What Regulators Have Actually Approved, Cited and Refused in AI-Enabled Manufacturing
Measured at the regulator's own front door, artificial intelligence in drug manufacturing is a rounding error. The gap between that number and the industry conversation is the most useful thing anyone can tell you about this market.
Between its creation in 2014 and December 2025, FDA's Emerging Technology Program accepted 191 proposals. Continuous manufacturing accounted for 72 of them. Novel unit operations took 27, novel analytical technologies 25, aseptic technologies 24, novel dosage forms 15, novel container closure systems 13, and distributed or point-of-care manufacturing 6. The category covering modelling, simulation, machine learning and artificial intelligence accounted for 9. Adam Fisher, staff director in CDER's Office of Pharmaceutical Quality, gave those figures at FDA's Regulatory Education for Industry meeting on 20 May 2026, reported by RAPS and by DCAT.
Nine acceptances across roughly twelve years is fewer than one a year. That is what AI in drug manufacturing looks like when you count it at the place where a regulator writes things down.
The number is not the whole truth, and the next section but one is about why. It is still a better starting point than the adoption percentages circulating in conference decks, because it counts named companies bringing specific technologies to a specific regulator on dated occasions. Most of the alternatives are survey self-report.
- 9 of 191 FDA Emerging Technology Program acceptances since 2014 fall in the modelling, simulation, machine learning and AI category. Continuous manufacturing has 72.
- ETP has graduated exactly one technology in its history: continuous direct compression, accepted in 2015 and graduated on 21 October 2021.
- The AI enforcement that exists is one warning letter, dated 2 April 2026, against a homeopathic manufacturer with insects in the facility. The citation is 21 CFR 211.22(c).
- On 30 August 2026 the binding EU text is still the 2011 Annex 11. Draft Annex 22 cross-references an Annex 11 clause that does not exist in the binding version.
- The best-documented pharmaceutical AI results came from 34 and 50+ deployed use cases at two sites over several years, alongside 3,000 people retrained.
191 acceptances since 2014, and 9 that involve AI
The Emerging Technology Program exists because CDER decided in 2014 that some manufacturing technologies were novel enough that a sponsor should be able to talk to the agency before filing rather than after. Acceptance is not an approval of anything. It is an admission ticket to a conversation. Here is the full distribution reported for the period from inception to December 2025.
| Technology category | Acceptances | Share |
|---|---|---|
| Continuous manufacturing | 72 | 37.7% |
| Novel unit operations | 27 | 14.1% |
| Novel analytical technologies | 25 | 13.1% |
| Aseptic technologies | 24 | 12.6% |
| Novel dosage forms | 15 | 7.9% |
| Novel container closure systems | 13 | 6.8% |
| Modelling, simulation, ML and AI | 9 | 4.7% |
| Distributed or point-of-care manufacturing | 6 | 3.1% |
Continuous manufacturing has produced 17 approved drug applications, the first being Vertex's Orkambi in July 2015. Eleven years, one technology, 72 acceptances, 17 approvals. That is the shape of a manufacturing technology that has genuinely made it through, and it is a slow shape.
The graduation record makes the point harder. FDA's graduated ETP technology page announces a single graduation in the programme's history: continuous direct compression, on 21 October 2021. Graduation means the Emerging Technology Team hands review responsibility for future submissions back to the standard quality assessment offices, because reviewers no longer need specialist help. Continuous direct compression was first accepted into ETP in 2015. Six years elapsed between a technology arriving at the front door and FDA judging its own reviewers competent to assess it unaided, and no second technology has followed. That is the calibration behind any business case assuming a regulator will get comfortable with a novel method inside a planning cycle.
What an ETP acceptance is, and what it is not
The 9 is a real number, and it undercounts. Understanding exactly how it undercounts is the difference between using it well and misusing it.
ETP is voluntary, and it is for technology novel enough to need pre-submission engagement on a filing. That scopes it tightly. An AI model that sets or controls a critical process parameter, or replaces a release test, ends up in Module 3 and plausibly ends up at ETP. An AI system that drafts deviation narratives, triages complaint text, schedules maintenance or answers questions about an SOP appears in no dossier and has no reason to visit ETP at all. Neither does a model whose sponsor judged it insufficiently novel to be worth the conversation.
So the 9 measures one thing precisely: AI that a sponsor believed was novel enough, and close enough to the regulatory filing, to be worth pre-clearing with FDA. It measures nothing about the population of models running in quality systems, MES layers and lab informatics across the industry, which is certainly larger by orders of magnitude.
