If your team has already used a generative AI tool to draft SOPs or master batch records, you are probably asking one of two questions. Either "are we in trouble?" or "how do we make this defensible before an investigator asks?" I get both, and in my view the honest answer to the first is usually "not yet, but you need to be able to show your work."
FDA does not prohibit AI-assisted drafting. What it enforces are the existing CGMP requirements for how a procedure or record gets written, checked, approved, and followed. A document that meets those requirements is acceptable whether a person typed it, copied it from a template, or edited it from a chatbot's first pass. A document that skips them is a deficiency regardless of the tool. The difference is that AI makes certain failures much easier to produce, so your controls have to be aimed at those failures.
Does FDA Allow AI to Draft SOPs and Batch Records?
Nothing in 21 CFR Part 210 or 211 says who or what has to produce the first draft. 21 CFR 211.100(a) requires written production and process control procedures that are "drafted, reviewed, and approved by the appropriate organizational units and reviewed and approved by the quality control unit." The regulation cares about the review and approval, and about the procedure assuring that the product has the identity, strength, quality, and purity it purports to have.
That matters because it tells you where the accountability sits. Under 21 CFR 211.22(c), the quality control unit is responsible for approving or rejecting all procedures or specifications impacting identity, strength, quality, and purity. An AI tool cannot hold that responsibility, so the approval has to be a real human decision made by someone qualified under 21 CFR 211.25(a), which requires the education, training, and experience to perform the assigned function.
The same logic applies outside drug GMP. For dietary supplements, 21 CFR 111.205 requires a master manufacturing record for each unique formulation and 21 CFR 111.255 requires a batch production record for each batch. The tool changes. The expectation that a qualified person owns the content does not.
What Do the Regulations Actually Require of an AI-Drafted Document?
The table below maps the core requirements to what they mean when a language model produced the first draft.
| Requirement | Citation | What it means for an AI-drafted document |
|---|---|---|
| Procedures drafted, reviewed, approved by organizational units and the quality unit | 21 CFR 211.100(a) | A named, qualified author owns the draft; QA approval is a genuine review, not a signature on a polished-looking document |
| Quality unit approves procedures affecting product quality | 21 CFR 211.22(c) | Reviewer needs the competence to catch a plausible but wrong statement |
| Personnel have education, training, experience | 21 CFR 211.25(a) | Authors and reviewers are trained on the AI use procedure and on the product |
| Master record prepared and signed by one person, independently checked by a second | 21 CFR 211.186(a) | The "second person" check must be independent of the AI and of the first person's reliance on it |
| Batch record documents each significant step and identifies who performed and checked it | 21 CFR 211.188(b) | AI must not touch executed batch data; the template is the only place it can help |
| Written procedures followed and documented at the time of performance; deviations recorded and justified | 21 CFR 211.100(b) | If the procedure was wrong because the AI invented a step, the deviation trail will expose it |
| Computer systems controlled and checked for accuracy | 21 CFR 211.68(b) | Applies if the AI is part of a system that produces or controls records |
| Validation, audit trails, and documentation controls for electronic records | 21 CFR 11.10(a), (e), (k) | Applies where electronic records are created or maintained under a predicate rule |
I would put that table in front of your QA team before you write a single control. It keeps the conversation anchored to what the regulation says rather than to what feels risky about AI.
Where AI Drafting Goes Wrong in a GMP Setting
The failure modes are specific, and once you can name them you can build checks that target them.
Invented specifics. A language model will produce a hold time, a mixing speed, a temperature range, or an acceptance criterion that looks entirely reasonable and has no connection to your validated process. It does not know the value is made up, and neither will a reviewer skimming for grammar.
Borrowed content from the wrong context. Ask for a cleaning procedure and you may get steps drawn from a different dosage form, a different regulatory framework, or a different company's equipment. The result reads fluently and is wrong for your line.
