The development team had run the numbers twice. Using AI, the specifications package would be complete within the deadline. Without it, the deadline was gone. So they took the request to the head of quality. She asked what references the model would work from, who would verify them, and who would stand behind the outputs. Nobody could answer. She waited, then said not yet.
She was right to. When an inspector later asks where a specification came from, the answer will have to name a source, a version, and a person. But holding the use of AI put her under pressure. Most of the people affected did not know how to meet the requirement, and some thought she had simply blocked the work.
Her position did not move. She knew the use of AI in regulated product development was new, and the expectations around it were still maturing. She also knew that if she was going to hold the work, she owed the team a path to yes.
Reading the Guiding Principles of Good AI Practice in Drug Development, issued jointly by the FDA and the EMA in January 2026, she saw the architecture of controlled work she had known since her early days in quality. Ten principles across two pages, written as direction companies can work from. So she trained the team on them.
She sorted the ten principles so the team could see how much they already practiced. Two are about the compliance of the whole system the model is used in, one for the risk-based approach they had applied for years, and one for adherence to standards, GxP among them. One is about data governance and documentation, the same data integrity problem in a new application.
Two are about knowledge governance, meaning what the model is allowed to work from, how the context is kept current, and how the system is monitored over its life. Four are about the point she cared about most, the people. Only a qualified person decides what goes in, what the model may do, and whether what comes back can be trusted.
One principle addresses the model directly. Some of the others reach into how its performance is assessed and maintained. Her team did not build the model. They were using a commercial one, chosen elsewhere in the company, but they still had to establish whether the system was suitable for this work.
So she told the team to treat the model’s construction as outside their control, but well inside their responsibility to govern its use. They owned the knowledge going in, the references and the data. They owned the setup, the context and intended use. And what came out was theirs too, the review, the records, and the decision to accept.
They learned what the model could and could not do. Then they wrote the controls that carried that ownership, a procedure, a work instruction, and a record. Before release, they tested the proposed use against defined acceptance criteria, including whether the human review caught unacceptable results. They also defined what would be monitored, how performance would be measured and judged, and which conditions would require reassessment.
Every one of those steps was familiar, because the company already ran systems like them for product quality. ICH Q10 names knowledge management and quality risk management as enablers of the pharmaceutical quality system. It has said so since 2008. She saw the 2026 principles as a way to extend that familiar structure to AI.
Before AI, the person who produced a deliverable needed to hold the qualification for it. The company relied on that qualification together with the supporting evidence, the method, and the required review. The signature recorded who stood behind the result, and the evidence showed why the work could be trusted. When asked who did the work, the company could point at a person.
AI changed that. A model works from the knowledge it is given. It has training but no qualification, and none of what it carries is specific to a given company or project. It signs nothing, so it cannot stand behind the result.
But the work still has to be justified, and that takes more than checking the output. The model works alongside people, and somebody needs the authority to decide what it may work from, what it may do, and whether the result can be accepted. Those decisions govern the work, whether they are made by the person performing it or by an authorized reviewer.
Every control in the quality system assumes a qualified person performs, verifies, approves, or accepts a step. When a qualified person makes those decisions, that qualification answers for the step. Accountability sits with that person, which is why the authority has to sit there too. That is human in command, deciding what the model may work from, what it may do, and whether the result can be accepted.
And that person is not alone in the work. In regulated life sciences, a deliverable moves through several functions before anybody signs, each bringing a discipline the others do not have. Some set what goes in, others review what comes back, and the approval comes from outside the group that produced the work. Quality contributes throughout while retaining its authority to challenge and reject. At the end, one person, or an accountable body such as an approval committee, confirms the result and stands behind it.
AI helped produce the deliverables. The company had to prove what the model used, what it produced, who checked it, and who accepted it. The procedure and work instruction defined the controls. The records showed their execution, making human command visible, repeatable, and provable.
The record of the knowledge process held the specifics. It showed which version of the reference set was effective on the day a document was produced. It named the person who owned that set, and the model and configuration that produced the output. For knowledge brought in from outside the company, it showed who checked it, when, and against which standard.
ICH Q10 supplied the quality system framework. The ten principles showed how it applies when AI is used. The company supplied the rest, because of its culture of controlled work. The project gained the time AI could give it. And time matters because the ultimate beneficiaries of the work are patients. More guidance will come, and she and the team will be ready when it does.
Other teams saw how much work that team completed, fast and in compliance, and started making requests. Her answer was now more often yes, because their proposals came with a procedure, a work instruction, a record, and a person in command.
That created a new challenge. The company’s change management system was built for a slower pace of change, so approvals started to slip and pile up. She knew somebody would come asking to apply AI to that too. And this time she knew how to say yes. ICH Q10, the ten principles, and the company’s own culture of controlled work were together the system that would carry that request too.
The system compliant AI was waiting for turned out to be the one the company already had.
That’s the Minerva Way.
