Building an Enterprise AI Gateway for Pharma: Guardrails, Audit Trails, and Why “Just Use ChatGPT” Isn’t an Answer

When we started DnXT Solutions, our vision was clear: bring modern technology to life sciences regulatory operations and make complex processes simpler, faster and more compliant. The pace of change in AI today is both exhilarating and, for many in pharma, deeply unsettling. I have personally sat across from countless regulatory leaders who see the potential — summarising vast document sets, classifying submissions, drafting cover letters, searching intelligently — and are paralysed by the compliance risk.

The problem is stark. Regulatory teams want to use AI. They watch colleagues in other functions, or friends outside the industry, getting instant answers from AI assistants. The temptation to “just use ChatGPT” for a quick task is strong. But in a regulated industry that is a non-starter. Sending confidential application data, trial subject information or proprietary formulation details to an outside service with no audit trail, no check for personal data and no compliance controls is not merely risky; it is a direct route to a regulatory problem. It is a data leak waiting to happen, and one that could jeopardise an approval and patient trust alike.

At the other extreme, the alternative often proposed is to build your own AI from scratch. For most pharmaceutical companies that is a multi-million dollar, multi-year undertaking requiring a specialist team — an enormous investment in something that needs to be integrated, not reinvented.

That left a gap. There was no practical middle ground: no managed, pharmaceutical-grade way to use AI that also enforced the controls life sciences requires. We saw the gap, felt our clients’ frustration, and built it.

The Core Problem: This Is a Governance Challenge, Not a Technology One

From the moment we started designing, one truth was obvious: AI in pharma is not primarily a technology problem. It is a governance problem. The question is not “can AI do this?” It is “can AI do this with a full audit trail, protection for personal data, strict separation between customers, and regulatory oversight?” If the answer to the second is no, then the technology, however impressive, is useless in our industry.

Every pharmaceutical company, whatever its size, will eventually need a controlled route for AI. It is not a luxury; it is inevitable. And building it into the platform from the start is immeasurably better than adding it later. Retrofitting compliance and security onto AI that is already in uncontrolled use is costly, error-prone, and rarely ends up genuinely robust.

“The question isn’t ‘can AI do this?’ It’s ‘can AI do this with a full audit trail, protection for personal data, strict separation between customers, and regulatory oversight?’ If the answer to the latter is no, then the technology, however brilliant, is useless in our industry.”

What We Built

At its heart, this is an intelligent intermediary. It sits between the user — or our own applications — and a range of AI providers, including Anthropic, OpenAI, Azure OpenAI, and models a customer hosts themselves. Supporting several providers matters, because no single AI model is right for everything. Different tasks suit different models, and different levels of data sensitivity demand different arrangements.

Here are the components that make it suitable for pharmaceutical use:

1. Choosing the right AI for the task

  • The need: not all AI models are equal. Some are fast and cheap, ideal for straightforward classification. Others are more capable and better suited to nuanced summarising. And some information is sensitive enough that it must never leave the customer’s own environment at all.
  • What we did: requests are directed to the most appropriate model. A fast, economical one handles document classification; a more capable one handles nuanced summarising. And where a document contains personal data or proprietary formulation details, the system can be configured to use only models the customer hosts themselves, so that information never leaves their control. That flexibility is how you balance performance, cost and risk.

2. Catching sensitive information before it leaves

  • The need: this is arguably the most important layer. The risk of accidentally sending patient identifiers, trial subject data or confidential formulation details to an outside AI service is simply unacceptable.
  • What we did: every request is scanned before it leaves our system. If patient identifiers, trial subject data, proprietary formulation details or other sensitive information are found, the system acts — blocking the request entirely, removing the sensitive parts, or flagging it for a person to review, depending on how the customer has configured it. This is not optional. It is a fundamental safeguard.

3. A complete audit trail

  • The need: in pharma, if it is not documented, it did not happen. That applies doubly to AI. Regulators need to know exactly what was used, by whom, on what information, and what came back.
  • What we did: every interaction is recorded in full:
    • Who made the request
    • What information was sent, including anything that was removed first
    • Which AI model and version was used
    • What it was asked
    • What it returned
    • The time, and a unique reference

    This is not basic logging. It is a detailed, unalterable record designed for 21 CFR Part 11, giving a complete and defensible history of every AI-assisted decision.

