We’ve been asked how our AI-powered compliance auditing tool, AICA, compares with the AI tools the FDA has rolled out. So we wanted to break it down here because there’s quite a bit of daylight between these, even though they may soon serve common purposes.
Back in May, the FDA announced two things at once. The first was Elsa 4.0, an upgrade to the internal AI tool it launched in June 2025. The second was HALO, a platform that the agency says consolidates more than 40 of its application and submission data sources, systems, and portals into one place. (Think of it like the data layer for Elsa.)
That same day, then-Commissioner Marty Makary announced a pilot of one-day inspectional assessments for facilities that AI has flagged as lower risk.
Again, because we’re busy implementing an AI compliance auditing tool across industry RA/QA teams, we're asked whether these are the same kind of thing. Mostly, they are not — at least if and until the FDA starts using its tools the way industry teams are using ours.
Let’s briefly look at what each one does, where the two worlds touch and don’t, etc.
What the FDA actually announced about its AI tools
Let’s start with Elsa, the FDA’s internal generative AI tool that helps staff members quickly read, write, summarize, and review large volumes of scientific and regulatory data (among other things).
According to the agency’s recent announcements, Elsa 4.0 is available to all FDA staff, from scientific reviewers to investigators. The new features the FDA listed include:
Custom agents
Document generation
Quantitative data analysis and visualization, including chart/graph creation
Web search through a secure web access feature
Voice-to-text dictation
Conversion of scanned documents and images into searchable text (OCR)
Enhanced flexibility in chat capabilities
Optimized search for finding key information in large document repositories.
The FDA says Elsa runs in a FedRAMP High Google Cloud Platform environment, does not train on input data or on data submitted by regulated industry, and isn’t connected to the open internet. The agency also states that staff verify inputs, analytical processes, and the use of outputs.
Now let’s move to HALO.
HALO stands for Harmonized AI & Lifecycle Operations for Data. According to the FDA, it’s not an analysis tool. It’s like the plumbing underneath Elsa, consolidating more than 40 disparate application and submission data sources, systems, and portals across all FDA centers into a single platform.
Chief AI Officer Jeremy Walsh described the shift in the agency’s press release: staff used to bring data to Elsa, and now, in his words, “Elsa sits on top of our data.”
So, again, you can think of HALO as the storage layer. At the Food and Drug Law Institute annual conference, acting CIO Sridhar Mantha told attendees that HALO is a single platform with the agency’s highest security level and that data inside it is compartmentalized and segmented by center, according to RAPS.
It’s worth remembering what the FDA said Elsa was for at launch (presumably, HALO helps on the data side now). The June 2025 press release listed accelerating clinical protocol reviews, shortening scientific evaluations, and identifying high-priority inspection targets.
Three tools, three somewhat different jobs
Now let’s pick these tools apart to show that they’re doing different things.
Elsa is a staff assistant. It reads, writes, and summarizes things for FDA employees. It’s not (at least officially) a compliance auditing/inspection engine itself. The FDA has never described it as one, and there’s no direct confirmation that they’re using it to actually run company data for inspection purposes beyond identifying who should be inspected. We’ve heard murmurs that some investigators may be using it to run parts of inspections and assist with observations, but we can’t confirm this, and the FDA seems very careful to omit it from its stated use cases.
HALO is infrastructure. Again, on its own, the FDA says it analyzes nothing. It makes the agency’s own records queryable in one place rather than in many.
AICA is a commercial product for the industries the FDA regulates. We built it! It reads a company’s own SOPs, policies, and work instructions against the CFR requirements the company selects, flags gaps, ties each observation to a specific section, suggests remediation, and produces a report that a qualified Quality professional reviews before it’s finalized.
The users do not overlap, nor does the data. Nobody at a pharma company will open Elsa themselves, and nobody at the FDA is running AICA. Elsa and HALO work on material that has already been submitted to the agency. AICA works on material a company has written for its own QMS.
So a word to the wise: if you encounter anyone framing these as competing products, they’re wrong (and probably trying to sell you something).
Where they actually touch
The point of connection between these systems is, at least for now, inspection targeting, broadly speaking.
The FDA’s one-day inspectional assessment pilot began internally in April 2026 and was publicly announced on May 6. The FDA says facilities are selected using risk-based criteria including product type, prior inspection outcomes, and operational characteristics. That appears to mean they’re having Elsa ingest company data to determine who they should prioritize for inspections.
As of late April, the FDA said it had completed roughly 46 assessments, most of which resulted in “No Action Indicated” outcomes. Some ran longer than a day when investigators found significant observations. The agency was explicit that these do not replace standard inspections and are not intended for higher-risk or complex facilities. Makary described the AI’s role plainly at FDLI, saying the tool identifies which facilities are low risk.
