Skip to Content

AI regulatory compliance for healthcare and pharma operations

A human decides. Every step leaves a record.
October 8, 2026 by
Hugo Acurio

The short answer

I build AI for regulated healthcare and pharma that runs in production and leaves a record an auditor can trace. My rule: the AI prepares and suggests, a human decides, and every step is logged. I've shipped it in telehealth (human-in-the-loop AI intake that lifted conversion 40% across 100K+ patient encounters over ~18 months) and in pharma (an AI sales agent that went from idea to production in 13 days, with an audit trail behind every step).

Who this is for

US telehealth, diagnostics and pharmacy companies scaling from $5M to $150M, plus pharma and device companies operating in Latin America. You already have AI in a regulated workflow, or you're about to, and it has to survive its first audit. If your compliance team hears about the model after it ships, this page is for you.

What AI compliance covers in a regulated operation

Most of what gets written about "AI compliance" is aimed at banks. In healthcare and pharma the work lands in four places, and all four depend on one operating record.

  1. Patient data. HIPAA in the US (my HelixVM patient operations ran inside the HIPAA perimeter, with PHI handled under BAAs). In Latin America it's the national data-protection laws, such as Ecuador's LOPDP and Brazil's LGPD.
  2. Quality systems. SOPs, deviations, CAPA. At Iris Global Ecuador that discipline earned a top 5% GDP certification (GWDP under ARCSA). An AI step is one more process step. It needs an SOP, an owner and a deviation path like any other.
  3. Pharmacovigilance. Adverse-event intake, case clocks, causality, reporting to the regulator. ARCSA's new standard takes effect Nov 4, 2026, ANVISA runs VigiMed, and COFEPRIS has a national center. The teams absorbing all of it were thin to begin with.
  4. AI-specific rules. The US got a new state AI law every ~2.5 days in 2025 (1,208 AI bills introduced, 145 enacted, per MultiState). Colorado SB 26-189 lands in January 2027. The EU pushed its high-risk obligations (Annex III) to December 2027 and AI in medical devices (Annex I) to August 2028, under Regulation (EU) 2026/1744.

The record a regulator can read

Black box on the inside, glass box on the record. The model can be probabilistic. The audit trail cannot. Every model call gets an input hash, a model version, a confidence score and a human on the supervision layer. When a regulator asks how a case was classified, you don't have to explain the model. You show the log.

The record is append-only, and it does two jobs: it's the agent's memory and it's the audit trail. Compliance stops being a report somebody assembles at quarter end. (The memory design is in How to give an AI agent memory without breaking the audit trail. The operating side is in The regulated operating system, built from zero.)

Why validate-once breaks for AI

Pharma validation works because what you validate holds still: the molecule, the process, the stability profile. AI moves. Frontier models change every few months and production systems drift.

The FDA data shows where validate-once still holds. It cleared a record 295 AI/ML devices in 2025 (Innolitics), roughly 75% of them in radiology and mostly narrow, locked models, and only about 10% carried a PCCP (the plan that lets a cleared model change). Locked models can be validated once. Everything else needs a harness: monitor every call, trace every output, and run AI failures through the same CAPA loop as any other deviation.

A deviation without a CAPA is a finding. A failure rate without a root cause should be one too.

Validation and the harness work together, and the harness is the part I build.

What I've shipped

  • Telehealth (HelixVM, VP Head of Operations). The patient-operations engine behind 100K+ patient encounters over ~18 months, inside the HIPAA perimeter. Human-in-the-loop AI intake lifted conversion 40% and cut appointment time 50%, human still in the loop. (Case study)
  • Pharma sales channel (Fenix Pharma). A production AI sales agent on a live channel, 13 days from idea to production, ~45% of warm leads recovered, every step logged. (Case study)
  • Pharmacovigilance (Iris). A regional pharmacovigilance platform built inside our ERP by Iris LLC, launching with Iris Global Ecuador ahead of ARCSA's Nov 4, 2026 standard, with Iris Mexico next. It's built and tested. No live adverse-event cases have gone through it yet, and I'll keep saying so until they have. (Case study)
  • Quality (Iris Global Ecuador). Top 5% GDP certification (GWDP under ARCSA), a 23-person org, and a move from operating losses to sustained profitability.

I presented this architecture to RA and compliance leads at Seton Hall Law's Latin America Healthcare Compliance Certificate Program in Bogotá, September 2026. (Notes from Bogotá)

What I don't do

I'm not a lawyer, and I don't give legal opinions. I don't prepare FDA submissions. When a decision needs counsel, counsel gets a system they can read.

How it starts

  1. Pick one workflow. One intake, one channel, one case type. We map who decides what today and where the record breaks.
  2. Build the record before the model. Log design, human checkpoints, deviation path, SOP. The model goes in last.
  3. Ship with a human on every decision that matters. Then widen the AI's share as the log earns it.

Putting AI into a regulated workflow and want a second read before the auditor's? Let's talk.

For the Latin American regulators specifically: AI in pharmacovigilance in Latin America.

Share this post
Tags
Archive

Frequently asked questions

What does an AI compliance expert do for a healthcare or pharma company?

Makes sure AI in a regulated workflow can be explained after the fact. In practice: map which decisions the AI touches, put a human on the ones that matter, and log every model call (input, version, confidence, reviewer) so an auditor can rebuild what happened. I do it as an operator. I build the system and run it.

How do you keep an AI agent compliant in a regulated healthcare channel?

Guardrails first, model second. The agent prepares and suggests, a human approves anything clinical, financial or regulatory, and every step leaves an append-only record. That is how I shipped a production AI sales agent at Fenix Pharma in 13 days without giving up the audit trail.

Can AI be used in pharmacovigilance under ARCSA, ANVISA or COFEPRIS?

Yes, with conditions. The reporting clock, causality and the final classification stay with the responsible pharmacovigilance team, and AI helps triage intake and pre-fill fields for human review. On the regional platform I'm building at Iris, AI comes after go-live, once the manual process is proven.

Do you need to validate an AI model the same way you validate a drug process?

Validate what holds still, monitor what doesn't. A locked model can be validated once. A model that updates needs continuous monitoring, traceability and a CAPA path for failures. Most 2025 FDA AI clearances were narrow, locked models, which shows where validate-once still works.

When should a telehealth or pharma company bring in AI compliance help?

Before the first model call touches a patient, a case or a regulator. Retrofitting an audit trail onto a live agent costs more than designing one in, and the calendar is filling up: Colorado SB 26-189 in January 2027, EU high-risk obligations in December 2027.