DSHEA or Drug? How AI Audit Tools Catch the Marketing Claims That Trigger FDA Enforcement
FDA's intended use doctrine can reclassify a supplement as a drug based on marketing copy alone. Here's how AI audit tools catch the violations before FDA does.
Your product formula hasn’t changed. Your ingredients are the same batch you’ve been running for three years. And then, one Tuesday, a warning letter lands in your CEO’s inbox — because your website stated that your magnesium supplement “helps reduce symptoms of depression.”
That single sentence — not the product, not the manufacturing process, not the lab results — reclassified your dietary supplement as an unapproved new drug under the FD&C Act. The formula is irrelevant. The clinical data is irrelevant. What matters, under FDA’s intended use doctrine, is what your marketing said.
This is not a hypothetical. FDA’s Office of Dietary Supplement Programs logged more than 100 warning letters to supplement manufacturers and distributors in a recent fiscal year, with the majority citing unauthorized disease claims embedded in product websites, Amazon listings, downloadable guides, and — critically — content that the company’s quality team never reviewed at all. The agency uses systematic digital monitoring, including third-party web crawl contractors, to find this language. And in our regulatory compliance consulting work at Aurora TIC, the pattern is almost always identical: the quality team signed off on the label, but nobody audited the marketing ecosystem. That gap is exactly what AI audit systems are now built to close.
Why the DSHEA Boundary Is Harder to Hold Than Most Teams Assume
The Dietary Supplement Health and Education Act of 1994 created a specific statutory carve-out within the FD&C Act’s drug framework. It permits manufacturers to make structure/function claims — statements describing how a nutrient or ingredient affects the normal structure or function of the human body. “Supports healthy immune response.” “Promotes bone density.” “Contributes to normal cognitive function.” These are lawful claims, provided the manufacturer submits a 21 CFR § 101.93 notification to FDA within 30 days of first marketing and includes the required disclaimer on the label.
What DSHEA does not permit is a disease claim — any language that asserts, implies, or is reasonably understood to mean the product diagnoses, cures, treats, mitigates, or prevents a specific disease or condition. That boundary is defined by FD&C Act Section 201(g)(1), which classifies as a “drug” any article intended for use in the diagnosis, cure, mitigation, treatment, or prevention of disease — regardless of what the label says it is.
The operational difficulty is this: the difference between a lawful claim and an unlawful one is often six words. “Supports healthy blood glucose levels” is a permissible structure/function claim. “Helps manage blood sugar in people with diabetes” is a drug claim. The word “diabetes,” in that context, is enough to trigger Section 201(g)(1).
FDA’s 2009 guidance on substantiation for dietary supplement claims outlines a multi-factor test for evaluating claim intent, but that guidance is now 17 years old. The marketing channels it needs to govern — TikTok product videos, Amazon A+ content modules, QR-coded landing pages, influencer licensing agreements — didn’t exist when it was written. The promotional surface area for supplement brands has expanded roughly tenfold since DSHEA passed. FDA’s enforcement staff has not grown at the same rate.
The 3 Zones Where Prohibited Claims Hide — and Where Manual Reviews Fail
In regulatory compliance consulting engagements with mid-size supplement and nutraceutical brands, we consistently find prohibited disease claims clustering in three places that routine label audits miss entirely.
Digital marketing assets. Product pages, FAQ sections, and downloadable ingredient guides routinely contain disease-specific language that a marketing manager approved without regulatory review. A label might carry a perfectly compliant claim, while the same product’s “clinical evidence” tab links to a PDF stating that the ingredient “reduced HbA1c levels in Type 2 diabetic subjects by 0.8% over 12 weeks.” That PDF — even though it cites a published peer-reviewed study — constitutes promotional labeling under FDA’s framework, and disease-specific outcome data in that context can constitute an implied drug claim for the product it describes.
Third-party marketplace listings. Amazon, Walmart.com, and iHerb all allow seller-populated product descriptions that FDA treats as labeling under the FD&C Act’s Section 201(m) definition. A company might maintain perfectly compliant factory labels while carrying entirely non-compliant marketplace copy written by an e-commerce specialist who has never opened 21 CFR Part 101. Warning letters triggered by Amazon listing content — content the brand’s quality team was unaware existed in its current form — are not unusual. They’re routine.
Testimonials and endorsed user-generated content. A testimonial posted on a brand’s website or social feed stating “this supplement cured my chronic migraines” can, under FDA’s 2009 endorsement and testimonial guidance, be attributed to the brand as an implied disease claim. Companies that select, feature, or amplify such testimonials bear responsibility for the claims those testimonials make. Most quality teams have no systematic process to archive or monitor this content at scale.
