Skip to content

PAN Lab example

Automated visual inspection of injectable drugs

Erring toward the scrap heap while guarding the one that gets through

ML visual inspection examines filled injectables for defects, deliberately tuned to over-reject: a missed defect reaching a patient is a safety failure, a scrapped good vial is only a cost. Modeled on a regulated deployment where the AI must be qualified inside a validated quality process - and the regulator's framework for AI in drug manufacturing is still developing. The over-reject tuning lowers the visible risk without removing it. So watch the two things it leaves open: the AI-specific qualification, and the human inspector backstop that over-trust can hollow out.

Stylized model of a documented deploymentIndustrial QA & operations AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Regulated-visual-inspection-class tuned to over-reject network: 6 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    The cost side of the documented trade-off is an action and is drawn accordingly: a rejected unit replicates into the batch's scrap stream at full strength, and the recheck that would reopen it is empty. That pairing is the exact shape of the asymmetry. Erring toward scrap is the right direction, and the reason it feels free is that a destroyed good vial generates no complaint and no signal - so over-rejection is simultaneously the one error this design produces by choice and the one error nothing downstream is looking for. Separately, the record documents how organizations in this industry say they want model updates handled - risk-based change control under the quality system, bounded models rather than free continuous learning - so that gate is drawn as the artifact every update passes through. A heavy workload against very limited capacity: filled-unit volume against a backstop that reviews a fraction. The batch store is no longer marked privacy-sensitive; it holds product, not people.

  • baseline

    This models the regulated-inspection pattern documented in the case file - not a reconstruction of the actual system. Machine-learning automated visual inspection of filled injectable drug products flags particulate and cosmetic defects in a safety-critical, regulated setting. The error trade-off is asymmetric and deliberate: a false accept (a missed defect reaching a patient) is a patient-safety failure, a false reject (a scrapped good vial) is a cost, so the system is tuned to over-reject - a chosen, owned governance decision in the safe direction, drawn on the model's self-loop.

  • baseline

    The AI-specific qualification is drawn as the latent independent model check, empty at baseline: an AI in a validated quality process must be qualified and monitored for drift, and because the regulator's framework for AI in drug manufacturing is still developing, that qualification is an emerging, not-yet-settled check - the deployment uses an AI the mature quality system does not yet have a finished way to validate over time.

  • assumed

    The human backstop is the second latent check, empty at baseline: the over-reject tuning lowers the visible risk without removing it, so a miss is rarer but not impossible, and the human inspector is the layer meant to catch the residual misses. Over-trust erodes that backstop exactly where it is load-bearing - the missed defect the asymmetric design was built to prevent - so choosing the error well does not discharge the governance; the qualification and the human backstop are what keep the residual risk covered. Consistent with the domain caveat, nothing here is a claim that a named manufacturer's AI let a defect ship.

  • assumed

    No patient-safety or defect-escape outcome is modeled here. This Lab reads institutional propagation only, and the patients who receive the products are boundary-only. The asymmetric trade-off, the over-reject tuning, the emerging regulatory qualification, and the over-trust risk to the human backstop live in the case file, and are never computed from anything in this diagram.

What this example does not show

  • No patient-safety or defect-escape outcome is modeled. The Lab reads institutional propagation only; the patients who receive the products are boundary-only, and the asymmetric trade-off, the over-reject tuning, the emerging regulatory qualification, and the over-trust risk live in the case file, never computed on this diagram.
  • Consistent with the domain caveat, nothing here is a claim that a named manufacturer's AI let a defect ship; the diagram draws the deliberate over-reject tuning, and the AI qualification and the human backstop as two latent checks, not a computed harm.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • Machine-learning automated visual inspection of filled injectable drug products flags particulate and cosmetic defects that manual inspection or fixed-rule cameras would otherwise judge. In this safety-critical, regulated manufacturing setting the error trade-off is asymmetric and deliberate: a false accept — a missed defect in an injectable that reaches a patient — is a patient-safety failure, while a false reject — scrapping a good vial — is a cost, so the system is tuned to over-reject rather than risk a miss. Because the inspection sits inside a validated pharmaceutical quality process, the AI cannot simply be switched on; it must be qualified within that process, and a regulator is actively developing the framework for how AI in drug manufacturing should be validated and monitored.

    empirical
    • Peer-reviewed Veillon, R., Shabushnig, J., Aabye-Hansen, L., et al. (2023). Applying Machine Learning to the Visual Inspection of Filled Injectable Drug Products. PDA Journal of Pharmaceutical Science and Technology, 77(5), 376-401. https://doi.org/10.5731/pdajpst.2022.012796 https://journal.pda.org/content/77/5/376
    • Government U.S. FDA, CDER/OPQ (2023). Discussion Paper: Artificial Intelligence in Drug Manufacturing. Docket FDA-2023-N-0487. https://www.fda.gov/media/165743/download
  • Two governable surfaces follow from putting AI inside a regulated inspection. First, qualification: an AI in a validated quality process is not simply deployed but must be qualified and monitored for drift, and because the regulator's AI-specific framework is still developing, the qualification of the model's behavior over time is an emerging, not-yet-settled check rather than a solved one. Second, the human backstop: the manual inspector is what catches the false accepts the over-reject tuning is meant to avoid, so if inspectors come to defer to the AI and stop scrutinizing, that backstop erodes exactly where it matters most — the missed defect the asymmetric tuning was designed to prevent. The governable reading is that the over-reject tuning lowers the visible risk without removing it, and the qualification and the human backstop are what keep the residual risk covered.

    empirical
    • Peer-reviewed Veillon, R., Shabushnig, J., Aabye-Hansen, L., et al. (2023). Applying Machine Learning to the Visual Inspection of Filled Injectable Drug Products. PDA Journal of Pharmaceutical Science and Technology, 77(5), 376-401. https://doi.org/10.5731/pdajpst.2022.012796 https://journal.pda.org/content/77/5/376
    • Government U.S. FDA, CDER/OPQ (2023). Discussion Paper: Artificial Intelligence in Drug Manufacturing. Docket FDA-2023-N-0487. https://www.fda.gov/media/165743/download

Where this connects

Institutional pressures in this domain

  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.

All of them in context on the Industrial QA & operations AI domain page.

Levers available here and the patterns behind them

Documented case histories