AI is now writing and changing methods. The audit trail was built for human operators.
Automation and informatics vendors are rapidly adding AI assistants: method authoring, run scheduling, deviation triage, troubleshooting. In a regulated laboratory each of those touches a controlled record.
Part 11 and Annex 11 both rest on attribution. A specific, identified person is accountable for a specific action, contemporaneously, and the record has to survive a challenge years later. ALCOA+ says the same in different words, and attributable is the first letter.
When a model drafts or edits a method, a new attribution gap can appear. The audit trail records the operator who was logged in. Depending on the system, it may not record that a model proposed the change, what the person actually authorized, or that the authorization existed before the run executed rather than being reconstructed afterwards.
A protocol can be correct, executable, and still not authorized.
AI is crossing from recommendation into execution.
This is not a forecast. Four dated, public announcements from the last two years describe the same movement: intent expressed to a model, then work performed on physical laboratory systems.
Insilico Medicine · July 2026
Insilico announced that rentosertib entered a Phase III clinical trial. Its target was identified by the company's AI platform and its molecule was AI-generated, so decisions made by models now sit at the head of a chain that reaches human dosing.
Lilly and NVIDIA · 2026
The two companies announced a co-innovation AI laboratory, described as connecting agentic wet labs and computational dry labs for continuous AI-assisted experimentation, with experiments, data generation and model development feeding one another.
Opentrons and HighRes · February 2026
The two companies announced a partnership to launch what they described as the industry's first AI agent-to-agent laboratory automation workflow, in which natural-language input becomes an experimental workflow and physical bench execution.
Thermo Fisher and NVIDIA · 2026
The two companies announced a collaboration applying AI to scientific instrumentation and laboratory performance, described in terms of a lab-in-the-loop environment connecting AI, agents and instruments.
The point is narrow. As long as a model only handed a scientist an answer, ordinary human review could remain the control boundary. Once a model can generate a protocol, invoke software, schedule work and set up the next experimental cycle, the control boundary has to move to where intelligence becomes consequence.
Sources: company announcements from Insilico Medicine, NVIDIA investor relations, Opentrons and Thermo Fisher investor relations, on the dates given.
Correct is not the same as authorized.
Four different questions arise around an AI-proposed action in a laboratory. Three of them already have owners, and Regulayer is not one of them.
Is the answer scientifically valid?Model evaluation and scientific review. Not Regulayer.
Will the protocol execute correctly?Simulation, protocol validation, instrument safety. Not Regulayer.
Does the account have permission to access the system?Identity and access management. Necessary, but not the distinction.
Is this action authorized by the human decision currently in force?Regulayer.
Regulayer does not discover the molecule, does not judge whether the biology is right, and does not validate a protocol. It answers one question, and then a second: can the organisation prove the answer afterwards without simply trusting the AI vendor's own log?
Where the layer sits
AI or scientific agent
proposes an action
The authorization boundary
- current human authority
- the decision in force now
- revocation and supersession
- allow, hold or escalate
- evidence created as the decision is made
ELN, LIMS, scheduler, workcell, robot, instrument, quality system
the experiment or the regulated action
The interesting case is not the first approval. It is what happens after it.
Illustrative authority change
- 09:14
- campaign authorized, under the model version then in use
- 11:42
- the authority changes, or the model changes
- 11:44
- a previously queued action reaches the boundary
- 11:44
- HOLD. What was authorized is not what is now executing.
Approvals in laboratory and quality systems are point-in-time gates. A scientist changes their mind mid-run, an approval is withdrawn, responsibility moves to another person, or the model underneath is updated. The newer decision should govern the next action, including work already in flight. That is how a scientist behaves during a run, and it is what the layer is built to enforce.
Four situations, one mechanism
AI-generated experimental methods
Before an AI-generated method becomes an executed or controlled method.
Closed-loop experimental campaigns
When a long-running AI campaign continues after the instruction, the approval or the authority has changed.
Autonomous laboratory execution
Before agent-generated intent becomes a robotic or instrument action.
GxP records and quality decisions
Where AI-generated output requires clearance by an authorised human, and the review itself has to leave evidence.
