[ GOOD AI PRACTICE · FDA + EMA · JANUARY 2026 ]
Good AI Practice, decoded for the regulated value chain.
A common set of ten guiding principles issued jointly by FDA and the European Medicines Agency to inform, enhance, and promote the responsible use of artificial intelligence for generating evidence across every phase of the drug product life cycle. Here are the ten principles verbatim, what each one means for day-to-day GxP execution, and the standards you use to qualify and define quality AI.
WHAT
Ten common guiding principles for using AI to generate evidence across the drug product life cycle.
WHO
Issued jointly by FDA (CDER & CBER) + EMA — a harmonized position across both regulators.
SCOPE
AI here refers to system-level technologies used to generate or analyze evidence across the drug product life cycle, including nonclinical, clinical, post-marketing, and manufacturing phases.
STATUS
The principles are a non-binding common framework — a foundation for good practice and consensus standards, not a regulation. Both sponsors and regulators will measure AI use against them.
[ THE TEN PRINCIPLES ]
The principle — and what it means on the floor.
Each principle’s statement is quoted verbatim from the FDA/EMA guidance. The line beneath it — “In GxP practice” — is SPEQ’s interpretation of how the principle lands in a regulated quality system, not FDA/EMA text.
Human-centric by design
The development and use of AI technologies align with ethical and human-centric values.
IN GxP PRACTICE — SPEQ INTERPRETATION
A human remains accountable for every AI-influenced decision. Patient safety and ethical use — not model convenience — set the boundary for where and how AI is deployed.
Risk-based approach
The development and use of AI technologies follow a risk-based approach with proportionate validation, risk mitigation, and oversight based on the context of use and determined model risk.
IN GxP PRACTICE — SPEQ INTERPRETATION
The same risk-proportionality that drives ICH Q9(R1) and CSA governs the AI: a model steering a batch-release decision earns far deeper validation than one drafting an internal summary.
Adherence to standards
AI technologies adhere to relevant legal, ethical, technical, scientific, cybersecurity, and regulatory standards, including Good Practices (GxP).
IN GxP PRACTICE — SPEQ INTERPRETATION
The guidance names GxP explicitly — AI in a regulated workflow inherits the full weight of Part 11 / Annex 11, data integrity, and quality-system expectations rather than sitting outside them.
Clear context of use
AI technologies have a well-defined context of use (role and scope for why it is being used).
IN GxP PRACTICE — SPEQ INTERPRETATION
Define the intended use before validating — the context of use is the AI equivalent of a validation intended-use statement, and it bounds what the model may and may not be relied upon to do.
Multidisciplinary expertise
Multidisciplinary expertise covering both the AI technology and its context of use are integrated throughout the technology’s life cycle.
IN GxP PRACTICE — SPEQ INTERPRETATION
Data scientists and the domain SMEs who own the regulated process work the problem together — the model builder cannot judge fitness-for-use alone, and the process owner cannot judge the model alone.
Data governance and documentation
Data source provenance, processing steps, and analytical decisions are documented in a detailed, traceable, and verifiable manner, in line with GxP requirements. Appropriate governance, including privacy and protection for sensitive data, is maintained throughout the technology’s life cycle.
IN GxP PRACTICE — SPEQ INTERPRETATION
ALCOA+ extends to the training set: provenance, transformations, and analytical choices are traceable and verifiable, and sensitive data carries privacy controls across the whole life cycle.
Model design and development practices
The development of AI technologies follows best practices in model and system design and software engineering and leverages data that is fit-for-use, considering interpretability, explainability, and predictive performance. Good model and system development promotes transparency, reliability, generalizability, and robustness for AI technologies contributing to patient safety.
IN GxP PRACTICE — SPEQ INTERPRETATION
Software-engineering discipline (design, version control, testing) applied to the model itself — interpretability and robustness are engineered in, not bolted on, when the output touches patient safety.
Risk-based performance assessment
Risk-based performance assessments evaluate the complete system including human-AI interactions, using fit-for-use data and metrics appropriate for the intended context of use, supported by validation of predictive performance through appropriately designed testing and evaluation methods.
IN GxP PRACTICE — SPEQ INTERPRETATION
Validate the whole system, not just the algorithm — including how humans act on its output — with acceptance metrics chosen for the intended use, mirroring qualification testing against pre-defined criteria.
Life cycle management
Risk-based quality management systems are implemented throughout the AI technologies’ life cycles, including to support capturing, assessing, and addressing issues. The AI technologies undergo scheduled monitoring and periodic re-evaluation to ensure adequate performance (e.g., to address data drift).
IN GxP PRACTICE — SPEQ INTERPRETATION
AI lives inside the QMS: change control, deviations, CAPA, and periodic review apply — and data drift becomes a monitored, re-qualification-triggering condition, not a silent degradation.
Clear, essential information
Plain language is used to present clear, accessible, and contextually relevant information to the intended audience, including users and patients, regarding the AI technology’s context of use, performance, limitations, underlying data, updates, and interpretability or explainability.
IN GxP PRACTICE — SPEQ INTERPRETATION
Users and patients get plain-language transparency on what the model does, how well, and where it stops — the AI counterpart of clear labelling and honest limitations reporting.
Principle titles and statements are quoted from the FDA/EMA “Guiding Principles of Good AI Practice in Drug Development” (January 2026). The GxP-practice line under each is a SPEQ interpretation, not FDA or EMA text.
[ WHY THIS MATTERS NOW ]
AI is entering every regulated workflow — the question is how to keep it in a state of control.
