Comment from The PharmAgility Consulting Group
AnonymousSupportBusiness
Summary: The PharmAgility Consulting Group supports the draft guidance but recommends that the FDA enhance it by explicitly addressing data provenance, lifecycle-based performance verification, and the foundational role of cybersecurity in AI governance. They argue that these additions are necessary to ensure that AI tools in the pharmaceutical and biotechnology sectors are reliable, secure, and fit for purpose.
The PharmAgility Consulting Group commends the FDA for its proactive and thoughtful approach in issuing draft guidance on the use of artificial intelligence (AI) to support regulatory decision-making for drug and biological products. As professionals working closely with regulated pharmaceutical and biotechnology companies, we see both the transformative potential and the operational risks that AI introduces into routine activities and regulatory interfaces.
We respectfully recommend that the agency enhance this guidance by explicitly addressing the expectation for responsibly sourced AI. While the draft appropriately emphasizes the need for trustworthy and transparent systems, further clarity on data provenance would provide essential direction to developers and users. Specifically, AI systems should be expected to derive insights from data that is not only high-quality, but also appropriately contextualized, verified, and ethically sourced for its intended use. In the regulated pharmaceutical and life sciences sectors, AI tools are increasingly deployed to support day-to-day decisions that directly affect product quality, regulatory compliance, and patient safety. Without clear expectations for how data is sourced and maintained, there is a risk of unknowingly relying on models built from flawed or unrepresentative datasets—ultimately compromising the reliability and integrity of regulatory outcomes.
We also encourage the FDA to further emphasize the importance of ongoing performance verification and reverification throughout the AI lifecycle. Such expectations should include routine assessment of AI systems as they continue to evolve and interact with new data inputs. Lifecycle management practices that incorporate regular testing, performance monitoring, and data reverification are critical to ensuring that AI systems continue to meet the scientific and regulatory standards required for high-stakes decision-making.
Additionally, we would like to comment on the reference to cybersecurity within footnote 23 of the draft guidance. While we understand and respect that cybersecurity risk may be outside the primary scope of this document, we believe that it is too foundational to the safe deployment of AI to be entirely relegated to a footnote. Cybersecurity underpins the trustworthiness of AI systems, especially when those systems are responsible for interpreting or generating data that informs regulatory decisions. We recommend that the FDA consider including cybersecurity as an acknowledged and necessary element of responsible AI governance—indicating that while it will not be detailed in this particular guidance, it must be addressed within the broader framework of AI oversight.
By explicitly integrating expectations for responsibly sourced data, lifecycle-based performance verification and reverification, and foundational cybersecurity considerations, the FDA can help ensure that AI tools adopted across the regulated life sciences industry are not only innovative, but dependable, secure, and fit for purpose. These elements provide essential guardrails for a future in which AI supports high-quality, compliant, and patient-centered outcomes.
We appreciate the opportunity to provide input and welcome further engagement on this important and evolving topic.