FDA's first AI-misuse warning letter wasn’t so much about AI
A "borderline" company, Purolea Cosmetics Lab, recently received an FDA warning letter, and it went viral as the first ever to explicitly cite AI misuse in quality operations. This is Part 3 of a three-post series arguing that AI regulation is currently amplifying disparities rather than levelling the playing field. So the obvious question: does this case counter that argument? Or are regulators — FDA specifically — paying closer attention to AI than the first two parts of this series gave them credit for?
What actually happened
On April 2, 2026, FDA issued a warning letter to Purolea Cosmetics Lab, a small homeopathic drug manufacturer in Livonia, Michigan, following a three-day inspection at the end of October 2025. The letter included a dedicated section — "Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing" — with no precedent in FDA enforcement history. The company had used AI agents to generate drug product specifications, manufacturing procedures, and master production records, and then distributed product without independently verifying that output. When investigators found that required process validation had never been performed, the company's explanation was, in effect, that the AI agent never told them it was required.
The coverage split, and why one side of it missed the point
Coverage of this letter has split into two readings. The mainstream take treats it as a clear signal that regulators are now actively scrutinising how companies implement AI in compliance work, offering a blueprint of what's expected going forward: qualified human review, documented control, validation, traceability.
I don't find that genuinely new for QARA. Those requirements have always been there. The sharpest take I read on this came from Etienne Nichols, who stripped the AI framing away entirely: read without it, the FDA's findings look like any inspector's worst-day list — insects and filth in the manufacturing area, unapproved homeopathic drugs labelled to treat shingles and genital herpes, no microbiological testing of finished product, no identity or purity testing of incoming components, no process validation before distribution, and a quality unit that hadn't established procedures, hadn't reviewed batch records, and hadn't implemented production controls. Those are the real problems. Everything in the letter about AI sits downstream of them.
Independent regulatory commentary backs this reading. One FDA regulatory attorney described the action as "a traditional cGMP enforcement action where AI is heavily involved" rather than a new AI-specific regulatory framework — the agency applying an existing rule, 21 CFR 211.22(c), to a new failure mode, not writing a new rule for AI itself.
Three broader reminders, not one new rule
Stripped of the AI headline, this letter leaves three reminders that apply well beyond Purolea:
Quality culture is queen. Without genuine commitment from the top, everything downstream unravels — the AI use here wasn't the root cause, it was a symptom of a quality unit that had already stopped functioning.
Claims and classification matter. Dear Purolea (not-so-)Cosmetics: labelling homeopathic products to treat shingles and genital herpes is a classification and claims failure that exists entirely independently of how the paperwork got written.
AI should augment quality capability, not replace competence and judgement. The moment AI output substitutes for a qualified reviewer's sign-off rather than feeding into one, you've removed the control that actually matters.
So, does this counter the series' argument?
I don't believe it does. This example doesn't prove heightened regulatory attention or enforcement specifically targeting AI. It shows that AI is increasingly embedded in quality operations and, as such, has to withstand the same requirements that have always applied — nothing about 21 CFR 211.22(c) changed to accommodate it. Its outcomes are shaped by quality culture, good or bad, exactly like every other input into a QMS. A well-run quality unit using AI-assisted drafting would have caught the same gaps; a poorly-run one would have produced the same failures with or without AI in the loop.
Put together with Parts 1 and 2 of this series, the picture holds: AI-driven disparities are real and current. General-purpose LLMs get a lighter regulatory touch than purpose-built health tools by virtue of intended-use framing. Companies that delayed AI Act compliance may get a durable grandfather-clause pass while early compliers carry the cost. And a single enforcement action against a company with no functioning quality unit to begin with doesn't represent regulators suddenly levelling that playing field — it represents them doing exactly what they've always done, to a company that would have failed inspection with or without an AI angle to make it newsworthy.
Regulation is not yet doing the levelling work this space needs. If you're navigating that gap, we can help you find a path through it.
Series navigation
Part 1: LLMs' health advice gets separate treatment
Part 2: AI Act’s postponement benefits the compliance laggards
References
FDA, Warning Letter to Purolea Cosmetics Lab (722591), 2 April 2026
Etienne Nichols, Greenlight Guru, What the Purolea warning letter really means for AI in medtech, April 2026
BioSpace, FDA's first AI-focused cGMP warning letter signals new scrutiny for manufacturers, July 2026 — including commentary from FDA regulatory attorney James Boiani
RAPS, FDA warns firm for inappropriate use of AI in drug manufacturing, April 2026
Methodology note: This article is based on Part 3 of my original three-post LinkedIn series (link), reflecting my professional experience and perspectives on the Purolea Cosmetics Lab FDA warning letter and its implications for AI in quality operations. AI assisted in elaborating the topic into a broader article by integrating background research, fact-checking of the warning letter's specific findings, and additional regulatory commentary. All analysis and regulatory perspectives are my own, and all content has been reviewed by me for accuracy.