The prevailing industry narrative around artificial intelligence (AI) governance often presumes that we are entering fundamentally uncharted regulatory territory—territory that will necessitate entirely new compliance architectures. The recent FDA–EMA guidance “Guiding Principles of Good AI Practice” suggests otherwise. It reinforces a more pragmatic conclusion: the existing global GMP framework already provides the structural foundation necessary for governing AI appropriately.
Across 21 CFR Parts 11 and 211, EU GMP Volume 4, and the ICH quality framework (Q9 (R1), Q10, and Q7), the core expectations are explicit and mature: clearly defined human accountability, validated and controlled systems, demonstrable data integrity, lifecycle-based management, and risk-based oversight. These are not emerging concepts; they are embedded in regulatory requirements.
AI is not an exception to this paradigm. It is not a regulatory outlier requiring a parallel governance universe. Rather, it is the next enabling technology to be developed, validated, deployed, and monitored within the established pharmaceutical quality system (PQS).
Part 1 of this series discussed how regulators are converging. Part 2 now supports Lachman’s first hypothesis: If CGMP is inherently current, then AI governance is not reinvention—it’s disciplined application of principles that the industry already knows. The FDA states this in its definition of CGMP:
“The flexibility in these regulations allows companies to use modern technologies and innovative approaches to achieve higher quality through continual improvement. Accordingly, the ‘C’ in CGMP stands for ‘current,’ requiring companies to use technologies and systems that are up-to-date in order to comply with the regulations.”
This part of the series aims to:
- Demonstrate that every FDA–EMA AI principle maps naturally onto longstanding GMP expectations.
- Reduce organizational anxiety by reframing AI governance as an extension—not an exception—within the PQS/QMS.
- Encourage teams to evaluate AI systems through familiar, existing quality lenses.
Why the Guiding Principles Feel Familiar: The Architecture Already Exists
What stands out in the FDA-EMA “Guiding Principles” is not novelty but continuity. Every theme reflects global quality concepts that have shaped pharmaceutical manufacturing for decades:
- Human-centric design is not new. GMP/PQS has long required that technologies be deployed to support people through defined roles, procedures, training, and fit-for-use systems, ensuring that individuals remain capable, informed, and able to intervene when it matters. Regardless of how advanced a system becomes, responsibility rests with qualified personnel. This is central to 21 CFR Part 211 expectations for Quality Units and EU GMP Qualified Persons, and naturally to AI: systems may support or render judgments provided there is risk-based documentation specifying how and when AI may act, and controls that ensure the human–system interface is auditable and reliable.
- Risk-based oversight continues to be the backbone. The foundational logic behind 21 CFR Part 211, EU GMP Annexes 11 and 15, and ICH Q9(R1) is technology-neutral—controls scale with impact and context. AI does not disrupt this principle; it simply expands the range of risks that must be assessed.
- Systems that interact with GMP data must meet GMP rigor. Data integrity, audit trails, secure access, and qualified platforms are not new expectations; they are established requirements under 21 CFR Part 11, EU GMP Annex 11, and ICH Q7 and Q10. AI-generated or AI-influenced data remains GMP data and, therefore, inherits the same standards.
- Model development parallels method and system design. Fit-for-purpose design, documented assumptions, traceability, and ongoing performance verification are long-standing PQS requirements. AI embodies these principles in software rather than in chemistry or equipment, but the underlying quality philosophy is the same.
- Lifecycle change management applies without modification. Model retraining, dataset updates, and algorithm changes are change-controlled events. The mechanisms—impact assessment, approval, and verification—are already embedded in the PQS and require reinforcement, not reinvention.
Are We Seeing the First Steps Toward Global Harmonization?
With FDA, EMA, and ICH expectations already aligned in underlying philosophy, the FDA-EMA “Guiding Principles” raise a natural question: Are we witnessing the early foundation of a globally harmonized AI guideline? Nothing formal has been announced. But the building blocks (ICH Q9(R1), Q10, and Q7, 21 CFR Parts 11 and 211, and EU GMP Volume 4) form a unified, technology neutral quality spine. Whether or not there is a future, dedicated AI guideline, the regulatory trajectory is clear: AI already fits within the global GMP/PQS ecosystem. The system is prepared for, not threatened by, this technology.
Thought Leadership Takeaway: The Biggest Compliance Risk Is Overengineering
One of the most common organizational missteps is treating AI as so exceptional that it requires its own parallel governance universe. This approach creates inconsistency, duplicated effort, and even unintended noncompliance. The FDA–EMA message is the opposite: AI belongs inside the PQS, not beside it. The principles confirm sufficiency, not deficiency, in the current system.
Call to Action: Test Your System, Not a Hypothetical Future
Pick one AI use case and assess it exactly as you would any GMP relevant computerized system:
- Is its intended use clearly defined?
- Is validation scaled to risk?
- Are roles and responsibilities explicit?
- Is lifecycle oversight documented and operational?
If these questions feel familiar, this is evidence the PQS is doing its job. If they feel unfamiliar, this signals where maturity is needed, not where an entirely new framework must be invented.
In Part 3, we’ll move from theory to practice: how to operationalize this alignment without slowing innovation.

