AI-generated regulatory files: who validates and signs them (FDA + EU AI Act)

Artificial intelligence can now draft a medical device technical file, a cosmetic safety report or a declaration of conformity in minutes. Under deadline pressure, that speed feels like a gift. But it has quietly changed the question a regulator asks when the file lands on their desk. It is no longer “did you use AI?” — almost everyone does. It is “who reviewed this, and whose name is on it?”

That shift is not theoretical. In 2026 the US FDA issued a warning to a cosmetics laboratory that had relied on AI-generated documentation without meaningful human review. In the European Union, the EU AI Act (Regulation (EU) 2024/1689) turns the same expectation into law: its Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output, can question it, and can override it. On both sides of the Atlantic the direction is identical, and it is only tightening.

The regulator’s question has changed

For years the compliance conversation was about whether a document existed: was there a technical file, a CPSR, a declaration of conformity? Now that AI can produce a plausible version of any of them on demand, the mere existence of the document proves very little. What an inspector wants to know is whether a qualified person stands behind it — because that person is who answers when something is wrong.

This is the single most important thing to understand about AI in regulatory work: the risk was never the technology. The risk is delivering what the technology produces without a professional validating it and signing for it.

What the FDA case actually tells us

The detail that matters in the FDA action is not that AI was used. It is that the output reached a regulatory context without a human who could vouch for it. Regulators are not banning AI; they are refusing to accept unaccountable AI. A submission that is fast but unverified is worse than a slow one, because it carries the appearance of rigour without the substance — and appearances are exactly what an inspection strips away.

Expect the pattern to spread. As more companies lean on generative tools for regulatory content, authorities are learning to look for the fingerprints of unreviewed AI: confident language around claims that do not hold, references that cannot be traced, and gaps where a specific requirement should be.

What the EU AI Act requires: oversight, not a rubber stamp

Article 14 of the EU AI Act sets out human oversight for high-risk AI systems. In plain terms, a person must be able to understand what the system produced, judge whether it is correct, and intervene or stop it — not simply click “accept”. “A human glanced at it” is not oversight. “A qualified professional validated it and takes responsibility for it” is.

Even where a specific regulatory task falls outside the Act’s high-risk list, the principle has already reset expectations across the sector. And it converges with a professional obligation that predates any AI law: the person who signs a regulatory document answers for it. The EU AI Act simply makes the absence of that person visible and, increasingly, unacceptable.

Where unreviewed AI output actually fails

In the files we review, the failure modes of AI-generated regulatory content are consistent:

  • Citations that do not exist. A regulation number, an article or a standard that reads perfectly but corresponds to nothing real — or that has been superseded.
  • Out-of-date limits. A migration limit, a permitted concentration or a classification taken from a version of the rule that no longer applies.
  • Silently dropped requirements. A test, an annex or a labelling element the model simply did not include, so the gap is invisible unless someone checks against the source.
  • Fabricated confidence. Conclusions stated as certain (“this product complies”) that the underlying evidence does not support.

None of these is exotic. Every one is exactly what an inspector, a notified body or a customs authority is trained to find — and exactly what a qualified reviewer catches before it leaves the building.

What “validated and signed” means in practice

At ASC Services we work the opposite way round to a self-service tool:

  • AI prepares the dossier: faster, and covering everything.
  • A qualified regulatory technician reviews every claim against the primary source — the regulation, the standard, the test report.
  • An adversarial check hunts specifically for the failure modes above: the hallucinated citation, the outdated limit, the missing requirement.
  • The technician validates the file and signs it in their own name, with full traceability of what backs each claim.

Our process is built to the EU AI Act and to EN 18286:2026, the European quality-management standard for AI published in 2026 — not yet cited in the Official Journal as a harmonised standard, so it does not yet confer an automatic presumption of conformity; we build to it as good practice, never as a claim of certification. The point is not the technology on the inside. It is the accountable professional on the outside.

Tool versus operated service: who carries the liability

Read the terms of the cheap regulatory-AI tools. Almost all of them make you accept, in the small print, that the responsibility for what you submit is yours. They automate a notification or generate a document; they do not take on the file, and they do not sign it. If the AEMPS, the FDA or customs stops your product, you are alone with an output no one validated.

The laboratory the FDA sanctioned had the tool. What it lacked was someone to validate and sign. That is the whole difference between a tool and a service: when the inspection comes, one leaves you holding the file, and the other answers for it with you.

How to tell a validated service from a wrapper

If you are evaluating an AI-assisted regulatory provider, four questions separate a real service from a thin wrapper around a language model:

  • Does a named, qualified professional sign the deliverable — or only “the platform”?
  • Who responds if an authority challenges the file: them, or you?
  • Can they show the traceability — which source backs each claim?
  • Does their contract accept responsibility, or transfer it to you?

If the answers point back to you, you have bought a tool, not compliance.

It applies to every regulated product

The same logic runs through every sector we work in: an MDR technical file for a medical device, a Cosmetic Product Safety Report, a food-contact declaration of conformity, a safety data sheet. AI can accelerate all of them; none of them should reach an authority without a qualified person validating and signing. The higher the regulatory stakes, the more the signature matters.

Frequently asked questions

Does the EU AI Act ban AI in regulatory work? No. Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output and can intervene. AI plus a qualified human who validates and signs is exactly what it asks for.

Is a signed regulatory file just a formality? No. The signature is who answers for the file in an inspection. “An AI generated it” is not a defence; “a qualified technician validated and signed it” is.

Will using AI make my submission look weaker to a regulator? Not if a professional validates and signs it. What weakens a submission is unreviewed content — inconsistencies and unsupported claims that signal no one checked.

How ASC Services helps

We produce your regulatory documentation with AI, and a qualified technician validates and signs every output — for the EU (AEMPS, EU AI Act) and for the US (FDA). Twenty years and hundreds of approved dossiers, none that you have to answer for alone. Whether it is an MDR technical file, a cosmetic safety report, or regulatory affairs run with AI, we make the speed of AI safe to submit. Talk to our team through our contact page.