The Cardinal Rule of GxP AI: ALCOA+ Applies to AI Output Too
There is a sentence that sounds harmless and is, in a regulated context, close to a confession: "I asked the AI and pasted the answer." It sounds like efficiency. It is, against the standard that governs every record in a GxP environment, a failure on every single count. That standard is ALCOA+, the nine attributes that define what makes data and records trustworthy in pharmaceutical work, and the central insight of this lesson is that ALCOA+ does not get suspended because some of the words on the page came out of a model. The opposite is true: the moment a model contributes to a regulated record, ALCOA+ becomes the lens through which that contribution is judged, and a workflow that cannot satisfy the nine attributes for its AI-assisted output is not a defensible workflow, however good the output looks. This lesson walks each attribute and shows what it demands when half the sentence was machine-generated, because the attributes are not abstractions; they are the precise, inspectable properties that separate an AI-assisted record an inspector accepts from one that triggers a finding. Learn them here, because every workflow in the rest of this program is, at bottom, a way of making AI output satisfy ALCOA+.
What ALCOA+ Is, and Why It Governs AI Output
ALCOA+ is the data-integrity standard that underlies GxP and 21 CFR Part 11. The original ALCOA names five attributes, Attributable, Legible, Contemporaneous, Original, and Accurate, and the plus adds four more, Complete, Consistent, Enduring, and Available. Together they define what it means for a record to be trustworthy enough to support a regulatory decision, and they apply to any data that ends up in a submission, a batch record, a case file, or a trial document, regardless of how it was produced.
The reason ALCOA+ governs AI output is that the standard is about the record, not about the author. A regulator does not care whether a sentence in a Module 2.5 was typed by a senior writer, dictated, or generated by Certara CoAuthor; the regulator cares whether the record is attributable to a responsible person, accurate against its source, contemporaneously documented, and so on through the nine. AI does not get a carve-out, and more importantly, AI introduces specific new ways to fail each attribute that did not exist when humans wrote everything by hand. The value of walking the attributes one by one is that each reveals a distinct discipline the AI-assisted workflow must build in, and the confession sentence fails because it builds in none of them. A professional who can recite the nine attributes against a model's output has the complete checklist for whether their AI use is defensible.
Attributable: Whose Judgment Stands Behind the Words
Attributable means the record can be traced to the person responsible for it, the who behind every entry. This is the attribute the confession sentence fails most fundamentally, because "I asked the AI" attempts to attribute the content to a tool, and a tool cannot be the responsible person. The model can draft, but the attribution must run to the named human who reviewed the draft, verified it against source, and adopted it as their own work. When a writer signs a Module 2.5 section, they are attributing every claim in it to themselves, and the fact that a model produced the first draft does not change who is accountable for the final words.
What attributable demands operationally is twofold. First, the final record must be owned by a named person who has done the verification that makes ownership meaningful, not a person who pasted and moved on. Second, the use of AI itself must be attributable, meaning the record of how AI was involved, the run, the prompt, the verification, traces to the person who used it. Attribution is not weakened by AI involvement; it is made more demanding, because there is now a tool in the loop whose contribution has to be bounded by a human who takes responsibility for it. The named-author principle that runs through this entire program is, in ALCOA+ terms, simply the Attributable attribute applied to AI-assisted writing.
Legible, Original, and Accurate: The Record Has to Mean What It Says
Legible means the record is readable and permanent, and for AI work this extends to the documentation of the AI involvement: a use log that is a scribbled note or a screenshot buried in a personal folder is not legible in the sense the standard requires. The AI use record has to be as readable and durable as the output it describes.
Original means the record is the original capture or a certified true copy, and AI introduces a subtle trap here. When a model summarizes a source, the summary is not the original; the source is. If a downstream writer begins treating the AI summary as the thing to cite rather than the source it compressed, the chain to the original is broken, and an inspector who asks to see the original finds a summary of a summary. The discipline is to preserve the link to the original source and to treat AI output as a derived record that always points back to its origin. Accurate is the attribute everyone thinks of first, and it is where hallucination does its damage: an accurate record is one that correctly reflects the facts, and a fabricated hazard ratio or a nonexistent table citation is, by definition, inaccurate. Accuracy for AI output is established by the verification disciplines of the previous lessons, reconciling each claim to source, because the model's fluency creates an appearance of accuracy that only checking can confirm or refute. The confession sentence fails Accurate because pasting without verifying leaves accuracy entirely to chance.
