Written for your quality unit, not for your marketing team
An AI agent inside a GxP process is a validated computerised system with a model in it. This page covers how that is governed, what is in place, and — the part most pages leave out — what is not.
What the agent is allowed to do
The six questions that come up in every quality review, answered without hedging. A hedge here means the review stalls.
Is our case data used to train models?
No. Case data is processed to produce your cases and nothing else. It is not used to train or fine-tune models, not pooled across clients, and not shared with a model provider for improvement. Zero-retention terms are required of any model provider in the processing path, and this sits in the agreement rather than only in a policy.
Does the agent make the reportability decision?
It produces the assessment and the evidence for it. Your accountable person makes the decision, and the system is built so that cannot be bypassed. Fatal and life-threatening cases, and anything on your configured escalation list, route to a human every time regardless of how clear the agent finds them.
How do you handle hallucination in the narrative?
Narrative drafting is where a language model most wants to smooth a gap into a plausible sentence, and a tidy narrative built on an inference is a finding waiting to happen. Every clause must be supported by a source span; unsupported content is not emitted, and gaps are left visible and flagged rather than filled.
Can an inspector see what the system did?
Yes. Every case retains the source documents, the model version, the prompt and configuration in force, every extracted field with its source span, every assessment with its reasoning, and the reviewing human's disposition — as a contemporaneous, attributable, tamper-evident record.
How is performance measured?
Against your reviewers' dispositions on your own cases, per case type and per product, rather than on a public benchmark. We publish no accuracy figure today because we have not earned one, and an unqualified number would be worthless to your quality team anyway.
What happens when the model changes?
A model or prompt change is a change to a validated system and is handled as one: impact assessment, regression against a held-out case set, documented approval, and a version recorded against every case processed under it. Silent model updates are incompatible with this setting and are not how the system is operated.
Commitments in the agreement, not aspirations on a website
01
Every field traces to a source span
A coded term, a seriousness call, a narrative sentence — each one links to the exact text in the source document that produced it. In a GxP setting an output nobody can trace is an output nobody can use, and an inspector will ask.
02
Ambiguity escalates, it does not resolve itself
The product's value is that only genuinely ambiguous cases reach a safety physician. That only holds if the agent is honest about which ones those are. Confidence is a routing decision, never a substitute for one.
03
The agent never decides seriousness alone on a fatal case
Death, life-threatening events and anything on your configured escalation list route to a human every time, regardless of how clear the agent finds them. Some decisions should not be automated even when they can be.
04
Nothing is asserted that the source does not support
Narrative drafting is where a language model is most tempted to smooth a gap into a plausible sentence. Thallyx leaves the gap visible and flags it, because a tidy narrative built on an inference is a regulatory finding waiting to happen.
A validated system, operated like one
Computerised system validation
The system is being built to be validated under a GAMP 5 risk-based approach — requirements traced to specifications, specifications traced to test evidence, and change control over the lot. Your validation package is a deliverable of the engagement, not an afterthought.
21 CFR Part 11 and Annex 11
Attributable, legible, contemporaneous, original and accurate records; unique user identification; secure, computer-generated, time-stamped audit trails that do not obscure prior entries; and electronic signature controls where signatures are applied.
Data integrity
ALCOA+ as the working standard. Source documents retained unaltered, every derived field linked to its origin, and no ability to edit a record without the change being recorded and attributable.
Inspection support
We expect to be in the room. Documentation, system demonstrations and personnel are made available for your regulatory inspections and client audits as a term of the agreement.
Case data is health data about identifiable people
Adverse-event reports are special category data under the GDPR and protected health information under HIPAA where a US covered entity is involved. Pharmacovigilance has a lawful basis, but that basis does not extend to anything beyond processing the case.
You are the controller
The marketing authorisation holder is the controller of its safety data. Thallyx processes on documented instructions under a data processing agreement, for the purpose of case processing and nothing else.
Minimum necessary, retained per your schedule
We hold what the case requires, for the period your retention schedule specifies — and PV retention periods are long, so that is a contractual term rather than a default.
Transfers and residency
Where data crosses a border we rely on Standard Contractual Clauses, the UK IDTA, or an applicable adequacy decision. Regional processing is agreed in the order form rather than assumed here.
Send us your vendor assessment
Including the awkward questions. We will answer them in writing, and tell you plainly where the answer is 'not yet'.