How does agentic AI become possible in GxP? QFINITY brings the governance perspective to an SAP expert workshop
Recap of the SAP expert workshop on AI in regulated pharma processes, Walldorf, August 18, 2026.
On August 18, 2026, QFINITY, represented by Oliver Herrmann, brought the governance perspective to an SAP expert workshop on AI in regulated pharma processes. The workshop followed an ecosystem format: selected organizations each represented their role, SAP as the vendor, Merck for the regulated industry, alongside specialists in governance, validation and guardrails. They work on the same questions because none of them can solve them alone, and these questions concern everyone in a regulated environment. Who is accountable when agentic AI is deployed in GxP processes? And how do you know that the answer holds up?
What the vendor delivers and what stays with the customer
QFINITY’s contribution followed one principle: the software vendor delivers the technical capability, embedded in a GxP-shaped governance that fits the governance systems of its users. What no vendor can deliver is the regulatory accountability of each individual customer. It arises on the customer’s side: in their own governance, in the validation of the systems in their own process, in their own controls.
The structural challenge behind this is an asymmetry. One product governance meets many governance systems of regulated users, and each of those users carries its GxP accountability itself, including for outsourced activities, as Annex 11 provides in its section on suppliers and service providers. That asymmetry is built into the structure, and harmonization alone does not resolve it. It takes defined interfaces where evidence crosses the boundary: model changes, provenance of training data, monitoring signals, audit rights reaching into the supply chain of the model providers.
The capability is delivered. The accountability is not.
The human stays accountable
Human oversight does not mean that a human is involved. The test question is: can that person still intervene and stop? This holds at every level, up to the roles that personally answer for what is released. We therefore put three questions to every agentic system, whatever the vendor:
- Can every action of an agent be attributed to an identifiable actor in the audit trail?
- Is a change in behavior detected without a version change?
- Are there defined paths for stop, rollback and re-verification?
In our ISPE iSpeak article Human-in-the-Loop as an Illusion of Control? we explain why the involvement of a human alone is not yet a control.
The yardstick is patient safety
The real yardstick of our industry applies to every activity: patient safety, product quality and data integrity. Audits are one of many controls in that picture. Good AI governance is not glamorous, it is downright unexciting. Instead of a dramatic stop, it shows in decisions that were carefully weighed before risks occur. The question we expect from an auditor is therefore no longer whether an AI policy exists, but: “Show me where your AI governance decisively shaped a decision.” The architecture has to be prepared for that question today.
Why we have a say here
These questions are not new to QFINITY. Supplier accountability, validation evidence and human responsibility have been our daily work for 22 years, for 200 clients in more than 20 countries, on the core team of GAMP 5 Second Edition and in the author teams of GAMP Good Practice Guides, from the RDI guide on data integrity to the eClinical guide. What is new is the context: AI is now arriving in regulated processes. Our role in this is that of the translator between the expectations of regulated users and those of the software vendor.
What comes next
The discussion continues. In October, Oliver Herrmann and Martin Heitmann take the topic to the ISPE Annual Meeting & Expo in Washington, D.C., with their talk “Progressive QA in AI-Enabled GxP Environments” on October 21. In December, QFINITY and Merck share the stage again. At the 19th Official GAMP 5 Conference in Mannheim, Oliver Herrmann and Alexander Kunz (Merck) moderate the panel “CSV at a turning point: Is our validation ready for digital reality?”
If you are asking yourself which role you play in this network and how your own governance stands up to the audit question, that is a conversation we are glad to have.





