Three clocks are colliding inside the world’s regulated factories. The first is AI adoption, which is running fast. Data and validation readiness is the second, and it is running slow. The regulator’s clock is the third — and it has just started.
The evidence that they are colliding is now hard to miss. In April 2026, the US Food and Drug Administration issued its first warning letter with a dedicated section on the misuse of AI in drug manufacturing. In the same months, three of the largest names in medical technology and pharma lost production to cyberattacks that never touched a controller.
This is the story the surveys keep telling, and the enforcement is starting to confirm.
The gap, in numbers
The industry’s own research is unusually consistent. Deloitte surveyed 150 life-sciences executives in April 2026. It found that 71% had advanced AI deployment over six months, but only 45% could show measurable performance gains, and only 13% had gains at scale.
Earlier Deloitte work was blunter. In its 2026 outlook, only 22% of executives said they had successfully scaled AI, and just 9% reported significant returns.
KPMG found the same shape. Among 124 life-sciences technology leaders, 87% said AI agents were being integrated into workflows. Yet 44% reported limited maturity in funding and scaling AI, and 93% said digital initiatives generate less than 1% of annual revenue.
The bottleneck is data. McKinsey estimates that healthcare and life sciences generated about 11,000 exabytes of data worldwide in 2025, and that roughly 97% of it remains untapped. One participant described raw data as “saltwater” — abundant, but unusable in its natural state.
Vendor surveys point the same way. MasterControl’s study of 300 life-sciences professionals found 69% stuck piloting AI, blaming a “connectivity crisis” of siloed systems and what it calls “infrastructure debt.” A Veeva study found 67% of companies abandon AI initiatives because of poor data quality.
Why the data is not ready
The problem is not that manufacturers lack data. It is that the data sits in systems that do not talk to each other, inside processes that were never designed for it.
Forrester, surveying more than 160 European manufacturing decision-makers for Octave, found that more than 70% describe production as data-driven. But two-thirds still say data silos hold them back, and half consider their transformation at an early stage. Documentation alone consumes up to 30% of staff time.
The pattern repeats across the sector. Quality events live in one system, production records in another, and documents in a third. Spreadsheets bridge the gaps. When a deviation needs investigating, someone reconciles the data by hand.
That is a slow, expensive way to run a factory. It also forms the foundation for AI. Gartner projects that 60% of AI projects lack AI-ready data — and in a regulated plant, every data failure passes through a compliance envelope.
The validation trap
Here is the part that makes pharma different from a bank. In most industries, you patch a vulnerable system quickly. In a validated plant, you cannot.
Any change to a validated computerised system — including a security patch — must pass change control and an impact assessment before it reaches production. Full revalidation can take months. Practitioners describe an exploitable window that stretches from patch release to deployment.
The regulators know this tension exists, and they are trying to loosen it. The FDA’s Computer Software Assurance guidance, finalised in September 2025, moved validation away from prescriptive, documentation-heavy test scripts toward risk-based “documented critical thinking.”
Under CSA, infrastructure and security patches typically need a documented impact assessment — hours of work, not weeks — rather than full revalidation. But the signed assessment must exist. The relief is real, and so is the paperwork.
The EU is moving in the same direction. Its draft revision of GMP Annex 11 grows from 5 pages to 19 and, for the first time, treats cybersecurity as a core GMP requirement. A new chapter demands patch management, network segmentation and penetration testing. It states that unpatched platforms are “highly vulnerable” and a “major risk for loss of data integrity.”
The tension is now written into the rules themselves.
The regulator’s clock: Annex 22
The most consequential document in this story is still a draft. EU GMP Annex 22, the first dedicated rule for AI in GMP manufacturing, went out for consultation in July 2025. The EMA targets a final text for late 2026.
Its central decision is a boundary. In critical GMP applications, Annex 22 permits only static, deterministic models — parameters frozen, identical inputs producing identical outputs. The draft excludes dynamic, self-learning and probabilistic models. So are generative AI and large language models, which belong in non-critical roles under documented human oversight.
The requirements are demanding. Manufacturers must define intended use before testing. Acceptance criteria must be set in advance and be at least as good as the process the model replaces. Test data must be kept strictly separate from training data.
The model must show its working through feature attribution. The system must log confidence scores and flag low-confidence outputs. And the model, the system and the process all sit under change control, with continuous monitoring for drift.
The EMA held a workshop in mid-2026 to ask whether regulators could relax the generative-AI restrictions with guardrails. The EMA has not published a decision.
Meanwhile, the FDA has already enforced. In April 2026 it cited a Michigan drug manufacturer, Purolea Cosmetics Lab, in a warning letter with a section headed “Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing.” The firm had used AI agents to draft specifications, procedures and master records without quality-unit review. It had also skipped process validation, explaining that the AI agent never told it validation was required.
The FDA’s position was unambiguous: an authorised human in the quality unit must review and clear any output from an AI agent. It is not banning AI. The agency is saying that accountability cannot be delegated to the model.
When the breach does not need the plant floor
The security record shows why readiness matters beyond compliance. In 2026, some of the sector’s largest manufacturers lost production to attacks that never reached a controller.
Boston Scientific detected an intrusion on 25 August 2026. The attacker reached an external-facing device and a limited part of its on-premises IT. CrowdStrike found no compromise of the SCADA environment. Manufacturing stopped anyway — order processing and shipping worldwide, for a company with more than $20 billion in revenue.
