I am a pharma-systems consultant specializing in AI validation & security. Working with CSV/QA, AI-platform, and security teams in regulated life sciences put LLM gateways and AI agents into GxP workflows without breaking security or compliance — and publish working artifacts that show you how to turn those controls into validation evidence. Start with the teaching and then check out the writing.
Embedding generative AI and agents into validated GxP workflows — gateway security controls, validation, and audit evidence.
Business analyst and technical lead across regulated pharma systems: computer system validation, CMMS/EAM, process analytical technology, and process intelligence.
Here live the core runnable gmp ai project artifacts. Enjoy!
Everything here is a curated teaching artifact. The reason is simple: the clearest way to communicate the way to have secure, validated AI is to build the smallest honest version of it and explain every part.
Read them in order — each artifact builds on the last, simplest to most complete.
An LLM gateway from scratch, in ~150 lines
What an LLM gateway actually does — a minimal, keyless FastAPI program between apps and model providers that adds five security controls one at a time, each answering a question a CSV/QA reviewer is already asking.
An ALCOA+ audit trail for LLM calls
The smallest honest example of turning AI telemetry into 21 CFR Part 11 validation evidence — a tamper-evident, hash-chained audit trail for every model interaction.
The "Zero to Validated" sequence
The flagship repos above build on each other, from the simplest possible gateway up to a vendor-comparison harness that can be used as validation evidence.
Notes from the field & Industry Info.
Shorter pieces on where regulated-pharma AI actually is, what the regulators are signaling, and the controls the industry keeps skipping. Based on real contracts and interactions (sanitized).
Security is now a GMP requirement
The 2025 Annex 11 rewrite puts pen-testing, MFA, and audit trails into GMP text — so for AI systems, the security controls and the validation controls are now the same controls.
How much validation does your AI actually need? Start with Context of Use
Before you validate a GxP AI system, classify it. A practical, cross-regime procedure — Context of Use, influence x consequence, Annex 22, GAMP 5, EU AI Act — that tells you how much evidence you actually owe.
What a CSV validator should look for in an LLM gateway
A pilot went well and the business wants it in production. The CSV team opens the architecture diagram and sees 'LLM gateway' in the middle. Here's what that means for validation — and the three failures to reproduce before signoff.