Valak AI · August 2026 · Pharmaceutical Manufacturing, Regulatory Compliance, Industrial AI
There is a particular kind of organizational anxiety that settles over a pharmaceutical plant the week before an FDA inspection. Quality teams pull late nights cross-referencing batch records. IT administrators audit access logs they haven’t touched in months. Operators suddenly remember that the historian has been rolling up data to five-minute averages for the past two years because no one ever changed the default.
Then the investigator walks in, sits down, and asks what the bioreactor temperature was at 03:14:22 on a Thursday night six weeks ago.
That question — specific, timestamped, unforgiving — is the entire data integrity problem in one sentence. Either the record exists at native resolution, linked to the sensor, the batch, and the qualified human who was responsible, or it doesn’t. There is no partial credit. There is no “we had a rolling average.” There is no version of “our AI flagged something but we’re not sure exactly what it saw” that satisfies a 21 CFR Part 11 audit or an Annex 11 inspection.
The pharmaceutical industry is in the middle of the most significant AI adoption wave in its history. And the regulatory frameworks governing that adoption — FDA 21 CFR Part 11, EU GMP Annex 11 (now in its most sweeping revision since 2011), the FDA-EMA joint AI principles released in January 2026, and the new GAMP 5 AI Validation Guide — have never been more precise, more demanding, or more actively enforced.
This is the article that maps where those two realities intersect: the ambition of AI-driven pharmaceutical manufacturing, and the absolute, non-negotiable compliance architecture that governs every byte of data that AI touches.
Why Pharma Data Integrity Is a Different Category of Problem
Before we talk regulations, it’s worth being honest about what makes pharmaceutical manufacturing data integrity categorically harder than data integrity in almost any other industry.
In most industrial environments, a missed data point is an inconvenience. In pharmaceutical manufacturing, a missed data point is potentially a patient safety event. The data produced by a SCADA system running a sterile fill-finish line isn’t operational telemetry in the conventional sense — it’s part of the batch record. It is, in a very real legal and regulatory sense, part of the evidence that a particular medicine was made correctly, to specification, under controlled conditions, and is safe to administer to a human being.
That framing changes everything about how you think about data collection, storage, AI analysis, and the audit trail that wraps around all of it.
The ALCOA+ Standard: The Eight Pillars of Pharmaceutical Data
Pharmaceutical data integrity is governed by a principle framework called ALCOA+. It’s been in use for decades, but it has taken on new urgency as AI systems begin touching regulated data. ALCOA+ requires that every data point be:
– Attributable — linked to the person, system, or device that created it, with a verified timestamp
– Legible — readable and interpretable throughout its full retention period
– Contemporaneous — recorded at the time of measurement, not reconstructed or transcribed afterward
– Original — the first record of measurement, not a copy or a derivative
– Accurate — a true reflection of the actual measurement, with any corrections formally documented
– Complete — the full record, including out-of-spec readings, alarms, and system errors — nothing deleted or hidden
– Consistent — uniform in format, time reference, and structure across the system
– Enduring — stored on validated media, backed up, and accessible for the full retention period (typically five to ten years in GMP environments)
– Available — retrievable quickly by authorized users for audits, investigations, and inspections
When you read that list, something becomes immediately clear: ALCOA+ is not a documentation standard. It is a *data architecture* standard. It describes what your data capture, storage, and retrieval infrastructure must do, not just what your document templates should look like.
A historian that samples every ten seconds fails ALCOA+. A system that rolls up to one-minute averages fails ALCOA+. An AI that processes data and produces recommendations without capturing what data it used and what logic it applied fails ALCOA+. Every single one of those failures represents a potential regulatory citation — and increasingly, a warning letter.
21 CFR Part 11: The Regulation That Was Written for a Different Era and Is Being Applied to AI Anyway
FDA 21 CFR Part 11 was finalized in 1997. The pharmaceutical industry was still largely paper-based. “Electronic records” meant a spreadsheet. “Electronic signatures” were a novelty. No one writing that regulation was thinking about machine learning models that process thousands of sensor readings per second and produce real-time batch disposition recommendations.
