
Computer Systems Validation × FDA × AI
How AI Changes the Core of FDA’s Idea of Computer Systems Validation
- FDA AI
- GxP AI
- CSA
- Part 11
- Model risk
- HITL

FDA’s idea of a computer system assumed software that changes when a human ships a version. Generative AI and machine learning change when data changes, when a prompt changes, when a vendor swaps a foundation model. That breaks IQ/OQ/PQ as the whole story. CSA was the first crack. AI is the canyon.
Predetermined change control plans from the SaMD conversation are leaking into manufacturing and quality AI. Training data, RAG corpora, and prompt logs are GxP records if they touch a GxP decision. Human-in-the-loop is a control, not a slogan. Model monitoring is periodic review that never sleeps. Part 11 audit trails must say who approved a gold set. If you cannot name those objects, you do not have a validation strategy. You have a demo.
What we will and will not automate
Document classification with a human release decision: in scope. Visual inspection with a challenge set and a fail-safe: in scope. Unattended batch-release language from a copilot: not until CSA and the QP say otherwise. SR Soft staffs that line. We do not staff “the model said so.”

- 01
Intended use sentence
What decision. What harm if wrong.
- 02
Data integrity on the corpus
ALCOA+ for gold sets and prompts.
- 03
HITL as a named control
Who. When. What they see. What they cannot skip.
- 04
Monitoring
Drift, hallucination on the actual process, stop conditions.
- 05
Change
Vendor model swap is a change. Prompt edit is a change.
- 06
S/4 placement
Joule beside release, not inside it, until QA signs.
Evidence objects per AI system
We do not send a data scientist to write a protocol. We send an applied scientist plus a CSV/CSA lead plus the SAP or MES owner of intended use. Fortune 500 quality organizations buy that cell for document AI, visual inspection, and deviation copilots. We file the visas. We write the intended-use sentence first.
The objects the V-model never named
A foundation-model swap is a change. A prompt edit is a change. A gold-set revision is a GxP record. Drift is periodic review that does not wait for the calendar. HITL must name who, what they see, and what they cannot skip. If the copilot can influence a GxP decision and you cannot produce those objects, you have a demo in a regulated process. We will not staff that as “innovation.”
Joule beside S/4 release, not inside it, until QA and the QP sign. Datasphere gold sets with ALCOA+. Integration Suite audit of model calls. That is the GxP-AI lane on our S/4 practice. Document AI and visual inspection with challenge sets are in scope. Unattended release language is not.