That distinction is not a weakening of the argument. It is the argument. AI deployed in pharmaceutical manufacturing today clusters almost entirely in the space where no filing is affected and no regulator needs to be told, because that is where the compliance burden is survivable. When someone says AI is transforming pharmaceutical manufacturing, the useful question is which side of that line the transformation sits on. Nine acceptances in twelve years answers it: not the filing side.
What FDA has cited: the Purolea letter of 2 April 2026
There is now exactly one piece of published FDA enforcement in which AI use is broken out as its own deficiency in a drug CGMP context. DLA Piper describes it as the first time FDA cited a drug manufacturer for improper reliance on AI, and ECA characterises it the same way. Those are their characterisations, not a claim FDA itself makes in the document.
The document is warning letter 320-26-58, issued by CDER on 2 April 2026 to Purolea Cosmetics Lab of Livonia, Michigan, following an inspection from 28 to 30 October 2025. FDA's live page for the letter returned a 404 when checked on 30 August 2026, and Wayback Machine records show the URL began returning a redirect after 11 July 2026; the text quoted here is from the archived copy captured on 8 June 2026.
The letter carries a section headed, in full, "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing." Its substance is short:
During the FDA inspection of your drug manufacturing facility, you stated to FDA investigators that you utilized artificial intelligence (AI) agents (b)(4) to help your firm comply with FDA regulations. Specifically, you used AI to create drug product specifications, procedures, and master production or control records to be in compliance with FDA requirements. If you use AI as an aid in document creation, you must review the AI generated documents to ensure they were accurate and actually compliant with CGMP. Your failure to do so is a violation of 21 CFR 211.22(c).
Then the sentence that made the letter travel. FDA had told the firm it had not conducted process validation before distributing product, as 21 CFR 211.100 requires. The letter records the response: "You replied that you were not aware of the legal requirement, as the AI agent you used (b)(4), never told you it was required."
Two things about this letter get consistently overstated, and both matter for anyone quoting it in a steering committee.
First, this is not a Pharma 4.0 site. Purolea made homeopathic products, including two marketed for shingles and genital herpes that FDA treated as unapproved new drugs. The same letter records insects, filth, leaves and clutter in the facility, a docking bay door opening straight onto the manufacturing area, no microbiological testing of finished product, and reliance on supplier certificates of analysis without verification. The firm had already ceased drug production. The AI finding sits inside a general collapse of the quality system, not beside an otherwise competent one.
Second, the legal content is unremarkable and that is precisely its value. FDA did not invent an AI rule. It applied 21 CFR 211.22(c), which has required the quality control unit to approve or reject procedures and specifications since 1978, and 21 CFR 211.100, which requires written production and process control procedures. The agency's closing instruction is the transferable part: if the firm resumes and uses AI for CGMP activities such as developing procedures and specifications, "any output or recommendations from an AI agent must be reviewed and cleared by an authorized human representative of your firm's QU."
The enforcement position, therefore, is not new law. It is that existing quality unit accountability does not move when the drafting moves to a model. Any firm whose AI programme is designed so that a named human in the quality unit approves the output before use is already on the right side of this letter. Any firm whose value case depends on removing that step is not.
What is binding on 30 August 2026, and what is only proposed
More AI programmes are mispriced by confusing draft text with binding text than by anything else. The table below is the state of play as of today.
| Instrument | Status on 30 August 2026 | Key dates |
|---|---|---|
| EudraLex Vol. 4 Annex 11, 2011 revision | Binding | Operative since 30 June 2011 |
| Draft revised Annex 11 and Chapter 4 | Draft, consultation closed | Published 7 July 2025, comments closed 7 October 2025 |
| Draft Annex 22, Artificial Intelligence | Draft, consultation closed | Published 7 July 2025, comments closed 7 October 2025 |
| 21 CFR 211.22 and 211.100 | Binding | In force since 1978 |
| FDA AI credibility draft guidance | Draft, non-binding | Issued January 2025, docket FDA-2024-D-4689, comments closed 7 April 2025 |
| EU AI Act, Regulation (EU) 2024/1689 | In force, staged application | Article 5 and Article 4 from 2 February 2025; GPAI from 2 August 2025 |
| Digital Omnibus on AI, Regulation (EU) 2026/1744 | In force | Official Journal 24 July 2026, in force 27 July 2026 |
Three of those rows need a sentence each.
