AI in GxP: Moving Beyond Governance to Operational Evidence
Explore AI in GxP beyond governance, with operational evidence, risk-based assurance, human oversight, traceability, and continuous AI lifecycle confidence.
share this

1.0. Introduction
Imagine an AI assistant supporting a deviation investigation inside a pharmaceutical organization. It retrieves controlled procedures, summarizes the investigation history, identifies potential root causes, drafts a CAPA, and presents its recommendation to a qualified reviewer. The workflow appears efficient. The reviewer approves the final outcome, and the organization moves on.
Six months later, a quality reviewer asks a different set of questions.
Which AI model version generated the recommendation? What data and knowledge sources influenced the output? Which instructions or configuration were active at the time? What did the AI actually do? What did the human reviewer change? Was the action within the system’s authorized scope? What happened when the underlying model, prompt, retrieval source, or workflow changed?
At that point, an uncomfortable distinction emerges.
Does the organization have an AI policy, or does it have evidence that the AI-operated process can be trusted?
That distinction will increasingly define the next phase of AI adoption in GxP environments.
2.0. A Candid Conversation: No Slides, No Scripts
Unlike traditional webinars, this LinkedIn Live session is an unscripted, presentation-free discussion. There will be no slide decks, no formal presentations, and no pre-defined script guiding the conversation.
Instead, the session is designed as a candid, experience-driven dialogue between practitioners who have worked directly across GxP, Quality, validation, regulatory compliance, and enterprise technology.
This format creates space for a more authentic exchange grounded in real-world implementation challenges, lessons learned, and practical experience rather than theoretical AI governance frameworks.
The discussion will explore what responsible AI adoption actually looks like when AI moves from experimentation into regulated operations. Rather than focusing on broad principles or policy statements, the conversation will examine how organizations can connect Context of Use, risk-based assurance, human oversight, traceability, change control, and operational evidence to the realities of AI-enabled and agentic systems.
The conversation will also look back at the lessons from 21 CFR Part 11 and the transition to electronic records and signatures, using that experience to consider what today's AI transition may require. The emphasis will be on how organizations can move beyond governance as a static exercise and build an operating model where trust is demonstrated through evidence generated throughout the AI lifecycle.
Rather than focusing on AI features or technology capabilities, the session will emphasize how Quality, IT, validation, business, and AI teams can make practical decisions in complex GxP environments and what it takes to make AI genuinely usable, governable, and defensible.
3.0. About Evjatar (Evi) Cohen
Evjatar (Evi) Cohen is a Life Sciences executive with 30+ years of experience spanning GxP compliance, Quality Assurance, computer system validation, and enterprise technology. His career includes significant leadership roles within the pharmaceutical industry, including Teva Pharmaceuticals, where he served as Head of IP Strategy Execution and Associate Director of Quality Assurance. At Teva, he led major e-records, e-signatures, electronic document management, validation, regulatory, and intellectual-property initiatives, and represented the Generic Pharmaceutical Association on the industry coalition involved in the development of 21 CFR Part 11. He also served as a Senior Computer Systems Validation Consultant and Project Manager supporting global pharmaceutical organizations.
Evi subsequently held senior global Life Sciences leadership positions at Appian and ServiceNow, driving technology strategy, client success, business growth, and digital transformation across regulated industries. Today, as Founder & CEO of EVVIA LLC, he focuses on bridging AI innovation and GxP compliance. His combination of hands-on pharmaceutical experience, regulatory expertise, validation leadership, and enterprise technology makes him uniquely positioned to discuss how organizations can adopt AI while maintaining practical, risk-based assurance and regulatory confidence.
4.0. The Inspection Question AI Creates
AI governance is becoming an established part of enterprise strategy. Organizations are creating AI policies, governance committees, model inventories, responsible-AI principles, risk classifications, approval processes, and oversight structures.
All of these are important.
But governance defines what an organization expects to happen. It does not, by itself, demonstrate what actually happened in a specific regulated process.
That difference becomes significant when AI moves from experimentation into operational GxP workflows.
A traditional software application may execute a predefined function according to established logic. An AI-enabled application can interpret information, generate content, retrieve knowledge, make recommendations, or influence a decision. An agentic system may go further, selecting tools and actions dynamically to accomplish a defined goal.
The assurance challenge therefore becomes less about whether an organization has approved the use of AI in principle and more about whether it can reconstruct and defend a particular use of AI.
