Ithos Global blog banner: AI in Regulated Industries — Risks and Practical Guidance for Responsible Adoption

Artificial intelligence is changing how organizations work. Used appropriately, it can help teams research faster, draft more efficiently, and improve responsiveness.

At Ithos Global, we embrace those benefits as part of our internal work processes while also placing clear guardrails around how AI is used.

In regulated industries especially, responsible adoption requires clear limits on how AI is used, what information AI can access, and who remains accountable for the outcome.

Our position is straightforward:

AI can improve efficiency and customer service, but only when it is used with clear boundaries, appropriate oversight, and full accountability.

Read on to learn how we use AI at Ithos, details on an FDA warning letter issued to a drug and cosmetics manufacturer recently after an inspection regarding many issues, including the incorrect use of AI in their processes, and a practical approach to responsible AI adoption.

Customer data is never part of the equation

Customer data is confidential.

Ithos does not share customer data with, enter it into, or otherwise expose it to AI tools. This is a firm commitment.

Organizations operating in regulated industries are responsible for protecting sensitive information and maintaining appropriate control over their data. Introducing confidential customer information into an external AI tool could create data governance, confidentiality, and accountability concerns.

AI may help us work more efficiently internally, but customer data is not used to achieve those efficiencies.

Efficiency does not replace human accountability

AI can generate content quickly. However, it cannot assume responsibility for whether that content is accurate, complete, or compliant.

That distinction became especially clear in an April 2026 FDA warning letter issued to Purolea Cosmetics Lab.

The FDA stated that the company had used AI agents to create drug product specifications, procedures, and master production or control records.

According to the warning letter, the company failed to review the AI-generated documents to confirm that they were accurate and compliant with CGMP.

The FDA also reported that the company had not conducted required process validation before distributing its drug products. When investigators raised the issue, company personnel stated that they had not known about the requirement because the AI agent had not identified it.

The FDA cited the company under 21 CFR 211.22(c) for failing to review the AI-generated documents appropriately and stated that any future AI-generated output or recommendations used for CGMP activities would need to be reviewed and cleared by an authorized human representative of the company’s quality unit.

The lesson here is that accountability cannot be delegated to AI.

AI can assist with regulated activities, but the responsibility for compliance and understanding the application of regulations remains with humans inside the regulated organization.

Why regulated industries require stronger guardrails

Every organization adopting AI must consider accuracy and data protection. Regulated organizations must also consider whether AI-assisted work can be validated, explained, reviewed, and defended during an inspection or audit.

Four questions are especially important:

Is the output accurate?

AI-generated information can contain errors, omissions, or unsupported conclusions. Qualified professionals must verify outputs before they are used to support regulated work.

Can the process be reviewed?

Organizations must understand where AI is being used, how its output is evaluated, and who approved the resulting decisions or work product.

Is confidential data protected?

Teams must establish clear rules governing what information may be entered into AI tools. Customer data and confidential information should not be exposed through uncontrolled use.

Who is accountable?

The organization and its personnel remain responsible for compliance. Reliance on an AI tool does not transfer that obligation to the technology or excuse a failure to meet regulatory requirements.

These controls allow organizations to use innovation without creating unnecessary risk. We take potential risks seriously on behalf of our customers at Ithos.

A pragmatic approach to AI adoption

Responsible AI adoption does not require choosing between avoiding AI entirely and using it without restraint.

It means applying the same disciplined thinking that regulated organizations already use when evaluating other tools and processes:

  • Define appropriate use cases.
  • Protect confidential information.
  • Require qualified human review.
  • Maintain clear accountability.
  • Evaluate accuracy before acting on an output.
  • Document decisions when AI supports regulated activities.

Innovation with appropriate control

AI can deliver meaningful value. Ithos uses AI tools internally to improve efficiency and support excellent customer service, but with clear boundaries.

Customer data remains confidential. AI does not replace professional judgment.

Human experts remain responsible for reviewing work, making all decisions, and meeting applicable requirements.

That is how regulated organizations can benefit from AI without allowing speed or novelty to outrun accountability.

Sources: FDA Purolea Cosmetics Lab Warning Letter

Related Posts