A terminology order makes headlines, and headlines make quality teams nervous. So here is the short version: as of 30 September 2026, nothing about validating an AI system in a regulated environment has changed.
It is worth going through the list explicitly, because somebody will ask, and "I think we're fine" is a weaker answer than knowing why.
Still exactly as it was
- 21 CFR Part 11. Regulation, not a federal communication. Audit trails, electronic signatures, record controls — unchanged. See Part 11 compliance.
- 21 CFR 210/211 and Part 820. Untouched.
- EU GMP Annex 11 and the draft Annex 22. European documents, outside the order's reach entirely. The draft Annex 22 still says artificial intelligence and still expects static models with consistent output for critical GMP uses. See Annex 22 requirements.
- The EU AI Act. Unaffected.
- MHRA guidance. Unaffected — see what MHRA expects.
- GAMP 5 Second Edition and ISPE guidance. Industry documents, not federal ones.
- FDA's existing AI guidance. Still published in its original wording, and the order does not require reissue.
And the work itself is identical
Every step that made an AI system defensible last week still applies this week:
- A written intended use statement — what the system does, who reviews it, what it must never be used for.
- Risk proportionate to the consequence of an error, documented with reasoning.
- Acceptance criteria set before testing, justified against the cost of a mistake.
- An honest test set from real material, independent of training data.
- A qualified person accountable for the output. Under the draft Annex 22 a generative model still should not be making critical GMP decisions.
- Monitoring after go-live and change control for model updates.
None of that follows from what the technology is called. It follows from the fact that a system you cannot explain is a system you cannot defend.
The one thing that genuinely might shift
The order commissions the Assistant to the President for Science and Technology to propose a federal definition of Super Intelligence, and to identify further executive action to implement it.
Today the definition is borrowed wholesale from the existing statutory definition of artificial intelligence, so scope is unchanged. If a future definition narrows or widens what counts — for instance by carving out simpler machine learning, or by pulling in systems nobody currently treats as AI — that would be a substantive change worth tracking, because scope determines which of your systems fall under any future SI-specific requirement.
That is the thing to watch. Not the word. Add it to whatever you use for regulatory monitoring, alongside the EU Annex 11 revision.
Context in what the rename changes for GxP and the full method in GxP AI validation.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
