An AI development platform for regulated work

Build the difference.

Your experts spend their days on documentation and manual work that adds little to the outcome. AI agents, software that carries out defined pieces of work within rules you set, can take that over.

Most teams think getting there means building everything themselves or adopting a finished product. The MugAIn Platform is the third answer: a ready foundation that carries what regulators expect, the audit trail, validation pathway, monitoring and system integrations, so your own experts can create the agents that fit your processes.

You build what makes a difference to you. We carry the rest.
Vision and mission

AI is for everyone, also at work

Outside work, AI already helps people write, plan and learn. We want the same to be true inside regulated and business-critical work.

Who we are
The build-adopt spectrum

Where does your organisation stand?

Every life sciences company adopting AI takes a position on this spectrum, whether it names it or not. Building means your own developers create everything, the infrastructure and the agents alike. Adopting means taking a vendor's finished product as it comes. The middle position, the configurator, does both: it adopts the regulated foundation and builds its own agents on top. Select a position to see what it asks of you.

1
Full builder
2
Builder-leaning
3
Configurator
4
Adopter-leaning
5
Full adopter

Not sure? Take the strategy check, it takes four minutes. →

Two colleagues mapping a process flow on paper in a Nordic office
You find your position by mapping your own processes, not by reading a vendor's slides.
Why the middle wins

Three things peak at the centre of the spectrum, not at either end

Cost you can read

Building in-house hides cost in salaries. Adopting turnkey caps value at the catalogue. At the centre, the platform is one line item and every agent has a small, known cost with attributable value.

Fewest hand-offs

Build everything yourself and every idea waits for engineers. Adopt a finished product and every idea waits for the vendor’s plans. At the centre, the person who knows the process creates the agent directly.

Adoption built in

Tools built by others must be pushed onto their users. When your expert shapes the agent, the expert is also its first user, and adoption spreads peer to peer.

See the full argument →

Start small, validate fast

First validated agent, fixed price, 60 days

One agent, one process, running validated in production within 60 days. Validated means documented evidence, under your quality system, that the agent does what you defined. Your own process expert creates it on the full platform foundation. The price is fixed, it fits budget lines you already have, and it credits fully against a platform subscription if you continue.

Talk to us about your first agent
The MugAIn Platform

Your experts build the agents. The foundation comes ready.

The platform draws one clear line through your AI setup. Above the line, everything that makes you different, created and owned by your experts. Below it, everything a regulator expects and no company competes on, built and maintained by us.

THE AGENTS Drafting agents create first versions Checking agents review against your rules Extraction agents structure your data Monitoring agents raise exceptions one clear line THE FOUNDATION Everything the agents run on, built and maintained by us Audit trail Validation pathway Quality monitoring EU data residency System integrations EU regulation docs Your agents deploy on top. The foundation carries them.
Yours, built by your expertsYour agents, your process logic, your validation criteria and acceptance thresholds, your data. All exportable, contractually.
Ours, maintained for youA foundation documented for EU regulation, a complete audit trail, a validation pathway, built-in quality monitoring, EU data residency, and maintained connections to your quality, lab and document systems, all re-approved with every release.
Built for the whole lifecycle

Go-live is the start, not the finish

Most AI evaluations stop at deployment. Regulated operations begin there. The same clear line that splits the platform also runs through time: with every release, we revalidate the foundation, and your team revalidates only the agents it built.

YOUR AGENTS Run continuously, shaped and owned by your experts At each release you revalidate only what you built, never the layer underneath THE FOUNDATION, OURS Quality monitoring, always on QMS, LIMS, PLM connections Ships revalidated, every release Maintained by us for the life of the platform, documented for inspection Your agents, logic and audit history leave with you, exportable Only the foundation is replaced Go-live Release n Release n+1 Exit, if ever the start, not the finish

Quality monitoring runs from day one: the platform watches every agent's output, you set what counts as acceptable and decide what happens when it slips, which is exactly the oversight the EU AI Act expects from you as the deployer, the Act's term for a company using AI in its operations. And if you ever leave, only the foundation is replaced. What you built goes with you.

