Someone in your company is already using Microsoft Copilot or ChatGPT. Probably several people. The question landing on quality teams right now isn't whether to allow it — it's where the line sits, and how to write that down in a way people actually follow.
Short version: general-purpose assistants are fine for plenty of work in a regulated company, and they cannot be the system of record for anything GxP. The useful part is understanding exactly why, because that tells you where the line goes.
Why a general assistant can't hold a GxP record
It isn't about the quality of the writing. It's about four things a regulated record needs that these tools don't provide.
- No record-level audit trail. Part 11 and Annex 11 expect a tamper-evident trail showing who created or changed a record, when, and what changed. Your tenant may log that a chat happened; that is not an audit trail for the content.
- No electronic signature. There is no compliant signing step, no re-authentication, no signature meaning.
- The version changes underneath you. The provider updates the model on its schedule. A validated state you cannot hold still is not a validated state — see change control and revalidation.
- No defined intended use. A general assistant does everything and is therefore validated for nothing. Validation starts with a narrow, written intended use.
None of that makes the tools unusable. It makes them unusable as the place a GxP record lives.
Where they're genuinely fine
- Summarising published guidance or a standard you already have access to.
- Drafting internal, non-GxP material — a meeting agenda, a project update, a job advert.
- Rewriting your own text for clarity, where you verify every sentence and the result goes through the normal controlled process.
- Helping someone understand a concept before they do the regulated work in the validated system.
- Coding and data work outside GxP systems.
The common thread: nothing leaves the assistant and becomes a record without a person putting it through the controlled system, where the audit trail and signature live.
Where people get into trouble
- Pasting a deviation or an investigation in to "help write it up". You have now sent regulated content to a system outside your quality system, and the draft has no traceability back to source.
- Asking it to interpret a regulation and acting on the answer. It will sound confident and is sometimes wrong — and there is no citation you can put in front of an inspector.
- Generating test scripts or validation documents and filing them. If the output becomes a GxP deliverable, the tool that produced it is in scope. See GxP AI validation.
- Uploading client or pre-approval material. Often barred by your own contracts, whatever your AI policy says. See data privacy in GxP AI.
"Can we validate Copilot?" — the honest answer
You can validate a specific, narrow use of a tool. You cannot validate a general assistant in the abstract, because validation is always against an intended use, and "answers any question" is not one.
So the question to ask is: what exactly would we rely on it for, what would go wrong, and would a person catch it? If the answer survives that, you write the intended use, set acceptance criteria, test on real examples, and keep a human approving. At that point you generally discover you want a tool built for the job — one with an audit trail, signatures, version control and a defined scope — which is the difference between an assistant and a validated system.
The draft EU GMP Annex 22 points the same way: it does not expect generative models to be making critical GMP decisions, and where generative AI supports lower-risk work, the control is a qualified person reviewing the output.
A policy people will actually follow
Blanket bans fail. People use the tools on their phones instead, and you lose visibility. A workable policy is short and specific.
- Name the approved tool and tenant. An enterprise tenant with contractual terms is a completely different risk profile from a personal account.
- List what must never go in: patient data, pre-approval material, client-confidential documents, anything from a GxP record.
- State the output rule in one line: nothing from an assistant becomes a GxP record without going through the controlled system and a named approver.
- Say where to go instead. If people need AI help with validation or clinical documents, point at the validated route — that is what GxP Copilot and TraceDraft exist for.
- Train on real examples, including a confidently wrong answer. See SOPs and training for AI.
For the wider regulatory picture, see GxP AI and AI governance services.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
