The architecture behind AI in regulated industries
Jul 28, 2026 10 min

The next phase of AI in regulated industries won’t be defined by the models organizations deploy, but how well they redesign the operating conditions around them.
A regulated enterprise can automate a workflow, deploy an AI co-pilot, or accelerate a supply chain and still increase risk if the operating model underneath it can’t prove what happened, who validated it, and whether the process met the required standard.
That’s the pressure building across pharmaceuticals, healthcare, finance, and other regulated sectors. AI is moving closer to high-stakes operational decisions, while the environments around those decisions remain defined by tight margins, fragmented systems, audit exposure, and little tolerance for error.
Organizations that gain value from AI and automation treat governance as part of the operating architecture. Controls can’t sit at the end of the process as a final approval step. They need to be embedded into the systems, workflows, and data foundations that shape the work from the start.
Mark Cuban Cost Plus Drugs (CPD) is a practical example of this shift. It operates on one of the simplest business models in healthcare: cost plus 15%.
That transparency has helped disrupt the pharmaceutical industry, but it also creates a unique operational challenge. When margins are intentionally thin, every system, workflow, and technology investment must justify itself.
As CPD expands across direct-to-consumer pharmacy, B2B pharmaceutical procurement, employer solutions, manufacturing, and pharmacy partnerships, operational efficiency becomes more than a technology objective–it becomes a business requirement. Compliance has to be auditable without slowing the system down. And complexity becomes a cost center.
Regulated innovation doesn’t scale when modern tools are layered onto fragmented processes, inconsistent data, and manual controls. The first requirement is operational cleanup. Data must be unified, standardized, and usable across the enterprise before AI can support higher-value work without adding new audit and compliance risk.
That changes how AI, automation, and modernization investments are evaluated. A tool that accelerates one workflow can still create downstream risk if the data is incomplete, the handoffs are manual, or the audit trail is difficult to reconstruct.
A system that produces faster outputs might still fail operationally if staff have to spend more time validating, correcting, or documenting what the technology did.
Before introducing new capabilities such as dependent accounts and auto-refill functionality, CPD first focused on simplifying and modernizing its platform architecture. Reducing unnecessary complexity created the flexibility required to introduce new patient experiences while maintaining operational efficiency.
In high-stakes, low-margin environments, technology has to do more than improve isolated tasks to actively reduce structural inefficiency built into the operating model.
Enterprise leaders know legacy fragmentation slows the business down. What’s often underestimated is how quickly that fragmentation escalates into a serious compliance issue when AI and automation enter the system.
When data lives across disconnected systems, teams lose visibility into process quality, decision logic, documentation, and handoffs. The organization may still be able to operate through manual effort, but that effort creates drag. People reconcile data, recreate context, validate exceptions, and prepare documentation after the fact.
AI doesn’t solve the foundation problem. It exposes it.
For example, the Cost Plus Drugs B2B Marketplace had to consolidate disparate supplier data and inventory logic before they could layer on predictive analytics. Without that foundational standardization, AI-driven inventory management would have been impossible because the system would have been optimizing based on flawed, siloed data.
Deploying advanced AI on top of siloed data and manual workflows makes governance harder, not easier. If the organization has to manage automated outputs without a clean view of the inputs, rules, approvals, and exceptions behind them, it creates risk during execution and greater exposure when regulatory questions arise.
Operational cleanup should be treated as a risk-control move, not a technical prerequisite. Data unification, standardization, and system integration help the enterprise understand how work moves, where decisions are made, and where evidence is produced.
Without that foundation, AI investments can create negative ROI. The business may spend more time inspecting outputs, correcting errors, and preparing audit documentation than it saves through automation.
Traditional governance models struggle when systems become faster, more connected, and more autonomous. A checklist can confirm whether requirements were reviewed, but it doesn’t create the structural visibility needed to manage AI-enabled workflows in regulated environments.
Compliance-by-design addresses that problem by making governance part of the system architecture. Security, validation, documentation, and oversight aren’t treated as separate workstreams. They’re built into the way the platform operates.
For CPD, this meant establishing compliance as a core architectural requirement while delivering the security and operational performance required by the business. Security by design, including encryption at rest and in transit, becomes part of the same operating foundation as efficiency.
As CPD expanded beyond its consumer pharmacy into B2B procurement, employer solutions, pharmacy partnerships, and manufacturing operations, governance requirements became increasingly interconnected. Visibility across transactions, inventory movement, approvals, and fulfillment workflows became essential not only for compliance, but also for operational scalability.
Regulated organizations require systems that provide real-time visibility into controls and automatically generate audit-ready documentation within the workflow itself.
That structure is what allows organizations to move faster without losing accountability.
CPD’s operating model demonstrates that automation is most effective when paired with clear human accountability. Technology can streamline onboarding, fulfillment, procurement, and operational workflows, while staff focus on exceptions, quality review, and business-critical decisions.
The risk in autonomous action isn’t only that AI makes a wrong recommendation or takes the wrong step. The larger concern is that the organization can’t clearly explain how the decision was reached, where oversight occurred, or whether the required control was applied.
Human-in-the-loop architecture helps resolve that concern by defining where automation can act and where human validation must remain part of the process.