And yet: 21 CFR Part 11 applies fully to any AI system processing GxP data.
The regulation’s core requirements are well known to anyone in pharma quality: electronic records must be attributable, date- and time-stamped, protected from unauthorized access, backed up, and available for FDA inspection. Electronic signatures must be linked to the individual who applied them and cannot be reused or reassigned. Audit trails must capture who did what, when, and — critically — why any changes were made.
Where AI Creates New 21 CFR Part 11 Complexity
The challenge with AI systems is that they create a new category of “action” that the original regulation never contemplated. When a machine learning model flags a batch as out-of-spec based on a pattern in the SCADA data, who “signed” that recommendation? When an AI agent correlates a bioreactor temperature deviation with a CIP sequence from two days prior and surfaces that as a root cause hypothesis, what is the audit trail for that reasoning?
The FDA’s enforcement posture in 2025 and 2026 has answered that question with increasing clarity:
– Algorithmic decisions that affect GxP records require audit trails that capture what data the algorithm used, what model version it was running, and what output it produced.
– AI output that enters the quality management system must be reviewed and approved by a qualified human before it is acted upon. The AI does not transfer regulatory accountability.
– Validation documentation for AI tools must be integrated into QMS records and updated when the model changes.
In April 2026, the FDA issued what became known as its first dedicated AI enforcement action against a pharmaceutical manufacturer — Warning Letter 320-26-58 to Purolea Cosmetics Lab. Under a heading that had never appeared in an FDA warning letter before — *”Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing”* — the agency documented that the company had used AI agents to generate drug product specifications, standard operating procedures, and master production records without any human review.
The FDA’s language was unambiguous:
> “If you use AI as an aid in document creation, you must review the AI generated documents to ensure they were accurate and actually compliant with CGMP. Your failure to do so is a violation of 21 CFR 211.22(c).”
The letter went further: any output or recommendation from an AI agent must be reviewed and cleared by an authorized human representative of the Quality Unit, in accordance with section 501(a)(2)(B) of the FD&C Act. That language is prospective. It applies to everything the company does going forward, not just what it did wrong in the past.
That is not a warning about future guidance. That is the law, applied right now, to AI systems in pharmaceutical manufacturing.
What 21 CFR Part 11 Means for SCADA-Connected AI
When AI is connected to your SCADA environment — reading process data, correlating historian trends, generating batch analysis, or surfacing anomalies — every output it produces that touches a GxP record falls under 21 CFR Part 11. That means:
1. The AI’s data inputs must be traceable to validated, calibrated sources.
2. The model or agent version must be documented and change-controlled.
3. Any finding or recommendation that enters the QMS must carry a documented human review and approval.
4. The audit trail must survive the full retention period — five years minimum, often longer.
5. Access to the AI system must be role-controlled, with unique user authentication and no shared credentials.
None of this is optional. None of it can be deferred to “once we scale.” And none of it is achievable if your underlying data infrastructure is sampling, averaging, or dropping signals.
EU GMP Annex 11: The Most Significant Revision in Over a Decade
The European Medicines Agency’s Annex 11 governs computerized systems in GxP environments across the EU. The existing version, written in 2011, was already stringent. The July 2025 draft revision is something else entirely.
The document grew from 5 pages to 19 pages. It was restructured from a handful of loosely organized principles into 17 discrete, formally organized sections. And it introduced requirements that are, in several cases, materially new expectations for the industry — not refinements of existing obligations but genuinely new things that regulated facilities are now expected to do.