What you can build

The agent types your experts can create

An agent on the platform carries out one defined piece of work within rules you set. In practice the agents your experts build fall into four working types. One is generative, it drafts new content. Three are discriminative, they judge content that already exists. The distinction matters, because regulators define and treat the two families differently.

Drafting agents

Create first versions of regulated documents from your templates and approved sources: deviation reports, CAPA drafts, sections of technical documentation. Your expert defines the structure, the sources and the acceptance criteria. Generative.

Checking agents

Review records against rules you define: completeness of a batch record, coverage of a GSPR checklist, consistency between a protocol and its report. The agent flags, your people decide. Discriminative.

Extraction agents

Turn unstructured sources into structured data: supplier certificates into coded fields, complaint text into classified records, literature into screening tables. Discriminative.

Monitoring agents

Watch a stream of records or outputs and raise exceptions: trends in quality data, drift in another agent's output, missing signatures before a deadline. Discriminative.

Generative, discriminative and the other distinctions that regulators rely on are defined terms in ISO/IEC 22989, the EU AI Act and IMDRF guidance. Read our AI types reference →

Engagement model

Three steps, cost you can read

Each step is a decision point, not a commitment to the next. And what you pay for the first agent is not lost if you continue.

credits fully against the subscription ↓ credits fully against the subscription
1

Posture workshop

Half a day with the people who will live with the decision. You leave with your position on the build-adopt spectrum and a concrete first agent candidate. No strings attached to it.

Fixed price
2

First validated agent

One agent, one process, running validated in production within 60 days, created by your own expert on the full foundation. A price that fits budget lines you already have.

Fixed price
3

Platform subscription

The maintained foundation as a running service: revalidated releases, quality monitoring, integrations and support. One number you can plan with, agreed before you commit.

One number

You get the numbers in the first conversation, not after a qualification process. Ask us →

Is your team the configurator type?

The configurator is the middle position on the build-adopt spectrum: you adopt the regulated foundation and build your own agents on it. It fits teams whose process experts know their workflows deeply and want to shape their own tools, without owning regulated infrastructure. Four minutes tells you whether that is you.

Check your AI strategy
Reference

Types of AI, an overview

A reference note on the vocabulary behind the agents: the families of AI, the capability levels, and the definitions in ISO/IEC 22989, the EU AI Act and IMDRF guidance that regulators hold you to. ← Back to the platform

Legal

Privacy and cookies

How MugAIn Group ApS handles personal data on this website and in our dialogue with you.

Data controller

MugAIn Group ApS, Vestre Teglgade 15, 2450 København SV, Denmark, CVR 46218701. Questions about personal data: info@mugaingroup.com.

What we collect

Information you give us when you contact us by email, phone or the strategy check: name, work contact details and the content of the dialogue. We do not collect more than the conversation requires.

Why and on what basis

To respond to your enquiry and to run our commercial dialogue with you, based on our legitimate interest in doing so. We do not sell personal data and we do not use it for automated decisions about you.

How long we keep it

For the duration of our dialogue and any customer relationship, after which the data is deleted in line with our retention schedule and bookkeeping obligations.

Your rights

You can request access, correction or deletion of your data, and you can object to our processing. You can also complain to Datatilsynet, the Danish Data Protection Agency.

Cookies

This site uses only the technical cookies needed to function. No tracking, no advertising cookies, no third-party analytics without your consent.

Full documents

The summary above is a plain-language overview. The signed documents below are the controlling versions.

Privacy Notice

The full notice, including the Article 13/14 processing matrix, cookie notice, recruitment notice and our AI processing and governance statement.

Privacy Notice v1.0 (PDF) →
Effective 26 August 2026

Subprocessor List

The current approved subprocessors used to operate the MugAIn Platform, with the service provided, processing purpose and processing region.

Subprocessor List v1.0 (PDF) →
Updated 26 August 2026

← Back to the front page

The premise

Adopt the foundation. Build the difference.

