Back to blog
Packaging artwork management: why AI can't be the pilot — and the hidden risks it carries in pharma and FMCG

October 1, 2026

Packaging artwork management: why AI can't be the pilot — and the hidden risks it carries in pharma and FMCG

By Guillaume Charetier - Growth Director & Carlos Blasi - CTO My Media Connect

In recent months we have witnessed a genuine gold rush around artificial intelligence. Platforms have appeared that promise to automate approvals, generate specifications, create standard operating procedures and even automatically validate artworks and packaging materials.

The proposition is attractive. If a tool can analyse documents, compare versions, identify errors and make decisions in a matter of seconds, it seems logical to assume it can shorten launch timelines, cut costs and simplify management of the artwork management chain.

Artificial intelligence undoubtedly has a meaningful role to play in process optimisation. It can help classify information, detect differences, suggest actions, speed up searches and reduce repetitive tasks. At MyMediaConnect we are also exploring AI-assisted features for specific, low-risk use cases.

However, there is a line we should not cross: artificial intelligence cannot pilot critical decisions in the artwork management chain.

This is especially important in sectors such as pharmaceuticals, consumer health, food and FMCG. An error on a pack is not simply a design issue. It can trigger a product withdrawal, a line stoppage, a regulatory breach, considerable financial loss or, in certain cases, a risk to health.

The question is not whether to be for or against AI. The question is deciding what role it should play, who retains responsibility and what controls must be in place when an automated recommendation can have operational, regulatory or health consequences.

The Purolea case: a warning sign

In April 2026, the FDA published a warning letter addressed to Purolea Cosmetics Lab, a pharmaceutical manufacturer based in Michigan. The letter includes a specific section entitled “Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing”, dedicated to the inappropriate use of AI in activities related to pharmaceutical manufacturing.

According to the FDA, Purolea had used artificial intelligence agents to help create product specifications, procedures and master production and control records. The company stated that it used these tools to support compliance with regulatory requirements.

The problem was not using AI as a support tool. The problem was that the company’s quality unit did not adequately review or verify the generated documents before incorporating them into manufacturing operations.

During the inspection, the FDA also found that process validation had not been carried out before the products were distributed. When the investigators pointed out this deficiency, the company replied that it was unaware of the requirement because the AI agent it was using had never told it.

The FDA’s response was clear: if a company uses artificial intelligence to help create documents related to cGMP activities, it must review those documents to ensure they are accurate and genuinely meet the applicable requirements. The responsibility of the quality unit cannot be transferred to an AI agent.

This case is an important warning for any organisation considering automating regulated processes. AI can generate a convincing answer, but it does not guarantee that the answer is correct, complete or legally sufficient.

Regulatory risk in the artwork management chain

Packaging management shares many of the elements that make cGMP activities particularly sensitive: defined procedures, controlled documents, traceability, formal responsibilities, change review and approval by authorised people.

In this context, an artwork can contain critical information:

  • Product name and description.
  • Composition, dosage or strength.
  • Warnings and contraindications.
  • Directions for use.
  • Codes, identifiers and legal data.
  • Batch and expiry information.
  • Marketing or health claims.
  • Languages and market-specific requirements.
  • Graphic elements associated with product identification.

A seemingly minor change can have serious consequences. An incorrect figure, a wrongly expressed unit, an inadequate translation, an omitted warning or an unreadable code can compromise the compliance of the pack.

Potential impacts include:

  • Product withdrawal or recall.
  • Destruction or reprocessing of printed materials.
  • Production stoppages.
  • Launch delays.
  • Logistics and distribution costs.
  • Inspections or penalties.
  • Loss of trust among consumers and customers.
  • Reputational damage to the brand.
  • Risks to patients or users of regulated products.

That is why the promise to “approve an artwork automatically” must be examined with great caution. The question should not only be how much time the tool saves, but also what happens if it gets it wrong, how the error is detected, who validates it and what evidence is recorded.

Automating tasks is not automating responsibilities

There is a fundamental difference between automating a task and automating a responsibility.

A platform can compare two versions of a document and flag that a word has changed. It can identify that a code is in a different position, that a colour does not match or that a graphic element has moved.

That is an objective assistance task.

It is something else entirely for the system to decide whether the change is acceptable, whether it complies with regulations, whether the information is correct or whether the material can go into production. That decision requires context, authority and accountability.

An automated system does not necessarily know:

  • The full history of the product.
  • Previously approved exceptions.
  • The regulatory obligations of each country.
  • The commercial priorities of the launch.
  • The correct interpretation of a claim.
  • The impact of a change on other materials.
  • The internal responsibilities defined in the quality system.

Artificial intelligence can help find patterns or make recommendations, but it should not become the ultimate owner of the decision.

In a regulated environment, one principle must always hold: AI can be the copilot, but not the pilot.

How technology should be used

The alternative is not a return to slow, manual, email-based processes. The alternative is responsible automation, designed from the outset around traceability and human oversight.

A suitable model can combine:

  1. Automatic version comparison. The system detects objective differences between two artworks: text, codes, colours, positions, sizes or graphic elements.
  2. Clear presentation of changes. Users can review differences in a visual, structured way, without having to compare entire files manually.
  3. Defined approval workflows. Each project follows a sequence of reviews and approvals in line with the organisation’s responsibilities.
  4. Mandatory human intervention. The final decision always rests with an authorised person, especially when the material concerns a regulated product.
  5. Complete activity log. The system records who reviewed, what comments they made, which version they approved and when each action took place.
  6. Version control. Only the approved version can move on to the next stage of the process.