The Four Changes That Matter Most
Audit trail scope expanded to data creation events. Under the previous version, audit trails were primarily triggered by changes and deletions. The 2025 draft requires audit trails to capture data *creation* events as well. If a temperature reading is logged, that logging event itself must be traceable. For pharma SCADA environments, this is a significant expansion: it means every sensor reading, every historian write, every OPC-UA tag update that produces a GxP record must generate an immutable log entry at the moment of creation.
Audit trails must be always-on and user-lockable. The draft makes explicit what many facilities have been treating as a best practice: audit trails must be enabled at all times and cannot be disabled by normal system users. Any attempt to disable audit trail functionality must be flagged as a suspicious event and investigated. Automated alerts should flag bulk deletions, after-hours modifications, and repeated failed login attempts.
Mandatory MFA and stricter access management. The 2025 draft introduces dedicated cybersecurity and access management sections that were previously handled only by implication. Multi-factor authentication is explicitly addressed. Shared credentials — one of the most persistent data integrity vulnerabilities in older SCADA environments — are incompatible with the updated standard. Every user action must be traceable to a named, authenticated individual.
Periodic revalidation on a defined schedule. A one-time IQ/OQ/PQ is no longer sufficient. The draft requires validation status to be reviewed on a documented schedule: monthly for high-risk systems, quarterly for routine systems, and always before batch release when process data supports the release decision. For AI systems, this means model performance must be reviewed, documented, and formally confirmed at defined intervals — not just when someone notices something seems off.
Alongside the Annex 11 revision, the EMA also introduced Annex 22, dedicated specifically to AI-based systems in pharmaceutical manufacturing. Annex 22 creates a formal lifecycle traceability requirement for AI: the model’s training data, validation approach, version history, and performance over time must all be documented and available for inspection. This is the EU’s explicit acknowledgment that AI is now a regulated component of the GMP environment, not a productivity tool that sits outside the compliance perimeter.
The comment period on the Annex 11 draft closed in October 2025. Final publication is expected in mid-2026. If it isn’t finalized already by the time you’re reading this, it will be very soon.
The FDA-EMA Joint AI Principles: When Two Major Regulators Agree
In January 2026, the FDA and EMA jointly released “Guiding Principles of Good AI Practice” — a coordinated statement on what responsible AI deployment looks like in regulated pharmaceutical environments. The fact that both agencies released a *joint* document is itself significant. It signals regulatory convergence at a global level, not just parallel guidance that companies can interpret differently depending on which market they’re selling into.
The joint principles are organized around themes that will be familiar to anyone who has read either agency’s recent enforcement actions: human oversight, transparency, validation, and accountability. But several elements stand out as directly relevant to SCADA-connected AI deployments:
-Explainability is not optional for GxP applications. An AI system that produces a batch disposition recommendation without being able to explain the data and logic behind that recommendation is not compliant, regardless of how accurate its recommendations happen to be. The system must be able to show its work — which means the underlying data used in every inference must be captured and auditable.
-Training data provenance must be documented. If your AI model was trained or fine-tuned on historical SCADA data, that data must be documented as part of the model’s validation dossier. If that historical data was sampled, averaged, or otherwise degraded before it was used for training, that degradation must be disclosed and its impact on model performance must be assessed.
-Drift monitoring is a regulatory expectation. AI models degrade over time as process conditions change. The joint principles make clear that ongoing monitoring of model performance is not a nice-to-have — it is a component of the validation lifecycle. For SCADA-connected AI, this means comparing current model outputs against ground truth at defined intervals and documenting the results.
The human-in-the-loop requirement is explicit and non-negotiable.** For any AI system whose output affects a GxP decision — batch release, deviation investigation, specification review — a qualified human must review and approve that output before it is acted upon. The AI can recommend. The human must decide. And that decision must be documented.
The GAMP 5 AI Validation Guide: Industry’s Attempt to Operationalize Compliance
In February 2025, ISPE released a dedicated AI Validation Guide as a supplement to GAMP 5. This is the pharmaceutical industry’s own attempt to translate the regulators’ principles into practical, implementable validation practices.
