<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>hristosbilis.ai</title><description>AI security for regulated pharma — making LLM gateways and AI agents auditable, validated, and 21 CFR Part 11-defensible.</description><link>https://hristosbilis.ai/</link><language>en-us</language><item><title>Where pharma AI actually is — a 2026 ISPE AI Summit field readout</title><link>https://hristosbilis.ai/writing/where-pharma-ai-actually-is/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/where-pharma-ai-actually-is/</guid><description>Two days inside the room at the 2026 ISPE AI summit: where regulated-pharma AI is really deployed, where it&apos;s going, and the one control almost nobody owns yet.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Security is now a GMP requirement</title><link>https://hristosbilis.ai/writing/security-is-now-a-gmp-requirement/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/security-is-now-a-gmp-requirement/</guid><description>The 2025 Annex 11 rewrite puts pen-testing, MFA, and audit trails into GMP text — so for AI systems, the security controls and the validation controls are now the same controls.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>How much validation does your AI actually need? Start with Context of Use</title><link>https://hristosbilis.ai/writing/how-much-validation-does-your-ai-need/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/how-much-validation-does-your-ai-need/</guid><description>Before you validate a GxP AI system, classify it. A practical, cross-regime procedure — Context of Use, influence x consequence, Annex 22, GAMP 5, EU AI Act — that tells you how much evidence you actually owe.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>What a CSV validator should look for in an LLM gateway</title><link>https://hristosbilis.ai/writing/what-a-csv-validator-should-look-for-in-an-llm-gateway/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/what-a-csv-validator-should-look-for-in-an-llm-gateway/</guid><description>A pilot went well and the business wants it in production. The CSV team opens the architecture diagram and sees &apos;LLM gateway&apos; in the middle. Here&apos;s what that means for validation — and the three failures to reproduce before signoff.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>An ALCOA+ audit trail for LLM calls</title><link>https://hristosbilis.ai/writing/alcoa-audit-trail-for-llm-calls/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/alcoa-audit-trail-for-llm-calls/</guid><description>The smallest honest example of turning AI telemetry into 21 CFR Part 11 validation evidence — a tamper-evident, hash-chained audit trail for every model interaction.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>An LLM gateway from scratch, in ~150 lines</title><link>https://hristosbilis.ai/writing/gateway-from-scratch/</link><guid isPermaLink="true">https://hristosbilis.ai/writing/gateway-from-scratch/</guid><description>What an LLM gateway actually does — a minimal, keyless FastAPI program between apps and model providers that adds five security controls one at a time, each answering a question a CSV/QA reviewer is already asking.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>