Does Using AI Trigger Part 11? The Question Is Misframed
This is the first question a quality function asks about any AI tool in a regulated workflow, and it is usually asked the wrong way round.
21 CFR Part 11 does not attach to tools. It attaches to electronic records that a predicate rule requires you to keep, and to electronic signatures applied to them. The question is therefore not "is this software Part 11 software". It is: does this system create, modify or maintain a record I am required to keep?
Working out which system is the system of record
Take a concrete case. A model drafts a section of Module 3. A regulatory writer edits it. The final document is checked into your document management system, reviewed and approved there, and submitted from there.
The Part 11 obligations sit on the document management system. That is where the required record lives, where the approval signature is applied, and where the audit trail has to exist. The drafting tool produced an input that a person reviewed and superseded.
Now change one thing. The tool itself becomes the place the approved document is stored, versioned and signed. Now it is a system of record, and Part 11 applies to it directly: audit trails, access controls, signature manifestations, retention.
The difference is not sophistication of the model. It is where the record ends up, which is an architecture decision you make and can therefore control.
Validation: the CSA lens
The other half of the question is validation, and Computer Software Assurance is the right frame.
CSA asks what the software is used for and what could go wrong. Applied here:
- What decision does the output feed? A search that helps someone find a document is not the same risk as an assessment that determines a reporting category.
- Is there qualified human review before the output has consequence? Where a person is accountable for accepting or rejecting each output, the failure mode is a reviewable error rather than an unnoticed one.
- Can you show why the output says what it says? This is the practical control and the one worth insisting on.
Traceability is the control that actually works
For a document-generating system, the useful safeguard is not a confidence score. It is that every assertion points at the source document it came from, so a reviewer can check it in seconds rather than re-deriving it.
That matters for two separate reasons. It makes review fast enough to actually happen, which is what keeps a human genuinely in the loop rather than nominally. And it means the evidence for a claim is a document you already control, not the model's recollection of one.
A system that cannot show its sources moves the burden onto the reviewer to verify everything from scratch, and reviewers under time pressure do not do that.
Where accountability sits
Unchanged. The sponsor is responsible for the content of its submissions and the integrity of its records. No tool transfers that, and no vendor claim about a model changes it.
FDA has issued draft guidance on the use of artificial intelligence to support regulatory decision-making for drugs and biologics, built around a risk-based credibility assessment: establish the question, establish the context of use, then justify credibility proportionate to the risk of the decision the output influences. That framing matches how the rest of the regulation works, and it is the right place to start rather than asking whether AI is permitted.
Frequently asked questions
Does 21 CFR Part 11 apply to AI tools?
It applies to electronic records required by predicate rules and to electronic signatures. Whether it applies to a given tool depends on whether that tool creates, modifies or maintains such a record.
If AI drafts a document, is the draft a regulated record?
Not by itself. What matters is where the approved document is stored, versioned and signed. That system carries the Part 11 obligations.
Do I have to validate an AI tool?
You have to assure it is fit for its intended use, proportionate to risk, which is what CSA describes. The scope depends on what the output is relied on for.
Does human review remove the risk?
Only if the review is real. Review that is fast enough to be done properly, on output whose sources can be checked, is the control; a sign-off on unverifiable text is not.
Who is accountable for an error in an AI-drafted submission?
The sponsor. Responsibility for submission content and record integrity does not transfer to a vendor or a model.
Has FDA said anything specific about AI?
Yes. FDA has published draft guidance on AI supporting regulatory decision-making for drugs and biologics, using a risk-based credibility assessment framework tied to the context of use.