News|Videos|October 6, 2026

PharmTech AI Pulse Check: On-Prem vs. Cloud AI

Shadow AI and vendor data retention put GMP records and trade secrets at risk. AI Pulse Check panelists outline what pharma AI policies require.

When OpenAI has to publicly clarify that a user's Codex prompts could not have influenced its system, while admitting that de-identified usage data can still shape models generally, and Anthropic launches a life sciences verification program in the same news cycle, the gap between we don't train on your data and we don't keep your data becomes a quality problem for pharma, PharmTech AI Pulse Check panelists argue.

Gourav Pandey, R&D quality lead at Takeda, says the industry is arguing over the wrong verb. Rather than debating whether vendors train on or retain company data, he argues, quality teams should be asking where the data lives, who can see it, how long it is held, and what happens to model weights once training is done. Patient data brings its own layer of guidance, he adds, and regulations such as the EU Data Act explicitly address controlling data flows. Pandey also flags a quieter risk: when industry data feeds models that are later tested against industry benchmarks, the model has effectively already seen the test. His prescription is for companies to write AI usage policies durable enough to survive vendors changing their terms next quarter, backed by contracts rigid enough to prevent retention of technical information.

Florin Muraru, an independent regulatory advisor specializing in EU and US regulatory strategy and AI governance, points to a report from last year finding that 77% of employees paste data into AI tools, most of them through personal accounts outside company control. He separates two risks. A batch record is a GMP record, and moving it outside controlled systems can break record control and data integrity. Formulation data is different, Muraru explains, because it is a trade secret, and the EU Trade Secrets Directive protects information only when a company takes reasonable steps to keep it secret. An employee pasting it into a personal account can undo that protection. "The minimum policy is short," he says: classify what may leave the company, allow only enterprise accounts with zero data retention written into the contract, and block personal accounts at the network level. Fully on-premises deployment is realistic only for the largest manufacturers, he argues; for midsized companies, the practical path is running models in their own instance on a major cloud provider with retention contractually switched off.

Richard Jaenisch, senior director of education, outreach, and digital experience at Open Biopharma, calls shadow AI a serious challenge but reads Anthropic's program differently. In his view, it addresses a censorship problem more than a trust problem: chemistry and biology work routinely touches hazardous combinations, and verification lets a provider identify who is legitimately doing that work. He is skeptical of zero data retention promises generally, citing OpenAI's policy shifts after The New York Times lawsuit and its decision to train on consumer subscription data while exempting team and enterprise tiers. Jaenisch expects federated and on-premises models to become the norm in pharma, noting that large manufacturers such as Lilly are already partnering with NVIDIA, OpenAI, and others to keep data in-house. "They don't trust them that much, and so they're clearly saying, 'You do it in our house, and maybe we have more control over it.'" He adds that if verified, sanctioned tools let scientists do more at work, the incentive to use shadow AI declines.

For quality and manufacturing leaders, the discussion reinforces a point made by Andrea Kerrigan, MSV, Branch Chief, OGAD, CVM, FDA: data integrity is one of three foundational elements determining whether digital tools deliver on their promise. The next phase of AI governance hinges on data classification, contract terms, and sanctioned tools good enough that employees have no reason to go around them.


Related to this article

PharmTech Weekly Roundup—October 2, 2026
This week on PharmTech, Merck diversified its pipeline, USP emphasizes supply chain security, AI systems are examined, and speakers preview their presentations at CPHI Milan and AAPS PharmSci 360.
CPHI Milan 2026: Nitrosamine Risk Mitigation, Part 1
Capsugel's Bram Baert and Sandrine Picco argue that chasing zero nitrite in pharmaceutical excipients is often impractical and costly. They recommend setting scientifically justified, risk-based limits and consistently staying below them.