This approach can be as efficient as full automation, yet it avoids turning a probabilistic tool into a regulatory authority.

At MyMediaConnect we have deliberately chosen this model. Our assisted comparison systems identify objective differences between versions, while the final decision and validation remain with an authorised user.

This does not mean using less technology. It means using it with a design better suited to the level of risk in the process.

The data sovereignty risk

The second risk to consider is data sovereignty.

Pharmaceutical, consumer health and FMCG companies handle highly sensitive information through their packaging processes. This information may include:

  • Product formulas and specifications.
  • Dosage and composition data.
  • Designs for launches not yet announced.
  • Market and pricing information.
  • Claims and positioning strategies.
  • Supplier and distributor data.
  • Information relating to complaints or consumers.
  • Materials subject to confidentiality agreements.

When a platform integrates external artificial intelligence services, data can flow between different providers, regions and subcontractors. That is why it is not enough to ask whether the system is “in the cloud”. You need to know what infrastructure it uses, where the data is processed, which providers are involved and what happens to the information sent.

The US CLOUD Act allows United States authorities to request certain data from providers subject to their jurisdiction, even when that data is stored outside US territory. Its specific applicability depends on multiple legal, contractual and technical factors, but jurisdictional risk should be part of the assessment of any cloud or AI provider.

For a European company, these are some essential questions:

  • Where is the data stored?
  • Where is it processed?
  • Which external providers are involved?
  • Are third-party AI model APIs used?
  • Can the data sent be stored?
  • Can it be used to train models?
  • Which sub-processors take part in the processing?
  • Is there an EU-only data residency option?
  • What encryption and access control measures are applied?
  • What happens if a foreign authority requests information?

The answers must be clear, documented and contractually verifiable.

At MyMediaConnect we prioritise minimising the exposure of sensitive data and being transparent about what information is shared, with whom and for what purpose. For critical decisions in the artwork management chain, we do not rely on APIs from US AI providers.

Economic risk and technology dependency

The third dimension is economic.

Many AI platforms rely on third-party models whose prices, usage limits and commercial terms can change. Cost may depend on the number of users, documents analysed, pages processed, words generated, API calls or tokens consumed.

This makes budget forecasting difficult, especially when a feature is deeply embedded in an operational process.

A provider may change:

  • The price per user.
  • The cost per volume of usage.
  • The limits included in each plan.
  • Storage terms.
  • The availability of a model.
  • Response times.
  • Terms for training on or reusing data.
  • Access to a specific API.

If a packaging management platform uses an external service for a critical function, any price change, outage or model discontinuation can have knock-on effects for the customer.

That is why finance and operations leaders should ask:

  • What percentage of the platform’s cost depends on third-party AI services?
  • Does the price include usage, or is it billed by consumption?
  • Are there volume limits?
  • What happens if the external provider raises its rates?
  • Is there an alternative provider?
  • Can the functionality be maintained without AI?
  • What continuity plan exists if the model becomes unavailable?
  • Will the customer receive advance notice of significant changes?

Artificial intelligence can reduce certain costs, but it can also introduce a new layer of dependency and volatility. Initial savings should not be assessed without considering total cost of ownership and continuity risk.

At MyMediaConnect, critical functions do not depend on external AI APIs. We use our own technology or controlled systems, with a more predictable cost model. We are exploring AI-assisted features for low-risk tasks, always under a hybrid approach that ensures the core of the platform is never subordinated to an external provider.

Three questions before choosing an AI platform

Before bringing an artificial intelligence solution into artwork management, any CMO, quality manager, operations director or CFO should ask three questions.

1. Who is accountable if the AI gets it wrong?

Responsibility cannot disappear just because the decision has been automated. It must be clearly defined who reviews, who approves and who is answerable when an issue arises.

2. Where is the data, and where does it flow?

The provider must explain the architecture, the storage regions, the external services and the applicable contractual and technical measures.

3. What happens if costs change or the service disappears?

Every critical function needs a fallback plan. A platform must be able to keep the essential process running even if an external model becomes more expensive, stops working or is withdrawn.

These questions are not meant to hold back innovation. They are meant to ensure that innovation is adopted with sound criteria for quality, security and operational sustainability.

AI as copilot

Artificial intelligence will play a growing role in process management. It can help uncover anomalies, summarise information, speed up comparisons and reduce administrative work.

But in the artwork management chain, especially in regulated sectors, efficiency cannot come at the cost of losing control.

Technology should make teams’ work easier, not replace the responsibility of authorised people. It should deliver speed without sacrificing traceability, automation without creating a black box, and analytical power without turning a recommendation into an automatic approval.

The lesson of the Purolea case is clear: the FDA did not simply question the existence of an AI tool, but the absence of adequate human review and the reliance on an automated answer to determine regulatory obligations.

At MyMediaConnect we advocate a pragmatic approach: use technology where it delivers measurable value, keep human checkpoints on critical decisions and design every process to be auditable.

Because an error in an artwork is not just a bug. In pharma, consumer health and food, it can become a risk to the company, to the brand and to people.

AI can accelerate the artwork management chain. But it must not pilot it.

Sources

Let's talk?