AI now touches every phase of the life cycle the guidance names — nonclinical, clinical, post-marketing, and manufacturing. It drafts protocols, triages safety signals, models toxicity to reduce animal testing, and increasingly informs process control on the shop floor. The opportunity is real; so is the risk of an unvalidated model quietly steering a regulated decision.
What the FDA/EMA principles make clear is that AI does not get a carve-out from good practice — it inherits it. A model in a GxP workflow carries the same expectations for validation, data integrity, change control, and human accountability as any other system of record. The principles are the “what”; the standards below are the “how” an organization qualifies its AI and defines what “quality AI” means in its own quality system.
[ WHERE THE HUMAN STAYS IN THE LOOP · SPEQ SYNTHESIS ]
The first question practitioners ask: where must a human stay accountable?
Principle 1 makes AI human-centric by design, Principle 2 makes oversight risk-based, and Principle 8 requires assessing the complete system including human-AI interactions. Applied to real GxP workflows, that resolves to a specific control point in each — the place where a person, not the model, remains accountable. The mapping below is a SPEQ interpretation of the published principles, not FDA/EMA text.
Batch-disposition support
WHAT THE AI DOES
Flags batches or parameters for attention and proposes a release/investigate recommendation from process and quality data.
THE HUMAN CONTROL POINT
The disposition decision stays with the authorised person (e.g. the Qualified Person), who reviews the underlying data — the AI output is decision support, never the decision. A model recommendation is not a batch record entry and cannot release product on its own.
Automated visual inspection
WHAT THE AI DOES
Classifies containers as accept/reject for particulates, cosmetic, or fill defects in place of or alongside manual inspection.
THE HUMAN CONTROL POINT
The system is qualified like any inspection equipment against a defined defect library with pre-set accept/reject criteria; humans adjudicate borderline results and monitor escapes, and performance is tracked for drift so degradation triggers re-qualification rather than passing silently.
Deviation triage & classification
WHAT THE AI DOES
Proposes a severity classification, routes the event, or drafts an initial investigation summary.
THE HUMAN CONTROL POINT
A quality decision-maker confirms the classification and owns the investigation and its root cause; the model can propose but cannot classify, downgrade, or close a deviation. The reportability-style judgement stays human because the consequences are.
Pharmacovigilance case intake
WHAT THE AI DOES
Extracts case data from source documents and proposes coding (e.g. MedDRA terms) for individual case safety reports.
THE HUMAN CONTROL POINT
A trained reviewer QCs the extracted fields, and the seriousness and causality assessments remain human medical judgements — not model outputs — because they trigger the expedited-reporting clock. Extraction accelerates intake; it does not replace the safety decision.
Regulatory-intelligence summarisation
WHAT THE AI DOES
Summarises guidance, regulatory changes, or literature for a practitioner audience.
THE HUMAN CONTROL POINT
A subject-matter expert verifies every actionable claim against the primary source before it is relied upon — the summary is a pointer to the source, never a substitute citation, and provenance is preserved. A model summary is evidence to be checked, not a conclusion to adopt.
The use cases, control points, and principle mappings are a SPEQ interpretation applying the FDA/EMA principles to common GxP workflows — not FDA or EMA text, and not an exhaustive list. The principle numbers (P1–P10) reference the ten principles above.
[ HOW TO QUALIFY & DEFINE QUALITY AI ]
The standards that turn principles into an auditable program.
The GAIP principles set expectations; these certifiable and consensus frameworks make them operational — the reference set an enterprise uses to qualify AI systems and define “quality AI” in its own governance.
These are external standards and frameworks maintained by their respective bodies. SPEQ curates the shelf; it does not publish or certify against them.
[ FREQUENTLY ASKED ]
Good AI Practice, in plain terms.
What is Good AI Practice (GAIP) in drug development?
Good AI Practice refers to the ten “Guiding Principles of Good AI Practice in Drug Development” issued jointly by the FDA (CDER and CBER) and the European Medicines Agency in January 2026. They are a common, non-binding framework for using AI responsibly to generate evidence across the nonclinical, clinical, post-marketing, and manufacturing phases of the drug product life cycle.
Are the FDA/EMA AI principles legally binding?
No. They are a common set of guiding principles — a foundation for good practice and future consensus standards — not a regulation. They are, however, the shared benchmark against which both sponsors and regulators will measure AI use, so aligning to them early is a practical expectation rather than an optional one.
How does GAIP relate to GxP?
GAIP explicitly folds AI into existing Good Practices. Principle 3 requires adherence to relevant standards “including Good Practices (GxP)”, Principle 6 requires data governance “in line with GxP requirements”, and Principle 9 requires risk-based quality management systems across the AI life cycle. In practice this means AI in a regulated workflow inherits Part 11 / Annex 11, data integrity (ALCOA+), and quality-system expectations rather than sitting outside them.
How does an organization qualify or define “quality AI”?
The GAIP principles set the expectations; certifiable and consensus frameworks make them operational. ISO/IEC 42001:2023 provides an auditable AI management system, ISO/IEC 23894:2023 and the NIST AI Risk Management Framework structure AI risk, the FDA/Health Canada/MHRA Good Machine Learning Practice principles cover ML life-cycle rigor, and — for the EU — the AI Act (Regulation (EU) 2024/1689) sets the legal conformity obligations for high-risk AI.
Which disciplines own AI governance inside a quality organization?
AI governance sits mainly with Computer System Validation (CSV/CSA), data integrity and documentation practice (GDocP), and the quality management system (QMS) — with engineering (GEP) where AI drives equipment or process control. SPEQ maps the ten principles across these disciplines so a quality team can locate each expectation in the roles it already runs.
AI still runs on the same disciplines.
The principles fold AI into GxP — validation, data integrity, and the quality system. Explore the disciplines that own AI governance, or see where your program stands today.