ARTIFICIAL INTELLIGENCE

By Akhila Gaddam, Vice President of Technical Services, NFP Holdings LLC

AI in Food Safety and GMP Systems: Practical Applications, Limitations, and Compliance Considerations

AI can assist the person doing the work, but it cannot replace the person accountable for the outcome

Three diverse professionals collaborating on AI research with laptops in a blue-lit office, with an AI brain projection.

Image credit: Suratsak Noikerdmee/iStock/Getty Images Plus via Getty Images

SCROLL DOWN

Artificial intelligence (AI) is no longer a distant concept for food safety, quality, and regulatory teams. Many of us are already using it, formally or informally, to review documents, summarize requirements, compare records, prepare for audits, or organize large amounts of information.

The question is no longer whether AI will enter food safety and Good Manufacturing Practices (GMP) environments; it already has. The more important question is how it can be used without weakening the controls on which these systems depend.

Food safety and GMP-regulated environments operate under a different standard than many other business functions. These systems are built around consistency, traceability, documentation, and accountability. Decisions must be explainable. Records must support the actions taken. If a conclusion is challenged during an audit or inspection, the company must be able to show how that conclusion was reached and what information was used to support it.

That is where AI needs to be viewed carefully.

The value of AI is not just defined by how quickly or how well it can generate outputs, but by whether those outputs can be verified and defended.

In food safety systems, AI can be useful. It can help organize information, identify possible gaps, compare documents, summarize large amounts of data, and support early-stage analysis. But it cannot be treated as a decision-maker. Responsibility for interpretation, compliance, product safety, and final quality decisions must remain with trained and qualified professionals.

Used correctly, AI can support the system. Used without boundaries, it can create risks that may not be obvious until the output is relied upon.

Why GMP Environments Require a Different Standard

In many settings, an AI-generated summary or draft may only need to be useful or reasonably accurate. In a GMP or food safety environment, that is not enough.

A procedure, investigation, supplier decision, hazard analysis, or product disposition decision must be based on reliable information and sound judgment. The person responsible for the decision must be able to explain it, support it, and connect it back to source data, regulatory requirements, or internal procedures.

This is why AI use in food safety systems cannot be evaluated only by convenience. A tool that produces a polished answer is not necessarily producing a reliable answer. A summary that sounds correct may still miss a critical detail. A suggested conclusion may be logical on the surface but incomplete because the tool did not have the full context.

That does not make AI unusable. It means AI has to be used within a defined process, with clear expectations for review and verification.

In practical terms, AI can assist the person doing the work, but it cannot replace the person accountable for the outcome.

Where AI Can Add Value

There are several areas where AI can provide real value in food safety and quality systems. The best uses are usually those that involve organizing information, comparing documents, identifying possible inconsistencies, or helping teams review large volumes of data more efficiently. In these areas, AI can save time without taking ownership of the decision.

Document Review and SOP Evaluation

Document review is one of the more practical uses of AI in quality systems. Standard operating procedures (SOPs), forms, policies, specifications, and supporting programs often change over time. In larger or more complex systems, related documents may not always be updated together. This can lead to gaps, inconsistencies, or outdated references that are easy to miss during routine review.

AI can help by comparing documents, identifying repeated language, flagging possible inconsistencies, or pointing out where an SOP may not fully align with another procedure. It can also help generate a first draft when a company is creating a new procedure or revising an existing one.

For example, if a company is updating an allergen control procedure, AI may help identify sections that should be reviewed, such as supplier controls, receiving checks, sanitation verification, label review, and employee training. That can be useful as a starting point.

However, the output still has to be reviewed against current regulatory requirements, internal practices, and site-specific controls. AI may not know how a facility actually operates. It may not recognize that a procedure was written a certain way because of a past deviation, a customer requirement, or a specific process limitation.

This is where the distinction matters. AI can help organize the review, but it cannot own the procedure.

Audit Readiness and Internal Assessments

Audit preparation is another area where AI can be useful. Preparing for an audit often requires reviewing a large amount of documentation across different systems: SOPs, training records, supplier files, complaints, deviations, corrective and preventive actions (CAPAs), environmental monitoring records, internal audit reports, and management review data.