Drift from the validated state. Your process validation and your approved specifications are the source of truth. An AI draft built from a general description of the process, instead of from the controlled documents, can quietly diverge from them. 21 CFR 211.100(b) requires written procedures to be followed and any deviation to be recorded and justified, so a procedure that diverges from the validated process puts your people in the position of following the document and breaking the process.
Missing the things nobody wrote down. Experienced authors put in steps because of a past deviation, a line quirk, or an inspection finding. A model has no memory of those, so the draft is often cleaner and less safe than the SOP it replaces.
Calculation and reconciliation errors in batch records. For yield, 21 CFR 211.103 requires actual yields and percentages of theoretical yield to be determined at the end of each appropriate phase. A formula embedded in an AI-generated template can be subtly wrong and still look correct on the page.
None of these are exotic. They are the same errors a rushed human author makes, produced faster and with more confidence. That is the real change AI brings, and it is why I think the review step needs to be redesigned rather than just retained.
Is the AI Tool Itself a GMP System That Needs Validation?
This is the question that trips up most teams, and the answer depends on how the tool is used.
If the AI is a drafting aid outside your quality system, the official record is the approved document in your document management system, and the tool never creates, modifies, or stores a GMP record. In my view, the risk is managed through the human review and approval controls above, and you do not need to validate the chat tool the way you would validate a LIMS. You do need a procedure that says how it may be used.
If the AI is built into the system that creates the record, for example a batch record platform that generates steps and stores them as the controlled version, then 21 CFR 211.68 and, for electronic records and signatures, Part 11 are in play. 21 CFR 11.10(a) calls for validation to ensure accuracy, reliability, and consistent intended performance, and 11.10(e) calls for secure, computer-generated, time-stamped audit trails. A model whose behavior changes when the vendor updates it makes that validation harder, which is why I tell clients to ask vendors how model versions are pinned and how changes are notified.
The practical test I use is simple. Can you point to the point in the process where a qualified human accepted responsibility for the content, and can you show what the approved document said at that moment? If yes, you are in a defensible position. If the AI output flows into a controlled record without that point, you have a validation problem and a data integrity problem.
What Has FDA Said About AI, and Does It Cover Document Drafting?
FDA's January 2025 draft guidance, Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products, sets out a risk-based credibility assessment framework with seven steps. Its scope is AI used to produce information supporting regulatory decisions about safety, effectiveness, or quality. As I read it, the draft excludes AI used for operational efficiencies, such as internal workflows, where the use does not affect patient safety, drug quality, or the reliability of results. Check the exact scope wording in the primary document on FDA's website before you rely on this summary.
I read that carefully, because the carve-out is conditional. A drafting aid that produces a communications memo sits comfortably outside it. A drafting aid that produces the instructions operators follow to make a product is harder to describe as having no effect on drug quality. My advice is to borrow the logic of the framework (define the context of use, assess the risk the output poses, and show evidence the output is credible) even though the guidance may not formally apply to you. The draft guidance is not a binding requirement, but it shows how the agency thinks about AI.
In Europe, the draft Annex 22 on artificial intelligence to the EU GMP Guidelines (EudraLex Volume 4) was released for public consultation in 2025. As I understand the draft, it limits critical GMP applications to static, deterministic models and excludes generative AI and large language models from them. For non-critical applications it contemplates their use with a qualified human in the loop. It is a draft and may change, so confirm the exact wording and consultation date in the primary document on the European Commission's EudraLex page. If you export to the EU or inspect to EU expectations, it suggests where the line is likely to land. Drafting support with accountable human review looks tolerable, and autonomous decisions inside critical processes do not.
How Do You Make AI-Drafted SOPs and Batch Records Acceptable to FDA?
Here is the control set I would put in place, in the order I would build it.