These are four applications of one mechanism, not four products.
Human oversight has to be more than a label.
FDA, April 2026
In a warning letter to a manufacturer, FDA addressed AI agents used to create specifications, procedures and master production records without adequate review, and stated that AI output used for CGMP activities must be reviewed and cleared by an authorized human representative of the quality unit. The record · 21 CFR 211.22
FDA and EMA, January 2026
The joint guiding principles for good AI practice in drug development ask that AI-related provenance, processing steps and analytical decisions be documented in a detailed, traceable and verifiable manner. The instrument
21 CFR Part 11
Regulated electronic systems carry audit-trail requirements, and separately require authority checks so that only authorized individuals perform the operation at hand. The instrument · Annex 22, draft
Regulayer makes the governing human decision enforceable at the moment of action, and provable long afterwards.
The failure this addresses is already documented in laboratories, with no AI involved. A reporting threshold nobody is recorded as approving. An automated threshold whose scope changed without a locatable authorisation. Clinical data deleted together with its own audit trail, two days after an inspection was pre-announced.
The Consequence Library: what the record shows, case by case
Discovery and regulated work are different arguments
Discovery and regulated work create different demands on the same control. In discovery, the priority is control over increasingly autonomous experimentation. In regulated work, that control must also leave evidence that can be inspected and independently verified.
The line between the two is moving. EMA's reflection paper on artificial intelligence reaches across the medicinal product lifecycle, discovery included, and the work that begins in a research campaign is increasingly the same work that later has to be explained. The instrument
Discovery and research use
- control over autonomous and closed-loop experimentation
- the human decision governing an experiment, preserved while the campaign runs
- current authority checked at the moment an action is attempted
- work already queued held when the authority behind it changes
- provenance across models, agents, software, instruments and partners
- evidence a collaborator, a licensee or an acquirer can verify independently
- all of it without scientific or proprietary data leaving the environment
In discovery, the value is control. Once a model can propose, change, schedule, coordinate or initiate experimental work, the organisation has to be able to say which human decision is governing the run, enforce it while the run continues, and show afterwards what that decision was across every system and partner the campaign touched.
GxP and regulated work
- enforceable human authorization, checked before the action
- contemporaneous evidence of the decision in force
- traceability from the governing decision to the action taken
- auditability that does not rest on the AI vendor's own log
- control at the point of consequence, not review afterwards
- records built to survive inspection and a later challenge
- verification by a third party, offline, without Regulayer
In regulated work, control has to leave evidence. Regulayer supplies enforceable authority, traceability and independently verifiable records alongside the existing quality system, created at the moment of the decision rather than reconstructed when someone asks for it.
The same layer serves both. What changes is what the organisation is buying: in discovery, control over autonomous work and provenance it owns; in regulated work, that control expressed in a form designed to fit existing quality-system, audit and inspection workflows.
How it fits beside what is already there
Instrument and informatics software already carries an authenticated user session with a meaning of signature. That is identity, and it is not the gap.
They supply identity. Regulayer supplies authority, enforcement and evidence, binding a signed authorization to the identity their system already established. It runs alongside the LIMS, the ELN, the scheduler, the quality system, the workcell and the model evaluation platform, and governs the one moment where their instructions become actions.
A person authorizes what the system is allowed to do. The authorization is enforced before the action runs, not reviewed after. It leaves a signed record that anyone can verify independently, offline, without Regulayer. It calls no model to make the authorization decision, so the decision is deterministic.
Deployment
Instrument networks are segmented, and method data is the crown jewels. Nothing has to leave.
Enforcement runs out of process from the system being governed, inside your own environment. Keys are generated within the deployment rather than escrowed with Regulayer. In the default mode there is no outbound call of any kind, so enforcement and evidence signing work on a machine with no route to the internet at all. Where independent time is required, a single cryptographic digest goes to a public timestamp authority, never the method and never its contents. The evidence remains verifiable outside Regulayer, without Regulayer acting as the verifier.
Every answer your security function will ask for, on one page you can forward
The estate
Patent pending across the estate. Control of a consequential action against current human authority, and evidence a third party can verify without the vendor, are filed subject matter.