04Manufacturing

FDA's First AI Warning Letter Cites a 1978 Rule

The first FDA drug letter to put artificial intelligence in a deficiency heading did not reach for a new rule. It reached for the paragraph that says the quality unit approves specifications, unchanged since 1978.

On 2 April 2026 FDA's Center for Drug Evaluation and Research issued Warning Letter 320-26-58 to Purolea Cosmetics Lab of Livonia, Michigan, after an inspection of 28 to 30 October 2025. Between the third numbered CGMP violation and the acknowledgement that the firm had stopped making drugs sits an unnumbered section headed "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing."

The section cites two things: 21 CFR 211.22(c) and 21 CFR 211.100. Both were published in the Federal Register on 29 September 1978, at 43 FR 45077, and both carry no amendment note in the current print edition of the Code of Federal Regulations. FDA did not need a new instrument, a guidance, an annex, or a statute with the word artificial in it. It used the paragraph that says the quality control unit approves specifications.

That is why the letter matters beyond a homeopathic micro-manufacturer in Michigan. If the deficiency attaches to the missing human approval rather than to the machine that drafted the document, most AI enforcement will never contain the word AI at all. It will look like every other quality unit finding of the last forty-seven years.

In short
  • Warning Letter 320-26-58, 2 April 2026, cites 21 CFR 211.22(c) for unreviewed AI-generated specifications, procedures and master production records.
  • The AI section is not one of the three numbered CGMP violations. It sits alongside them as a standalone heading, and 211.22(c) is cited nowhere else in the letter.
  • The words "artificial intelligence", "algorithm" and "software" appear zero times in 21 CFR part 211 (1 April 2024 print edition, searched 30 August 2026).
  • The firm's recorded defence was that the AI agent never told them process validation was required. FDA treated silence as no defence at all.
  • On 30 August 2026 the binding EU computerised-systems text remains the 2011 Annex 11. Draft Annex 22 is not law.

What the letter actually says

The letter is eight pages and the AI content is four paragraphs of it. The rest is a conventional small-site CGMP letter: insects and clutter in several areas, a docking bay door that when opened exposed manufacturing to the outside environment, homeopathic product released with no microbiological testing, and supplier certificates of analysis relied on without establishing the supplier's reliability. The three numbered CGMP violations cite 21 CFR 211.165(b); 21 CFR 211.84(d)(1), (d)(2) and (d)(6); and 21 CFR 211.22, the last with sub-references to 211.22(d), 211.22(a) and 211.100(a).

Then the AI section, which reads in relevant part:

During the FDA inspection of your drug manufacturing facility, you stated to FDA investigators that you utilized artificial intelligence (AI) agents (b)(4) to help your firm comply with FDA regulations. Specifically, you used AI to create drug product specifications, procedures, and master production or control records to be in compliance with FDA requirements.

If you use AI as an aid in document creation, you must review the AI generated documents to ensure they were accurate and actually compliant with CGMP. Your failure to do so is a violation of 21 CFR 211.22(c).

And the forward-looking instruction, the sentence quality units should paste into their SOP:

If you plan to resume drug production, and use AI to help with CGMP activities, such as development of procedures and specifications, any output or recommendations from an AI agent must be reviewed and cleared by an authorized human representative of your firm's QU in accordance with section 501(a)(2)(B) of the FD&C Act.

Note what is absent: no request for a model card, no demand for training data provenance, no reference to FDA's own draft AI guidance. The tool is redacted as "(b)(4)" and is irrelevant to the finding.

Why the citation is 21 CFR 211.22(c)

The choice of paragraph is exact, and repays reading the text rather than the summary. 21 CFR 211.22(c) says:

The quality control unit shall have the responsibility for approving or rejecting all procedures or specifications impacting on the identity, strength, quality, and purity of the drug product.

The firm told investigators it had used AI to create specifications, procedures and master production or control records. Those are, word for word, the objects that 211.22(c) makes the quality unit responsible for approving or rejecting. The citation is almost mechanical. FDA did not have to argue that AI is risky, that hallucination is foreseeable, or that a language model is a computerised system requiring validation. It had to observe that documents governed by 211.22(c) entered the quality system without the approval 211.22(c) requires.

Note that 211.22(c) is cited nowhere else in the letter. The general quality unit violation, numbered 3, cites 211.22(a) for batch records not reviewed before release and 211.22(d) for procedures not established or followed. Paragraph (c) was held back for the AI section. That is a drafting choice by the Office of Manufacturing Quality, and it defines the enforcement surface: the record, not the model.

There is a road not taken here. 21 CFR 211.68, "Automatic, mechanical, and electronic equipment", requires at paragraph (b) appropriate controls over computer or related systems so that changes in master production and control records are instituted only by authorised personnel. That is a closer fit to "a machine wrote our master production records" than the quality unit rule is, and FDA did not cite it. The economical reading is that the agency saw a missing human decision rather than an uncontrolled system.