AI can help organize this information and identify areas that may need closer review. It can summarize records, compare documents against a checklist, or help prepare questions for an internal assessment. It can also support trend review by helping group recurring issues, repeated observations, or common documentation gaps.

“Supplier qualification is not only a document collection exercise; it is also a risk-based decision. AI can support that decision by organizing information, but it should not make the decision.”
Tints and shades, Monochrome photography, Black, Black-and-white, Line, Style
Monochrome photography, Parallel, Black, Black-and-white, Line, White

One useful application is a controlled form of mock audit. If a company provides AI with a defined set of regulatory requirements or internal audit criteria, the tool may help compare documents against those expectations and flag areas for follow-up.

But the quality of that output depends heavily on the quality of the input. If the prompt is vague, the documents are incomplete, or the regulatory criteria are not clearly defined, then the results may be incomplete or misleading.

Audit readiness is not just about whether documents exist. It is about whether the system works, whether records support the work being performed, and whether employees understand and follow the process. AI can help prepare for that review, but it cannot replace the actual assessment of the system.

Supplier Qualification and Risk-Based Oversight

Supplier qualification is a good example of where AI can help, but only up to a point.

Supplier files often contain a large number of documents: questionnaires, certifications, specifications, allergen statements, country-of-origin statements, food safety plans, third-party audit reports, letters of guarantee, and test results. Reviewing and organizing this information can be time-consuming, especially when companies manage many suppliers or raw materials.

AI can help summarize a supplier packet, compare documents, or flag missing information. It may help identify whether required documents are present, whether dates are current, or whether certain claims appear inconsistent across records. This can improve the efficiency of the review and help quality teams focus their attention.

What AI cannot do is understand the full context of the supplier relationship, the material risk, the manufacturing process, or the company's internal qualification standard.

For example, a supplier document package may appear complete on paper, but the material may still require additional review because of its intended use, country of origin, history of nonconformance, allergen risk, adulteration risk, or customer-specific requirements. AI may summarize the file, but the final decision still requires technical review.

Supplier qualification is not only a document collection exercise; it is also a risk-based decision. AI can support that decision by organizing information, but it should not make the decision.

Deviation and CAPA Review

AI can also support deviation investigations and CAPA processes, particularly when there is a need to review historical data.

One of the more useful applications is identifying similar past deviations. In many quality systems, historical records are not always easy to search. AI may help surface similar events, identify recurring themes, or connect issues across equipment, materials, processes, departments, or time periods.

That can be valuable. A deviation investigation should not happen in isolation if similar issues have occurred before. AI can help the investigator see patterns that may otherwise take much longer to identify.

However, this is also one of the areas where caution is most important. Just because a pattern is identified does not mean the root cause is understood.

AI may identify that similar deviations occurred on the same line, with the same ingredient, or during the same process step. That information can help direct the investigation, but it does not establish root cause. The investigator still has to evaluate the process, interview personnel where needed, review records, assess contributing factors, and determine whether the evidence supports the conclusion.

If an AI-generated pattern is accepted too quickly, there is a risk of choosing the wrong root cause and implementing a CAPA that does not actually fix the problem. In that case, AI may make the investigation look more complete while still leading the team in the wrong direction.

The better use is to treat AI as an investigation support tool. It can help gather and organize information. It can suggest areas to scrutinize. But the conclusion must come from a qualified review of the evidence.

Where AI Does Not Fit

AI should not be used as the basis for final decisions in some areas in food safety and GMP-regulated systems.

AI should not make final decisions on hazard analysis, preventive controls, product release, product rejection, root cause determination, supplier approval, or regulatory interpretation. These decisions require technical knowledge, process understanding, risk assessment, and professional judgment.

AI also should not be used when the output cannot be traced back to reliable source material. If a conclusion cannot be explained, justified, and connected to the information used to support it, then it should not be relied upon in a quality system.

