← Blog

Pharmaceutical AI Audit Trails Follow the Predicate Rule, Not the Tool

Parminder Singh
Parminder Singh··5 min read
Summarize with AI

FDA guidance states that the agency intends to interpret the scope of 21 CFR Part 11 narrowly, applying it to records maintained electronically in place of paper and relied on to perform regulated activities. That scoping test decides whether an AI interaction needs a Part 11 audit trail. This article works through the test, the enforcement discretion positions FDA has stated and the request-level evidence a sponsor needs regardless of how Part 11 lands.

Industry Verticalsai-governanceai-compliancepharmaceuticalsauditdata-protection
Pharmaceutical AI Audit Trails Follow the Predicate Rule, Not the Tool

FDA's guidance on Part 11 scope and application states that "the Agency intends to interpret the scope of part 11 narrowly." Part 11 reaches records "required to be maintained under predicate rule requirements and that are maintained in electronic format in place of paper format," records kept electronically and "relied on to perform regulated activities," electronic records submitted to FDA and electronic signatures equivalent to handwritten ones. AI audit trail pharmaceuticals scoping therefore begins with the predicate rule and the record, not with the AI tool.

That ordering saves a lot of argument. A model used to draft an internal brainstorming note is not in scope because no predicate rule requires that note. A model whose output is relied on in a regulated activity brings the resulting record into the analysis.

TL;DR

  • Part 11 scope follows the predicate rule and whether an electronic record replaces paper or is relied on for a regulated activity.
  • FDA has stated enforcement discretion on specific Part 11 requirements for validation, computer-generated time-stamped audit trails and protection of records.
  • Enforcement discretion does not relieve predicate rule obligations for record retention and availability.
  • Independent of Part 11, a sponsor needs per-request records showing identity, data class, destination and policy decision for AI traffic carrying regulated or patient data.

Apply the scoping test record by record

The FDA guidance on Part 11 scope and application gives a workable sequence. Identify the predicate rule that requires the record. Determine whether the record is maintained electronically in place of paper. Determine whether it is relied on to perform a regulated activity. The guidance also notes that records generated electronically but printed to paper, where the paper version is the one relied on, generally do not trigger Part 11.

Run that sequence across the AI uses in the organization and the list sorts itself quickly. A model summarizing adverse event narratives that feed a safety report touches a record a predicate rule requires. A model proposing candidate protocol text that a human rewrites before any regulated record exists does not.

Document the reasoning per use case with a date and an owner, because the scoping decision is itself the artifact an inspector will question first.

Enforcement discretion is narrower than it sounds

FDA states that it will "exercise enforcement discretion regarding specific part 11 requirements for validation," and similar discretion "regarding specific part 11 requirements related to computer-generated, time-stamped audit trails" and the protection of records. Each position carries a condition.

On validation, the guidance recommends that decisions "take into account the impact the systems have on your ability to meet predicate rule requirements." On records, it states that organizations must still "comply with all applicable predicate rule requirements for record retention and availability."

So the discretion is about Part 11's specific technical mandates, and the underlying predicate obligation stays intact. A sponsor that reads the discretion as permission to keep no AI interaction records has misread it, because the predicate rule still requires the record to exist and be available.

GxP data reaches models through three paths

Regulated activity data moves toward models by three routes, and they need different evidence. An internal validated application calls a model endpoint as part of a defined process. A scientist or safety reviewer uses a browser assistant with data copied from a regulated system. A vendor platform performs inference inside its own environment on data the sponsor submitted.

The second path is the one that most often carries patient-level narratives and the one least likely to appear in a validation package. Covering it means inspecting AI-bound HTTP traffic from managed devices and applying policy to the content.

Pharma GxP AI compliance covers the validation framing. HIPAA AI audit trail covers the overlapping obligation where protected health information is involved.

Four fields that support an inspection

A per-request record carries the fields an inspector can test. The authenticated identity of the user or service that made the request, from the organizational directory rather than a shared application credential. The classification of the content, including whether patient-identifiable or trade-secret material was detected. The resolved destination model and environment. The policy version in force and the decision.

The scene that decides this is a room with an inspector, a laptop and one sampled interaction from eighteen months ago. Either the four fields are present for that interaction or the answer becomes a description of intended behavior, which is the weakest position a sponsor can occupy in an inspection.

Independence of the record matters under inspection

An audit trail produced and held by the same application whose behavior is being examined is weaker evidence than one written on a separate path. Part 11's own framing of audit trails emphasizes computer generation and time stamping for exactly this reason.

For AI traffic, writing the per-decision record at an enforcement point outside the calling application gives that separation without modifying every validated system. Signed audit logs for AI requests covers the mechanism, and AI audit trail requirements by regulation covers how other regimes express the same requirement.

Retention follows the predicate rule, which in clinical and safety contexts commonly means years rather than the default retention a logging platform ships with.

Boundaries worth stating in the control narrative

An HTTP enforcement point covers model-bound traffic from applications and managed devices. It does not cover a model running locally inside a validated instrument, inference embedded in a vendor's own platform or a researcher's personal device outside management.

Name those exclusions with the evidence source for each. The NIST AI Risk Management Framework covers documented treatment of residual risk under MANAGE, which is where an honest exclusion list belongs.

DeepInspect

DeepInspect is a stateless proxy for authenticated HTTP traffic between enterprise users or agents and LLM endpoints. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding, and every permit, redaction, reroute or block produces a signed per-decision record outside the calling application's write path.

For a pharmaceutical sponsor, that produces an inspection-ready record of model-bound traffic on a write path the operating application does not control. DeepInspect does not perform computerized system validation, make the Part 11 scoping determination, cover instrument-local inference or replace quality oversight. Book a demo today.

Frequently asked questions

Does Part 11 apply to a generative AI assistant used in a GxP environment?

It depends on the record, not the assistant. Identify the predicate rule requiring the record, determine whether the record is kept electronically in place of paper and whether it is relied on to perform a regulated activity. FDA has stated it intends to interpret Part 11 scope narrowly, so document the scoping decision per use case with the reasoning and the date.

What does FDA's enforcement discretion on audit trails mean in practice?

FDA has stated it will exercise enforcement discretion regarding specific Part 11 requirements related to computer-generated, time-stamped audit trails, while requiring compliance with underlying predicate rule documentation needs. The practical reading is that the predicate rule still determines what must be recorded, retained and made available.

How do we handle patient narratives pasted into a browser assistant?

Treat it as a flow requiring detection before transmission. Inspect AI-bound requests from managed devices for patient-identifiable content, block or redact it, record the detection and report that population separately from application-mediated traffic so the coverage claim stays accurate.

Who owns the AI scoping decision?

Quality assurance owns the Part 11 and predicate rule determination, with input from the system owner and IT on how the record is produced and retained. Record the named owner and the date, and revisit the decision when the AI use changes or the vendor ships a capability that alters what the record contains.