The most cautious regulator in the country put AI agents inside its own review process. If you’ve been telling your board that agentic AI is “too risky for a regulated environment,” that argument just expired.
Last December the FDA gave its staff agentic AI — not a chatbot, but systems that plan and execute multi-step work across pre-market reviews, post-market surveillance, inspections, and compliance. The agency that decides whether your drug ships now runs agents on the reviews themselves.
Most people read that as “even the FDA is doing it.” That’s the wrong takeaway. The lesson isn’t that they did it. It’s how.
Look at the choices. The agents run in a locked-down GovCloud environment. The models don’t train on staff inputs or on anything industry submits. Human oversight is built into the workflows. Use is optional, not mandated. And the work is scoped to specific, bounded tasks — not “go run the agency.”
None of that is about the model. All of it is architecture. The FDA didn’t ask whether the AI was smart enough. It decided where the data lived, what the agents could touch, who stayed in the loop, what stayed optional, and how narrow the job was. Then it turned the thing on.
That’s the whole playbook for regulated work, and the most conservative shop in the industry just published it for free.
So the real question on your next agentic project isn’t “is the model good enough.” It’s “have we made the same five decisions the FDA made before they trusted it.” If you can’t answer those, the model was never the problem.