Purolea Six Months Later: A Line in the Sand, Not a One-Off

The Purolea warning letter, dated 2 April 2026 and posted to the FDA’s public database as reference number 722591, has become the most cited pharmaceutical enforcement action of the year.1 The facts are unusual enough to be memorable. A small manufacturer told inspectors during a facility inspection that it had deployed a general-purpose AI agent to generate its drug product specifications, its master production and control records, and its standard operating procedures. When investigators asked why the firm had distributed products without conducting process validation as required under 21 CFR 211.100, company representatives said they had not been aware the requirement existed because the AI agent had never told them it was.2

That sentence, quoted verbatim in the warning letter and repeated by every trade press outlet that covered the case, is why Purolea matters. It captured a failure mode the industry had discussed abstractly for two years but had never seen in a formal enforcement document: a regulated firm treating a general-purpose language model as a substitute for a qualified person, and doing so on the record.5

The FDA’s response was not to invent new law. The warning letter cites 21 CFR 211.22(c), which requires that the quality control unit review and approve procedures affecting the identity, strength, quality, and purity of the drug product, and 21 CFR 211.100, which requires written procedures for production and process control to be reviewed and approved by the quality unit.6 Neither provision mentions AI. Both apply cleanly to it. Morgan Lewis, in one of the most widely read legal commentaries of the quarter, called this “growing scrutiny of AI overreliance” and warned sponsors that FDA was signalling how it would treat similar fact patterns going forward.7

The Sakara Digital read.

Purolea is not important because a tiny contract manufacturer used AI badly. It is important because FDA chose to write a dedicated deficiency section rather than fold the finding into a general documentation citation. That formatting choice tells you where inspector attention is going for the rest of the decade.

The Trend Picture: What FDA Enforcement Data Actually Shows

Warning letter volumes rose sharply through 2025 and into 2026 independent of the AI storyline. FDA issued 303 drug warning letters in fiscal year 2025, a 59% increase over fiscal 2024, and the second half of calendar 2025 alone saw 327 letters, up 73% year over year.8 Data integrity findings appeared in roughly 15% of all fiscal 2025 letters and in approximately 60% of letters directed to Indian manufacturing sites.8 Against that backdrop, AI-specific citations remain a small share of total volume, but the trajectory is what matters.

The reconstructed pattern below draws on FDA’s published warning letter index, agency remarks at the Parenteral Drug Association meetings, and trade press coverage of Q2 2026 enforcement activity.9 Numbers reflect letters that explicitly named AI, machine learning, algorithmic decision support, or generative model outputs as contributing to the cited deficiency, and are deliberately conservative. A letter that cites unvalidated computerised systems without naming the underlying model has not been counted here even where trade coverage suggested AI was involved.

FDA Warning Letters Citing AI-Adjacent Deficiencies

By quarter, October 2025 through June 2026. AI-specific = letter names AI/ML/GenAI explicitly. AI-adjacent = letter cites unvalidated computerised systems, disabled audit trails on ML-enabled platforms, or undocumented model outputs in GMP records.
0
Q4 2025
Oct-Dec
1
Q1 2026
Jan-Mar
3
Q2 2026
Apr-Jun (AI-specific)
11
Q2 2026
Apr-Jun (AI-adjacent)
18
Projected Q3 2026
Jul-Sep (blended)
Explicitly names AI/ML AI-adjacent (unvalidated computerised systems, unreviewed audit trails, undocumented model outputs)

Three signals emerge from the tally. First, Purolea was the earliest formal AI-named citation, but it was not alone by end of Q2 2026: FDA issued at least three warning letters in April and May 2026 that named AI or automated systems by function in the deficiency text, according to law-firm client alerts and the FDA’s own indexing.7 Second, the far larger category is AI-adjacent letters where the underlying technology is a machine learning model, a validated automation platform, or a generative system, but the citation is written in the older language of computerised systems, audit trails, and process control. These letters would have been catalogued as data integrity cases before Purolea. Now they are increasingly being read as AI cases by industry counsel and by inspectors preparing follow-on visits.10

Third, the internal FDA signalling is louder than the external count. The agency established a formal CDER AI Council in 2024 to consolidate work previously divided among the AI Steering Committee, the AI Policy Working Group, and the AI Community of Practice.11 By mid-2026, inspector training modules on AI recognition and documentation review had rolled through several district offices, and the January 2025 draft guidance Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products had completed public comment and was in revision.12

The geographic pattern is also worth noting. Of the AI-adjacent letters issued in Q2 2026, the majority were directed at overseas manufacturing sites, particularly in India, following the pattern that has held for data integrity findings for the last several years.8 That is not because Indian manufacturers are disproportionately deploying AI, but because they are disproportionately inspected. As inspection frequency ramps back to pre-pandemic levels and inspectors carry AI-recognition training with them, the reported findings will follow the same geographic distribution as the inspections. Sponsors that rely on contract manufacturers in these jurisdictions should assume that their partners will be asked to demonstrate AI controls on the same terms they themselves would face.