A 1978 rule, and the word that is not in it

The second citation is more interesting, because it is a citation for something the regulation does not say. FDA writes that investigators found "you had not conducted process validation prior to distribution of your drug products, as required under 21 CFR 211.100". But 211.100 is titled "Written procedures; deviations" and does not contain the word validation. Paragraph (a) requires written procedures for production and process control designed to assure that drug products have the identity, strength, quality and purity they purport to possess, reviewed and approved by the quality control unit; paragraph (b) requires those procedures to be followed and documented at the time of performance.

Searching the 1 April 2024 print edition of 21 CFR part 211 on 30 August 2026, the string "validat" occurs five times in the whole part: twice in 211.84(d) on supplier test results, once in 211.94(c) on depyrogenation, once in 211.113(b) on aseptic and sterilisation processes, and once in 211.110(a), which requires control procedures "to monitor the output and to validate the performance of those manufacturing processes that may be responsible for causing variability". None is in 211.100 or 211.22. The same search returns zero occurrences of "artificial intelligence", zero of "algorithm" and zero of "software".

So the modern process validation requirement is a construction placed on 211.100(a) and 211.110(a), and the modern AI requirement is a construction placed on 211.22(c). One construction is decades old, the other is months old, and both rest on text written in 1978. That is the operative fact for anyone building an AI governance framework: you will be inspected against general obligations interpreted at inspection time, not against a checklist you can read in advance. A framework built to satisfy a future AI annex, and only that, is built for the wrong exam.

"The AI agent never told you it was required"

The most quoted sentence in the letter is the firm's own. FDA records that when investigators pointed out that process validation had not been done, "You replied that you were not aware of the legal requirement, as the AI agent you used (b)(4), never told you it was required."

It is easy to read this as a story about a naive operator, and at Purolea's scale it partly is. But the failure mode generalises badly. There are two distinct failures in this letter and they need different controls.

FailureWhat went wrongWhat fixes it
Unreviewed outputThe AI produced specifications and records that nobody in the quality unit approved on any documented basisAn approval step with a defined evidentiary standard; 211.22(c)
Unasked questionThe AI did not raise a requirement that applied, and nobody noticed the gapA requirements register maintained independently of the model; 211.100

Review controls catch only the first. Nearly every AI governance SOP written in the last two years contains a human-in-the-loop clause aimed at it, and almost none contains anything that would have caught the second, because a reviewer checking an AI-drafted document for accuracy is checking what is on the page. The regulation the model never mentioned is not on the page.

Kalie Richardson of Hyman, Phelps & McNamara, quoted by RAPS, put the first failure plainly: the issue is "that no one reviewed it and it was completely inaccurate". Failure two is the one that will catch a competent organisation, precisely because a competent organisation trusts its review step.

The defence against it is unglamorous and predates AI entirely: an enumerated, version-controlled list of the regulatory requirements applicable to each document type, owned by regulatory affairs and quality, that a reviewer works through as a checklist. If the only place your requirements knowledge lives is inside a model's weights or a retrieval index nobody maintains, the model's silence is your quality system's silence.

Is it really the first? What I could and could not verify

The headline says first, and the coverage is unanimous: ECA Academy, RAPS, BioSpace and ISPE's Pharmaceutical Engineering blog all call it the first FDA drug CGMP warning letter to cite AI use. The limits of that are worth stating. Verified directly from the letter text: date, reference number, heading wording, CFR citations, quoted passages, inspection dates, and the firm's cessation of drug production. Not verified: that no earlier letter mentions AI. FDA's warning letter database is not readily searchable by full text across redacted CGMP letters and I did not reproduce an exhaustive count. Treat "first" as the trade press's claim, not a count I reproduced. The substance does not depend on it — first or fourth, the citation is 211.22(c) either way.

One caveat the coverage skips. Purolea is not a case study in enterprise AI governance. It is a very small firm that also had insects in the plant and sold unapproved products labelled for shingles and genital herpes. The letter recommends a consultant qualified under 21 CFR 211.34 and a six-system audit, as FDA did in roughly 87% of the 85 drug GMP warning letters analysed for 2025 by Pharmaceutical Online. Read it as FDA stating where AI outputs sit in the quality system, not as evidence that inspectors are auditing sophisticated deployments.

What is binding on 30 August 2026, and what is not

Precision matters here, because the letter is already being used in vendor decks to sell compliance against rules that do not yet exist.

