- Before
- Reads intake forms that do not match the design, chases reviewers, and takes every idea to a monthly committee.
- Now
- Opens a cited classification with the conflicts already found, picks a redesign, and signs with the conditions on the record.
One AI idea, from intake to the inventory
Dr. Maya Chen, head of the QC laboratory at Plant 3 in Leiden, wants an assistant that triages about 40 deviations a month. Here is what happens to AIU-2041, screen by screen, in the working solution.
- 01Morning
Every AI idea, on one risk landscape
Dana Okafor · Lead, AI governance officeDana opens the solution to 10 open AI ideas, 4 waiting for her and a board meeting on Thursday with 3 decisions on the agenda. The landscape places each idea by EU AI Act category and GxP impact: emotion scoring under Prohibited, candidate screening under High-risk, the patient chatbot under Transparency. The deviation triage assistant sits in the tray marked “Not classified yet”.
Regulatory clock: “Q4 2026 · Annex 22 final text expected · 6 decisions to re-check.”
- 02Submitted Oct 4
Five plain-word answers and four documents
Dr. Maya Chen · Head of QC laboratory, Plant 3The intake interviewer asked Maya five questions. Her answers: the assistant would read new deviation reports and suggest minor, major or critical; “ideally it sets the class in the QMS so the investigation starts faster”; no personal data; Nimbrel Cloud AI’s hosted model, already used for meeting notes. She attached the design and data flow, the vendor’s model card, the vendor’s enterprise terms and the QA-114 deviation SOP.
“Intake complete — ready to classify. 5 answers and 4 documents. Six agents check them against 23 clauses in the rule library.”
- 03One click
Six agents classify, each step in view
The agentsDana presses “Run classification”. The document reader pulls 23 fields from the four documents, each with its page. The AI Act classifier finds minimal risk — not an Annex III use, 93 %. Then the warnings: the GxP classifier sees a critical GMP use with a generative model, the privacy classifier finds employee names in the inputs and the vendor’s no-training option not elected, and the consistency check catches the sponsor’s answer contradicting the design.
Consistency check: “‘No personal data’ disagrees with design §3.1 · 2 redesigns proposed.”
- 049.1 seconds later
“Not allowed as designed” — and exactly why
GxP & credibility classifierSection 2.3 of the design says the assistant sets the deviation class in the QMS record. QA-114 says the class decides investigation depth, whether a CAPA is required and whether batch disposition is held. Draft Annex 22 §1 keeps generative models out of critical GMP applications, and the company’s AI policy 6.5 says generative AI must not make a GxP decision. Every clause is one click from its highlighted passage.
The agents never approve a generative model in a critical GMP use — they propose redesigns: suggestion only (about 6 weeks), a static validated classifier (about 4–6 months), or send it back.
- 05Redesign chosen
Suggestion only — a QA reviewer decides
Dana Okafor · Lead, AI governance officeDana picks the recommended redesign and the classifiers re-check. GxP criticality moves from critical GMP to non-critical GMP with a person in the loop; model risk on the FDA influence × consequence grid drops from high to medium; personal data becomes “employee data · minimised”; vendor terms become “approved with no-training option”. Each change shows what it was before.
- 06Planned
Six assessments with owners and due dates
Assessment planner & routerThe planner turns the classification into the work: an AI validation plan for Sam Patel in IT Quality, a security review of hosting, region and connectors for Omar Haddad, the no-training option for Hannah Brooks in procurement, a privacy note and name removal for Lena Ortiz — no DPIA, with the reason recorded — AI literacy training for 12 QA reviewers, and a monitoring plan for agreement, overrides and drift. Five conditions of approval are written alongside.
Condition 1: “Suggestion only — the assistant never sets the class.”
- 07Thursday’s board
Approved with conditions, signed
Dana Okafor · Board chairThe approval route shows the sponsor, the agents, IT Quality and Security done, and the AI review board next. Dana opens the approval, reviews the five conditions, and signs with her password. The meaning of her signature is recorded with it, and the sponsor gets a note: approved as a suggestion-only assistant, QA reviewers decide every deviation.
“Meaning: I approve this use case with the conditions above.”
- 08Registered
Into the AI inventory, with its review date
Assessment planner & routerOnly after the signed decision does the planner write inventory entry REG-0413: owner Dr. Maya Chen, enhanced review, the hosted model and its vendor, five conditions, next review Jan 7, 2027 and then quarterly, monitoring of agreement and override rates and of model version changes. The six assessments go to their owners.
“Approved and signed · inventory entry REG-0413 · 6 assessments sent.”
- 09When a rule moves
Annex 22 goes final — what changes?
Dana Okafor · Lead, AI governance officeAnnex 22 is still a draft, with the final text expected in Q4 2026. Dana previews the re-check: six decisions cite the draft, open use cases and inventory entries alike, and all six are re-classified by the same agents. None changes tier; the adverse-event capture and the patient chatbot each gain an operator training record. Nothing changes until she confirms and the sponsors are told.
“Nothing changes until you confirm.”
- 10Every month
How fast ideas get an answer
Dana Okafor · Lead, AI governance officeIn the last 30 days: 24 ideas received, 19 decided, a median of 6.1 days from intake to decision against a target of 7, and 14 % sent back for missing documents or contradictions. 18 of the 24 were minimal risk under the AI Act — so the office spends its time on the few that are not.