Contemporaneous: The Record Is Made When the Work Is Done
Contemporaneous means the record is created at the time the activity occurs, not reconstructed later from memory. This attribute has a specific and easily missed implication for AI work, rooted in the fact that model output varies run to run. Because temperature makes the same prompt produce different output on different occasions, the documentation of an AI run has to be captured at the time of that run, not reconstructed afterward, because afterward the exact run cannot be reproduced. A writer who decides three weeks later to document how AI was used in a section cannot regenerate the precise prompt, model version, and output that actually produced the kept text; the contemporaneous capture is the only faithful record.
This is why every workflow in this program insists on capturing the run as it happens, the prompt, the system prompt, the model and version, the temperature, the timestamp, the sources, and the human verification. It is not bureaucratic box-ticking; it is the Contemporaneous attribute applied to a process whose outputs are not reproducible after the fact. The confession sentence fails Contemporaneous because it captures nothing at the time, leaving only a memory that "the AI helped," which is precisely the reconstructed-from-memory record the attribute forbids. The cost of missing this is felt sharply on Day 74, when an Information Request asks exactly how a section was produced and the only honest answer is that no one recorded it.
Complete and Consistent: Nothing Quietly Dropped, Nothing Quietly Contradicted
Complete means the record includes all the data, with nothing deleted or omitted, including the changes made and the reasons. For AI work, completeness has a sharp edge: if the writer accepted some of the model's output and rejected or overrode other parts, the complete record shows what was changed and why, not just the polished final text. An audit trail that shows only the accepted output, with no trace of where the human disagreed with the model and corrected it, is incomplete, and the incompleteness hides exactly the human judgment that makes the record defensible. Showing the override is not an admission of weakness; it is the evidence that a human was in control.
Consistent means the record does not contradict itself or other records, the same data agreeing across every place it appears, in the expected sequence. AI introduces a specific consistency risk because a model can produce a value or a characterization in one section that disagrees with another section produced in a different run, and because a fabricated cross-reference is an inconsistency between a claim and the document structure it cites. The consistency-finding strength from earlier in this chapter is, in ALCOA+ terms, a tool for satisfying the Consistent attribute, used to detect where AI-assisted sections disagree before the disagreement is filed. A function that runs a cross-section consistency sweep over its AI-assisted Module 2 is, whether it frames it this way or not, operationalizing the Consistent attribute of ALCOA+.
Enduring and Available: The Record and Its AI Provenance Survive
Enduring means the record persists for its required retention period in a durable form, and Available means it can be retrieved when needed, by an inspector, a reviewer, or an auditor, throughout that period. These two attributes are often treated as an IT concern, but for AI work they carry a specific obligation: the record of how AI was involved must endure and be available for the same period as the record it helped produce. If a submission must be retained and retrievable for years, the AI use log that documents how a Module 2.5 section was produced has to be retained and retrievable for the same years, in a form that an inspector can actually access, not a chat history in a personal account that vanishes when the employee leaves.
This is where the casual use of consumer AI tools collides with the standard most directly. A writer who used a personal chatbot account to draft a section has produced an AI provenance record that is neither enduring nor available in any defensible sense; it lives in a personal account, outside the company's systems, beyond the reach of retention controls and inspector access. The same work done in a validated enterprise deployment with logging produces a provenance record that endures and is available because the system was built to make it so. The two attributes together are a strong argument for why regulated AI work belongs in governed, logged, enterprise tools and not in whatever a writer happens to have open, and they are the bridge to the next chapter's treatment of Part 11 and Annex 11, which specify how that endurance and availability are achieved.
The Same Module 2.5 Section, Documented Two Ways
The fastest way to feel the difference the attributes make is to watch two writers produce the identical paragraph and document it differently. Both start from the same Phase 3 CSR, both ask the same enterprise model for a draft of the Module 2.5.4 efficacy summary, and both end with a paragraph that reads exactly the same on the page. The output is indistinguishable. What is distinguishable, and what an inspector actually examines, is everything around the output.