The guide is notable for several reasons.
First, it acknowledges explicitly that AI systems in pharmaceutical manufacturing span a spectrum of risk and complexity — from simple rule-based automation at one end to adaptive machine learning models with opaque internal logic at the other. The validation requirements scale accordingly, but they never reach zero: even the simplest AI tool that touches GxP data requires some form of documented validation.
Second, the guide introduces the concept of AI system lifecycle documentation as a GMP artifact. Like a piece of manufacturing equipment, an AI system must have a formal record of its qualification, its configuration, its change history, and its performance over time. This documentation doesn’t replace the traditional IQ/OQ/PQ framework — it extends it to cover the unique characteristics of AI systems, including model versioning, retraining events, and performance drift.
Third, the guide addresses data quality as a validation prerequisite. Before an AI system can be validated for a GxP application, the data it depends on must be validated. If the SCADA data feeding the model hasn’t been collected and stored in a manner consistent with ALCOA+, the model itself cannot be considered validated regardless of how well it performs in testing. The data foundation has to be right before the AI layer can be right.
That last point is where most pharmaceutical AI implementations run into trouble — and where the gap between ambition and compliance reality tends to open widest.
The Real Problem in Pharma SCADA Environments: The Data Foundation Is Often Broken
Here is something that is rarely discussed openly in pharmaceutical AI vendor pitches: most existing pharma SCADA and historian environments were not built with AI compliance in mind. They were built for process control and process monitoring. They were configured by control engineers whose job was to keep the line running, not by data architects who were thinking about audit trails, model training data provenance, or the requirements of a 2026 ALCOA+ audit.
That means the data foundation that pharmaceutical AI is being asked to stand on is, in many facilities, structurally compromised. Not because anyone was negligent — but because the standards have advanced faster than the infrastructure, and because the original infrastructure was designed for different purposes.
The Sampling Problem
The most widespread data integrity issue in pharma SCADA environments is also the most invisible: data sampling. Most historians are configured — either by default or by deliberate choice to manage storage costs — to capture data at intervals rather than at native resolution. Five-second samples. One-minute averages. Exception-based reporting that drops values within a configured deadband.
Each of these choices makes operational sense when you’re thinking about historian capacity and screen refresh rates. Each of them is a compliance liability when you’re thinking about ALCOA+ and the “complete” and “original” requirements.
A batch record that relies on sampled historian data is not, strictly speaking, a complete record. A transient temperature excursion that lasted eight seconds and fell between two five-second sample windows does not appear in that batch record. When an investigator asks whether there was a temperature deviation during a particular unit operation, the answer based on the sampled data is “no.” The true answer might be “yes, but we didn’t capture it.”
For AI systems, this problem is compounded. A machine learning model trained on sampled historical data has learned patterns from a dataset that systematically excludes the rarest, shortest-duration events. Those events — the brief pressure transients, the millisecond current spikes, the two-second temperature fluctuations — are precisely the events most likely to precede a process failure. Training on sampled data is training on a dataset that has already had the most valuable information removed.
The Audit Trail Gap
The second widespread problem is the audit trail architecture — or its absence. Many SCADA environments were deployed before the current audit trail requirements were as explicit as they are today. They capture operational events — setpoint changes, alarm acknowledgments, operator logins — but they don’t capture data creation events in the way the 2025 Annex 11 draft now requires.
When an AI system is added on top of such an environment, it inherits these gaps. If the underlying historian doesn’t log the creation of every data point with a validated timestamp and an attribution to the source device, then the AI system’s audit trail — no matter how well designed — is tracing back to a foundation that doesn’t fully exist. The chain of custody for the data breaks at the point where the historian first recorded it.
The Skills Gap
There is a third problem that is less technical and more human, but no less real: the pharmaceutical industry is in the middle of what regulators and industry analysts are calling a widening skills gap between traditional GMP roles and data-driven positions.
