Good AI Practice, decoded for the regulated value chain.
A common set of ten guiding principles issued jointly by FDA and the European Medicines Agency to inform, enhance, and promote the responsible use of artificial intelligence for generating evidence across every phase of the drug product life cycle. Here are the ten principles verbatim, what each one means for day-to-day GxP execution, and the standards you use to qualify and define quality AI.
Ten common guiding principles for using AI to generate evidence across the drug product life cycle.
Issued jointly by FDA (CDER & CBER) + EMA — a harmonized position across both regulators.
AI here refers to system-level technologies used to generate or analyze evidence across the drug product life cycle, including nonclinical, clinical, post-marketing, and manufacturing phases.
The principles are a non-binding common framework — a foundation for good practice and consensus standards, not a regulation. Both sponsors and regulators will measure AI use against them.
The principle — and what it means on the floor.
Each principle’s statement is quoted verbatim from the FDA/EMA guidance. The line beneath it — “In GxP practice” — is SPEQ’s interpretation of how the principle lands in a regulated quality system, not FDA/EMA text.
Human-centric by design
The development and use of AI technologies align with ethical and human-centric values.
A human remains accountable for every AI-influenced decision. Patient safety and ethical use — not model convenience — set the boundary for where and how AI is deployed.
Risk-based approach
The development and use of AI technologies follow a risk-based approach with proportionate validation, risk mitigation, and oversight based on the context of use and determined model risk.
The same risk-proportionality that drives ICH Q9(R1) and CSA governs the AI: a model steering a batch-release decision earns far deeper validation than one drafting an internal summary.
Adherence to standards
AI technologies adhere to relevant legal, ethical, technical, scientific, cybersecurity, and regulatory standards, including Good Practices (GxP).
The guidance names GxP explicitly — AI in a regulated workflow inherits the full weight of Part 11 / Annex 11, data integrity, and quality-system expectations rather than sitting outside them.
Clear context of use
AI technologies have a well-defined context of use (role and scope for why it is being used).
Define the intended use before validating — the context of use is the AI equivalent of a validation intended-use statement, and it bounds what the model may and may not be relied upon to do.
Multidisciplinary expertise
Multidisciplinary expertise covering both the AI technology and its context of use are integrated throughout the technology’s life cycle.
Data scientists and the domain SMEs who own the regulated process work the problem together — the model builder cannot judge fitness-for-use alone, and the process owner cannot judge the model alone.
Data governance and documentation
Data source provenance, processing steps, and analytical decisions are documented in a detailed, traceable, and verifiable manner, in line with GxP requirements. Appropriate governance, including privacy and protection for sensitive data, is maintained throughout the technology’s life cycle.
ALCOA+ extends to the training set: provenance, transformations, and analytical choices are traceable and verifiable, and sensitive data carries privacy controls across the whole life cycle.
Model design and development practices
The development of AI technologies follows best practices in model and system design and software engineering and leverages data that is fit-for-use, considering interpretability, explainability, and predictive performance. Good model and system development promotes transparency, reliability, generalizability, and robustness for AI technologies contributing to patient safety.
Software-engineering discipline (design, version control, testing) applied to the model itself — interpretability and robustness are engineered in, not bolted on, when the output touches patient safety.
Risk-based performance assessment
Risk-based performance assessments evaluate the complete system including human-AI interactions, using fit-for-use data and metrics appropriate for the intended context of use, supported by validation of predictive performance through appropriately designed testing and evaluation methods.
Validate the whole system, not just the algorithm — including how humans act on its output — with acceptance metrics chosen for the intended use, mirroring qualification testing against pre-defined criteria.
Life cycle management
Risk-based quality management systems are implemented throughout the AI technologies’ life cycles, including to support capturing, assessing, and addressing issues. The AI technologies undergo scheduled monitoring and periodic re-evaluation to ensure adequate performance (e.g., to address data drift).
AI lives inside the QMS: change control, deviations, CAPA, and periodic review apply — and data drift becomes a monitored, re-qualification-triggering condition, not a silent degradation.
Clear, essential information
Plain language is used to present clear, accessible, and contextually relevant information to the intended audience, including users and patients, regarding the AI technology’s context of use, performance, limitations, underlying data, updates, and interpretability or explainability.
Users and patients get plain-language transparency on what the model does, how well, and where it stops — the AI counterpart of clear labelling and honest limitations reporting.
Principle titles and statements are quoted from the FDA/EMA “Guiding Principles of Good AI Practice in Drug Development” (January 2026). The GxP-practice line under each is a SPEQ interpretation, not FDA or EMA text.
AI is entering every regulated workflow — the question is how to keep it in a state of control.
AI now touches every phase of the life cycle the guidance names — nonclinical, clinical, post-marketing, and manufacturing. It drafts protocols, triages safety signals, models toxicity to reduce animal testing, and increasingly informs process control on the shop floor. The opportunity is real; so is the risk of an unvalidated model quietly steering a regulated decision.
What the FDA/EMA principles make clear is that AI does not get a carve-out from good practice — it inherits it. A model in a GxP workflow carries the same expectations for validation, data integrity, change control, and human accountability as any other system of record. The principles are the “what”; the standards below are the “how” an organization qualifies its AI and defines what “quality AI” means in its own quality system.
The standards that turn principles into an auditable program.
The GAIP principles set expectations; these certifiable and consensus frameworks make them operational — the reference set an enterprise uses to qualify AI systems and define “quality AI” in its own governance.
These are external standards and frameworks maintained by their respective bodies. SPEQ curates the shelf; it does not publish or certify against them.
Good AI Practice, in plain terms.
What is Good AI Practice (GAIP) in drug development?
Good AI Practice refers to the ten “Guiding Principles of Good AI Practice in Drug Development” issued jointly by the FDA (CDER and CBER) and the European Medicines Agency in January 2026. They are a common, non-binding framework for using AI responsibly to generate evidence across the nonclinical, clinical, post-marketing, and manufacturing phases of the drug product life cycle.
Are the FDA/EMA AI principles legally binding?
No. They are a common set of guiding principles — a foundation for good practice and future consensus standards — not a regulation. They are, however, the shared benchmark against which both sponsors and regulators will measure AI use, so aligning to them early is a practical expectation rather than an optional one.
How does GAIP relate to GxP?
GAIP explicitly folds AI into existing Good Practices. Principle 3 requires adherence to relevant standards “including Good Practices (GxP)”, Principle 6 requires data governance “in line with GxP requirements”, and Principle 9 requires risk-based quality management systems across the AI life cycle. In practice this means AI in a regulated workflow inherits Part 11 / Annex 11, data integrity (ALCOA+), and quality-system expectations rather than sitting outside them.
How does an organization qualify or define “quality AI”?
The GAIP principles set the expectations; certifiable and consensus frameworks make them operational. ISO/IEC 42001:2023 provides an auditable AI management system, ISO/IEC 23894:2023 and the NIST AI Risk Management Framework structure AI risk, the FDA/Health Canada/MHRA Good Machine Learning Practice principles cover ML life-cycle rigor, and — for the EU — the AI Act (Regulation (EU) 2024/1689) sets the legal conformity obligations for high-risk AI.
Which disciplines own AI governance inside a quality organization?
AI governance sits mainly with Computer System Validation (CSV/CSA), data integrity and documentation practice (GDocP), and the quality management system (QMS) — with engineering (GEP) where AI drives equipment or process control. SPEQ maps the ten principles across these disciplines so a quality team can locate each expectation in the roles it already runs.
AI still runs on the same disciplines.
The principles fold AI into GxP — validation, data integrity, and the quality system. Explore the disciplines that own AI governance, or see where your program stands today.