1. Write an AI use procedure that defines permitted and prohibited uses
Say plainly what the tool can do (produce a first draft, reformat, summarize a change, check for internal inconsistency) and what it cannot do (generate process parameters, approve content, edit executed batch records, make deviation or release decisions). This procedure is the first thing an investigator will ask for, and it is the strongest evidence you had control from the start. If you are building the broader governance around it, ISO/IEC 42001:2023 clause 6.1.2 on AI risk assessment and clause 6.1.4 on AI system impact assessment give you a recognized structure to work from, and our page on ISO 42001 for GMP manufacturers explains how those clauses connect to a GMP quality system. Certify Consulting sells ISO 42001 services, so weigh that accordingly. ISO 42001 is an AI management system standard. It can structure your AI governance, but it is not a 21 CFR 211 requirement and does not demonstrate CGMP compliance.
2. Feed the tool controlled sources and keep process data out of its imagination
Give it your approved specifications, validated parameters, and current SOP as the inputs, and instruct it to flag anything it cannot source instead of filling gaps. Better still, have it produce a draft with bracketed placeholders wherever a value must come from a controlled document. A placeholder is an honest gap. An invented number is a defect that looks finished.
3. Name an accountable human author
The author, not the tool, signs as having drafted the procedure for purposes of 21 CFR 211.100(a). That person must be qualified in the subject matter under 21 CFR 211.25(a) and trained on your AI use procedure. If the author cannot explain why each step is there, the draft should not move forward.
4. Verify against source, line by line
Reviewers should do a documented comparison of every parameter, limit, calculation, and reference against the validated process, the specification, and the equipment qualification. A review comment that says "looks good" does not demonstrate this. A traceability table that shows each critical value and its source does. For batch records, add a specific check of every calculation and every unit of measure.
5. Make QA review independent and informed
The quality unit's approval under 21 CFR 211.22(c) must be a real review. Tell the reviewer the document was AI-assisted, give them the verification record, and train them on the typical AI errors listed earlier. A reviewer who does not know the draft came from a model will review for the errors a person makes and may miss the ones a model makes.
6. Keep the right records, and be deliberate about which
The approved, versioned document is the GMP record. Whether you also retain prompts and raw outputs is a judgment call. I lean toward retaining the verification record and the version history, and keeping prompts for significant or high-risk documents, because they let you reconstruct how a questionable step entered the draft. Decide, write it down, and apply it consistently.
7. Put the tool under change control
Model versions, vendors, and settings change. Treat a material change to the tool the way you would treat a change to any system that influences your documents, consistent with the change management expectations in ICH Q10. Re-verify a sample of outputs after a change.
8. Protect confidential formulation and process data
A public tool that retains your inputs can expose proprietary formulas and process know-how. Use enterprise agreements with defined data handling, or keep sensitive values out of prompts and in your placeholders.
What About Batch Records Specifically?
Batch records deserve their own paragraph because the risk profile is different. A master batch record is a template that gets approved once and used many times, so an error in it replicates across every batch. That is an argument for heavier verification at the master stage. 21 CFR 211.186(a) already requires that the master record be prepared and signed by one person and independently checked and signed by a second, and you should treat the AI as a contributor to the first person's work, never as a substitute for the second person's check.
The executed batch record is a different matter. 21 CFR 211.188(b) requires documentation that each significant step was accomplished, including the identification of the persons performing and checking each step. Those entries are contemporaneous observations by real people. AI should never generate, fill in, summarize into, or "clean up" executed batch data. If someone uses a tool to rewrite an entry after the fact, you have a data integrity problem that no amount of documentation will fix. FDA's December 2018 guidance Data Integrity and Compliance With Drug CGMP: Questions and Answers is the document I would reread with your team before rolling out any of this.
