Guest Column | September 3, 2026

When To Trust And When To Verify AI-Enabled Validation Systems

A conversation between Louie Rayal of GSK and Life Science Connect's Jon O'Connell

developing secure code, risk mitigation-GettyImages-2261595149

FDA's 2022 guidance on computer software assurance (CSA) and other recent regulatory position papers have paved the way for artificial intelligence to support the validation life cycle. When the focus is on assessing risks and potential failure modes, AI can substantially speed up the steps through test development and script writing, among other mundane validation-associated tasks, giving the humans more time to focus on patient-centric issues.

That's according to Louie Rayal, vice president of governance, risk, and compliance at GSK U.K. He'll be talking about how AI can help the validation process during the ISPE 2026 Annual Meeting & Expo. He gave us a preview of the talk he's giving with Compliance Group Inc.'s managing partner, Khaled Moussally, by answering some specific questions.

Describe the pressure validation teams are under, being asked to move faster with leaner headcount and regulatory expectations remaining steady state or even growing.

Rayal: Validation teams are being asked to deliver more with fewer resources while supporting increasingly complex digital ecosystems, cloud platforms, AI-enabled solutions, and frequent software releases. At the same time, regulators continue to expect a strong demonstration of product quality, patient safety, and data integrity.

Under those conditions, the challenges increase to produce validation documentation while applying critical thinking to make informed, risk-based decisions at the speed the business requires.

That’s why approaches like CSA and AI are so important. Together, they allow teams to focus their effort on the areas that matter most rather than spending valuable time creating documentation that adds little value.

You suggest AI helps exchange esoteric documentation for meaningful evidence. Can you offer an example of documentation that CSA and AI together let you eliminate or shrink? What made you confident that nothing important was lost?

Rayal: One example is reducing lengthy narrative documents that often duplicate information already available elsewhere, such as detailed test scripts or traceability documentation. AI can generate concise summaries, identify gaps, and link evidence across requirements, risks, and testing, while CSA encourages teams to focus on demonstrating confidence rather than documenting every activity. We gain confidence because the critical evidence is still there; risk assessments, objective test results, approvals, and traceability remain intact. We’re simply removing redundant documentation that doesn’t improve quality or inspection readiness and focusing on high-risk items that ensure product quality and patient safety.

Failure mode and effects analysis (FMEA) is traditionally a slow, team-intensive exercise built on institutional knowledge. Does AI help spotlight failure modes a team might miss, or does it mostly optimize or speed up documentation?

Rayal: I believe AI does both, but its greatest value is helping teams think more broadly. AI can suggest potential failure modes based on historical data, industry practices, and similar implementations that a team may overlook. That said, AI should never replace the expertise of cross-functional SMEs. The team still determines which risks are credible, how they should be assessed, and what controls are appropriate. AI accelerates the process and expands the discussion, but human judgment remains the final authority.

ICH Q9(R1) emphasizes risk-based critical thinking over checklist-driven quality management. Are you concerned that teams could lean on AI output as a substitute for the critical judgment Q9(R1) wants to see, or do safeguards do their job?

Rayal: That’s a valid concern, which is why governance matters just as much as the technology itself. AI should support decision-making, not replace it. Organizations need clear expectations that AI-generated content is a starting point requiring expert review and approval. Human accountability for risk assessments and validation decisions should never change. When AI is used within a well-defined governance framework, it enhances critical thinking rather than diminishing it.

Walk us through the handoff points across the validation life cycle you describe from risk assessment to report authoring. In what areas is AI most helpful and, conversely, where are humans still heavily involved?

Rayal: AI provides the most value in preparing draft risk assessments, generating test scenarios, identifying traceability gaps, summarizing results, and producing validation reports. These activities are time-consuming but largely administrative. Human expertise remains essential when defining intended use, determining system criticality, approving risk acceptance, investigating deviations, and making final release decisions. Those decisions that require business context, technical expertise, and accountability are areas where people remain indispensable.

Testing is a good example of where this division plays out in practice. Many modern test automation tools now have integrated AI capabilities that can generate and execute test scripts with minimal human setup. But human involvement remains critical at the close of the testing cycle — reviewing all AI-generated output, confirming that defects were fully remediated, and ensuring nothing was missed before sign-off.

CSA inevitably produces artifacts an inspector will scrutinize. What does an audit-ready AI-generated rationale need to include for an inspector to trust that it's complete?

Rayal: Inspectors want transparency more than perfection. AI-generated rationale should clearly identify the inputs used, explain how conclusions were reached, and maintain traceability back to requirements, risks, testing, and approvals. It should also show that qualified personnel reviewed and approved the final decisions. Ultimately, inspectors are looking for objective evidence that a risk-based process was followed and that human oversight remained in place throughout.

What specific decision points require a human sign-off no matter how confident the AI output is?

Rayal: Any decision that could impact patient safety, product quality, regulatory compliance, or data integrity should always require human approval. That includes intended use, system classification, risk assessments, acceptance of residual risk, deviation disposition, validation conclusions, and production release decisions. AI can provide recommendations and support analysis, but accountability for these decisions must always rest with qualified individuals.

For a validation team that's under-resourced right now and skeptical that AI can help without adding risk, what's the defensible business case in terms of time, risk, or inspection readiness for making the switch?

Rayal: The strongest business case is about giving skilled people the validation resources that allow them to spend more time applying expertise instead of creating paperwork. AI can significantly reduce the effort required for document preparation, evidence review, traceability, and report generation while improving consistency and identifying potential gaps earlier. When implemented with strong governance and human oversight, organizations can improve productivity, strengthen inspection readiness, and maintain compliance without compromising quality or patient safety. That’s a compelling outcome for any validation organization facing growing demands and limited resources.

About The Expert:

Louie Rayal is vice president of governance, risk, and compliance at GSK. Previously, he was a senior director of IT quality, regulatory, and compliance at Abbott and before that, he filled a similar role at Takeda. He received an MBA from Lake Forest Graduate School of Management and a bachelor's degree from University of Illinois at Chicago.