The Bolt-On Problem

When a platform built in 2012 adds AI features in 2025, the AI has to work within assumptions that predate it. The way information is stored was never designed to record that AI did something. The audit trail was never built to tell a person’s action apart from a machine’s. And the whole system was designed for the pace of human clicking, not for software that asks a hundred questions a minute.

This is not a criticism of established platforms — they were well designed for their time. It is an observation that adding AI to an existing design is fundamentally different from designing for AI from the start.

The question for life sciences organisations is whether that difference matters enough to justify the risk of moving to a newer, less proven AI-native regulatory platform.

What “AI-Native” Means in Practice

The term is used loosely in marketing. Here is what we mean by it, with concrete examples:

Audit trails that cannot be skipped

In a bolt-on approach, developers add a line of code to record each action after it happens. In DnXT, the part of the platform that writes information creates the 21 CFR Part 11 audit record itself, every time something is created, changed or removed. Nobody chooses whether to record it. It is simply what happens when information is written.

Why this matters for AI: software might carry out hundreds of actions in a single session. If recording each one depends on somebody having remembered to add that line, gaps are statistically inevitable at that volume.

Separation built in, not applied by habit

A bolt-on approach keeps customers apart by remembering to add a filter to every request and checking permissions in each screen. DnXT enforces separation at four independent levels: establishing who is asking, carrying that identity through the request, holding each customer’s information in its own database, and checking permissions. Each works on its own, and each fails loudly rather than quietly guessing.

Why this matters for AI: software has none of the contextual awareness a person has. It will not notice that a result contains another customer’s information. Building separation into the foundations means the wrong information cannot come back, whatever is asked for.

Compliance limits that are absolute, not configurable

A bolt-on approach makes compliance gates configurable steps that can be skipped or overridden. DnXT makes them structural. In our design for how AI assistants connect, there is no way to sign a document — the capability simply does not exist for them.

Why this matters for AI: as these assistants become more capable, pressure to let them do more will grow. “Do not sign documents” as an instruction can be talked around by a determined user. A capability that does not exist cannot be.

The Counter-Arguments (We Take These Seriously)

An honest assessment means acknowledging why the AI-native argument might not matter:

Data advantages dwarf design advantages

Veeva holds submission data from hundreds of pharmaceutical companies spanning decades. That data — what gets approved, what gets rejected, what agencies care about — is enormously valuable for making informed recommendations. A newer platform with a better design but less data may produce worse results.

Good design is necessary but not sufficient. The best-designed platform with no regulatory data is less useful than a well-designed one with deep regulatory data.

Enterprise trust takes years to build

A top-20 pharmaceutical company evaluating regulatory technology will ask for customer references, validation documentation, SOC 2 reports and evidence of multi-year reliability. A newer company — including DnXT — has less of that evidence, however good the technology is.

This is a real limitation. When the consequence of failure is a delayed approval, enterprise buyers are rationally conservative.

“AI-native” is partly marketing

Every platform built after 2023 calls itself AI-native. The term has become a signal rather than a specification. Sophisticated buyers should look past the label and ask concrete questions: how is the audit trail actually created? How is customer separation actually enforced? What can AI do here, and what can it not do?

Bolt-on AI can be good enough

If a company already uses Veeva RIM and adds Veeva’s AI features, the result may be perfectly good for their needs. The AI helps with drafting, regulatory intelligence and timeline prediction. That the audit trail was retrofitted rather than built in may not matter if the company’s quality team has validated the implementation.

A perfect design that requires migrating everything is often worse than a good-enough one that works with what you already have.

Where DnXT Sits

DnXT was built in the 2020s assuming AI would be part of the picture. Our audit trails, customer separation and compliance limits were designed for a world where AI participates in regulatory work. We have a substantial set of AI capabilities in production and a validated compliance foundation.

We also have a small team, a limited number of enterprise references, and the customer-facing AI connection still in design rather than production. We are earlier in the trust-building journey than our competitors, and we would rather say so.

The AI-native regulatory platform argument is strongest for organisations starting fresh — new biotechs, new regulatory teams, or companies frustrated enough with their current tools to accept the risk of moving. For organisations deeply invested in an existing platform, the bolt-on route may well be the pragmatic choice.

The question is not whether building for AI from the start is technically better — we believe it is. The question is whether that advantage outweighs the switching cost, the data you leave behind, and the trust a newer vendor has not yet earned. For some organisations it will. For others it will not. Both are rational decisions.

This article was written by the DnXT Solutions team. We’ve tried to present both the case for our approach and the genuine counter-arguments. If you think we’ve overstated our position or understated the competition’s strengths, we welcome that conversation at se******@***********ns.com.