If a quality reviewer asks why an AI-generated recommendation was accepted, the organization should be able to explain the intended use, the relevant context, the controls that applied, the evidence available to the reviewer, and the final human decision.
If an inspector asks what changed since the system was originally assessed, the organization should not have to reconstruct the answer manually from disconnected documents and email threads.
This is the emerging challenge of operational evidence.

5.0. What 21 CFR Part 11 Teaches Us About Technology Transitions
There is a useful historical parallel in the transition from paper-based records to electronic records.
When FDA issued the final 21 CFR Part 11 regulation in March 1997, it established criteria for electronic records and electronic signatures under specified circumstances. The regulation became effective in August 1997. Part 11 operates alongside the underlying FDA record keeping requirements, or predicate rules, it did not independently create those underlying recordkeeping obligations.
The deeper lesson from that transition is not simply about electronic signatures or audit trails.
It is about trust.
Organizations were adopting technology that changed how regulated information was created, maintained, signed, retrieved, and controlled. The industry therefore needed ways to demonstrate record integrity, accountability, security, and appropriate control in an electronic environment.
AI represents another technology transition, but with an important difference.
With electronic records, the central question was often whether a record remained trustworthy after moving from paper to a computerized environment. With AI, the organization may also need to understand how an intelligent system influenced the creation, interpretation, recommendation, or execution associated with that record.
That expands the evidence model.
The question is no longer simply, “Can we show the record?”
It becomes:
Can we show how the AI contributed to the process that produced the record, and can we demonstrate that the contribution was appropriate for its intended use?
This does not mean every AI system requires an elaborate explanation of every internal model operation. It means organizations need appropriate traceability, accountability, reproducibility where feasible, and evidence proportionate to risk.
The historical lesson of technology adoption remains relevant, innovation becomes sustainable in regulated environments when trust is not merely asserted, but demonstrated.
6.0. Context of Use Is More Important Than the AI Label
One of the most important changes in AI assurance is recognizing that “AI” is not itself a sufficient risk category.
Consider three scenarios.
An employee uses an AI assistant to brainstorm ideas for an internal presentation. Another AI system summarizes controlled procedures for a quality professional. A third AI agent recommends a product-quality action, updates information in a validated system, or performs a regulated workflow with limited human intervention.
All three involve AI. Their assurance requirements should not be assumed to be identical. The more useful question is:
What exactly is the AI being used to do?
This is the importance of Context of Use (COU).
FDA’s January 2025 draft guidance on AI supporting regulatory decision-making for drugs and biological products explicitly proposes a risk-based credibility framework tied to a particular Context of Use. The document is draft, nonbinding, and not for implementation, but it illustrates an important direction: AI credibility should be assessed in relation to the specific role and use of the system rather than treating AI as a uniform technology category.
FDA and EMA have also published guiding principles emphasizing concepts such as human-centric design, risk-based approaches, clear context of use, data governance, risk-based performance assessment, lifecycle management, and clear essential information for AI in drug development.
These principles point toward a practical way of thinking about AI assurance. The level of assurance should reflect the AI system’s influence on the process, the consequence of error, the sensitivity of the data involved, the degree of autonomy, its effect on regulated records or decisions, and the effectiveness of human oversight.
The AI label tells us very little. The Context of Use tells us where the risk actually lives.
7.0. What Operational Evidence Actually Looks Like
Operational evidence is not another name for documentation. It is the body of evidence that allows an organization to reconstruct a meaningful AI-assisted or AI-driven event and understand whether the process remained within its approved boundaries.
Consider the deviation investigation scenario again.
Suppose an AI system retrieves approved SOPs, historical deviations, investigation records, and other authorized knowledge sources. It summarizes the available evidence, proposes a potential root cause, and drafts a CAPA for review.
A defensible evidence trail would connect the approved intended use and Context of Use with the actual execution. It would identify the model and relevant configuration, the applicable prompt or agent instruction version, the knowledge and retrieval sources used, the information supplied to the system, and the output it generated. It would also capture what actions were performed, what the qualified reviewer accepted or rejected, what comments or modifications were made, and what final decision was approved.
If an exception occurred, that exception should be visible. If a human reviewer overrode the recommendation, the oversight should be demonstrable. If the system changed after deployment, the organization should be able to determine what changed and whether the change affected the approved use or risk profile.
This is where different forms of evidence connect.
- Design evidence establishes what the system is intended to do.
- Testing evidence demonstrates whether defined controls and expected behaviors have been appropriately assessed.