A second interpretive point: the raw count of “AI-named” warning letters is a poor leading indicator, because warning letters lag inspection findings by months and represent only the small subset of findings serious enough to warrant public enforcement. The more useful indicator is Form 483 observation content, which is not systematically published but which trade press and consulting firms track through client debriefs. Consultants report that AI-related 483 observations are appearing in a meaningfully larger share of inspections in 2026 than in 2025, even where those observations have not yet resulted in escalated warning letters. That backlog implies the next several quarters of published enforcement volume will be higher than the current count suggests.

303
FDA drug warning letters in FY 2025, up 59% from FY 20248
15%
Share of FY 2025 warning letters citing data integrity failures8
4
Distinct AI-named deficiency patterns visible in Q2 2026 letters and trade coverage10

A Deficiency Taxonomy: How AI Failures Are Being Cited

Across published warning letters, MHRA blog posts, and law-firm commentary in the six months since Purolea, a taxonomy has taken shape. It is not codified in guidance yet, but the same patterns recur across published letters, trade coverage, and consultant reports. Naming these patterns is useful because it lets a quality organisation self-diagnose before an inspector arrives.

PATTERN 1

Delegated Judgement

An AI system produces a GMP-relevant document (specification, SOP, master batch record) and the output is used without documented review by a qualified person. This is the Purolea pattern, and it is the archetypal 21 CFR 211.22(c) violation as applied to AI.

PATTERN 2

Undocumented Model Updates

A validated ML-enabled system receives a model refresh from the vendor or from an internal data science team, and the change is not run through change control. The audit trail shows a version bump but no risk assessment, revalidation, or QA approval.

PATTERN 3

Hallucination in Regulatory Correspondence

An AI-drafted inspection response cites regulations, guidance documents, or standards that do not exist, or cites the wrong ones. The MHRA has publicly flagged this as a distinct pattern and warned that it will treat such responses as evidence of inadequate oversight, not innocent error.3

PATTERN 4

GenAI in Regulated Authoring Without a Framework

Medical writers, quality engineers, or CMC authors use generative AI to draft protocols, deviation investigations, or CTD sections, but the organisation has no policy, no attribution, and no evidence of the human review that transforms model output into a signed record. Inspectors are asking to see the policy.

The taxonomy matters because the four patterns imply different remediations. A Pattern 1 case (delegated judgement) is almost always fixed by rewriting SOPs to require documented QA review of any AI-generated document that becomes part of the regulated record. A Pattern 2 case (undocumented updates) requires the change control system to explicitly recognise model version changes, retraining events, and prompt template changes as controlled changes. A Pattern 3 case (hallucination in correspondence) requires an editorial checkpoint before any AI-drafted regulatory reply leaves the building. A Pattern 4 case (GenAI in authoring) requires an enterprise policy and, increasingly, a tool-level control that leaves an audit trail of what was drafted by a model versus what was written by a human.13

What makes the taxonomy uncomfortable for many organisations is that the four patterns are not mutually exclusive. A single enterprise deployment of generative AI in a medical writing team can produce Pattern 1 (documents used without QA review), Pattern 3 (fabricated citations in a submission), and Pattern 4 (no authoring policy in place) simultaneously. A single validated MES with embedded ML for predictive maintenance can produce Pattern 2 (undocumented model updates) even where the surrounding validation package is impeccable. Sponsors accustomed to organising their computerised systems inventory around discrete platforms are finding that the AI risk cuts across platforms, and that the remediation has to cut across platforms too.

The taxonomy also creates a useful signal for boards and audit committees. When leadership asks the quality organisation “what is our AI compliance posture,” the answer is rarely useful because the question is too broad. The more actionable form of the question is “which of these four patterns have we mapped, and which have we not yet mapped.” Organisations that can answer with specificity, naming the systems, the policies, and the controls that address each pattern, are demonstrably ahead of organisations that cannot.

Cross-cutting deficiency: absence of a “context of use” statement.

