The first time I saw an AI approve a CAPA closure, I'll admit I paused. Not because the decision was wrong — it wasn't — but because I couldn't find a written record of who decided the AI was allowed to make that call.

This was about 18 months ago, back when we were still evaluating eQMS platforms. Both had some AI features in various states of maturity. The question that nagged me then — and keeps nagging me now — is simpler than it sounds: does your tool have an explicit, written list of things the AI is not allowed to approve?

I'm not talking about capability. Any sufficiently complex system can technically do just about anything. I'm talking about the explicit governance boundary — the line drawn in your QMS that says "AI assists here, but a human must be in the loop for these decisions."

Why the list matters more than the feature

ISO 13485:2016 is clear enough on management responsibility. EU MDR Article 2 (46) defines "human oversight" in terms that imply someone has to be accountable for decisions. FDA's guidance on AI/ML-based software keeps circling back to "intended use" and "meaningful human control." But none of these documents hand you a checkbox list of AI-forbidden tasks.