The value comes from placing human judgment at the right points in the workflow. Routine steps can be automated to reduce manual effort and improve consistency, while compliance-critical actions can be routed for review, approval, or exception handling.
This moves teams away from low-value administrative work and toward higher-value oversight. Operators aren’t spending as much time entering data, chasing documentation, or checking routine steps manually. Their role shifts toward validating outputs, managing exceptions, and applying judgment where the business needs it most.
For regulated enterprises, this is the practical path to scaling AI. The organization gains efficiency without surrendering control, and every critical step remains visible, reviewable, and auditable.
This shift is visible in CPD’s fulfillment operations. Where staff once spent hours reconciling manual orders or chasing documentation, they now manage exceptions flagged by the platform. The human-in-the-loop isn’t checking routine data entry. They’re reviewing critical quality checks and high-stakes order validations, allowing the system to handle the high-volume, routine fulfillment at speed.
Agentic AI becomes relevant to regulated industries when it can coordinate across enterprise systems while maintaining control, transparency, and documentation.
In environments connected to platforms such as SCADA, eQMS, SAP, Epic, or core banking systems, AI has to do more than predict what might happen next. It has to support governed action across workflows that can be inspected and validated.
That requires systems that can help execute work, guide users through required steps, perform QA checks, and produce the documentation needed to support audit readiness.
In practical terms, this can include AI co-pilots and batch assistance tools that guide operators through standard operating procedures, perform essential quality checks, and automatically generate required audit documentation. The system reduces repetitive effort while preserving the validation needed for regulated work.
The same principle applies to back-office processes. Automated administrative tasks, such as drafting SAP purchase orders, can shift staff away from repetitive data entry and toward managerial review of automated outputs. The operational savings come from reducing manual work while improving the consistency and traceability of the process.
The primary value is more than speed. It’s also cleaner execution, stronger oversight, and lower exposure in the processes where mistakes are expensive.
Within CPD’s ecosystem, future AI-enabled workflows could support activities such as pharmaceutical inventory forecasting, procurement recommendations, manufacturing planning, customer service assistance, and operational reporting. The value comes not from autonomous decision-making alone, but from ensuring every recommendation remains visible, explainable, and reviewable by the appropriate stakeholders.
In regulated industries, innovation has to withstand scrutiny, making automated auditability a critical measure of whether AI-enabled transformation is working.
Automated auditability means the system can produce a reliable record of what happened across the workflow. It captures the relevant data, documents the steps taken, identifies where human validation occurred, and makes the process easier to inspect. That record cannot be reconstructed only after the fact. It has to be generated as work moves through the system.
This is where structural governance creates business value. It reduces the cost and effort of proving compliance. It also reduces the operational strain that comes from fragmented documentation, manual review, and unclear ownership.
For executives, this reframes the modernization agenda. The goal isn’t to deploy AI broadly and hope governance keeps up. It’s to build operating systems where efficiency, control, and evidence move together.
That’s what enables regulated enterprises to move from experimentation to scale.
Emerging initiatives such as mobile pharmaceutical manufacturing pods further reinforce the importance of auditability. As manufacturing becomes more distributed, organizations require systems capable of documenting production activities, validation steps, quality controls, and operational decisions in real time.
These efforts point to a broader operating reality for regulated sectors. Speed and control have to be designed together.
When the foundation is designed correctly, compliance supports speed because the system is already structured to produce visibility, validation, and evidence. Teams can move faster because they’re not rebuilding the audit trail after the work is done. Leaders can scale automation because the control model is embedded in the architecture.
That’s the operational blueprint regulated enterprises need as AI moves closer to core business processes.
Whether supporting direct-to-consumer pharmacy operations, institutional purchasing through Cost Plus Marketplace, or sterile injectable manufacturing through CPD’s 503B business, CPD’s ability to generate evidence as work occurs becomes a competitive advantage rather than simply a compliance requirement.
It also requires a different standard for transformation partners. The work can’t stop at implementation. It has to connect architecture, governance, integration, and workflow design in a way that supports long-term operational resilience.
Codal works with regulated organizations to build the systems, workflows, and data foundations that make AI-enabled operations easier to control, validate, and scale. That work connects system integration, compliance-by-design, and AI-enabled workflows so organizations can reduce operational drag while preserving auditability.
For regulated enterprises, the advantage will come from building systems that can move faster while proving more. That’s where structural governance becomes more than a risk-control function and becomes the operating model for sustainable innovation.
Throughout Codal’s Fireside Chat with Jon Horbaly, CFO of Cost Plus Drugs, one theme surfaced repeatedly: trust.
As AI becomes more deeply embedded within regulated industries, trust becomes one of the most important outcomes organizations measure. Not simply trust in the technology itself, but trust in the systems, data, workflows, and governance models that support it.
Organizations that successfully scale AI won’t be those that automate the most processes. They will be those that build environments where efficiency, transparency, accountability, and trust reinforce one another.
Watch the Codal Fireside Chat with Cost Plus Drugs to learn more about the architecture behind their model and the importance of building meaningful technology relationships.
Explore our latest expertise on innovation, design, and technology, or connect with us directly to see how we can help accelerate your digital transformation.