On this page
Agent-drafted and human-edited content distinguishable in every record.
Pilot on one document type: baseline, shadow drafting, live with sign-off, readout.
Built against the evidence expectations of a regulated quality system, not a shipped certification claim.
Challenge
Quality teams already use AI to draft deviations, investigations and batch records, and a person still signs the release. The inspector's question is not whether the draft was good. It is how the record can be shown to be sound.
- The signature carries the liability. A finding lands on the quality lead and the site, never on the tool's vendor.
- A draft without provenance is not evidence. If the sources behind a conclusion cannot be produced, the record cannot be defended.
- Model behaviour changes underneath you. A record written months ago must remain explainable after the model has moved on.
What makes a record defensible, not just correct
- Attributable to a sourceEvery assertion resolves to batch data or a procedure version.
- ContemporaneousCompiled as the investigation happens, not gathered later.
- Attributed to the right authorWhat the model drafted and what a person changed, stored apart.
An AI-drafted quality record
The signature carries the liability, and it is never the vendor's.
- Reproducible after the model movesModel and prompt version pinned to the draft they produced.
- Sequenced by the site's own SOPApprovals follow the existing chain, e-signed in order.
Solution
An inspector does not ask whether AI drafted the record. They ask what it was based on, who changed it, and which version wrote it. The record carries all three.
- Sources attached to every assertion. Each statement in a draft resolves to the batch data, procedure version or prior investigation it came from.
- Authorship separated and recorded. What the agent drafted and what a person changed are distinguishable in the record.
- Model and prompt version pinned to the record. The exact configuration that produced a draft is stored with it.
- Release stays a human act. The agent prepares; it cannot dispose or release.
What Makes a Record Defensible Rather Than Correct
An inspector rarely disputes the conclusion. The question is how the site knows the conclusion is sound, and whether it can show that now, on this record, without assembling anything.
- Attributable to a source. Every assertion in a draft resolves to the batch data, procedure version, equipment log or prior investigation it came from. A statement with no source does not enter the record.
- Contemporaneous with the work. The evidence is compiled as the investigation happens, not gathered later when a question arrives. A record built after the fact is a reconstruction and it reads like one.
- Attributed to the right author. What the model drafted and what a person changed are stored separately and stay distinguishable, including the case where a reviewer accepted a draft unchanged.
- Reproducible after the model has moved. The model and prompt version that produced a draft are pinned to it, so a record written last year remains explainable once the underlying model has been replaced.
- Sequenced by the site's own SOP. Approvals follow the chain the SOP already defines and are e-signed in order. The system does not invent a shorter route because a shorter one exists.
The Deviation the Model Has Never Seen
The failure mode worth designing for is not a bad answer on a familiar deviation. It is a confident answer on an unfamiliar one, because nothing in the output looks any different.
- Unfamiliar is a state, not a low score. A deviation that does not resemble the site's history is flagged as unfamiliar and routed to a person before anything enters the QMS, rather than being drafted at reduced confidence and signed anyway.
- Routine keeps its speed. The separation is the whole value. If every case routes to a person the drafting is worthless, and if none do the record is not defensible.
- Escalation is named in advance. Who sees an unfamiliar deviation, and inside what window, is agreed before go-live rather than decided during one.
- Disposition is out of scope entirely. Batch release is not a threshold that can be raised. It is outside what the agent may do at all.
The artifact that decides this is not a demo.
It is one sample audit package, reviewed with quality and regulatory leads, because that is the thing an inspector will actually hold.
Outcome Derived
This is a 60 to 90 day pilot on a single line, cell, category or product family. The figures below are what the pilot measures against a baseline captured in its first two weeks. They are targets and instrumentation, not results already delivered.
- Records reproducible at inspection. Designed so a record from any date can be reconstructed with its sources and its authorship.
- Draft-to-approval time measured. Compared against the baseline captured before the pilot, on one document type.
- Nothing claimed about certification. This maps to the evidence an inspection asks for. It is not, and is not presented as, a held certification.
Highlights
- Every AI-touched output is bound to what it read, the tool version that produced it, and the time it was produced.
- A deviation unlike anything the model has handled before is routed to a person instead of drafted through. Familiar cases keep their speed.
- The review chain mirrors the site's own SOP: investigator, quality reviewer, then release authority, in sequence and e-signed.
- The agent prepares. It cannot dispose, release or close a batch, and that limit sits in the layer rather than in an instruction.
- Designed to map to the evidence a regulated inspection asks for. Not presented as a held certification for the site's quality system.
Frequently asked questions
Do we have to replace the quality AI our team already uses?
No. The drafting and triage tools stay. This is the checkpoint every output passes before anything enters the QMS or a batch record, so the tools your team already chose become defensible in the record rather than being swapped out for someone else's.
What does an inspector actually get?
One record rather than a reconstruction. It shows what the draft was based on, which procedure version and batch data it read, the model and prompt version that produced it, what a person changed, and the e-signed approvals in the order the site's SOP defines.
What happens on a deviation the model has never seen?
It is flagged as unfamiliar and routed to a person before it can enter the record. That case is the one no drafting tool handles well, because an unfamiliar deviation produces output that looks exactly as confident as a familiar one and nothing in the text signals the difference.
Is CreateOS claiming a GxP or Part 11 certification for our system?
No. The controls are designed to map to the evidence expectations a regulated quality system carries, and validation of your system remains yours. Anything presented as a shipped certification for your site would be wrong, and this study does not present one.
Is there risk to a live batch during the pilot?
None in the first weeks. Drafting runs in shadow and the evidence record is generated for every output while nothing touches a live record or a release, so the quality team reviews a real audit package before anything is switched on.








