Trading expensive remediation cycles for continuous, reconstructible governance that accelerates time-to-market.
An untitled letter from the U.S. Food and Drug Administration (FDA) can cost up to $750,000 to answer. Caught in design, the same defect is resolved for under $10,000. That spread is the entire economics of compliance in life sciences AI, and most organizations are sitting on the wrong side of it. For Tarini Mohapatra, Chief Executive Officer and Co-Founder of TFives, the cause is not the technology: “It is how we approach compliance.”
Why Remediation Costs What It Does
Teams still treat regulatory review as an afterthought before release. Engineers build a tool, get it working, then hand it to quality to check against healthcare standards. By then the software is fully constructed, and the proof gets rebuilt afterward from inboxes, decks, and screenshots. That reconstruction is where budgets go. “First, build compliance in, not on,” Mohapatra explains. “The industry treats compliance like a final checkpoint. You build the solution, get it working, and then compliance comes in, and you are refactoring and repurposing.” The cost is not the fix. It is the excavation required to prove what happened months after it happened.
Permission Is Not Proof
The problem compounds when agents act autonomously. Consider four calls in a regulated workflow:
- The application programming interface (API) gateway approves all four.
- A compliance check finds one clean.
- One is running a changed model version with safety text truncated.
- One has a serving configuration that cannot be verified.
- One was executed against an expired standard operating procedure.
While there are four green, approved rows in the log, an inspector would write up three observations: permission was granted; authority was never established; and a standard audit trail cannot tell the difference. This is the gap Mohapatra argues that teams must engineer across.
“Secondly, bridge the two worlds,” he says. “AI lives in probability. Regulators live in rules. These are fundamentally different. AI can produce different outputs for the same input. The FDA demands deterministic precision.” Bridging it means wrapping probabilistic models inside deterministic controls: the thresholds, decision boundaries, and encoded rules that turn a statistical output into something a regulator can hold accountable.
What Governance Actually Requires
Governance here is not an automated sign-off. Agents move at machine speed while the human stays accountable where it legally matters. People still certify; the system makes that certification provable, holding four things together for every action:
- What rule applied.
- What evidence existed.
- Who signed.
- The ability to replay all three later.
The scope has to be jurisdictional rather than national, with rules, citations, and standard operating procedures encoded across regimes from the FDA to the EU Artificial Intelligence Act 2024, so one encoded change propagates everywhere at once. Further, it belongs beside the systems of record, not inside them. Pharmaceutical work is scattered across systems that were never designed to talk to each other, with medical, scientific, batch, trial, safety, and quality functions each holding a fragment of the evidence. A compliance layer that competes with business software platforms, such as Veeva or SAP, will lose; one that orchestrates those fragments onto a single case identifier becomes the spine that regulated AI runs on.
Replay Changes the Cost Curve
Most organizations still assess alignment through periodic reviews and manual checklists, leaving blind spots between milestones while a model drifts. “Stop thinking about compliance as a gate you pass through once. Make it real-time,” Mohapatra says. “Check it at every decision and every iteration so it gets updated continuously.” Replay is the higher bar: reconstructing a decision exactly as it stood at any moment in the past. A log records that something happened. Replay demonstrates it was allowed, which is the only form of evidence that survives contact with an inspector. When proof is produced as the work happens, rather than assembled under inspection pressure, the $750,000 remediation cycle collapses into a $10,000 design correction, and audit preparation shrinks from weeks of scrambling to one export.
The compounding matters as much as the savings. Each rule encoded once makes the next update cheaper, and teams stop rebuilding evidence per submission and start inheriting validated patterns from work already cleared. Traceability, monitoring, and human oversight stop being separate exercises and become properties of how the system runs. That is how compliance stops taxing velocity and starts creating it. In an industry where speed to market affects both revenue and patient outcomes, the organizations that can prove their systems were allowed to act will ship, while competitors are still reconstructing why. “The bottom line,” Mohapatra says, “compliance shouldn’t be why your AI projects fail. It should be why they succeed faster than anyone else’s.”
Follow Tarini Mohapatra on LinkedIn for more insights on AI compliance, life sciences technology, and regulatory strategy in healthcare.