- Operational evidence shows what happened during actual use.
- Human-oversight evidence demonstrates where qualified people exercised judgment.
- Change-control evidence demonstrates how the organization maintained control as the system evolved.
Together, these create something more valuable than a policy document, a defensible chain from intended use to actual outcome.
8.0. Why Agentic AI Requires a Continuous Evidence Model
Agentic AI changes the assurance conversation because the system can interpret goals, retrieve information, make decisions, interact with systems, and execute actions not simply generate an output. In a GxP environment, organizations therefore need evidence of what the agent was intended to do, what it actually did, what information it used, what controls constrained it, and where human oversight occurred.
Traditional validation establishes an important baseline, but AI systems can evolve through model updates, configuration changes, new knowledge sources, and changes in connected applications. This makes continuous evidence increasingly important.
A practical evidence model connects intended use to risk, risk to controls, controls to operational evidence, evidence to human accountability, and changes to ongoing assurance. Execution records, provenance, configuration information, human approvals, exceptions, and performance monitoring can collectively demonstrate that the AI-enabled process remains within its approved Context of Use.
The goal is not to document every AI interaction. It is to maintain risk-based, traceable, and meaningful evidence that demonstrates the process remains controlled and defensible over time.

9.0. Join the Live Conversation
The future of AI in life sciences will not be determined by the number of AI policies an organization publishes.
It will be determined by whether the organization can demonstrate what the AI did, why it was authorized, what a qualified person reviewed, what changed, and why the resulting process remained within its approved Context of Use.
That is the shift from governance theater to operational evidence.
AI governance remains essential. But governance becomes meaningful when it reaches the operational layer when intended use is connected to controls, controls are connected to evidence, evidence is connected to human accountability, and changes are connected to ongoing assurance.
The objective is not another broad conversation about “AI and compliance.”
It is a practical question:
What will it take to make AI genuinely usable, governable, and defensible in a GxP environment?
đź“… LinkedIn Live Event
September 30, 2026 | 12:00 PM EST
AI in GxP: Moving Beyond Governance Theater to Operational Evidence
Featuring
Evjatar (Evi) Cohen – Founder & CEO, EVVIA LLC
Hosted by
Nagesh Nama – CEO, xLM Continuous Intelligence
This unscripted, presentation-free podcast-style discussion is a timely conversation for life-sciences leaders navigating AI adoption in GxP environments. It will examine how organizations can move beyond policies and governance frameworks to connect intended use, risk-based controls, operational evidence, human accountability, and ongoing assurance so that AI adoption is not only governed in principle, but defensible in practice.
👉 Reserve your spot to join the live conversation and gain practical lessons from leaders at the forefront of next-generation pharmaceutical manufacturing.
10.0. Recent LinkedIn Live Events by xLM ContinuousTV
Why Content Innovation Cloud (CIC) for Pharma: Modernizing Compliance
Designing Biologics Facilities: Strategy to Operational Excellence
The Board's View of Quality Risk: Governance, Al, and the New cGMP Playbook
11.0. About the Authors
Nagesh Nama
CEO, xLM Continuous Intelligence | Founder, ValiMation
Nagesh is a pioneer in AI/ML-driven GxP compliance with nearly three decades of experience helping pharmaceutical, biotech, and medical device companies navigate validation, data integrity, and regulatory compliance. He is the founder and CEO of both ValiMation (founded 1996) and xLM Continuous Intelligence, the company that first introduced a Continuous Validation platform supporting IaaS/PaaS/SaaS environments compliant with 21 CFR Part 11 and Annex 11. Today, xLM offers a comprehensive suite of continuously validated AI/ML managed services spanning intelligent validation (cIV), predictive maintenance, temperature mapping, and GxP AI agents. Nagesh is a member of the Forbes Technology Council and the Fast Company Executive Board, a contributor to Forbes and Fast Company, and has been featured on Microsoft's AI Agents Vlog. He holds an M.S. in Manufacturing Engineering from the University of Massachusetts, Amherst.
Kashyap Joshi
Program Manager, AI/ML ContinuousOS Apps | xLM Continuous Intelligence
Kashyap Joshi is a Program Manager at xLM, where he leads the implementation of complex AI systems for life sciences organizations by aligning stringent GxP regulatory requirements with next‑generation technology and xLM’s ContinuousOS Suite of Apps to deliver measurable ROI, continuous compliance, and long‑term transformation for clients across pharma, biotech, and medical devices.
share this