InstrumentStatus on 30 August 2026Bearing on this letter
21 CFR 211.22(c), 211.100Binding. Published 43 FR 45077, 29 Sept 1978The actual citations
FDA draft guidance on AI for regulatory decision-making, Jan 2025Draft guidance, not final, not bindingNot cited in the letter
EU GMP Annex 11 (2011)Binding in the EUWould be the EU hook, not an AI rule
Draft revised Annex 11 and new Annex 22Draft. Consultation 7 July to 7 Oct 2025, final text not adoptedNo legal effect
EU AI Act, Article 5 and Article 4Applicable since 2 February 2025Prohibited practices and AI literacy, not GMP records

FDA's January 2025 draft guidance on AI in regulatory decision-making sets out a seven-step, risk-based credibility assessment framework keyed to context of use and expressly covers manufacturing. It remained in draft as of 30 August 2026, it was not cited in the letter, and even when final it would be guidance, which by its own boilerplate does not establish legally enforceable responsibilities.

In Europe, a firm doing what Purolea did would be answered from the 2011 Annex 11 and EU GMP Chapter 4, not from anything AI-specific. The new Annex 22 and the revised Annex 11 went out for public consultation on 7 July 2025 alongside a revised Chapter 4, the consultation closed on 7 October 2025, and neither had been adopted as of 30 August 2026. Anyone quoting an Annex 22 clause number as a requirement today is quoting a draft.

On the EU AI Act, what is live is live: Article 5 prohibited practices and Article 4 AI literacy since 2 February 2025, general-purpose AI model obligations since 2 August 2025, Article 50 transparency from 2 August 2026. The deferral of high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) originates in the Commission's Digital Omnibus on AI, proposed 19 November 2025, provisionally agreed 6 May 2026 and confirmed by the Council on 13 May 2026; commentary published as late as 8 July 2026 still described Official Journal publication as pending, so confirm the OJ citation before putting those dates in a filing. None of it would have been the instrument here regardless: drafting a batch record with a chatbot is not a high-risk AI system under Annex III.

What this means in practice

The action list is short, and none of it is about models.

Make AI-drafted GxP records identifiable at the record level. Not a policy statement, a field: which documents in your QMS were machine-drafted, by what, when, from what inputs. If you cannot produce that list during an inspection you cannot demonstrate that your review step was ever applied. This is the commonest gap in AI programmes that otherwise look mature.

Define what review of an AI-drafted specification means, in writing, before it happens. Proofreading is not approval. A defensible standard is that the reviewer can state the source for each acceptance criterion: a compendial monograph, a development report, a stability dataset. If the only basis is that the text looked right, 211.22(c) is not satisfied.

Keep the requirements register outside the model, enumerated by document type and walked as a checklist. It is the only control that addresses the failure Purolea described.

Decide who signs. Clearance is by "an authorized human representative of your firm's QU". Not the author, not the automation owner, not the IT function that deployed the agent. If your workflow routes approval for 211.22(c) records to anyone outside the quality unit, change it this quarter.

Do not build only for Annex 22. The binding rules that will be used against you are already in force and almost entirely silent about AI. That silence is not a gap in the regulations. It is how the regulations work.

Questions people ask about this

What did the FDA warning letter to Purolea say about AI?
Warning Letter 320-26-58, dated 2 April 2026, carries a section headed "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing". It records that the firm used AI agents to create drug product specifications, procedures and master production or control records, and states that failing to review those documents for accuracy and CGMP compliance violates 21 CFR 211.22(c).
Which regulation did FDA cite for AI-generated records?
21 CFR 211.22(c), which makes the quality control unit responsible for approving or rejecting all procedures or specifications impacting the identity, strength, quality and purity of the drug product. FDA also cited 21 CFR 211.100 for the absent process validation, and section 501(a)(2)(B) of the FD&C Act. No AI-specific rule was cited, because none exists in 21 CFR parts 210 and 211.
Is there an FDA regulation on artificial intelligence in drug manufacturing?
No binding one. The phrase "artificial intelligence" does not appear anywhere in 21 CFR part 211 as searched in the 1 April 2024 print edition on 30 August 2026. FDA published a draft guidance in January 2025 on AI supporting regulatory decision-making for drugs and biologics, setting out a risk-based credibility assessment framework, but it remained draft as of 30 August 2026 and guidance is not binding.
Does the EU have a binding GMP rule for AI yet?
Not as of 30 August 2026. The binding computerised-systems text in EU GMP is still the 2011 Annex 11. A revised Annex 11 and a new Annex 22 on artificial intelligence were published for public consultation on 7 July 2025, the consultation closed on 7 October 2025, and the final texts have not been adopted.
What is the practical lesson for a quality unit using AI?
Enforcement attaches to the approval step, not to the model. An inspector does not need a view on your architecture to write a 211.22(c) finding; they need only ask who approved a specification and on what basis. Make AI-drafted GxP records identifiable, and define what review of one actually requires.