This becomes especially important when AI is used to interpret regulations or summarize requirements. AI-generated regulatory summaries can sound confident even when they are incomplete, outdated, or missing context. In a regulated environment, the source matters. The actual regulation, guidance document, standard, or internal requirement must be reviewed and verified.

There is also a confidentiality concern that companies need to address directly. Supplier records, formulas, specifications, customer requirements, deviations, investigations, and internal procedures may contain sensitive or confidential information. Before using AI tools, companies need to define what information can be entered, which tools are approved, where the information is stored, and whether the use of that information is consistent with internal confidentiality and data protection requirements.

This is not just an IT issue; it is a quality system issue. If AI is being used to support quality or food safety work, then the company needs to understand and control how it is being used.

“The expectation is simple: if you use it, then you must be able to defend it.”
Tints and shades, Monochrome photography, Black, Black-and-white, Line, Style
Monochrome photography, Parallel, Black, Black-and-white, Line, White

The Core Risk: Variability and Reproducibility

One of the biggest challenges with AI in GMP environments is variability.

Current AI tools do not always produce the same output every time, even when the request is similar. A small change in the prompt, the source material, or the context provided can lead to a different answer. In some cases, the answer may be better. In other cases, it may be less accurate or may leave out something important. That variability matters in a GMP system.

GMP systems are built around consistency and repeatability. Procedures are controlled. Records are reviewed. Changes are documented. Decisions are expected to be supported by evidence. If a tool produces different outputs without a clear reason, then it becomes difficult to rely on that output unless there is a strong review process around it.

This is especially clear when AI is used for SOP development or regulatory review. The quality of the output depends heavily on the quality of the information provided. If the prompt is too general, the answer may be too general. If the regulatory source is not provided, the answer may rely on incomplete or outdated information. If the tool does not understand the site-specific process, it may produce a procedure that looks complete but does not actually fit the operation.

This does not mean the tool has no value. It means the output has to be treated appropriately. In a quality system, an AI-generated output should be considered a draft, a prompt for review, or a supporting input. It should not be treated as a verified conclusion unless it has been reviewed against source data, current requirements, and the actual process.

The expectation is simple: if you use it, then you must be able to defend it.

Governance and Practical Controls

As AI use becomes more common, companies will need to define practical controls around it. Without clear expectations, employees may use AI inconsistently, informally, or in ways that create risk for the organization.

At a minimum, companies should define which AI tools are approved for use, what types of information may be entered, and which activities are acceptable. They should also define which activities are prohibited. For example, using AI to summarize an internal training procedure may be acceptable if the output is reviewed before use. Using AI to make a final product disposition decision should not be acceptable.

A practical AI policy for quality systems should address several basic questions:

  • Which AI tools are approved?
  • What data can and cannot be entered?
  • What tasks may AI be used for?
  • What tasks are prohibited?
  • Who is responsible for reviewing the output?
  • How should AI use be documented?
  • How should source references be verified?
  • When is additional quality or regulatory review required?

These controls do not need to be overly complicated, but they do need to be clear.

AI may be useful for creating training summaries from approved SOPs, supporting trend analysis for management review, organizing supplier qualification documents, preparing internal audit checklists, or helping summarize large data sets. These uses can save time and improve consistency when the outputs are reviewed.

The boundary needs to be firm when AI starts replacing review, judgment, or accountability.

Existing Systems vs. AI-Ready Systems

The effectiveness of AI depends heavily on the system in which it is being used.

In many existing quality systems, information is spread across different locations. Procedures may not use consistent language. Records may be stored in different formats. Supplier documents may vary in structure. Historical deviations may not be easy to search. In those environments, AI can still help, but the output may be limited by the quality and structure of the underlying information.

If the data is not structured, then the output will not be consistent.

This is one of the most practical limitations companies will face. AI cannot fully compensate for poor documentation practices, unclear workflows, or inconsistent records. In some cases, using AI may actually expose those weaknesses by showing how difficult it is to retrieve or compare information across the system.

Newer or evolving quality systems have an opportunity to think differently. If companies are implementing new documentation systems, supplier management programs, deviation systems, or training platforms, they can build more structure into the process from the beginning. Consistent naming, defined fields, controlled document relationships, and clear workflows can make information easier to review, whether by people or AI-supported tools.