Across all four patterns, the recurring missing artefact is a written, versioned statement of what each AI system is being used for and what it must not be used for. Both the FDA’s January 2025 draft guidance and the EMA reflection paper make a pre-specified context of use foundational to any credibility argument. Firms that cannot produce one on request are being asked to demonstrate their controls in far more granular detail.14

What FDA Inspectors Are Now Trained to Look For

Inspector attention in the second half of 2026 is being directed at four practical questions during any GMP inspection where AI is likely to be in play. These are drawn from trade press coverage of FDA presentations at ISPE and PDA meetings this year, the January 2025 draft guidance’s credibility framework, and consultant reports from firms that debrief clients after inspections.9

Question one: can you show me the inventory?

Inspectors are asking regulated firms to produce a list of AI and machine learning systems that touch GMP-relevant activities, including systems embedded inside otherwise-validated platforms. This includes automated visual inspection, LIMS with ML-driven anomaly detection, MES with predictive maintenance, and now, increasingly, general-purpose language models used to draft or summarise regulated content. Firms that cannot produce an inventory are being asked why, and how they can be sure their change control system knows what to protect.

Question two: what is the context of use for each system?

For each inventoried system, inspectors want a written statement of the specific decision or task the AI is supporting, the risk classification (patient safety, product quality, data integrity), and the boundary of acceptable use. This is directly borrowed from the FDA’s 7-step credibility assessment framework in the January 2025 draft guidance and from the EMA’s reflection paper.14

Question three: show me the human review that transforms output into a record.

For every AI-generated artefact that becomes part of a batch record, deviation investigation, CAPA, or regulatory submission, inspectors want to see the specific SOP that governs the review, the qualifications of the reviewer, and the audit trail entry that documents when and how the review happened. This is the direct enforcement lever from Purolea, and it is now being applied broadly.15

Question four: what happens when the model changes?

Inspectors are asking to see change control records for model updates, retraining events, and prompt or system-prompt changes. They are looking for evidence that the quality unit was involved in evaluating whether the change required revalidation. This is where undocumented model updates become a citable finding, and it is the pattern most likely to be missed by organisations that treat their vendors’ quarterly model refreshes as invisible operational events.16

A useful pattern we see with clients is to preempt this line of questioning by rehearsing it internally. Quality leadership walks the inventory with an outside reviewer playing inspector, asking the four questions in sequence, and noting where the answers are thin. The exercise usually surfaces two or three specific systems where documentation is weakest, and those become the immediate remediation targets. It is not glamorous work, and it is not novel in structure (mock inspections have been a QA staple for decades), but it is now the fastest way to convert Purolea-era anxiety into concrete controls.

The trap for large sponsors. Many biopharma organisations run pilots outside the quality system, then quietly move them into production without formal validation. Inspectors are now asking directly whether any AI system currently touching GMP records was ever a pilot, and if so, whether the transition to production was documented. This is the enforcement flavour of the shadow-IT problem, and it does not require Purolea-scale naivety to trigger a finding.

EMA and MHRA: Parallel Enforcement Patterns

Anyone reading only the FDA warning letter database is missing half the picture. European regulators are moving in the same direction and, in the case of the MHRA, are speaking more bluntly than their American counterparts about what they are seeing in the field.

The MHRA’s June 2026 blog post

On 29 June 2026, the MHRA Inspectorate published a post titled “Use of AI for GXP inspection responses: setting standards without stifling innovation.”3 The post is short, plainly written, and unusual in its directness. It reports that inspectors have received responses to inspection findings that contain references to MHRA guidance that does not exist, citations of inappropriate regulatory frameworks, and, in at least one case, an AI-generated response to a patient-safety-impacting deficiency that contained material inaccuracies including non-existent references and inaccurate information that delayed resolution.

The MHRA’s closing sentence became widely quoted across compliance channels: “Those who use AI responsibly will thrive, whereas those attempting to use technology to obscure inadequate responses, fill resource or expertise gaps, or hide a lack of knowledge causing serious deficiencies will be scrutinised.”3 No formal enforcement action followed the blog post in Q2 2026, but the signalling was clear: fabricated citations in inspection responses will be treated as a compliance failure, not a documentation error.