AI at work is not one product. It is agents that do the work, running on a platform that keeps it compliant. Where you sit between building all of it and adopting all of it is the decision every company should start with.

AGENT complaint triage AGENT CAPA drafting AGENT audit prep Platform validation · audit trails · integrations · compliance the work the foundation built by you adopted Build control, but the whole regulatory burden is yours Adopt fast, but a vendor decides what your AI can do Configurator adopted foundation, built agents
The argument

Full build delays your first validated agent. Full adopt lets a vendor define what counts as compliant.

Full build means your own developers create everything, infrastructure and agents alike. Full adopt means taking a vendor's finished product as it comes. Control falls as you move from building to adopting, and speed rises. That trade is real, but it is not the whole picture. Several factors do not move in a straight line at all. They turn in the middle.

At the build end, cost hides in salaries, every idea waits for engineers, and finished tools must be pushed onto the experts who did not shape them. At the adopt end, the price is clean but the value is capped, your knowledge waits on the vendor's plans, and adoption depends on how well someone else's tool fits your work. The middle is the only place where cost is a single readable line, the expert builds directly, and the person who built the tool is also its first user.

So we asked the same question of every decision in the framework: does the advantage keep moving toward one end, or does it turn? Here is where all fifteen land, including the ones that argue against us.

4

Favour building

The advantage keeps rising the more you build yourself.

  • Team capacity
  • Control vs speed
  • Data control
  • Exit
10

Turn in the middle

Worse at both ends, best at the configurator position.

  • Cost transparency
  • Cost over time
  • Expert hand-offs
  • Adoption
  • Regulatory baseline
  • Change control
  • Audit trail
  • Quality monitoring
  • Systems integration
  • Security weaker case
1

Favours adopting

The advantage keeps rising the more you adopt finished.

  • Time to first result
Decision by decision

Where each of the fifteen actually lands

Same fifteen, same test, one row each. A dot marks where the advantage sits. A bar means it keeps moving in one direction and never turns.

Peaks in the middle Leans that way, less sharply Moves in a straight line
1 Builder 2 3 Configurator 4 5 Adopter

How you work seven decisions

Team capacity
The more engineers you have, the further left you can afford to sit
Control vs speed
This is the axis itself, and it is a real trade
Cost transparency
Hidden in salaries at one end, capped by licence at the other
Time to first result
Adopting finished software is genuinely faster
Cost over time
Fixed team at one end, per-user fees that grow at the other
Expert hand-offs
Fewest steps between the person who knows and the tool
Adoption
Peaks just right of centre, where shaping is easiest

What you own eight decisions

Security
Attested foundation plus your own visibility, but the case is weaker
Regulatory baseline
Your interpretation alone at one end, the vendor’s at the other
Change control
Re-approve everything, or re-approve blind. The middle re-approves least
Data control
Your own infrastructure really is the strongest position
Audit trail
Complete and yours to configure, without building the logging
Quality monitoring
The platform watches, you set the thresholds
Systems integration
Standard connections maintained, special ones still yours
Exit
If you built all of it, there is nothing to take back

Nine peak in the middle, one leans that way, and five move in a straight line. Those five are the honest cost of the configurator position. If you have the engineers to build, want maximum control, need the fastest possible first result, hold data that must never leave your own infrastructure, or expect to walk away with everything, the ends of the spectrum have a real case. For most regulated companies, most of the time, they do not.

Facilitator walking a team through assessment and decision phases on a whiteboard
The trade is best decided in a workshop with the people who will live with it. That is a session we run with you.
Honest about the trade

What the middle asks of you

The configurator position, the middle of the spectrum, is not free. It asks you to accept a foundation you did not build, deliberately, in exchange for speed on the agents that differentiate you. It requires process experts willing to shape their own tools and one internal owner for the platform. If you have neither, or if total control of every layer is non-negotiable for you, a different position fits better, and we will say so.

The framework

The fifteen decisions behind every AI strategy

Whether it is written down or not, every company adopting AI answers these fifteen questions, by decision or by default. Seven are about how you work: who builds, who pays, how fast, and how ideas survive the journey from expert to tool. Eight are about what you own: security, compliance, data, evidence, and what happens when things change or end. Reading them costs ten minutes. Answering them by default can cost years.