FDA's AI guidance is still a draft. The agency's own guidance page, captured on 24 August 2026, still labels it "Draft Guidance for Industry and Other Interested Parties," January 2025, and carries the standard legend: "Not for implementation. Contains non-binding recommendations." Its seven-step credibility assessment framework is a useful structure and it explicitly reaches the manufacturing phase, but nobody is obliged to follow it, and a sponsor who has followed it has not thereby satisfied any requirement.
The EU AI Act is genuinely law, and the deferrals are genuinely law too. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the application date for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products already covered by EU product safety law under Annex I to 2 August 2028. What it did not defer still bites: Article 5 prohibited practices and the Article 4 AI literacy obligation have applied since 2 February 2025, general-purpose AI provider obligations since 2 August 2025, and Article 50 transparency duties from 2 August 2026. If you deferred your AI Act workstream on the strength of a headline about postponement, the literacy and transparency pieces were never in the postponed set.
And then the detail that tells you how young this regulatory architecture is. Draft Annex 22 clause 4.3, headed "No decrease," reads: "The acceptance criteria of a model, should be at least as high as the performance of the process it replaces. This implies, that the performance should be known for the process which is to be replaced by a model (see Annex 11 2.7)." The binding 2011 Annex 11 has no clause 2.7. Its section 2 is a single unnumbered paragraph on personnel, and its numbering runs to 17. The AI annex cross-references a clause that exists only in the draft Annex 11 published beside it. The two documents were designed as a package and neither works properly without the other, which is a structural reason to expect them to be adopted together rather than separately.
What the draft Annex 22 would refuse, and the sentence it hangs on
The draft is six pages long. Ten numbered sections plus a glossary: scope, principles, intended use, acceptance criteria, test data, test data independency, test execution, explainability, confidence, operation. Searching the consultation PDF published on 7 July 2025 on 30 August 2026, the word "agent" appears zero times, "agentic" zero times, and "cost" zero times. This is not a document written with the current market in mind. It is a document about validating a classifier.
Its refusals are stacked in the scope section and each one narrows the last. The annex applies to models that learned from data rather than being explicitly programmed. It applies to static models, and says dynamic models that continuously learn during use "should not be used in critical GMP applications." It applies to models with deterministic output, and says probabilistic models "should not be used in critical GMP applications." Then the conclusion:
Following the above, the document does not apply to Generative AI and Large Language Models (LLM), and such models should not be used in critical GMP applications. If used in non-critical GMP applications, which do not have direct impact on patient safety, product quality or data integrity, personnel with adequate qualification and training should always be responsible for ensuring that the outputs from such models are suitable for the intended use, i.e. a human-in-the-loop (HITL).
Read carefully, the exclusion is narrower than the headlines suggest and the permission is broader. "Critical" is defined in the scope as direct impact on patient safety, product quality or data integrity. Below that line, generative models are contemplated, with a qualified human owning the output. That is where essentially all deployed pharmaceutical language-model work already sits, and it can be kept there by design.
The refusal may also not survive. EMA's GMP/GDP Inspectors Working Group convened a multistakeholder workshop on 30 June and 1 July 2026 specifically to gather expert input on a risk-based approach to generative AI and large language models in GMP, including guardrails as control and mitigation measures. An agency does not run that workshop if it is content with a flat exclusion. Final text has been signalled for delivery to the European Commission in Q4 2026, with no operative date announced. Until then, none of it is enforceable, and the requirement your inspector can actually cite is the 2011 Annex 11 principle that where a computerised system replaces a manual operation "there should be no resultant decrease in product quality, process control or quality assurance."
PreCheck, FRAME and the programmes that do not mention AI
Two FDA initiatives get cited as evidence of regulatory momentum behind manufacturing AI. Both are worth understanding precisely, because neither is about AI.
The PreCheck Pilot Program opened on 1 February 2026 in response to Executive Order 14293. Between 1 February and 1 March 2026 FDA received over 80 requests. On 29 June 2026 the agency announced seven participants: Amneal, Cellares, Eli Lilly, FUJIFILM Biotechnologies, Kriya Therapeutics, Kyowa Kirin and Regeneron, each tied to a named new US facility. FDA describes the scoring as an objective framework weighing products to be manufactured, stage of facility development, timeline to market and innovation in facility development and manufacturing operations.
Reading that press release in full on 30 August 2026, the phrases "artificial intelligence," "machine learning," "digital" and "automation" appear zero times. PreCheck is a domestic capacity and supply chain programme with a facility readiness phase and a pre-approval phase. It is a real acceleration mechanism and not an AI one. Roughly one applicant in twelve was selected, which is worth knowing before advising anyone to apply.