The people who understand pharmaceutical compliance — who can navigate 21 CFR Part 11, who know ALCOA+ cold, who have lived through an FDA data integrity inspection — are often not the same people who understand machine learning pipelines, OPC-UA protocol stacks, and historian architecture. And the people who understand the technology often don’t have the GMP instinct that tells you *why* a particular data architecture choice is a regulatory liability.
Deploying AI in a pharmaceutical manufacturing environment requires bridging that gap. It requires people — or systems — that understand both the technology and the compliance context deeply enough to make the right design choices before a warning letter explains what the wrong ones were.
What a Compliant AI Architecture for Pharma SCADA Actually Looks Like
Given everything above, what does a pharmaceutical manufacturer actually need to deploy AI in a SCADA environment in a way that survives a 21 CFR Part 11 audit, satisfies the 2025 Annex 11 draft, and aligns with the FDA-EMA joint principles?
The answer breaks down into four architectural requirements. None of them are optional. All of them are interconnected.
1. Lossless Data Capture at Native Resolution
The foundation is non-negotiable: every signal that an AI system processes must be captured at native resolution, with no sampling, no averaging, and no deadband-based data dropping. This is not an AI requirement specifically — it is an ALCOA+ requirement that predates AI by decades. AI just makes the stakes higher, because AI systems that process sampled data have a systematically different view of the process than the process actually exhibited.
Lossless capture has historically been treated as an expensive luxury because full-resolution industrial telemetry generates large volumes of data. But lossless does not mean uncompressed. Patent-pending, property-aware compression approaches — like those built into the Valak architecture — exploit the structural characteristics of industrial telemetry (values that move in small deltas, timestamps that advance predictably, tags that repeat the same shape indefinitely) to achieve double-digit lossless compression ratios. The economics of “keep everything” have changed. There is no longer a technically credible argument for accepting sampled data in a regulated environment.
2. Immutable, Always-On Audit Trails from the Point of Data Creation
The second requirement follows directly from ALCOA+ and from the 2025 Annex 11 draft: audit trails must capture data creation events, not only changes and deletions. Every write to the historian, every tag value captured by an OPC-UA subscription, every reading that will ultimately appear in a batch record must generate an immutable log entry at the moment of capture — timestamped by a validated time source, attributed to the source device, and protected from modification by normal user access.
This is architecturally different from bolting an audit trail onto the output end of an AI system. The audit trail has to start at the sensor. It has to be continuous from the point of measurement to the point of batch record. Any gap in that chain — any point where data passes through a system that doesn’t log what it receives — is a gap in the compliance architecture.
3. Read-Only AI Access to Control Systems
This is both a safety requirement and a compliance requirement. An AI system that has write access to SCADA setpoints or control parameters creates a category of risk that is categorically different from an AI system that only reads and analyzes. The compliance implications are significant: write access creates an AI-initiated action pathway that requires validated safety functions, formal change control, and a human approval workflow before every write. In most pharmaceutical SCADA environments, the operational risk alone makes write-access AI architecturally unacceptable.
Read-only AI is deployable. It can be validated. It can sit in an air-gapped on-premises deployment that satisfies the cybersecurity requirements of the 2025 Annex 11 draft without requiring the manufacturer to extend its validated network perimeter to a cloud service. The AI observes, analyzes, and recommends. The qualified human decides and acts. That is the compliance architecture. That is also, not coincidentally, the architecture that produces the best real-world outcomes: AI is genuinely better at pattern recognition and anomaly detection than humans; humans are genuinely better at exercising contextual judgment in high-stakes situations.
4. Human-in-the-Loop Workflows with Documented QU Sign-Off
The fourth requirement is the one the Purolea warning letter made explicit: every AI output that affects a GxP record must pass through a documented human review and Quality Unit approval before it is acted upon. This applies to deviation investigations, batch disposition recommendations, specification reviews, SOP generation, and any other AI-assisted workflow that produces output that enters the QMS.