Which Uses of AI Carry Which Level of Risk?
| Use | Risk | Suggested control |
|---|---|---|
| Reformatting or tidying an already approved SOP | Low | Author confirms no change in meaning; normal change control |
| Drafting a new SOP with placeholders for all critical values | Moderate | Source-linked verification table; informed QA review |
| Drafting a master batch record template including calculations | Higher | Independent calculation check, second-person verification under 211.186(a), pilot run before release |
| Generating process parameters or limits | High, generally avoid | Parameters come from validation and specifications only |
| Writing or altering entries in an executed batch record | Prohibited | Not a permitted use under any circumstances |
| AI embedded in a system that stores controlled records | High | Computer system validation, Part 11 controls, vendor change notification |
What If You Already Used AI to Draft Documents?
Many companies are in this position. The remediation is more manageable than people fear, and it starts with an honest inventory.
- Identify every controlled document that had AI involvement. This usually means asking authors directly and promising that the purpose is remediation.
- Risk-rank them using the table above. Begin with anything affecting critical process steps, cleaning, and batch record calculations.
- Run the source verification on each one, documenting the comparison against validated sources, and correct what you find.
- Issue the AI use procedure and train people, so that the next draft is controlled from the beginning.
If you want an outside view of your AI governance gaps, our ISO 42001 gap assessment is one option. It reviews your AI management system against ISO 42001. It does not assess your compliance with 21 CFR 211 or Part 11, and it does not replace the document verification above.
A finding that you discovered, assessed, and corrected is a far better story than a finding that an investigator uncovered. Do not rewrite history or quietly swap documents. Use your change control and deviation systems, and keep the trail.
What Should You Say When an Investigator Asks?
Be direct. If an investigator asks whether AI was used to draft procedures, say yes, show the AI use procedure, and show the verification record for the document in question. Investigators generally respond better to control and candor. They tend to respond poorly to evasion and to discovering after the fact that a tool was involved and no one mentioned it.
The question they are really asking is the same one 21 CFR 211.100(a) asks: did qualified people draft, review, and approve this, and does it assure the product is what it claims to be? If your records answer that question, the tool you used to get to the first draft becomes a minor detail.
I think the companies that handle this well will treat AI as a very fast, very confident junior author whose work always gets checked by someone who knows the process. The ones that struggle will treat it as a shortcut around the check. If you want help building the AI use procedure or checking your remediation plan, contact us and we will talk through where you stand.
Published by Certify Consulting, which provides ISO 42001 consulting services. Last updated: 2026-10-07
Frequently Asked Questions
Is it acceptable to use AI to draft SOPs under FDA GMP rules?
Yes, provided the document goes through the review and approval that 21 CFR 211.100(a) requires. The regulation requires procedures to be drafted, reviewed, and approved by the appropriate organizational units and approved by the quality control unit. It does not specify who or what produces the first draft, so accountability rests with the qualified humans who verify and approve the content.
Do I need to validate ChatGPT or a similar tool if I use it to draft batch records?
If the tool is a drafting aid outside your quality system and never creates, modifies, or stores a GMP record, validation in the LIMS sense is generally not the control that matters. The human verification and approval controls matter. If the AI is built into the system that creates or stores controlled records, 21 CFR 211.68 and 21 CFR Part 11 (including 11.10(a) validation and 11.10(e) audit trails) are in scope.
Can AI fill in or edit executed batch records?
No. 21 CFR 211.188(b) requires documentation that each significant step was accomplished, including who performed and checked it. Executed entries are contemporaneous records by real people, and using AI to generate, summarize into, or rewrite them creates a data integrity problem.
Does FDA's AI guidance apply to AI-drafted SOPs?
FDA's January 2025 draft guidance on AI to support regulatory decision-making for drug and biological products excludes AI used for operational efficiencies that do not affect patient safety, drug quality, or reliability of results. Because SOPs and batch records direct how product is made, it is hard to argue every drafting use has no effect on quality, so I recommend applying its risk-based credibility logic anyway.
What should I do if we already used AI to draft controlled documents?
Inventory every document with AI involvement, risk-rank them, verify each against validated sources and specifications, correct discrepancies through change control, and then issue an AI use procedure and train staff. Document the whole effort so you can show an investigator that you found, assessed, and corrected the issue.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.