Compliance risk gets blamed for pretty much everything that stalls in regulated learning and development—every time. But the data tells a different story – honestly, a more interesting one. This blog is an excerpt from a webinar hosted by LTEN and presented by Arun Prakash, EVP of Life Sciences at Infopro Learning, built around a real case that took one pharma company from 300 pilot users to over 100,000 governed users across ten-plus languages. Zero compliance compromises the whole way through. Here’s what actually separated that outcome from the pilots that never make it out of the sandbox.
Why “Compliance Risk” Might Not Be Your Real Blocker
During the session, attendees were asked to vote on the major barrier to expanding the use of AI in their own organization. Skills/capabilities and compliance/regs were tied at 31% each. Follows the overall industry trend. Here’s where it gets interesting: unregulated firms also get stuck in their tracks at almost the same rate.
MIT’s study found that 95% of enterprise GAI pilots have no financial P&L impact. McKinsey revealed that two-thirds of companies remain in the pilot or experimental phase, while only 39% achieve any enterprise-level financial impact. The probability of failure remains constant regardless of any GxP obligations in place. The issue here is not about compliance being complicated – it definitely is. The real question is whether it is compliance itself that hinders your progress, or something else taking its name.
Statistics of the 2025 Pistoia Alliance show that the issue is even more pronounced. Only 9% of life science companies reported that regulations hindered their AI adoption, down from 23% a year ago. Perception is leading risk by a factor of 5, and this gap keeps widening rather than narrowing. What we refer to as a compliance wall is nothing but fog, unread regulations, a scary story heard somewhere, and a lack of clear lanes, which turn any use case into a “no” by default due to habit rather than reason.
The Trails Are Already Being Carved, Whether You’ve Approved Them or Not
The session opened with a story from 1914. An Ohio State professor waited until winter, then went up in a hot-air balloon and photographed the trails students had already worn into the snow rather than using the paved sidewalks. The university then paved those exact paths, as simple as that.
The parallel is clear, and the point is compelling. Your workforce is doing the same thing right now with AI tools, whether IT signed off or not. 78% of employees admit to using AI tools their organization never sanctioned. In a GxP environment, that’s not some hypothetical risk lying out on the horizon.
That’s ungoverned, uncontrolled use of tools happening today inside systems built specifically for FDA and Annex 11 obligations. There’s no AI adoption decision left to make at this point. Your people already made it for you. The only question is whether it falls within the scope of coverage.
The Five Boundaries That Actually Matter (The List Is Shorter Than People Expect)
The specific regulatory boundaries that still apply once AI enters the picture are a short list. Data integrity under ALCOA Plus (attributable, legible, original, accurate) still applies to AI system records exactly like it always has. Change control and Standard Operating Procedures (SOPs), Part 11 and Annex 11 audit trail requirements around who prompted what and who approved it, when, still govern the process the same as before. There’s a distinction worth drawing in validation, too.
CSV/CSA considerations cover an AI running within a GxP process. An AI can prepare a document; however, change control will retain responsibility for the process, and the approval point remains in its traditional place. Any item related to claims or involving patients requires MLR review.
None of this is new regulation invented specifically for AI. It’s the same framework life sciences has run for years, just applied to a newer tool. The fog was never really the regulations themselves. It was not knowing which ones actually applied to a given use case, which is a completely different problem than the one most people think they’re solving.
How the Actual Case Study Scaled From 300 to 100,000-Plus Users
Scaling up did not happen all at once, and essentially, that’s the whole story. The year 2024 saw a pilot with 300 users, who were granted access to a sandboxed environment with basic Microsoft Copilot functionality and no autonomous agents. Usage was organic and observed, so scaling was done based on evidence, not assumptions. The pilot ran for close to a year, and all approvals from the IT department, CISO, and compliance team were in place in advance to support any future scaling.
Then in 2025, the pilot moved to 8,000 users. Mandatory training based directly on lessons learned by those first 300 users organically through usage, essentially following in their footsteps, was required as a precondition to gaining access to Copilot. Governance measures were formalized as prompt guides and standard operating procedures, and the agents’ capabilities were rolled out in gated stages rather than through a single big-bang launch.