The FRAME initiative is closer to the point. CDER established it to build the regulatory framework for advanced manufacturing, and it prioritised four technologies: end-to-end continuous manufacturing, distributed manufacturing, point-of-care manufacturing and the use of artificial intelligence in manufacturing. FRAME's AI output so far is a discussion paper, Artificial Intelligence in Drug Manufacturing, published in 2023 and explicit that it "is not a draft or final guidance" and is "not intended to convey any current regulation or policy." It raises five areas of consideration: cloud oversight of manufacturing data, the data volumes generated by connected equipment, how AI application in manufacturing should be described to the agency, standards for developing and validating models, and continuously learning systems that adapt to real-time data. Those are questions, and three years on they remain questions. FRAME published proposed ICH guideline work in March 2026, and the 2017 ETP guidance is slated for update by the end of 2026.
The plain reading is that the manufacturing AI framework in the United States is at the discussion-paper stage while the enforcement is at the warning-letter stage. That is an uncomfortable order of events for anyone planning a filing.
The lighthouse numbers: 34 use cases at Wuxi, 50+ at Södertälje
The best-evidenced pharmaceutical manufacturing AI results in the public record are not one system. They are portfolios.
AstraZeneca's Wuxi and Södertälje sites joined the World Economic Forum's Global Lighthouse Network in October 2024. Wuxi deployed 34 fourth industrial revolution use cases, including AI and algorithms, aimed at manufacturing synchronisation, and reported a 55% increase in output, a 44% reduction in lead time, an 80% decrease in non-perfect batches and a 54% improvement in productivity. Södertälje implemented more than 50 solutions including machine learning and optimisation algorithms, alongside upskilling 3,000 employees, and reported a 56% increase in labour productivity and a 67% reduction in development lead times for new products.
| Site | Deployed use cases | Disclosed outcomes |
|---|---|---|
| AstraZeneca Wuxi | 34 4IR use cases | +55% output, -44% lead time, -80% non-perfect batches, +54% productivity |
| AstraZeneca Södertälje | 50+ solutions, 3,000 staff upskilled | +56% labour productivity, -67% development lead time |
Three things to take from this, and none of them is the percentages.
The unit of change is a portfolio, not a product. Thirty-four use cases means 34 intended-use descriptions, 34 sets of acceptance criteria and 34 change control entries under the draft Annex 22 model. That cost structure is dominated by the long tail of small tools, not by one large system.
The second variable at Södertälje is 3,000 people. A site does not retrain 3,000 employees as an afterthought to a software deployment. Where disclosed results exist at this scale, workforce change is inside the number, and a business case carrying the tooling but not the retraining is not comparing like with like.
The outcomes are site operating metrics — output, lead time, batch quality, labour productivity — not model metrics. Nobody published a confusion matrix. If your programme reports accuracy and F1 while the disclosed benchmark reports output and lead time, the two cannot be compared, which is part of why buying one ambitious system is so tempting and so misplaced. That temptation has a specific failure mode in quality workflows, set out in the evidence on why multi-agent architectures degrade deviation investigations.
Why adoption is slow, in the regulator's own words
It is convenient to blame regulators for slow manufacturing innovation. FDA's own strategy document on innovative manufacturing technologies, produced under a PDUFA VII commitment, records something else. Summarising stakeholder feedback from the June 2023 Duke-Margolis workshop, it identifies the major regulatory barrier as a lack of international harmonisation rather than domestic requirements: even with a clear set of FDA expectations, manufacturers remain uncertain about acceptability in foreign markets.
Then it says the barrier that actually decides most cases lies outside its own purview:
Other key barriers to the adoption of innovative manufacturing may lie outside FDA's purview — most notably, financial and commercial considerations. Adopting innovative manufacturing methods entails a significant upfront investment and manufacturers may have limited resources to invest, may not expect a sufficient long-term return on that investment [...]
The document adds that firms may decline to adopt these methods whatever the regulatory position, and that the problem is particularly acute for generic manufacturers on smaller margins. The panel discussion returned to the same theme: hesitancy is due in large part to concerns about commercial viability.
That is the regulator saying, in a published strategy document, that the binding constraint on manufacturing innovation is the business case. It is worth quoting in the room where someone is proposing that clearer AI guidance would produce a wave of adoption. Guidance addresses the second-order barrier. It does not address the first.
The corollary matters for how you scope AI work. Projects that need a filing change carry regulatory risk, multi-market approval risk and a capital profile that has to clear an investment committee. Projects that improve a documented process without touching the dossier carry none of those. The 9 out of 191 is partly a regulatory story and mostly an economic one.