The first writer pastes the draft, skims it, fixes a comma, and moves on. There is no record that the model was used, no capture of the prompt or the model version, no note of which sources were in the window, no evidence that the hazard ratio in the paragraph was checked against the TLF, no record that anything was changed, and the only trace of the model's involvement is a chat thread in the writer's personal account. The paragraph is in the submission and its provenance is, for all practical purposes, gone. If a Day 74 Information Request asks how the efficacy figures were derived and verified, the honest answer is that no one can say, and the paragraph that reads so cleanly is now a liability whose accuracy rests entirely on hope.
The second writer works in the governed deployment, loads the CSR and the final TLF package, and captures the run as it happens. They reconcile the hazard ratio, the median, and the table citation against the actual TLF cells, find that the model wrote the right hazard ratio but cited the wrong table, correct the citation, and log that override with its reason. They run the consistency check against the Module 2.7.3 draft, confirm agreement, and sign the section under their name, with the whole provenance retained in the system. The paragraph reads the same as the first writer's, but it is Attributable, Accurate, Contemporaneous, Original, Complete, Consistent, Enduring, and Available, and when the Day 74 request lands, the answer is a clean, retrievable record. Same words, opposite defensibility, and the entire difference is the discipline the attributes name. The lesson is that ALCOA+ is not visible in the output; it is visible only in what surrounds the output, which is precisely why an inspector asks for the surroundings. It is also why the perceived time saving of the first writer is an illusion: the minutes saved by skipping verification and capture are borrowed against a far larger cost later, when the unprovenanced paragraph has to be reconstructed, defended, or withdrawn under a clock, and the second writer, who looked slower, is the only one who is actually finished.
Why "I Pasted the Answer" Fails All Nine, and What Replaces It
Return to the confession sentence and run it against the full standard. "I asked the AI and pasted the answer" is not Attributable, because it attributes content to a tool and the human did no verification to ground their ownership. It is not Accurate, because nothing was checked. It is not Contemporaneous, because nothing was captured at the time of the run. It is not Original in any traceable sense, because the link to the source was never established. It is not Complete, because there is no record of what was changed or why. It is not Consistent in any verified way, because no consistency check was run. It is not Legible, Enduring, or Available, because there is no durable, retrievable record of the AI involvement at all. One careless sentence, nine failures. That is why it is a confession.
What replaces it is not a heavier version of the same casual act; it is a different act entirely. The defensible pattern is to use a governed tool, load the real sources, capture the run as it happens, verify every claim against source by its type, document what was accepted and what was overridden and why, run the consistency check, and own the final record under a name, with the whole provenance retained where an inspector can find it. Stated as a list it sounds like a lot, but in a well-designed workflow most of it is built into the tool and the process, which is exactly what the rest of this program teaches. The nine attributes are not a burden bolted onto AI use; they are the definition of using AI in a way that produces a trustworthy record, and a professional who internalizes them has the single most portable test in the field: for any AI-assisted record, ask whether it is Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available, and if the answer to any of the nine is no, the work is not done.
Key Takeaways
- ALCOA+ governs AI output because the standard is about the record, not the author. The nine attributes, Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available, apply to any data in a submission regardless of how it was produced, and AI introduces specific new ways to fail each one.
- Attributable is the named-author principle in ALCOA+ terms: attribution runs to the human who verified and adopted the output, not to the tool, and the AI involvement itself must be attributable to the person who used it.
- Contemporaneous has a sharp AI-specific edge: because temperature makes runs non-reproducible, the run must be captured as it happens, the prompt, system prompt, model and version, temperature, timestamp, sources, and verification, since it cannot be faithfully reconstructed later.
- Complete means showing the overrides, and Consistent means catching the contradictions. A record that shows only accepted output hides the human judgment that makes it defensible, and a cross-section consistency sweep over AI-assisted Module 2 is the Consistent attribute in action.
- "I asked the AI and pasted the answer" fails all nine attributes, which is why consumer-tool AI work, whose provenance is neither enduring nor available, belongs nowhere near a regulated record. The defensible replacement, governed tool, loaded sources, captured run, claim-typed verification, documented overrides, consistency check, named ownership, retained provenance, is what every workflow in this program is built to deliver.
Skill.re