By early 2026, the program had scaled to 130,000+ users. Named accounts, role-based tracks tailored specifically for each department’s use cases and regulations, champions and power users at the department level, localization into 10+ languages. It took them two years, but with one consistent, evidence-driven expansion, they never broke compliance to reach a number.
What Compliant AI Actually Looks Like Day to Day
There are four checkpoints in the operational workflow that recur at each stage, regardless of the scale of the activity. The first is a data checkpoint. Nothing in the record, trial data, or validated system escapes the controlled environment, so the tool works within the existing control framework and does not introduce a new risk point.
The second involves SOP rules that clearly specify whether AI may draft in the space, and this is stated explicitly in the SOP documents, which gives a clear indication of where the answer lies.
Third is the audit trail, which shows who initiated it, when, and who approved it; in short, Part 11 logic applied to the AI process’s output. Fourth is the final sign-off that maintains human accountability for regulated outputs. Again, it uses the same power of document control that the life sciences had developed over the years.
No need to build a compliance infrastructure from scratch; the AI fits into the workflows of the life sciences industry.
Why Governance Should Work in Three Lanes, Not One Gate
Instead of a one-size-fits-all compliance checkpoint, governance passes through three distinct lanes. Green lane includes pre-approved use cases, internal enablement drafts, onboarding content, quiz banks, non-GxP content, where L&D operates without waiting in line. Amber lane includes initial drafts of GxP process training, SOP summaries, and similar content, and requires guardrails plus SME QA approval. Red lane is the stop lane: system procedure validation, claims, patient-facing content, compliance review required, and humans are accountable for everything before it can move forward.
According to a 2026 Grant Thornton survey, 78% of executives failed to complete an independent AI governance review within 90 days, suggesting that most organizations hold views on governance but lack a framework for lanes. The benefits of establishing governance lanes are tangible and real. Organizations that are fully integrated with AI are four times more likely to generate revenue from their AI technology than those who still work on it, 58% compared to 15%. The governance approach described here does not act as a brake on the process. Instead, it becomes a mechanism that focuses review effort on high-risk items only.

Are You Ready to Scale AI in a Regulated Environment?
AI readiness requires three conditions, and all three must be fulfilled, not just two. Firstly, named boundaries imply that there is documentation of the actual constraints, and they can be linked to a termed regulation rather than just assumed. Secondly, defined tiers, not checkpoints, where the green, amber, and red categorization of each tier is documented, and the legal design tiers are only used once for every use case. Finally, the readiness condition requires capability at scale, where training ensures compliance, local leaders reinforce it consistently, and content is updated as policies change.
Where was the live audience when it was asked about its readiness regarding the three conditions? Zero respondents satisfied all three. In other words, none did. About a third of the respondents had two conditions ready, while another fraction had only one, which in almost all cases was named boundaries and no lines yet drawn. There is definitely a gap between where the organizations are and where they need to be. However, this gap is not just a gap, but it is very specific and can be closed.
The three steps that the organization needs to take are quite straightforward. First, name the boundaries by writing down the regulations that apply to the organization. Then draw the lines, define the green, amber, and red lanes, and publish them for everyone to see. Lastly, reinforce the compliance behavior and ensure it becomes a habit rather than just a PDF in the drive. The blog discusses the framework, but the full webinar covers the case study and governance process in more depth. Watch the webinar replay: From Pilot to Program, Making AI Work for Regulated L&D.
Frequently Asked Questions (FAQs)
-
remove How can organizations tell if a compliance issue is actually a skills problem?Organizations can review performance data, assessment results, learner behavior, and recurring errors to identify whether employees lack the required knowledge or practical skills rather than simply treating the issue as a compliance gap.
-
add Why is skills development important for compliance training in life sciences?Effective skills development helps employees apply regulatory requirements in real-world situations. Practical learning can improve decision-making, reduce process errors, and strengthen compliance beyond basic policy awareness.
-
add How can L&D teams address skills gaps while maintaining compliance?L&D teams can combine compliance training with role-based learning, scenario-based practice, assessments, and ongoing reinforcement. This approach helps employees build the skills to apply compliance requirements consistently in their roles.
