IT · Automation

AI Agents & Workflows: Automation with Human Release

We build AI agents and automation workflows that remain defensible in a GxP environment. Every step is versioned, every decision traceable, every release stays with a person – under GAMP 5, Annex 11 and Regulation (EU) 2024/1689.

Our services for AI agents and workflows

Automation pays off where people move data between systems – and that is exactly where undocumented deviations often arise in GxP. We automate those paths with agents and workflows without losing the regulatory logic.

Start

Process capture & use case

Assessment

We capture volumes, handling times, error sources and GxP relevance. That yields a defensible automation use case with clear inputs and outputs – before technology is chosen.

Deliverable: process pack with feasibility, risk and ROI estimate

  • Boundary: automation vs. custom software
  • Data flow between CRM, ERP, LIMS and email
  • Prioritisation by audit risk and effort

Agent

Configure AI agents

LLM · MCP

Agents for bounded tasks with a clear success criterion: written task description, defined data sources and a limit at which control passes to a person.

Deliverable: working agent with documentation of task, sources and escalation

  • Pre-qualification of enquiries and routing
  • Knowledge search with a source for every answer
  • Draft reports for human review
  • OpenAI, Claude – model choice justified per use case

Automation

Workflows with Activepieces & n8n

Activepieces · n8n

We connect agents and business systems via workflows you can read and audit. Both platforms are open source and self-hostable – data stays in your infrastructure.

Deliverable: production workflow with log per run and error handling

  • Integration with HubSpot, Salesforce, SAP and lab IT
  • Email, approvals, notifications
  • Retry and alert to responsible owners

GxP

Validation & CSV

GAMP 5 · CSV

For regulated use we validate workflows to CSV standards. Audit trail, change control and data integrity are planned before implementation.

Deliverable: URS, risk assessment, test cases and validation report

  • Version control of workflow configuration
  • Logging: input, result, timestamp
  • Integration into change control

Compliance

EU AI Act & transparency

EU AI Act

Automated decisions sit under GMP law and the EU AI Act at once. We document risk class, human oversight and transparency duties – including Art. 50 labelling where required.

Deliverable: role and transparency documentation under Regulation (EU) 2024/1689

  • Risk classification and prohibited practices check
  • Human oversight at GxP decision points
  • Link to EU AI Act check

Operations

Run, monitoring & handover

Run · Handover

We operate the platform during the project or hand over runbooks, monitoring and training. MCP integration enables standardised connection of further AI systems.

Deliverable: operated automation or documented handover to your IT

  • Self-hosted in your environment
  • Extension to further workflows as a programme
  • Case story: Access to web app
LIMS integration case story ›

What sets us apart: An AI agent does not replace release. We build human oversight into the workflow – instead of documenting it afterwards.

Process with manual transfers?

Book an initial call

AI pathfinder

Which starting point describes your project?

Choose your scenario – you get the right entry point with references and contact route.

Automate manual transfers

Data from system A to system B, email approvals, notifications: we map the process and build the first workflow in Activepieces or n8n.

Automation from one source means process, agent, workflow and validation evidence from one team – without a handoff gap between business, IT and QA.

Reference: Access-to-web-app migration in under 270 hours. Read case story

Three roles in an audit-ready workflow

GxP decisions stay with people. The agent supports, the workflow logs – the system remains under change control.

Human

Release & oversight

Qualified staff review GxP-relevant results and release – Annex 11 and Art. 14 EU AI Act.

Agent

Task & escalation

Bounded sub-steps with source citation; handover when uncertain or at GxP threshold.

System

Log & version

Audit trail per run, configuration version, change control on changes.

An AI agent does not replace release. EU GMP Annex 11 requires additional review for critical data, and Art. 14 of Regulation (EU) 2024/1689 demands effective human oversight for high-risk systems. We build both into the workflow.

EU AI Act

EU AI Act check

For provider and deployer duties, use the public EU AI Act check: eight questions on risk classes, prohibited practices, transparency, human oversight, documentation and GPAI under Regulation (EU) 2024/1689.

Start EU AI Act check

Technology stack

Open source, self-hostable, GDPR-aligned
Flexible workflow platform for complex integrations
LLM integration
OpenAI and Claude – model choice justified per use case
MCP
Model Context Protocol for standardised AI system integration

What you receive

Process capture with volumes, handling times and error sources as the baseline
Working workflow in your environment, self-hostable, configuration under version control
Description per agent: task, data sources, limits and escalation path
Logging of every run with input, result and timestamp
For GxP use: URS, risk assessment, test cases and validation report
Documentation of roles and transparency duties under the EU AI Act

Who are AI agents and workflows for?

IT leadership, business units and QA in pharma, biotech and labs – when manual data transfers, undocumented email approvals or hard-to-search SOP libraries create audit-relevant risk.

Regulatory framework: EU GMP, ICH and FDA references

Automated decisions sit under two rule sets at once: GMP law and the EU AI Act.

AI agent or classic workflow?

Not every automation needs a language model. Rule-based workflows are often the faster entry – agents where interpretation and knowledge search are required.

AI agent

  • Interpretation, knowledge search, drafts
  • Source citation and escalation to people
  • Higher documentation and AI Act effort

Workflow (rule-based)

  • Fixed rules: if A, then B
  • Data transfer, approvals, notifications
  • CSV often simpler, less AI Act complexity

FAQ: AI agents and workflow automation

What is an AI agent?
Software that uses a language model to break a task into sub-steps and call tools or systems. In regulated use, each agent gets a fixed task boundary and hands over to a person as soon as a GxP decision is required.
Can AI workflows be used in a GxP-compliant way?
Yes, under two conditions: the workflow is specified, tested and under change control – like any computerised system. Release of GxP-relevant results stays with qualified staff. We validate to CSV standards and document roles under the EU AI Act.
Why Activepieces instead of Zapier or Make?
Activepieces is open source and self-hostable, so GxP data does not leave your infrastructure. That simplifies privacy evidence and qualification of the operating environment. At high call volumes, operation is more predictable than usage-based cloud tariffs.
How long does implementation take?
A bounded workflow without validation typically takes one to two weeks. Several connected agents with database integration need four to eight weeks. We plan GxP validation separately and align it with your QA.
Does data stay in the cloud?
Not if you do not want it to. Activepieces and n8n run self-hosted in your environment. We configure LLM calls deliberately – on-premise, private endpoints or with data minimisation per use case.
What are the first steps?
Name one process with many manual transfers. We assess feasibility, GxP relevance and effort – and propose either a rule-based workflow or an agent with escalation logic.

Reference projects: AI agents

Automation in CSV, migration and LIMS integration.

Next step: process capture for a first workflow

Name one process with many manual transfers. We assess feasibility, GxP relevance and effort.

Get in touch