L7 | CHATS

thought leadership

AI Governance Starts Before Agents Can Act

by Vasu Rangadass, Ph.D. | posted on July 22, 2026

I recently came across a thoughtful post outlining three developments the author believes pharma will see by the end of this year: a top-10 pharmaceutical company pausing an agentic AI deployment, regulators moving from guidance toward formal requirements, and vendors racing to position themselves as the governance layer for AI. What made the post compelling was the author’s framing: these were continuations of trends already underway rather than bold predictions. One line in particular stayed with me: “Buying an AI platform gives you AI capability. It doesn’t give you AI governance.”

I agree with that observation. But what interested me more was what those three developments have in common. Each points to the same underlying problem, and that single line about capability and governance explains much of what the industry is about to experience.

In my view, pharma has sequenced its AI journey backward. Capability was purchased first. The operational foundation on which governance depends was assumed, deferred, or left to someone else. The consequences of that sequencing error are now beginning to surface, and the reason has little to do with the pace of the technology. AI is exposing weaknesses that have existed in operational environments for years.

 

The sequencing error

Consider how agentic AI is actually entering pharmaceutical organizations today. A pilot begins in a sandbox, where it answers to nobody. It performs well, enthusiasm builds, and the pilot gradually moves into regulated territory: deviation handling, batch documentation, quality investigations, or decisions that ultimately support regulatory submissions. The moment that transition happens, the conversation changes. And unlike previous software waves, these agents rarely stay inside a single application, a problem I will come back to.

In conversations with pharma leaders, I keep encountering the same realization at exactly this point. The questions an inspector will ask about an AI-assisted decision have almost nothing to do with model performance. Where did the source data come from? Which version of which model produced this output? What context was available when the decision was made? Who approved the change that placed this agent into the workflow? Who owns the outcome?

Every one of those questions concerns evidence, accountability, and control. The artificial intelligence is almost incidental. When those answers live in screenshots, exported spreadsheets, disconnected audit logs, and tribal knowledge, the deployment is one audit away from a pause. The model may have worked exactly as intended. The evidence surrounding its use did not.

None of this should surprise anyone who has watched previous technology waves move through this industry. We saw the same pattern when electronic records replaced paper. The technology was never the difficult part. Demonstrating control over the technology was. Agentic AI simply raises the stakes because it increases both the speed and complexity of operational decision-making, making provenance, traceability, and accountability even more important than before.

Regulators have already signaled where this is heading. The FDA’s draft guidance on the use of AI to support regulatory decision-making for drugs and biologics is built around a risk-based credibility assessment framework. Sponsors are expected to establish the credibility of an AI model within its intended context of use and support that credibility with evidence. The agency has also disclosed that submissions containing AI components already number in the hundreds and continue to increase. Notice here what the FDA chose to emphasize: credibility, provenance, and accountability. Whether formal requirements arrive this year or next is almost beside the point. The direction is already clear. The evidence burden is moving upstream, and it will no longer be sufficient to assemble a credibility story after the fact. Increasingly, that story will need to emerge naturally from the way work is executed.

 

Multiple governance layers don’t solve the problem

The vendor landscape has read these same signals, and its response is creating the next challenge. Many enterprise software vendors are now positioning their systems as the governance layer for AI. From each vendor’s perspective, the positioning is understandable. Every solution naturally seeks to extend governance over the workflows it manages.

The difficulty is that no large pharmaceutical company operates inside a single system. A typical organization already relies on multiple systems spanning research, development, manufacturing, quality, and regulatory operations. Those systems were never designed to function as one operational environment, yet AI agents increasingly need to move across them. If each solution introduces its own governance model, organizations inherit multiple model inventories, multiple audit trail formats, multiple definitions of validation, and multiple answers to a fundamental question: who owns an AI-generated outcome when a workflow crosses system boundaries?

And it’s a fact that workflows in pharma always cross system boundaries. A technology transfer touches development data, manufacturing execution, quality systems, and regulatory documentation. An AI agent participating in that process cannot be governed by any single vendor’s layer because no single layer has visibility into the complete operational context.

This is why I struggle with the phrase governance layer. A layer sits on top of something. Governance that sits on top of fragmented systems can only observe fragments. Real governance behaves as a property of the operational fabric itself. Lineage, context, traceability, and accountability either exist where work is executed, or they must be reconstructed later by people working under deadline pressure. The life sciences industry has decades of experience with how that second approach performs during an inspection.

 

Foundation before agents

That thinking shaped the architectural decisions we made at L7 Informatics long before agentic AI became the industry’s dominant conversation. We built L7|ESP® as a unified operational backbone first: a platform where scientific data, processes, instruments, applications, and people connect through a shared ontology, a common model of the entities and relationships that scientific work touches, with lineage and traceability captured as work is executed rather than reconstructed afterward. Only then did we introduce L7|SYNAPSE™, bringing agentic AI into workflows where context, provenance, and execution history already exist.

The sequencing matters more than any individual AI capability. When an agent operates inside an environment where context, lineage, version history, and human oversight are already native characteristics of execution, governance becomes an outcome of the architecture rather than a separate initiative. That is the difference between infrastructure that is merely AI-ready and infrastructure that is AI-actionable, where governed execution comes native to the environment. Organizations trying to bolt governance onto AI operating across disconnected systems face a fundamentally different challenge because the gaps they are trying to govern exist precisely where no single platform has complete visibility.

 

The better question

Most conversations I hear in pharma begin with some version of the same question: “How do we govern AI?” But I would encourage leaders to ask a different one instead: “Why are we asking AI to operate on a foundation that was never built for it?” Answer that honestly, and many of the downstream governance questions become easier to solve.

The organizations that emerge strongest over the next several years will be the ones that can explain, trace, validate, and defend every significant decision their AI systems help make, because they built governance into the way they operate from the beginning instead of treating it as a layer to be added later.

Buying AI capability is relatively easy. Building an operational environment in which that capability can be trusted, governed, and defended is considerably harder. The companies that recognize the difference will spend the coming years compounding that advantage while others are still trying to reconstruct the evidence their AI should have generated all along.

ABOUT THE AUTHOR

Vasu Rangadass, Ph.D., President & CEO

Vasu Rangadass, Ph.D., is the President and CEO at L7 Informatics, Inc., a leader in life sciences workflow and data management. Previously, Dr. Rangadass was the Chief Strategy Officer at NantHealth, following its acquisition of Net.Orange, the company he founded, to provide an enterprise-wide platform to simplify and optimize care delivery processes in health systems. Before Net.Orange, Vasu was the first employee of i2 Technologies (currently Blue Yonder), which later grew to be a global company that revolutionized the supply chain market through innovative approaches based on the principles of Six-Sigma, operations research, and process optimization.