The EMA reflection paper and its downstream effect

The EMA adopted its final Reflection paper on the use of Artificial Intelligence (AI) in the medicinal product lifecycle on 30 September 2024, jointly through the CHMP and CVMP.17 The document is not enforceable in the way a guideline is, but it establishes the analytical framework that European inspectors are now using. It sets out a risk-based approach that scales scrutiny to the potential impact on patients and to the criticality of the decision the AI supports. It emphasises data quality, representativeness, and monitoring for bias, and it explicitly warns that small-population data sets create risks that generic performance metrics will hide.18

EU GMP Annex 22

The most consequential European development is the draft EU GMP Annex 22 on AI in manufacturing, which was released for stakeholder consultation on 7 July 2025 and has now moved into finalisation. A multistakeholder workshop on 1 July 2026 gathered expert input from industry, notified bodies, and inspectors on the finalisation trajectory, with enforcement phasing expected across 2027 and 2028.4 Annex 22 is important because it does two things at once: it treats static, deterministic AI models as permissible for critical GMP applications with strong controls, and it restricts dynamic, continuously-learning models and generative AI to non-critical applications with documented human oversight.19

The joint FDA-EMA principles

In January 2026, the FDA and EMA jointly published ten “good machine learning practice” principles for AI in the medicinal product lifecycle.20 The principles are not enforcement law, but they represent the first time the two agencies have published a common framework for what they consider defensible AI practice. Sponsors reading warning letters and MHRA blog posts through the lens of these principles will find the through-line clear: pre-specified context of use, documented data provenance, transparent model performance, human oversight, and a change control system that treats model updates as controlled changes.

RegulatorInstrumentDateEnforcement force
FDADraft guidance on AI credibility for regulatory decisionsJanuary 2025Non-binding, but framework used in inspections
EMA (CHMP + CVMP)Reflection paper on AI in the medicinal product lifecycleSeptember 2024Non-binding, but establishes analytical framework
FDAWarning letter 320-26-58 to Purolea Cosmetics LabApril 2026First formal AI-named cGMP enforcement action
FDA + EMA (joint)Ten good machine learning practice principlesJanuary 2026Non-binding but joint agency framework
MHRAInspectorate blog: AI in inspection responsesJune 2026Signalled treatment of AI hallucinations as compliance failure
European CommissionDraft EU GMP Annex 22 on AI in manufacturingJuly 2025 draft; 2026 finalisationWill be enforceable once adopted, phased 2027-2028

The industry response to Purolea moved through a predictable arc across the six months that followed. In April and May, the dominant reaction was to dismiss the case. Purolea was, after all, a marginal firm that had shut down its operations. By June, several developments had shifted sponsor behaviour, and a set of practical learnings had crystallised across quality organisations that we work with and observe in the field.

1

Enterprise AI inventories are being built with quality involvement, not just IT involvement.

The earliest sponsor AI inventories were built by IT security teams for cyber risk purposes. In Q2 2026, more sophisticated organisations began rebuilding these inventories with quality, regulatory, and manufacturing IT involvement, adding fields for GMP relevance, context of use, and validation status. Two of the top-ten pharma companies published internal guidance in Q2 requiring this rebuild.

2

GenAI-in-authoring policies are moving from draft to signed.

Many biopharma organisations had draft policies on generative AI in regulated authoring sitting unsigned since late 2025. The MHRA blog post in June 2026 accelerated approvals. Signed policies typically now require explicit tool authorisation, attribution in the record, and a documented human editing pass before any AI-drafted content becomes part of a submission or an inspection response.

3

Change control is being extended to model versions.

For validated ML-enabled systems, change control processes are being rewritten to treat model version changes, retraining events, prompt template updates, and vendor model refreshes as controlled changes requiring quality review. The resistance point is usually operational tempo: vendors ship updates on their cadence, not the customer’s.

4

Inspection response workflows are being formalised.

Where before an inspection response was drafted by the responsible function and reviewed by regulatory affairs, several organisations are now inserting an explicit editorial checkpoint to catch AI-drafted content and fabricated citations before responses are transmitted. Some are using their own AI-based citation checkers as a control on human writers using AI-based drafting tools, which is a genuinely new pattern.

5

Training is shifting from “how to use AI” to “how AI can fool you.”

The dominant sponsor training in 2025 was optimistic prompt-engineering education. In Q2 2026, training added explicit modules on hallucination, model failure modes, and the specific failure mode where confident, fluent output masks a factual error. Inspectors have signalled that they are asking to see this training content.

What good looks like. The organisations that are furthest along have a written AI governance framework that reads like a computerised systems validation framework with three additions: a context of use statement for every model, a documented change control extension for model versions and prompt templates, and an editorial checkpoint for any AI-drafted content that will enter a regulated record. None of this is exotic. It is CSV extended for AI.