Before the check

What we mean by an AI strategy

Most companies we meet do not have one yet, and the word carries a different meaning in every room. So here is ours, plainly, before we ask you fifteen questions. A strategy is not a list of pilots and it is not a position on build versus buy. It is four things, written down, that together tell your organisation what to do when nobody senior is present.

The four parts

One objectiveWhat the organisation is trying to achieve with AI, in a single sentence, with a date attached. If it could be said by any company in your industry, it is not yet an objective.
A few business goalsThe concrete outcomes that would show the objective was met. Two to four of them. Each one measurable by someone outside the project.
Five or six policiesThe standing rules that decide the hundred smaller questions nobody will escalate. A policy is a rule you could hand to a team lead who then makes the call without you.
Measurement pointsWhat you will read to know whether the policies are working, and how often you will read it. Chosen before you start, not after the first result arrives.

A worked example

One company's strategy, not a template. Yours will differ in every line. It is here because a shape is easier to argue with than a definition.

Objective

Take a fifth of the documentation effort out of our quality organisation within eighteen months, with every output defensible on inspection day.

Business goals

Two regulated processes running with validated AI support by the end of Q3, measured in hours returned per week.
No audit finding attributable to AI-supported work.
One named internal owner and at least four people able to build unaided by year end.

Policies

Start where the work is repetitive and the source of truth is already approved. Novel judgment stays with people.
Choose candidates by expected hours returned, not by how interesting the technology is.
Pair one process expert with one specialist on every build, so the knowledge ends up inside the company rather than in a supplier's account team.
Assume every regulation that could apply does apply, until legal says otherwise in writing.
Free the people doing this from other duties. Nobody builds a validated agent in the margins of their day job.

Measurement points

Hours returned per week, per process.
Time from idea to validated agent in production.
Share of agent output accepted by reviewers without rework.
Number of people able to build without help.
Audit findings attributable to AI-supported work.
Where the strategy check fits. Of the five policies above, exactly one is about where the capability comes from and who builds what. That is the policy our fifteen decisions cover, and nothing else. The check will not write your objective, choose your goals or set your measurement points, and any tool that claims to do all four in four minutes is selling you something. We would rather be precise about our scope than generous about it.
AI strategy check

Sanity check your AI strategy in four minutes

Fifteen decisions locate where your build-adopt boundary actually runs. An AI agent is software that carries out a defined piece of work, like drafting a document or checking records, within rules you set. No technical background needed, answer for how your organisation really is, not how it should be. Nothing is stored or sent anywhere.

Two things to know before you start. First, scope: this covers one policy inside an AI strategy, the sourcing decision, not the whole thing. Here is what we mean by an AI strategy, and where these fifteen sit inside it. Second, the source: we build and sell a platform, so we have a commercial interest in one of the five positions this check can return. We have written the questions to be answerable honestly in any direction, and every position comes with the case against it. Read the result knowing who wrote it. Prefer to read the questions before answering? See what the fifteen decisions cover.
Audit-ready by design

Built for your regulators, not adapted to them

Audit-ready by design is three separate promises, each with its own evidence. The foundation is built and evidenced as a validated system. The AI running on it is governed as its own layer, with human oversight in the architecture. And the work your teams produce on it is structured to the frameworks your assessors read. Your auditors will test each one separately, so each one stands on its own.

Regimes differ by industry. The obligations underneath them do not: traceability, version control, documented human oversight, change control, and evidence produced on demand. A foundation designed against the standards below is built on those obligations, whatever your own regime calls them.

The foundation is evidenced against
ISO 13485, clause 4.1.6GAMP 5GxP and Annex 1121 CFR Part 11ISO 27001GDPR and EU data residency

Since February 2026, the FDA's QMSR incorporates ISO 13485 into 21 CFR Part 820. The same foundation evidence now serves EU and US expectations.