At the same conference, Steven Musser, associate commissioner for human food research, was asked whether AI is used in inspections. His answer, as reported by RAPS, was that he does not currently see how an investigator would integrate AI during an inspection itself. What AI is good at, he said, is detecting anomalous patterns, and he pointed to a shrimp pilot program aimed at spotting adulteration and fraud.
So the honest version of the current use case seems to be quite narrow. The FDA’s AI, based on official indications, is not inspecting anyone. It’s helping decide where investigators go and how much time an establishment warrants. Skadden’s write-up of the FDLI meeting drew the practical conclusion for industry that we agree with: companies should expect AI to be applied to their submissions and should run their own analysis on material before filing.
That, at least at the moment, is the closest thing to a real link between what the FDA built and what AICA is doing inside RA/QA teams. It’s a link about sequence, not about function.
In case you haven’t seen our AICA demo, it puts a finer point on what that system can do and who it’s for:
Some more nuances
Musser named a limitation at FDLI that seems to apply to every tool in this category, including ours with AICA.
The AI powering these systems reports what the literature says without weighing the methodological quality of the sources. It can tell you that 100 papers reached one conclusion and 3 reached another, without assessing which studies were better designed. He also noted that outputs vary across queries, raising questions about reproducibility.
The equivalent limitation for AICA is worth stating here. It compares what a procedure says against what a regulation requires. It does not judge whether a procedure is well designed for a particular operation, whether anyone follows it, or whether the batch records support it. That requires context and human interpretation that simply can’t be ingested into the system.
Documentation review is part of a broader program that also covers implementation, quality records, personnel interviews, and facility observation. AICA also does not (at the moment) audit against a company’s internal standards, only against regulatory requirements.
What a former FDA enforcement director expects next
David Elder spent 23 years at the FDA, including serving as director of the Office of Enforcement and the Office of Regional Operations, and earlier as an investigator and compliance officer.
In a June 8, 2026 guest column for Pharmaceutical Online, he wrote that the FDA has begun using AI both before and during certain inspections and remote regulatory assessments, and described Elsa as supporting the thoroughness and efficiency of inspections by analyzing and comparing information from multiple sources.
The sourcing and wording here matter.
Elder states this as current practice. The FDA has not said it publicly, and the footnote he attaches to that section points to the Investigations Operations Manual and two compliance programs rather than to any agency statement about Elsa itself. So what you have is a well-placed former official describing something the agency, at least from what we can tell, has not described in an announcement attached to its tool. That deserves to be taken seriously, but carefully.
The remainder of his piece is forward-looking, and he labels it that way. He lists the company data he expects investigators would feed such a tool: complaint databases, deviation and out-of-specification investigations, change control records, CAPA data, risk management files such as FMEAs, and key SOPs and work instructions.
He pairs that with FDA-held data, including adverse event systems, Field Alert Reports, the Recall Enterprise System, and prior inspection records. His sample queries carry a note that they are illustrative of the thinking only, and he calls the practice currently in its infancy.
The takeaway for an RA/QA team
The comparison we’re sometimes asked for, “whose AI is better,” does not exist because the tools are not doing the same work.
No hard evidence or announcements establish that the FDA is running QMS documentation through Elsa today. The FDA has confirmed using Elsa for inspection targeting, among other things. A former enforcement director describes more than that and does not cite an agency statement to support it. A few unverified accounts we’ve heard describe more still. Those are different levels of evidence, and collapsing them into a single claim is how an industry talks itself into a panic.
What they share is a direction. The FDA has spent a year making its own data faster to query, and it has started using that capability to decide where investigators spend their time. Whether that capability eventually points at company records during an inspection is a question no one outside the agency can answer right now.
Which is why the case for running your own analysis first does not depend on the strongest version of the story being true. If the FDA never goes beyond targeting, a company still benefits from knowing where its written system is thin before it lands on a target list. If Elder is right about where this goes, the same work matters more and needs to extend past procedures into quality data. Either way, the homework is the same, and it is homework a company can do without waiting to find out which version is correct.
We built AICA to give industry teams the compliance audit tooling that we’d expect the FDA to use itself at some point. The teams we’re onboarding now want to be ahead of the game.
Have questions or want to get a demo?
Want to see whether AICA fits your team? Visit aica.thefdagroup.com to learn more and get in touch. You can also email Eric directly at eboyd@thefdagroup.com and let him know you’d like to set something up. We’re onboarding teams to the tool right now.