A Preparedness Checklist to Avoid Becoming the Next Case

The following checklist is drawn from published FDA and EMA frameworks, MHRA signals, and the patterns emerging in Q2 2026 warning letters. It is not exhaustive, and it is not a substitute for legal or regulatory counsel. It is the working list we use with clients to stress-test their AI posture ahead of expected inspections and audits.

Inventory and classification

  • Every AI or ML system that touches GMP, GCP, GLP, or GVP activities appears on a single inventory maintained by the quality function.
  • The inventory includes systems embedded inside otherwise-validated platforms, not just standalone AI tools.
  • Each entry has a written, versioned context of use statement that specifies the decision or task supported, the boundary of acceptable use, and the risk classification.
  • Shadow AI use, including individual employees using consumer-grade tools for regulated tasks, is explicitly addressed in policy.

Validation and credibility

  • Validation strategy is scaled to the risk classification, using either the FDA’s 7-step credibility framework or the EMA reflection paper’s risk-based approach as an organising structure.
  • Data provenance is documented for training, validation, and monitoring data sets.
  • Performance metrics include not just aggregate accuracy but subgroup performance for populations relevant to the intended use.
  • Ongoing monitoring is defined with clear thresholds that trigger review.

Human oversight and documentation

  • Every AI-generated artefact that becomes part of a regulated record has an SOP that governs the review and specifies reviewer qualifications.
  • Audit trails capture when a human reviewed AI output, what was reviewed, and what the reviewer changed or approved.
  • Records make clear where a document was AI-drafted versus human-authored, with attribution recoverable during inspection.
  • The quality unit has authority and evidence of exercising authority over AI-generated content.

Change control

  • Change control explicitly recognises model version changes, retraining events, and prompt template changes as controlled changes.
  • Vendor model refreshes are governed by a vendor management SOP that requires notification, risk assessment, and documented QA position before deployment.
  • Rollback and revalidation triggers are defined.

Regulatory correspondence

  • Every inspection response, 483 reply, and formal regulatory correspondence passes through an editorial checkpoint that verifies citations and factual claims.
  • Where AI drafting tools are used to prepare correspondence, use is disclosed internally and a human review pass is documented.
  • Staff are trained to recognise hallucination patterns and are supported by tooling that flags common failure modes.

Training and culture

  • Training content addresses model failure modes, not just usage.
  • The quality culture treats AI as a tool that expands human capability, not one that replaces human judgement.
  • Leadership visibly reinforces that time pressure is not a defence for skipping human review.
Where sponsors most often fail this checklist.

The two most common gaps we see are on inventory (organisations do not know which validated platforms contain embedded ML they need to control) and on change control (organisations do not treat vendor model refreshes as controlled changes). Both gaps produce Purolea-shaped exposure without any of the Purolea-shaped naivety.

Conclusion

The Purolea warning letter is often described as the FDA’s first shot across the bow on AI in pharmaceutical manufacturing. Six months on, that framing is close but incomplete. Purolea was the moment the agency chose to name AI directly in a deficiency section rather than fold it into a broader documentation citation. What has followed is not a wave of Purolea-style enforcement, because no serious sponsor is quite that naive. What has followed is a slower and more consequential shift in how existing regulatory instruments (cGMP, GxP, computerised systems validation, data integrity) are being applied to AI-enabled operations. The MHRA’s blunt language about fabricated citations, the FDA’s inspector training on AI recognition, the EMA reflection paper, the joint FDA-EMA principles, and the imminent finalisation of EU GMP Annex 22 are all pieces of the same picture. The regulatory posture is now enforcement-oriented, and the burden is on sponsors to show that their controls are commensurate with the technology they have deployed.

The good news for sponsors that have taken quality systems seriously for decades is that this shift does not require an entirely new discipline. Computerised systems validation, change control, quality unit oversight, and data integrity practices are the foundation on which AI governance is built. What is new is the surface area those disciplines have to cover: more systems, more embedded models, more vendor-driven change, and a new class of failure mode in which fluent output masks factual error. The organisations that will come through the next two years cleanest are the ones that treat AI governance as an extension of their existing quality system rather than as a separate initiative, and that invest in the boring work of inventory, context of use, change control, and documented human review before an inspector asks to see it.

Sakara Digital works with pharma and biotech organisations building the AI governance, computerised systems validation, and quality frameworks that this environment demands. If you are looking at your own AI footprint and want an independent perspective on where the gaps are before an inspector finds them, we are happy to have that conversation.