4. Strict separation between customers

  • The need: in a shared platform, ensuring one customer’s information and AI activity is entirely separate from another’s is non-negotiable.
  • What we did: each customer’s information, configuration and AI activity is separated both logically and physically. Nothing can cross between them, which is what pharmaceutical regulation requires.

5. Answers grounded in your own documents

  • The need: AI is powerful and prone to inventing things — producing answers that sound plausible and are simply wrong. For regulatory use that is unacceptable. Answers must be grounded in verified documents.
  • What we did: before the AI answers anything, the platform first finds the relevant passages in the customer’s own documents. Those passages are supplied to the AI along with the question, so its answer is drawn from the customer’s own authoritative material and can be checked against it. This dramatically reduces invention and makes the output something you can rely on.

Beyond Technology, Into Governance

Making AI safe for pharmaceutical use is not just about the software. It is about the rules governing its use:

  • Controlling who can use what. Not everyone needs access to every AI capability. Administrators define who may use which features, on which document types, with which models.
  • Controlling which models are allowed. Customers decide which models are available, whether they are hosted externally or internally, and which kinds of documents may be sent outside their environment. This lets each organisation set its own risk appetite and enforce it consistently.
  • Explaining the answer. Especially for classification or risk assessment, it is not enough for AI to give an answer. The system shows why, pointing at the specific passages behind it. That is vital under regulatory scrutiny, and it is how people come to trust the output.

The Hard Decisions

Building something genuinely useful and genuinely compliant always involves difficult choices.

Hosting the AI yourself, or using the cloud

We knew from day one that one size would not fit all. Some global top-20 pharmaceutical companies have explicit rules that certain information — preclinical research, highly sensitive intellectual property — may never leave their own environment under any circumstances. For them, even a private cloud arrangement may not be enough. So while connecting to leading cloud AI services was essential for flexibility, we also invested heavily in supporting models a customer runs themselves. It makes our deployments more complex. It is also non-negotiable for genuine pharmaceutical compliance.

Speed against safety

Scanning every request for sensitive information is not free. On large documents it adds a measurable delay. There were internal arguments for making the scanning lighter, or optional for “less sensitive” work. We shut that down quickly. With pharmaceutical information there is no such thing as “less sensitive” where personal or proprietary data is concerned. The risk of a breach far outweighs a marginal gain in speed. We made the scanning as efficient as we could and accepted the small delay. Safety wins.

Newer is not always better

The AI landscape moves at breakneck speed, and new models constantly claim better scores. The temptation is to always chase the newest. But in a regulated environment, stability, consistency and predictable behaviour matter more than headline performance. We learned to favour models that behave consistently for a given task and are properly supported over the long term. We continuously evaluate newer ones, but cautiously, and we validate before we switch. A model that performs reliably for a specific regulatory task is usually preferable to a newer, more powerful one whose behaviour might change without warning.

The Road Ahead

Using AI properly in regulatory operations is just beginning. What we have built is a foundation that addresses the immediate needs: compliance, security and governance. It is about letting regulatory teams actually innovate with AI rather than only talk about it, by providing the safeguards that protect sensitive information and preserve regulatory integrity.

If you are wrestling with how to bring AI into your regulatory work safely, you are not alone. We have walked this path, built the answer, and learned the hard lessons. The future of regulatory operations is undeniably AI-assisted — but only if that AI is secure, auditable and compliant.

See How It Works

Curious how a controlled route for AI could change your regulatory operations while keeping you compliant? Let’s connect and show you how DnXT lets life sciences companies use AI securely and effectively.

Request a Demo Today

About DnXT Solutions

DnXT Solutions provides cloud-native eCTD publishing, review, and regulatory compliance tools for life sciences companies. With 340+ submissions published and 20+ customers, DnXT is the regulatory platform purpose-built for speed and accuracy.