The AI is governed under
ISO/IEC 42001EU AI Act, Article 50EU AI Act high-risk controlsDraft GMP Annex 22 directionNIS2
Your work products are structured to
EU MDR and IVDRISO 14971IEC 62304 and 62366-1ICH and GMP frameworks

These are frameworks the agents are fluent in, with traceability from requirement to evidence. They are not certifications of the platform. Your assessor knows the difference, and so do we.

Six commitments

What you can hold us to

EU data residency

Data and operations stay in jurisdiction by design. No dependency on a non-EU parent's hosting choices or legal reach.

Deployer duties, met on schedule

Under the EU AI Act, a company that uses AI in its operations is a deployer, with a duty to monitor and oversee it. Transparency duties apply from August 2026 and the high-risk control set from December 2027. The platform's built-in monitoring does the watching, you set the limits, and the whole arrangement is documented for inspection, built to those dates rather than promised for them.

One trail, one system of record

A complete, regulated-grade audit trail records every agent action, configurable to your auditors' expectations rather than pieced together from separate systems.

Validation pathway

Validation means proving a tool is suitable for its intended use, and holding the evidence that says so. Agents validate against an existing, documented foundation, so that evidence is reusable rather than rebuilt each time, and every platform release ships revalidated, which keeps it current. Your change control covers only what you built.

Your logic stays yours

Agent definitions, validation criteria and audit history are contractually exportable. Lock-in is limited to the foundation layer, the part that never differentiated you from competitors.

Straight answers

No absolute compliance claims. Compliance is a shared outcome: we bring the qualified foundation and the documentation, you bring your process context and validation decisions.

Straight answers, in practice

Four claims you will not hear from us

A compliance page that only adds badges is easy to write and hard to trust. These are the claims we leave off, and what we say instead.

Not "compliant out of the box"

No system is. Your validated state depends on your intended use, your processes and your decisions. We shorten the path and carry the platform-level evidence. The destination is shared work.

Not "certified against ISO 14971"

The platform is not a medical device and does not perform risk estimation as a regulated function. It produces risk management files structured to ISO 14971, with traceability from hazard to control to verification. That claim you can check.

Not "AI that decides for you"

Generative AI does not make GMP-critical decisions on this platform. Draft Annex 22 points that way, and the architecture got there first: agents draft, check and evidence, your people decide and sign.

Not "AI Act ready"

Too vague to verify. We name the articles, the duties and the dates instead, so you can hold us to them.

On inspection day

What your auditor sees

One system of record. Every agent has a documented definition, a validation file against the qualified foundation, and a complete trail of what it did, when, and under whose oversight. You answer questions from your own records, not from a vendor's black box.

TimestampAgentActionRecordOversight
2026-07-08 08:41:12Literature search agent v2.0Source search across approved literatureCAPA-2026-039Read only, logged
2026-07-08 09:14:03CAPA drafting agent v1.3Draft created from approved sourcesCAPA-2026-041Pending review, QA
2026-07-08 09:14:04CAPA drafting agent v1.3Source list logged, 3 documentsCAPA-2026-041Attached to record
2026-07-08 09:14:05Quality monitoringOutput scored against your criteriaCAPA-2026-041Within limits
2026-07-08 09:52:30CAPA drafting agent v1.3Draft created from approved sourcesCAPA-2026-039Pending review, QA
2026-07-08 09:52:33Quality monitoringConfidence below your thresholdCAPA-2026-039Flagged for review
2026-07-08 10:02:47Human reviewerDraft reviewed and approvedCAPA-2026-041M. Sørensen, QA
2026-07-08 11:18:09Human reviewerDraft returned with commentsCAPA-2026-039A. Lindqvist, QA
2026-07-08 11:47:22CAPA drafting agent v1.3Revision created, prior version retainedCAPA-2026-039Pending review, QA
2026-07-09 06:00:00Platform release 4.2Foundation revalidatedVAL-FND-4.2MugAIn, documented

Excerpt, illustrative. The record changes with the industry, the trail does not. Every agent action lands in one exportable trail, configurable to your auditors’ expectations.