The workflow architecture for this isn’t complex, but it has to be explicit and documented. The AI surfaces a finding. The finding is logged with the model version, the data sources used, and the timestamp. A qualified reviewer examines the finding, applies their professional judgment, and either approves, modifies, or rejects it. That review and decision is logged with the reviewer’s authenticated credentials and a timestamp. The approved or modified output enters the QMS. The entire chain — from AI observation to human decision to QMS record — is traceable, auditable, and available for inspection.
That chain is the whole compliance argument. Break any link in it and you’re in the same position as Purolea.
The Air-Gap Argument: Why On-Premises AI Isn’t a Limitation in Pharma — It’s a Feature
There is a tendency in the broader AI conversation to treat on-premises, air-gapped deployment as a compromise — the thing you do when you can’t do cloud. In pharmaceutical manufacturing, that framing is exactly backwards.
Cloud-connected AI systems that process GxP data require the manufacturer to extend its validated network perimeter to an external service provider. That extension requires supplier qualification, a formal assessment of the provider’s data security controls, a data processing agreement that satisfies GDPR and pharmaceutical data residency requirements, and an ongoing oversight obligation that doesn’t disappear when the contract is signed. The 2025 Annex 11 draft’s new cybersecurity sections make the bar for cloud-connected regulated systems higher, not lower.
An on-premises, air-gapped AI deployment that processes SCADA data without sending it outside the facility’s validated network perimeter sidesteps this entire category of complexity. The data stays where the controls are. The validation boundary is clear. The inspection readiness is straightforward. Regulators can see the system, validate the configuration, and verify the audit trails without needing to review a cloud provider’s SOC 2 Type II report.
For pharmaceutical manufacturers who are serious about deploying AI at scale — not as a pilot project but as a validated, inspection-ready capability — the air-gapped on-premises architecture isn’t a constraint to be worked around. It’s the right answer.
The Skills Gap Is Real, and It Has a Name: The Compliance-Technology Bridge Problem
It would be dishonest to write this article without acknowledging the organizational challenge that underlies all of the technical ones.
Pharmaceutical AI deployments are failing — not in pilot, but in production, and not because the AI is bad but because the organizations deploying it don’t have enough people who understand both sides of the equation. They have GMP experts who know the regulations but don’t understand what a data pipeline actually does. They have data engineers who can build the pipeline but don’t understand why ALCOA+ matters. They have quality directors who can write an AI governance policy but can’t evaluate whether the SCADA historian’s sampling configuration violates it.
This isn’t a criticism. It’s a structural reality of an industry that is digitalizing faster than it can hire and retrain. The pharmaceutical industry’s skills gap between traditional GMP roles and data-driven positions is well-documented, actively discussed in regulatory circles, and showing no sign of closing on its own.
The practical implication is that AI systems deployed in pharma SCADA environments need to be designed to bridge this gap — not to require it to be closed first. The technology has to be explainable enough that a QA director can interrogate it. The audit trails have to be organized in a way that a compliance team can present them during an inspection. The validation documentation has to be structured in a way that a quality team can maintain it without a dedicated machine learning engineer.
The best pharmaceutical AI is not the most technically sophisticated pharmaceutical AI. It’s the pharmaceutical AI that a compliance team can own, a quality director can sign off on, and an FDA investigator can audit.
Where Valak Sits in This Picture
Valak was designed for industrial environments where the data has to be right before anything else can be right. That design philosophy maps directly onto the compliance requirements of pharmaceutical manufacturing.
The read-only OPC-UA architecture means Valak never writes to your control systems. It observes, captures, and reasons. The path by which AI could inadvertently modify a controlled process is engineered out at the protocol level — not mitigated by policy, but removed by design.
The patent-pending lossless capture means the data Valak works with is the data as the process actually produced it. No sampled averages. No dropped transients. No gaps between sample windows where a real event could hide. The full-resolution record exists, is affordably stored, and is queryable — which is exactly what ALCOA+’s “complete,” “original,” and “available” requirements demand.
