
How AI is Being Implemented Alongside Compliance Concerns
ACTO's Parth Khanna on context engineering, role-based design, and why agents should be certified before deployment — just like reps.
Over recent years, the pharmaceutical industry has generally embraced AI. Due the nature of the technology, various companies have implemented it across multiple sectors. Now, the question that everyone is asking is: where is AI having an actual impact?
In March of this year,
Khanna recently spoke with Pharmaceutical Executive, where he elaborated on this topic, while also discussing how things have evolved in the months since he initially wrote his original piece.
Pharmaceutical Executive: How is AI being alongside compliance restraints?
Parth Khanna: When it comes to compliance and governance, the first and most important step is building and designing agents the right way from the start — through what we call context engineering. The more context an agent has during development, the better it understands the standard operating procedures and guardrails it needs to operate within. That foundation is essential.
The second key element is building role-based agent systems. When agents are designed around a specific role, they can inherit the compliance protocols and guardrails that correspond to that role. If I'm designing an AI agent system for a sales rep, for example, I already know from the human world what a sales rep can and cannot do — and many of those compliance requirements can be built directly into the agent. Roles at the center of the design process is not just a preference for us; it's an essential architectural principle.
Once you've designed your agents in a robust, role-specific way, the next critical step is observability and testing. Rather than deploying agents into the field and hoping they give the right answers, the right approach is to examine and certify agents in a test environment before deployment — verifying that they respond correctly to a defined set of questions and scenarios. This is no different from how we train and onboard field teams: we make sure people are certified and pass a knowledge assessment before they stand in front of a customer. We should hold our agents to the same standard.
Finally, on the notion of ongoing observability: the goal is to move agentic systems from a black box to a glass box. That means continuously monitoring agent responses after deployment — and giving agents the same assessments you ran before launch at regular intervals, to catch any drift before an agent starts saying or doing something it shouldn't.




