Viewpoint by Ching Chee F., Senior Consultant at Amaris Consulting
The regulatory window that opened in 2025 is closing. For life sciences organizations, 2026 is the year the new rules stop being drafted and start being expectations.
Three major updates are reshaping how pharmaceutical, biotech, and medical device companies manage the software and digital systems at the heart of their operations. The FDA has finalized a new framework for computer software assurance (CSA) that replaces decades of document-heavy validation with a risk-based approach. Europe’s core rulebook for pharmaceutical manufacturing, largely unchanged since 2011, is being rewritten for the first time. And regulators on both sides of the Atlantic are setting rules for how artificial intelligence can be used in regulated environments. For organizations still running on legacy compliance thinking, this is not a future problem. It is a present one.
Why the old approach stopped working
Computer System Validation (CSV) was never designed to be a documentation exercise. Somewhere between regulatory guidance, audit culture and risk aversion, it became one. Companies would produce thousands of pages of test scripts for off-the-shelf software already validated by the vendor, documenting what everyone knew worked, in formats regulators had largely stopped caring about.
The result was predictable: validation projects running months longer than the system implementations they were meant to support, teams buried in paper reviews, and a widening gap between what the binders described and what was actually running in production.
The global CSV services market reflects real demand for a better approach. Valued at approximately $4.4 billion in 2025 and growing at around 10% annually, it is expected to reach $11 billion by 2035 (Research Nester, 2025). The growth is there. What is changing is the regulatory logic underneath it.
What computer software assurance actually changes
The FDA’s final computer software assurance guidance, published in September 2025, makes the shift explicit. Its core argument: confidence in software should come from critical thinking about risk, not from completing documentation templates.
Under CSA, the central question changes from “have we documented everything?” to “have we tested what actually puts patients and product quality at risk?” That sounds obvious. In practice, it means companies can legitimately reduce or eliminate scripted testing for lower-risk system functions, rely on vendor documentation where it is credible, and concentrate human effort on the parts of a system where failures would have real consequences.
This is particularly relevant for the growing share of life sciences IT runs on SaaS platforms and commercially developed software. Applying traditional validation protocols to a configurable off-the-shelf system was always a stretch. CSA gives quality teams formal permission to stop doing it.
One thing worth saying plainly: CSA asks more people, not less. Less paper, more judgment. That is a harder shift than it sounds.
Europe rewrites the rulebook and adds a new chapter on AI
While the FDA was finalizing its framework, European regulators were doing two things at once, both of which will land in the next twelve months.
Europe’s pharmaceutical manufacturing guidelines include a section specifically governing computerized systems. That section, known as Annex 11, has not been meaningfully updated since 2011. A lot has changed since then. Cloud adoption was limited when it was written. SaaS platforms were unusual in regulated environments. AI was not embedded in manufacturing operations. The revised version, now past public consultation and expected to be finalized in mid-2026, addresses all of this directly.
The update strengthens expectations around supplier oversight. Organizations remain fully responsible for GMP compliance even when systems are built, hosted, and updated by third parties. It requires continuous lifecycle governance rather than one-time validation events. It also tightens data integrity controls for modern architectures, covering cloud platforms, distributed systems, and software that updates continuously rather than in fixed releases.
On the same day the Annex 11 revision went to consultation; regulators published a draft of an entirely new section dedicated to artificial intelligence in pharmaceutical manufacturing. This is the first regulatory framework of its kind in the EU context. Its final version is expected before the end of 2026, with enforcement phased in through 2027 and 2028.
The AI rules draw sharp lines. In critical applications, meaning those directly affecting patient safety, product quality, or data integrity, only static and deterministic machine learning models may be used. Adaptive models are prohibited. Generative AI tools, including large language models, are excluded from critical manufacturing decisions entirely. They may support non-critical tasks, but only under mandatory human supervision.
The requirement with the most practical weight: any AI-based decision in a regulated context must demonstrably perform at least as well as the validated manual process it replaces. AI cannot be adopted simply because it is faster or cheaper. It has to be proven, with documentation, testing, and ongoing monitoring, to be at least equivalent to what it displaces.
What this means right now for life sciences organizations
The combined effect of these updates is a real change in what good compliance looks like day to day. Three things follow directly.
Validation effort needs to be redistributed, not just cut. Computer software assurance is not a license to do less work. It is a mandate to do different work. The time saved on low-risk documentation should move into deeper risk analysis and testing for the functions that genuinely matter. Organizations that treat CSA as a cost reduction exercise will find themselves underprepared for the scrutiny that comes with it.
AI governance cannot be retrofitted after deployment. Companies already using AI or machine learning in quality, manufacturing, or laboratory systems need to establish governance frameworks before those systems face an inspection, not in response to one. That means performance baselines, explainability requirements, and change controls built in from the beginning. Doing it backwards is a considerably harder problem.
Supplier relationships need to become more formal. Both the revised guidelines and CSA place explicit expectations on organizations to actively govern their software vendors. Audit programs, quality agreements and transparency into how vendor software is developed, updated, and maintained are no longer optional formalities. Choosing a cloud or SaaS solution does not transfer the compliance responsibility to the provider.
What comes next asks for something harder
For life sciences organizations, the compliance landscape is not shifting, it has shifted. FDA computer software assurance guidance is final. Europe’s manufacturing rules for computerized systems are weeks or months from their final version. The AI framework is close behind. Companies that treat these as future considerations are already behind.
The good news is that organizations adapting now, before enforcement lands, have real room to build validation programs around what actually matters: patient safety, product quality and data integrity, rather than documentation volume. The binders had a good run. What comes next asks for something harder: expertise, judgment, and the infrastructure to prove both.
Amaris Consulting’s Life Sciences practice supports pharmaceutical, biotech and medical device organizations through this regulatory transition, across computer system validation, qualification, quality assurance and AI compliance readiness. Contact us