The on-premises, air-gapped deployment model means the pharmaceutical manufacturer’s validated network perimeter stays intact. Process data doesn’t leave the facility. The compliance boundary is the same boundary the manufacturer has always managed. The additional supplier qualification and cloud security assessment that the 2025 Annex 11 draft would require for a cloud-connected system simply doesn’t apply.
The agentic reasoning layer — the part that actually investigates anomalies, correlates deviations, and surfaces findings in plain language — is built on top of this foundation. It doesn’t replace the GMP expert’s judgment. It gives the GMP expert faster, better-evidenced access to the information they need to apply that judgment. The AI surfaces the finding. The qualified human makes the decision. The decision is documented. The audit trail is intact from sensor to QMS.
That architecture was not designed specifically for pharmaceutical manufacturing. It was designed for any industrial environment where the data has to be right, complete, and auditable. But pharmaceutical manufacturing may be the environment where those requirements are most acute — and where the cost of getting them wrong is highest.
What FDA Enforcement Trends Tell Us About the Next Two Years
The April 2026 Purolea warning letter was the first FDA enforcement action with a dedicated AI section. It will not be the last.
FDA enforcement activity in the pharmaceutical manufacturing space has been intensifying for two years. The pattern of that enforcement — increasingly focused on data integrity, AI governance, and the human-in-the-loop accountability gap — suggests a regulatory posture that is moving faster than most industry AI governance programs.
The compliance infrastructure the FDA is building — validation requirements for AI in GxP applications, explicit human review obligations, audit trail requirements for algorithmic decisions — is not being announced well in advance of enforcement. It is being enforced first, with the underlying framework revealed in the warning letters themselves. The Purolea letter created regulatory precedent not through rulemaking but through enforcement. That is how FDA has historically moved when it believes the industry already understands the principle but is choosing not to apply it.
The manufacturers who will be best positioned in this environment are not the ones waiting for a final guidance document to tell them exactly what to do. They are the ones who have already aligned their AI architecture with the underlying principles: complete data, always-on audit trails, human accountability, documented validation, and a clear boundary between AI recommendation and human decision.
The Bottom Line
There are two ways to deploy AI in a pharmaceutical manufacturing environment.
The first way treats AI as a technology layer that gets added on top of whatever data infrastructure already exists, with compliance documentation written after the fact to justify choices that were made for operational or cost reasons. This approach produces pilot results that look compelling and production deployments that fail inspections.
The second way starts with the compliance requirements and works backward to the technology. It begins with the question: what does every data point that this AI touches need to look like in order to satisfy 21 CFR Part 11, ALCOA+, and Annex 11? It answers that question before selecting a technology, before writing a validation protocol, and before connecting anything to the SCADA system.
The second approach takes longer to get started. It costs more upfront. It requires more careful thought about data architecture, audit trail design, and human workflow. And it is the only approach that produces an AI deployment that can survive a serious regulatory inspection — which, given the enforcement trends of the past eighteen months, is no longer a theoretical concern.
The compliance clock is ticking. The data foundation either works or it doesn’t. The audit trail either exists or it doesn’t. The qualified human either reviewed and documented the AI’s output or they didn’t.
When the investigator walks in and asks what the bioreactor temperature was at 03:14:22 on a Thursday night six weeks ago, the answer is either there or it isn’t.
Build the infrastructure so the answer is always there.
Valak is the Sasquatch Labs Industrial Series: agentic AI on patent-pending lossless telemetry for OPC-UA, SCADA, and historian data — every signal captured, nothing dropped. Built for industrial environments where the data has to be right.
*Learn more at [valak.ai](https://www.valak.ai) · [blog.valak.ai](https://blog.valak.ai)*
*© 2026 Valak AI by Sasquatch Labs, Inc. Patent-pending.*