Ask us the hard questions before your auditor does. Book a conversation →

Regulatory watch

The ground moves. We build to it.

Audit-ready by design means designed against where the rules are going, not where they were. Four dates the platform is built to.

February 2026, in force

The FDA's QMSR incorporates ISO 13485:2016 into 21 CFR Part 820. One quality standard now serves both jurisdictions, and so does the foundation evidence.

Mid 2026, expected

The revised EU GMP Annex 11 and the new Annex 22 on AI reach final publication. The platform is designed against the drafts, not waiting for the print.

August 2026

EU AI Act Article 50 transparency obligations apply. Met at the platform level and documented for your file.

December 2027

High-risk obligations apply to stand-alone AI systems, with rules for AI embedded in regulated products following in August 2028. The control set is architected now.

Colleagues working together around a laptop in a bright office
About MugAIn Group

Built in Denmark, for the EU's most regulated industries

MugAIn Group ApS builds the MugAIn Platform, an AI development platform for organisations whose work is regulated or business-critical. The team combines platform engineering, applied AI and deep regulatory-commercial experience from the medical device and pharma value chain.

Portrait of Michael Møllmann

Michael Møllmann

CEO and Co-founder. Leads the company and its direction.
LinkedIn profile

Portrait of Jens Jepsen

Jens Jepsen

CTO and Co-founder. Leads platform engineering and architecture.
LinkedIn profile

Portrait of Phillip Kroll-Møller

Phillip Kroll-Møller

CPO and Co-founder. Leads platform deployment and customer experience.
LinkedIn profile

Portrait of Mark Lindhardt

Mark Lindhardt

CRO and Partner. Leads sales, marketing and business development.
LinkedIn profile

Ecosystem

Who we work with

We make sure the platform carries our customers’ long-term adoption and the requirements that come with it. Our partners extend what that is worth: direction before the first agent, implementation and support after it.

Vision and mission

AI is for everyone, also at work

Outside work, AI already helps people write, plan and learn. We want the same to be true inside regulated and business-critical work.

Our vision
Everyone finds the right AI tools to help them balance effort, time and cost. Not the biggest tool or the newest one, the right one for the work in front of them.
Our mission
To make AI available to everyone. In our corner of the world that means the process experts in regulated companies, who deserve tools they can shape themselves without becoming developers or compliance officers.

Our values carry this into the daily work. You will meet them in every conversation with us.

Our values

Five values you can expect from us

Courage grounded in expertise

We move early on new AI capability, but only where our regulatory and process knowledge tells us it will hold up under inspection.

Trust before technology

Nothing we ship asks you to take our word for it. The audit trail, the documentation and the honest answer come before the demo.

Everyday ambition

The measure of AI is not what it does on a stage but what it does on a Tuesday, for the person running the process.

Straight answers

We say what the platform does, what it does not do, and when we are not the right fit. A short honest conversation beats a long sales cycle.

Responsibility stays human

AI carries out the work, people carry the accountability. We design the platform so that this line never blurs.

Next step

See whether the configurator position fits you

Four minutes, fifteen decisions, and a map of where your build-adopt boundary runs. Or skip straight to a conversation.

Contact

We would rather meet where the work happens

The best conversations start on your site, in front of the actual process. You are also welcome to visit us in Copenhagen.

Email

info@mugaingroup.com
We reply within one working day.

Phone

+45 29 10 09 01
Weekdays, Copenhagen hours.

Office

MugAIn Group ApS
Vestre Teglgade 15
2450 København SV, Denmark
CVR 46218701

What happens next

How a first conversation runs

1

A short call

Thirty minutes. You describe one process that eats your experts' time, we tell you honestly whether an agent fits it and what it would take.

2

A visit to the work

We come to your site and look at the actual process with the people who run it. The mapping happens where the work happens.

3

A posture workshop

Half a day with the people who will live with the decision. You leave with your position on the build-adopt spectrum and a concrete first agent candidate.

Not ready to talk yet? Take the strategy check first, it takes four minutes →