen on human oversight, and enough of the scope to know why it mostly isn't you. Six: ICH's reflection paper on advanced manufacturing — short, and it names the terms a future ICH topic would have to harmonise. Seven: the Annex Eleven revision with the Chapter Four draft — your data pipeline falls under it as a computerised system. Eight: the EMA–FDA guiding principles — two pages; read them with the FDA draft open. Then the tools when you need them: Q twelve for change, the Q eight-nine-ten Points to Consider for risk, FDA's data integrity questions and answers and PIC/S zero four one for the basement, Computer Software Assurance, GMLP, and FDA's device credibility and PCCP guidances for where the vocabulary came from. These are linked, in that order, at the end of this episode's show notes.

43:20 Sam If you only read two: the FDA draft and Annex Twenty-two, together, in one sitting. They're written by two agencies that had clearly read each other. Everything else in the season is the argument about the gap between them.

43:31 Sam That's season one: nine questions, one rulebook, read while it was being rewritten. Thank you for walking with us. Check the sources. Next season asks the question under this one: is the data there yet.