FDA's First AI Warning Letter: Don't Blame the Wallpaper
In April 2026, the FDA warning letter to PurOlea attracted significant attention for its references to the use of AI. Of every compliance concern the letter identified, AI was the least consequential.
AI became the headline. It was never the core problem. Inspectors found foundational GMP failures: facility cleanliness, maintenance, and basic manufacturing controls.
Read the letter
PurOlea Cosmetics Lab was a small operation in Livonia, Michigan, making homeopathic drug products - among them "Dermveda Extra Strength Shingles Relief" and an "Ultra Genital Herpes Relief" product, marketed with disease claims that made them unapproved new drugs.
FDA's investigator observed insects, filth, leaves, and clutter in several areas of the facility, and a docking bay door that left manufacturing exposed to the outside environment. The firm released finished drug products without testing for microbiological attributes. It did not test incoming components for identity, relying instead on supplier certificates of analysis without ever establishing that the supplier data was reliable. That is not an AI problem, it is a fundamental quality oversight problem.
Who was independently verifying the data, qualifying the suppliers, and making the decision that those materials were acceptable for use? Since when does AI replace the quality unit?
Buried in that: the firm told investigators it had used AI agents to create drug product specifications, procedures, and master production and control records "to be in compliance with FDA requirements," then used those documents without human review. Asked why it had not performed process validation, the firm said it was "not aware of the legal requirement, as the AI agent you used ... never told you it was required."
The question isn't whether AI was used
The more important question for regulatory and quality professionals is not whether AI was used, but how it was governed. Where were the experienced quality and regulatory voices in the decision-making process?
At PurOlea, there were none to be found. The company had four employees. No regulatory staff. No quality or GMP manufacturing staff. Its founder came to drug manufacturing from a sales and marketing background - five years as a sales representative, a marketing degree, no prior regulated-manufacturing experience.
A more realistic interpretation is that PurOlea treated AI as a shortcut to capabilities that normally require experienced quality and regulatory leadership. Under pressure to move quickly and demonstrate progress to investors and clients, the organization relied on AI in areas where technology simply cannot substitute for regulatory judgment, GMP experience, or an effective quality system.
Why the model said nothing
"The AI never told us" is not the defense it sounds like. It is an accurate description of how these general-purpose AI systems behave, and worth understanding properly.
A general-purpose model answers the question in front of it, using only the context it is given. It cannot see your loading dock, and it has no standing instruction to raise what you did not ask about. These systems are also trained on human preference ratings, and people rate agreeable answers highly, so a model tends to confirm your framing rather than interrogate it. Anthropic's own published research on sycophancy found that human raters and the preference models trained on them will sometimes prefer a convincingly written but incorrect response over a correct one.
Ask a chat window for an SOP and you get an SOP. You do not get "there are insects in your production area." A system purpose-built for regulatory work behaves differently, because the guidances, the standards, and the product's own regulatory history sit inside it, and it is designed to flag the gap you missed.
Even so, the tool was never the deciding factor. Ask any frontier model whether a facility with insects and filth in the production area meets CGMP and it will tell you no, immediately, every time. The information was always available. What was missing was the judgment to go looking for it, and to recognize that a generated SOP is a draft rather than a controlled record. That is not an AI failure. It is a quality failure that AI happened to be standing next to.
The rule FDA actually wrote
FDA's rule in the letter is boring and correct: "If you use AI as an aid in document creation, you must review the AI generated documents to ensure they were accurate and actually compliant with CGMP."
That is the same standard already applied to a contractor's draft or a purchased template. FDA did not ban AI. It declined to let a model hold the quality unit's job - because a model cannot be held accountable. FDA tied that directly to 21 CFR 211.22(c), which places responsibility on the quality unit for approving or rejecting procedures and specifications affecting product quality.
The industry drew the wrong lesson
Vendors and consultants turned this letter into "AI is radioactive in GMP." Commercial regulatory and quality teams cited it to pause tools that would have sat behind citation and human approval anyway. That reading gets the causation backwards. This was not a frontier AI failure. It was a firm with a broken quality system using a chatbot as wallpaper over structural compliance problems, then acting surprised when the inspector looked behind it.
If your organization has a functioning quality unit, document control, and people who know Part 211 without asking a chatbot, your risk is not that the FDA will punish you for using AI. Your risk is treating a firm with fundamental quality unit failures as the reason to keep your dossier and QMS trapped in manual, inefficient ways of working.
AI can support expert judgment, but it should not replace the regulatory and quality expertise needed to interpret health authority expectations and maintain a compliant manufacturing operation.
AI can draft. Human judgment and expertise remain essential.
For the mechanics of a warning letter and what a response has to contain, see our glossary entries on the FDA warning letter response and the Form 483 that usually precedes one, and on AI in regulatory affairs. The full corpus of published letters is searchable in our warning letter search, and the enforcement trend behind them is in What FDA Warning Letters Stopped Being About.
Sources
- FDA, Purolea Cosmetics Lab - 722591 - 04/02/2026 - fda.gov
- RAPS, FDA warns firm for inappropriate use of AI in drug manufacturing - raps.org
- BioSpace, FDA's first AI-focused cGMP warning letter signals new scrutiny for manufacturers - biospace.com
- MasterControl, FDA issues first warning letter for AI compliance - mastercontrol.com
- Anthropic, Towards Understanding Sycophancy in Language Models - anthropic.com