What this means in practice
Classify every model against the criticality line before you fund it. Direct impact on patient safety, product quality or data integrity puts a model inside draft Annex 22's scope and inside the argument about static, deterministic architectures. Everything else is outside. It is a two-hour exercise per use case and it changes the architecture, the validation cost and often the vendor. Doing it after the pilot is how programmes die at the quality gate.
Write the quality unit approval step into the design, not the SOP. The Purolea citation is 21 CFR 211.22(c) and it is binding today in the United States regardless of what Europe does with Annex 22. If an AI system produces specifications, procedures, master production records, batch record content or investigation conclusions, a named quality unit representative approves the output before use, and the record shows it. A system that makes that step tedious will have it bypassed, and the bypass is the finding.
Stop citing draft clauses as requirements in internal documents. A risk assessment that says "Annex 22 requires" is wrong on 30 August 2026 and will be quoted back at you. Write "draft Annex 22, published 7 July 2025, not adopted" and let the sentence carry its own qualification. The same applies to FDA's January 2025 draft guidance, which still carries the non-binding legend. Where you want to design to a draft because you expect adoption, say that explicitly as a business decision.
Budget for the portfolio shape. If the disclosed benchmark is 34 to 50 use cases over several years plus large-scale retraining, a programme built around one flagship system is not a smaller version of that benchmark, it is a different thing. Plan for many small validated tools, a shared validation approach that makes the twentieth one cheap, and a training line in the budget that is not an afterthought.
Know who signs. In practice the sign-off chain for a GMP AI deployment is the process subject matter expert on intended use and acceptance criteria, quality assurance on validation and change control, the system owner on configuration, and the quality unit on any output that becomes a GMP record. Draft Annex 22 clause 2.1 lists that same cast — process SMEs, QA, data scientists, IT and consultants — and requires close cooperation during algorithm selection, training, validation, testing and operation. If your project plan has data science and IT but no named process SME accountable for the intended-use description, you do not have a GMP project yet.
Be sceptical of percentage claims, including the ones above. The lighthouse figures are company-disclosed and reviewed as part of a recognition process, which puts them above the average case study, but they remain self-reported and cover whole sites over years. The investigation-time reductions circulating in this market are overwhelmingly vendor-published. Where a number matters to a decision, ask which document it came from and on what date; if the answer is a slide, treat it as a slide. That is the same habit that separates a defensible deployment from an architecture producing confident, well-documented wrong answers.
The honest summary is short. One warning letter, nine emerging technology acceptances, one graduated technology in twelve years, two draft European instruments that are not law, one draft FDA guidance that is not binding, and two well-documented sites whose results came from doing forty small things properly. Anyone selling you a faster story than that is selling.
Questions people ask about this
- How many AI projects has the FDA Emerging Technology Program accepted?
- Nine. Speaking at FDA's Regulatory Education for Industry meeting on 20 May 2026, CDER's Adam Fisher reported 191 acceptances into the Emerging Technology Program from its 2014 inception to December 2025. Of those, 9 were categorised as modelling, simulation, machine learning or artificial intelligence. Continuous manufacturing accounted for 72.
- Has the FDA issued a warning letter about artificial intelligence?
- Yes. On 2 April 2026 CDER issued warning letter 320-26-58 to Purolea Cosmetics Lab of Livonia, Michigan, following an October 2025 inspection. It carries a section headed "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing" and cites 21 CFR 211.22(c) for failing to review AI-generated specifications, procedures and master production records.
- Is EU GMP Annex 22 on artificial intelligence in force?
- No. On 30 August 2026 the binding EU requirement for computerised systems remains Annex 11 in its 2011 revision, operative since 30 June 2011. Draft Annex 22 and a draft revised Annex 11 were published for consultation on 7 July 2025, the consultation closed on 7 October 2025, and neither has been adopted.
- Does the EU AI Act apply to pharmaceutical manufacturing yet?
- Partly. Prohibited practices under Article 5 and the Article 4 AI literacy duty have applied since 2 February 2025, and general-purpose AI obligations since 2 August 2025. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, moved most standalone high-risk obligations to 2 December 2027 and embedded ones to 2 August 2028.
- What results have pharmaceutical lighthouse sites actually disclosed?
- AstraZeneca's Wuxi site reported 34 fourth industrial revolution use cases producing a 55% output increase, 44% lead time reduction and 80% fall in non-perfect batches. Its Södertälje site reported more than 50 solutions plus 3,000 employees upskilled, yielding 56% higher labour productivity and 67% shorter development lead times.