West Pharmaceutical took its systems offline globally in May 2026 after a double-extortion ransomware attack. Attackers exfiltrated data and encrypted systems. Shipping, receiving and manufacturing stopped worldwide at an S&P 500 supplier of injectable-drug packaging.
Stryker lost ordering, shipping and manufacturing for weeks in March 2026. NHS England asked its partners to prioritise clinically important supplies. Novo Nordisk faced a claim that hackers stole 30 AI models and the manufacturing processes for Wegovy and Ozempic. McKesson, which distributes about a third of North American pharmaceuticals, faced a data-theft extortion demand reported above $55 million.
Dragos, which tracks industrial threats, explains the mechanism. Ransomware “does not need to touch a PLC.” Attackers reached VMware hypervisors hosting SCADA, historian and engineering workloads, and encrypted the virtualization layer. That removed operator visibility and control without a single industrial-protocol interaction.
The numbers are stark. Industrial ransomware rose 49% year over year, with manufacturing taking more than two-thirds of victims. Average dwell time in OT environments was 42 days. Only 30% of OT networks have visibility. And 24% of manufacturing sites have no OT incident response plan at all.
The World Economic Forum put the operational risk plainly: a restored application may still leave a plant unable to release a medicine, if the quality evidence is incomplete.
The bill: batches, deviations and patients
It is not measured only in downtime. The cost shows up in batches that cannot be released and in patients who cannot get their medicine.
Industry benchmarks put unplanned pharma downtime at about $260,000 per hour, with aseptic filling lines near $450,000 per hour. A single biologics batch can be worth $500,000 to over $5 million. A deviation investigation runs $25,000 to $55,000. Batch rejection frequently exceeds $1 million.
Poor data quality compounds all of it. Gartner puts the average annual cost at $12.9 million per organisation, and pharmaceutical estimates run at 15–25% of revenue.
Then there is the second-order effect. USP’s 2026 shortages report found that the average drug shortage now lasts more than five years, up from about two years in 2019. Discontinuations rose 60% in a single year. And 44% of drugs in shortage depend on a key starting material made in only one country, usually China or India.
The EMA has warned that shortages lead to rationing, delayed treatments, weaker alternatives and medication errors. A manufacturing disruption is a patient-access event.
The India angle
India sits at the centre of all of this. It supplies about 20% of the world’s generic medicines and 60% of its vaccines, to more than 200 countries.
Data integrity has been the most common cause of international audit failures at Indian sites — fabrication of analytical data, backdated records, weak audit trails, insufficient system validation. That history is why the country’s rules are tightening.
Revised Schedule M aligns Indian GMP more closely with WHO-GMP, adding Pharmaceutical Quality Systems, Quality Risk Management, computerised-system compliance and ALCOA+ data integrity. CDSCO now requires state drug controllers to report inspection findings monthly.
The regulator is also digitising itself. CDSCO’s planned Digital Drugs Regulatory System would unify central and state regulation and integrate 21 national databases, with a first phase targeted within 18 months. The agency says more than 99% of its processes are already online and it is piloting AI.
On the factory floor, necessity is driving the shift as much as ambition. Cipla deployed Körber’s PAS-X manufacturing execution system and electronic batch records at Patalganga, later extended to Indore and Goa, reporting roughly 75% less manual data entry. For Indian manufacturers, data integrity has become a licence to export, not a competitive extra.
What to watch
Three markers will show whether the readiness gap closes or widens.
First, whether Annex 22 survives consultation intact. If the EMA relaxes its stance on generative AI, the compliance picture changes; if it holds, then a large share of current AI enthusiasm sits outside critical GMP by design.
Second, whether manufacturers publish completion and inspection-outcome data for their AI inventories. Right now, 36% of validation professionals say they have little or no familiarity with the rules they will be judged against.
Third, whether the security record changes behaviour. The lesson of Boston Scientific and West is that the plant floor is not the only way to stop production. Segmentation, visibility and OT-specific incident response are the controls that decide how long a line stays dark.
The technology is not the hard part. The data, the records and the validation underneath it are.

Editor’s Note
Sources: this feature draws on independent research and does not rely on the vendor release that prompted it. It draws on Deloitte’s mid-2026 and 2026 Life Sciences Outlook surveys, KPMG’s Global tech report 2026: Life Sciences, NVIDIA’s 2026 State of AI in Healthcare and Life Sciences, McKinsey’s January 2026 life-sciences analysis, Kneat’s State of Validation 2026, MasterControl’s digital maturity research, a Veeva-cited study, and Forrester research for Octave. Regulatory material is from FDA warning letters and CSA guidance, the EMA/PIC/S draft Annex 11 and Annex 22 texts, and EU GMP Chapter 4.
Security data is from SEC filings and company statements by Boston Scientific, West Pharmaceutical Services and McKesson, reporting on Stryker and Novo Nordisk, Dragos’s 2026 OT Cybersecurity Year in Review and Q2 2026 analysis, and a World Economic Forum commentary. Cost and shortage data is from Gartner-cited benchmarks, USP’s 2026 Annual Drug Shortages Report, and ASHP. India material is from CDSCO documents, PIB notifications, and trade and academic sources. All figures come from their originating organisations, and TechRecast has not independently audited them.

