Used well, AI takes the repetitive lookup and drafting off a regulatory team so the qualified people spend their time on judgement. Used badly, it produces fluent, confident answers that are not grounded in your data, which in a regulated function is worse than no answer at all. The difference is entirely in how it is built and where it is pointed. This article is practical guidance, not legal advice.
What it does
The useful work is narrow and real: assembling a draft answer to a customer questionnaire from your own product facts, checking product composition against a changed candidate list, surfacing the right document from a large archive, and keeping a record of what was produced and approved. In each case the value is speed and traceability on work that is high-volume and low-judgement. None of it involves the machine making a regulatory decision.
Grounding and citation, in plain terms
A general chatbot answers from patterns in its training data. It has never seen your products and it will still answer as though it has. A grounded system works the other way round: it retrieves the relevant passages from your own verified documents, and writes the answer from those passages, with a citation pointing back to each one. If the fact is not in your documents, it does not have an answer to give.
That citation is the whole point. It lets a reviewer confirm the answer against the source in seconds instead of trusting the machine, and it is what makes the output defensible if a customer or an auditor asks later. Answering from your documents, with a reference, is a different activity from answering from general knowledge, and it is the only version that belongs anywhere near regulatory work.
What it should not be used for
This is the more important half of the article. A tool is only safe if its limits are explicit, so here are the lines that do not move:
- Autonomous regulatory submissions. Nothing is filed to a regulator without a competent person reviewing and submitting it. The system prepares; the person decides.
- Safety decisions. Classification calls, exposure judgements and anything bearing on safety stay with the qualified people who own them. AI supports the lookup, not the decision.
- Control systems and process safety. It does not touch SCADA, PLCs, safety instrumented systems or SIL-rated functions, and it does not do HAZOP, LOPA or safety-case work.
- Answering from general knowledge. It should answer from your documents, not from a modelβs training data. If the answer is not in your source of truth, the correct output is "I do not have that", not a confident guess.
- Being the record. The regulatory record is your controlled documents, not a chat history. The system points to the record; it is not a substitute for it.
Want a system built around these limits?
We design for the constraints above from the start: grounded answers, citations, and a human approval gate on every regulated output. A short technical call, no pitch.
Book a technical callThe human approval gate
Every regulated output passes through a named person before it is used. The system drafts and cites; the competent person reviews, edits and approves. This is not a nicety bolted on at the end, it is the core of the design, and it is why the honest promise is "less manual effort and better traceability", not "hands-off compliance". Anyone offering the second thing is selling you a risk, not a tool.
Where to start
Start with one high-volume, low-judgement task where the facts already exist in your documents, such as questionnaire responses, and build the source of truth for that first. Prove the grounding and the citations on a task you can check easily, keep the human gate in place, and expand only once the pattern has earned trust. That is the whole approach we take across the chemical and process industries.
Frequently asked questions
Can AI replace our regulatory affairs team?
No, and that is not the goal. It removes the high-volume lookup and drafting so your specialists spend their time on judgement. The competent person remains responsible for every regulated output.
How is this different from ChatGPT?
A general chatbot answers from its training data and will produce confident wrong answers about your products. A grounded system answers only from your own verified documents, shows a citation for each answer, and defers to a human. The difference is the source of the answer and the audit trail.
Does it guarantee we are compliant?
No. It reduces manual effort and improves traceability. Compliance remains the responsibility of your competent person. Be wary of any vendor who tells you otherwise.
What happens when it does not know?
A well-built system says it does not have the answer and routes the question to a person, rather than inventing one. That behaviour is a design choice and a large part of what makes it safe to use.
Sources
Regulatory obligations referenced here are set by the authorities below. Confirm your own obligations against them. This article is practical guidance, not legal advice.
The whole picture: what we take on and where we stop.
A concrete account of why a general model fails at this work.
The highest-volume documentation task, and a good first use case.