cd /news/ai-policy/the-ai-approval-boundary-nobody-talk… · home topics ai-policy article
[ARTICLE · art-126432] src=dev.to ↗ pub= topic=ai-policy verified=true sentiment=· neutral

The AI approval boundary nobody talks about until the audit finds it

A quality-management engineer working in a Class II medical device environment describes discovering that an AI feature in an eQMS had approved a CAPA closure without any written record of who authorized the AI to make that decision. The engineer argues that regulated manufacturers need an explicit, documented list of AI-prohibited approvals — such as CAPA closure, reportability, risk acceptability, and regulated submissions — to satisfy ISO 13485, EU MDR human-oversight requirements, and FDA guidance on meaningful human control. A peer at a smaller European Class I shop reportedly spent two days reconstructing records after their eQMS auto-closed low-risk CAPAs without a formal root cause review.

by read3 min views1 publishedSep 11, 2026

The first time I saw an AI approve a CAPA closure, I'll admit I d. Not because the decision was wrong — it wasn't — but because I couldn't find a written record of who decided the AI was allowed to make that call.

This was about 18 months ago, back when we were still evaluating eQMS platforms. Both had some AI features in various states of maturity. The question that nagged me then — and keeps nagging me now — is simpler than it sounds: does your tool have an explicit, written list of things the AI is not allowed to approve?

I'm not talking about capability. Any sufficiently complex system can technically do just about anything. I'm talking about the explicit governance boundary — the line drawn in your QMS that says "AI assists here, but a human must be in the loop for these decisions."

ISO 13485:2016 is clear enough on management responsibility. EU MDR Article 2 (46) defines "human oversight" in terms that imply someone has to be accountable for decisions. FDA's guidance on AI/ML-based software keeps circling back to "intended use" and "meaningful human control." But none of these documents hand you a checkbox list of AI-forbidden tasks.

So you have to build it yourself. And if you're building it, you need to know what boundaries your platform has already drawn — or whether it has drawn any at all.

In our setup (Class II, Greenlight Guru, about 200 people), the AI features we use are largely advisory. The system flags potential NCs from complaint text. It suggests CAPA linkages. It drafts risk matrix summaries. But closing a CAPA? That requires a named human in the approval chain. Always has. We wrote it into our SOP.

I know qmsWrapper takes a similar approach — they've documented that their AI blocks on CAPA closure, reportability, risk acceptability, and regulated submissions. That's the kind of explicit statement I can point to in an audit. "Here's where the line is. Here's why. Here's who drew it."

Does your eQMS vendor give you a written list of AI-prohibited approvals? Or did you discover the boundary by accident, the way I almost did?

Because there's a meaningful difference between:

Each has a different audit posture. The first is defensible. The second is fine if your SOP is good and people follow it. The third is a gap waiting to surface.

A peer at a smaller shop (Class I,在欧洲) told me about a near-miss last year. Their eQMS had been auto-closing low-risk CAPAs after 90 days of no activity. Worked fine for months. Then someone realized that a legitimate corrective action had been "closed" without a formal root cause review — because the AI treated the silence as acceptance.

No harm done. They caught it. But they spent two days reconstructing the record and updating their workflow. If a notified body had audited during that window, the CAPA would have shown as closed with no human sign-off.

ISO 13485:2016 clause 8.5.2 wants to know that corrective action adequacy is reviewed. If your system auto-closes CAPAs, can you demonstrate that a human made the adequacy determination? Even if they just clicked "confirm closure" on a pre-filled form?

I'd genuinely like to know how others are handling this. Specifically:

The EU AI Act and ISO 42001 (AI management systems) are going to make this more formal over time. But the audit-ready answer shouldn't wait for regulation to force the question.

For me, the working heuristic is simple: AI can recommend. Humans must approve — in writing, in the record, with accountability. The line is only as good as the evidence that someone drew it and the system respects it. Does your current eQMS have an explicit, documented list of AI-prohibited approvals — and if so, how did you get the vendor to confirm it?

── more in #ai-policy 4 stories · sorted by recency
── more on @greenlight guru 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-ai-approval-boun…] indexed:0 read:3min 2026-09-11 ·