AI Governance
AI Agent Governance Scenarios, Part 4: The "Efficiency Shortcut"
The system did not change and no change control was raised, but the way people actually used it drifted from a structured review workflow to a single question.
This is the fourth in a five-part series of practical AI-governance scenarios for quality professionals.
The scenario
An organisation implemented an AI agent to assist QA reviewers with batch record review. The intended workflow was structured and sequential: the agent flags potential issues, the reviewer evaluates those flags, and the reviewer makes the final determination — the agent accelerates the review; it does not replace it.
During a routine review meeting, quality leadership discovers that a number of reviewers have quietly changed how they use the agent. Instead of running the structured workflow, they ask a single direct question: "Are there any compliance concerns in this batch record?" The agent returns a short, reassuring summary — "No major documentation issues detected" — and the reviewer proceeds with minimal further evaluation. This approach has become common practice. The system configuration has not changed. No procedure has been updated. No change control has been raised. Yet the effective process has shifted fundamentally.
Is this acceptable, and what would you do about it?
Issue 1 — the defined review workflow is bypassed. The agent was validated to support a structured process; that structure defines the scope within which its outputs can be considered reliable. A general question invokes a surface-level interpretation rather than the systematic check the workflow was designed to run, and the reviewer has no visibility into what was actually evaluated. From a GMP perspective this is a process deviation, whether or not anyone documented it as one — the gap between written procedure and actual practice being invisible to the quality system makes it worse, not better.
Issue 2 — the agent is used as a decision shortcut. When a reassuring summary is accepted with minimal further review, the agent has effectively become a decision authority rather than a review assistant — a fundamental inversion of the intended relationship. "No major issues detected" is not a QA release decision; it is an output that requires human interpretation to be meaningful, and the distinction between "the AI found no issues" and "the record is acceptable" is being collapsed.
Issue 3 — human verification is reduced. GMP requires meaningful, independent verification, not cursory confirmation of what an agent has already reported. When a reviewer's evaluation is shaped primarily by the agent's conclusion, the independence of that verification is compromised — and a reviewer expecting a clean record may apply less scrutiny than one approaching the record fresh, a well-documented cognitive effect amplified by algorithmic authority.
Issue 4 — informal behaviour change without governance. This is arguably the most significant issue: the written procedure describes the approved workflow, but actual practice has diverged, and that gap is invisible without active oversight. Behavioural changes to how a tool is used constitute an effective process change, even without a formal update — governance has to extend beyond initial validation to include periodic review of interaction logs, competency checks, and clear escalation pathways for identified workarounds.
Two different failure modes
This scenario and the "Game Changer Agent" scenario illustrate two distinct failure types. A technology-governance failure is a change in how the system itself is controlled — visible, and usually caught by existing change control. A human behavioural-drift failure — this one — is a change in how people interact with a system that has not technically changed at all: no alarm triggers, no change control initiates, and the quality system may be entirely unaware anything has shifted. AI risk in GMP is primarily about governance and behaviour, not the model itself, and the most significant risks often come from how people choose to use a tool rather than from what the tool does.