Before companies expect reliable AI outputs, they may need to first improve how their own information is organized. That may not sound as exciting as adopting a new tool, but it is often the more important step.

TABLE 1. Fake Internet Domains Registered as Part of Typosquatting Campaign

Takeaway

AI has a meaningful place in food safety and GMP systems, especially where teams need to review large amounts of information, identify possible gaps, compare records, or improve the efficiency of routine quality activities. It can support document review, audit readiness, supplier qualification, deviation trending, CAPA review, training preparation, and management review.

Those are valuable uses. In many cases, they can help quality teams work more efficiently and identify issues earlier.

But AI has to be used with the right boundaries. It should not make final food safety, quality, regulatory, or product disposition decisions. It should not replace technical judgment. It should not be relied upon when the output cannot be traced, explained, or verified.

As AI use continues to expand, the food safety and GMP community will need clearer expectations around appropriate use, documentation, data protection, and review. Until those expectations are more formally defined, responsibility remains with the companies and individuals using these tools.

AI is not the problem. Uncontrolled use is the problem.

The answer is not to avoid AI, and it is not to use it without limits. The right approach is to use AI where it adds value, define where it does not belong, verify the output, and keep accountability with the people responsible for the system.

AI can support food safety systems, but it cannot be responsible for them.

Note

The Bioeconomy Information Sharing and Analysis Center (Bio‑ISAC) is a nonprofit, member‑driven organization that serves as a trusted hub for sharing and analyzing threat information specific to the life sciences, biotechnology, and broader bioeconomy sectors. Its mission is to improve cybersecurity and biosecurity resilience by enabling confidential, two‑way exchange of intelligence on vulnerabilities, incidents, and emerging risks among industry, academia, and government, and by supporting coordinated vulnerability disclosure, workforce training, and practical guidance at the cyber‑bio interface.

References

  1. Fahnestock, L., S. Streuli, G. Gill, R. DeVito, J. DeFrancesco, M. Randhawa, D. Dyjack, and R. Baker. "Decoding training needs: Using relevance and exposure to identify training needs in the retail food regulatory workforce." Journal of Environmental Health 87, no. 1 (2024): 24–32. 
  2. Bare, G., T.N. Kim, C.W. Hedberg, N. Dutra, C. Walker, and D. Dyjack. "Pillars of governmental environmental public health: A guide to scalable environmental public health programs." National Environmental Health Association. 2025. https://www.neha.org/Pillars-of-Governmental-Environmental-Public-Health
  3. Baker, R., S. Streuli, G. Gill, J. DeFrancesco, C. Somaiya, R. DeVito, D. Dyjack, and M. Randhawa. "Decoding training needs: Developing a needs assessment tool to inform workforce capacity building in retail food safety." Journal of Environmental Health 86, no. 6 (2024): 34–38. 
  4. Streuli, S., G. Gill, R. DeVito, L. Fahnestock, J. DeFrancesco, C.K. Somaiya, D. Ramirez, R. Baker, D. Dyjack, and M. Randhawa. "Decoding training needs: Exploring demographic data to understand retail food regulatory workforce composition and inform capacity building." Journal of Environmental Health 86, no. 8 (2024): 34–40. 
  5. National Environmental Health Association (NEHA) "Analysis of REHS/RS exam performance and job task alignment." Unpublished internal report. 2026.

Further Reading

Akhila Gaddam is Vice President of Technical Services at NFP Holdings LLC, where she oversees regulatory compliance, food safety, quality systems, and technical operations/formulation for dietary supplement manufacturing. With more than 15 years of experience in GMP-regulated industries, she has led the development and implementation of food safety, quality, and regulatory programs across manufacturing operations. Akhila holds a B.Pharm. degree and an M.S. degree in Pharmaceutical Engineering and is a published industry author with a particular interest in the intersection of emerging technologies, regulatory compliance, and food safety systems.

AUGUST/SEPTEMBER 2026

Font, Line, Text