For pharma, biotech, medical devices, and clinical research

AI may inform. A human owns the decision.

FDA's position is unambiguous. AI may inform the work, but a human must remain responsible for the decision and be able to explain why it was appropriate. No dashboard satisfies that requirement on its own. Guard produces the receipts that do.

Aligned to FDA CSA, FDA and EMA Good Machine Learning Practice, ICH Q9, GAMP 5, ISO 42001, and EU AI Act.

Fragmented frameworks. One consistent obligation.

There is no single AI rulebook

Validation teams piece together governance from FDA Computer Software Assurance, the 2025 FDA draft on AI credibility, ICH Q9 quality risk management, GAMP 5 for automated manufacturing, ISO 42001, and voluntary standards. Every framework is right about part of the problem. None is complete for agents.

2026 raised the bar

FDA and EMA jointly issued ten Good Machine Learning Practice principles in early 2026. EU AI Act high-risk obligations are phasing in this year. The direction is clearer. The methods are still fragmented.

Human accountability is non-negotiable

The one point every framework agrees on. Agents may propose. Humans decide. Every decision needs a recorded reason. Guard is the runtime layer that makes that recording automatic instead of forensic.

How Guard covers the underlying principles.

Every framework agrees on the same set of principles. Guard applies them at the runtime layer so they hold on every agent action, not just at annual review.

Human accountability

Clinical-adjacent and patient-safety-adjacent agent actions block until a human review event is recorded. Agent proposes, human decides, both are on the audit chain.

Groundedness

Agent proposals lacking provenance to an authoritative source (protocol, monograph, published study, internal SOP) trigger a warning. Missing citation is a first-class signal.

Intended use scope

Actions outside the validated intended-use scope warn. Off-label, unvalidated, and research-only scopes are surfaced immediately.

Data integrity for GxP systems

Writes to LIMS, EDC, MES, EBR, or CTMS require a two-person integrity check. Agent proposes, human confirms, both events are recorded with time and identity.

Credibility assessment

Expired or missing credibility assessment blocks agent action. Cadence is set proportional to risk tier and pathway.

Change control

Model swaps in regulated pathways warn without an accompanying revalidation event. Silent model changes break FDA CSA validation status.

PHI handling

Agent actions on PHI-classified data require documented HIPAA scope check. Data classification and access basis are confirmed before commit.

conduct-life-sciences v1.0.0

Nine rules ship in the pack today.

Every rule is tagged to FDA CSA, FDA/EMA GMLP, ICH Q9, GAMP 5, ISO 42001, HIPAA, or EU AI Act Article 26. Evidence attaches to every decision.

Block

Clinical decision-adjacent agent action without recorded human review.

Block

Agent write to LIMS, EDC, MES, EBR, or CTMS without two-person integrity check.

Block

Agent action when credibility assessment is expired or missing.

Block

Patient-safety-adjacent action without human-in-the-loop attestation.

Block

Agent action on PHI-classified data without documented HIPAA scope check.

Warn

Agent proposal lacking provenance to authoritative source.

Warn

Agent action outside validated intended-use scope.

Warn

Model swap in regulated pathway without accompanying revalidation event.

Audit

Every artifact-touching agent action for FDA CSA lifecycle traceability.

How it plugs in.

Guard sits between your agents and every GxP system. Existing validation process wraps around it.

  1. 1. Install the pack. One click from the Registry. Rules load, framework mappings attach, audit chain begins recording.
  2. 2. Declare intended use and risk tier per agent. Tier and intended-use scope drive the obligations. Deviation triggers warnings or blocks.
  3. 3. Guard evaluates every proposed action. Clinical, safety, GxP writes, and PHI-adjacent actions get the strictest treatment. Everything else stays fast.
  4. 4. Every decision is a signed audit row. Validation team gets a queryable evidence table. FDA CSA lifecycle traceability without manual archaeology.
  5. 5. Your existing validation process wraps around Guard. Credibility assessments, intended-use scope, change control, and periodic review all point at the same audit chain.

Human accountability, provable at commit.

Nine rules. One pack. Aligned to every framework your validation team is already reconciling.

Life Sciences | Conduct | ConductAI