FDA is using AI to inspect quality systems. Sampling is no longer the limit.

On June 2, 2025, the Food and Drug Administration (FDA) launched Elsa, a generative artificial intelligence (AI) tool built for its own staff. Eleven months later, on May 6, 2026, FDA upgraded the tool to Elsa 4.0 and connected it to a new internal data platform called HALO, which consolidated more than 40 separate application and submission data sources into one place.
Chief AI Officer Jeremy Walsh described the shift in one sentence: Elsa sits on top of our data. The same release listed the new feature set, which includes two very important items for medical device companies: Elsa 4.0 can convert scanned documents and images into searchable text, and its optimized search to find key information inside large document repositories.
When read together, those two items point toward a potentially significant shift in how FDA inspects medical device manufacturers. Because the constraint that shaped medical device inspection for 25 years was never a rule. It was arithmetic. And FDA just solved the arithmetic on its side of the table.
BONUS RESOURCE: Click here to download your free Cybersecurity Gap Assessment Checklist!
What is Elsa? And what does FDA use it for?
Elsa is an internal, large language model-based assistant available to FDA staff, from scientific reviewers to field investigators. It runs inside a FedRAMP High secure cloud environment. FDA has stated that the models do not train on input data or on data submitted by regulated industry, and that human subject matter experts verify inputs, analytic processes, and output implementation at every stage.
Keep that last point in mind. Elsa does not issue a Form 483. Investigators do. No regulation changed, no inspection authority expanded, and no new recordkeeping requirement appeared. What changed is how much of a quality management system (QMS) a single investigator can realistically examine with the time they have.
FDA has also been explicit that AI cuts both ways on inspection burden. On the same day it announced Elsa 4.0, the agency launched a pilot for one-day inspectional assessments, using risk-based criteria and AI-assisted analysis to identify lower-risk facilities suitable for a shorter visit. Roughly 46 assessments had been completed by late April 2026, most closing as No Action Indicated.
There’s still a minimum number of records FDA will look at, but no longer a maximum
Since Feb. 2, 2026, every FDA device inspection has been conducted under Compliance Program 7382.850, Inspection of Medical Device Manufacturers, which organizes QMSR requirements into six QMS areas and four other applicable FDA requirements. The program tells investigators how to scope an inspection, and the instruction it gives is a minimum rather than a target.
Under Inspection Model 1, which covers routine surveillance of a previously inspected site along with compliance follow-up, for-cause, and premarket approval postmarket inspections, the investigator selects at least one element from each QMS area and evaluates the related requirements. Model 2, used for baseline surveillance at sites with no inspection history and for premarket approval preapproval inspections, names a much longer list of specific elements to be evaluated at minimum. Both models carry the same footnote. If the inspection reveals objectionable conditions, or if the minimum requirements do not allow an adequate assessment, the investigator should consider selecting additional elements.
Record selection follows the same logic. The compliance program directs investigators to choose records based on identified product risks and their own experience and professional knowledge, and says that in most cases multiple records should be reviewed to give the investigator assurance that requirements are met. No upper bound appears anywhere.
So the written instruction is a floor with a standing invitation to go further. What has actually bounded device inspections is the investigator's calendar.
Isolated findings become systemic findings
When an investigator reviews 20 complaint files and finds two where the decision not to open a corrective action was thinly justified, those two are observations. Explainable ones, often. A quality engineer can walk through the rationale, point to the risk assessment, and the conversation moves on.
Run the same question across every complaint file from the past three years and the output changes category entirely. Patterns appear that no selection of records could have shown: complaints from one product family consistently closed without investigation, a six-month window where justification language was copied forward verbatim, training records that postdate the procedure revisions they supposedly cover. None of those findings is about an individual record. Each is evidence that a process does not operate the way its procedure says it does.
The compliance program already points investigators in that direction. It states that because QMS processes are integrated, evaluating one requirement during an inspection may make it necessary to evaluate requirements in other areas of the system. Following those connections by hand is slow. Following them across a full record set is the kind of work a model does well, and what FDA investigators look for under QMSR has always included exactly that sort of internal consistency.
Records requests are where you’ll see the difference
A reasonable objection at this point is that none of it matters unless FDA has the documents, and FDA only has what it sees on site.
That objection is several years out of date, and the compliance program says so directly. Section 704(a)(4) of the Federal Food, Drug, and Cosmetic Act gives FDA authority to request records in advance of or in lieu of an inspection. The Food and Drug Omnibus Reform Act of 2022 extended that authority to device establishments, where it had previously covered only drug establishments. CP 7382.850 carries a dedicated attachment on remote regulatory assessments and statutorily authorized records requests, and it lists follow-up to a remote regulatory assessment as a trigger for a for-cause inspection.
In June 2025, FDA finalized its guidance on conducting remote regulatory assessments, formalizing remote records reviews and remote interactive evaluations as standing tools rather than pandemic workarounds. The guidance sets out that FDA generally expects requested records and information to be submitted electronically, and that the agency may review electronic systems and source records through livestream, video, or screen sharing. Refusing to participate in a mandatory remote regulatory assessment is a violation of the act.
Put the pieces in sequence. FDA can request a defined body of records remotely, expects to receive it electronically, can run optical character recognition (OCR) across anything scanned, and can search the result at depth. The site visit does not need to be long for the review to be thorough.
There’s an asymmetry built into inspections now
Most device manufacturers still audit themselves the way FDA has historically audited them. Internal audit programs pull samples and management review looks at summary metrics. Pre-inspection readiness work focuses on the areas and record types an investigator is most likely to ask for, which is both a sensible way to spend limited time and an increasingly poor description of what is about to be read.
The gap is no longer between a company's quality system and the regulation. The gap is between what a company knows about its own quality system and what a regulator can now find out in an afternoon.
Closing it doesn’t require predicting which records FDA will pull, which was always a losing game. It requires being able to ask questions across a complete record set rather than a selection, and that capability depends almost entirely on where the records live. Full-coverage review is straightforward against structured, connected, electronically signed records with real traceability between design inputs, risk controls, verification evidence, and post-market data. Against PDFs in folders, approval threads in email, and a training matrix maintained in a spreadsheet, it’s not possible at any price.
BONUS RESOURCE: Click here to download your free Cybersecurity Gap Assessment Checklist!
Greenlight Guru shows you what full-coverage review finds, before FDA does
Full-coverage readiness on the manufacturer's side rests on three things: a real count of every record population, links between records a system can follow without manual reconstruction, and an honest test of how long producing a complete set under 21 CFR Part 11 actually takes. Most teams have not run that last test, and the surprise is better absorbed in a conference room than in a records request with a clock attached.
Get your free demo to see how Greenlight Guru keeps those three things true by default, or start with our blog on FDA inspections under QMSR if you want the detail first.
Etienne Nichols is the Head of Industry Insights & Education at Greenlight Guru. As a Mechanical Engineer and Medical Device Guru, he specializes in simplifying complex ideas, teaching system integration, and connecting industry leaders. While hosting the Global Medical Device Podcast, Etienne has led over 200...
Related Posts
FDA inspections under QMSR: a guide to Compliance Program 7382.850
Ultimate Guide to Software as a Medical Device (SaMD)
The Risk Management + Design Controls Connection: What Device Makers Need to Know
Get your free download
Cybersecurity gap assessment checklist
.png?width=250&height=321&name=Quality%20Lead%20Magnet%20Slide-in%20(5).png)