How AI Audit Tools Flag Disease Claims Before FDA Does
The traditional approach to claim compliance involves a trained regulatory affairs professional reading marketing copy line by line against a working knowledge of prohibited language. At $150–$250 per hour, with most supplement brands generating 20 to 40 new content assets per month, this is expensive, slow, and structurally incomplete — nobody can manually audit a brand’s entire digital footprint on a rolling basis.
AI-augmented audit tools change the cost structure. Aurora TIC’s DeepGMP regulatory analysis module approaches this differently:
-
Full ecosystem ingestion — the system pulls label PDFs, scrapes all product URLs, retrieves active third-party marketplace listings, and processes archived email and PDF promotional materials. Not just the physical label; the entire promotional surface area.
-
Claim intent classification against FDA’s disease-term taxonomy — DeepGMP runs each content unit against a reference taxonomy of more than 700 disease and condition terms that FDA’s enforcement teams actively flag, assigning a risk score at the sentence level, per asset, per SKU.
-
Contextual semantic differentiation — the system distinguishes “supports heart health” from “reduces the risk of coronary artery disease” not through keyword matching alone but through sentence-level semantic analysis. This dramatically reduces false positives while catching the indirect and implied disease claims that simple keyword filters miss entirely.
-
Audit-ready output — flagged content is delivered in a structured memo format with risk severity ratings, the specific FDA basis for flagging, and suggested compliant rewrites. This output is formatted for direct use in a pre-submission regulatory review or an internal CAPA response.
In a recent engagement with a nutraceutical brand managing 87 active SKUs across 4 sales channels, this approach surfaced 23 instances of probable disease claims in marketing assets. A manual audit conducted six months earlier found zero. That gap doesn’t reflect on the auditor’s competence — it reflects the fact that the manual review covered the label and the primary product page, while the AI sweep covered the entire ecosystem including marketplace listings and gated PDF content the regulatory team didn’t know were being indexed.
What a Defensible Structure/Function Claim Program Actually Looks Like
Three components have to work in parallel for a supplement brand to hold its DSHEA classification under sustained scrutiny.
Pre-launch claim review means every marketing asset — not just the label — goes through classification before it’s published. Under 21 CFR § 101.93(a), structure/function claims require notification to FDA within 30 days of first marketing. If AI review flags a claim as disease-implicating at the pre-launch stage, that is the last moment to reclassify and rewrite. Not after a Form FDA 483, and certainly not after a warning letter has been issued and publicly posted to FDA’s database.
Continuous monitoring means running scheduled sweeps — weekly at minimum for brands with active marketing programs — across all channels where new content is published. A quarterly label audit is structurally inadequate when your e-commerce team is publishing new content daily. AI-powered continuous monitoring makes weekly sweeps operationally feasible at a cost that quarterly manual reviews can’t match.
Documented substantiation files mean having a per-claim evidence dossier that links each structure/function claim to what FDA describes as “competent and reliable scientific evidence” — in practice, controlled human clinical trials in the specific population the claim addresses. If that file doesn’t exist, the claim is legally vulnerable regardless of how carefully the language is drafted.
These three elements together form the core of a mature regulatory compliance consulting framework for supplement marketing — and they are the standard we work from in every labeling and claim audit engagement.
The actionable takeaway: if your last compliance review was confined to the physical label, you’ve audited roughly 20% of your actual regulatory exposure. The warning letters that appear on FDA’s public database aren’t usually triggered by a misworded label claim that your RA team caught and approved in good faith — they’re triggered by a product description written by a contractor in 2022 that nobody has touched since. Build a process that covers the full promotional surface area. Or use AI tools to do it for you. The cost of a pre-market sweep with Aurora TIC’s DeepGMP starts at $500. The cost of an FDA warning letter — including remediation, outside counsel, and the platform suspensions that typically follow — runs $50,000 to $250,000 before it’s resolved. The math on preventive compliance is not complicated.
Written by Sam Sammane, Founder & CEO, Aurora TIC | Founder, Qalitex Group. Learn more about our team
Reserve early access to our AI audit tools — including DeepGMP for promotional claim classification. Contact us
Related from our network
- Supplement Label Testing and Potency Verification at Qalitex Laboratories — Third-party analytical testing to build the substantiation file your structure/function claims require.
- NHP Label Compliance Under Health Canada at Androxa — Canadian natural health product regulatory support, including NHPD labeling review and GMP compliance for the Canadian market.
Benötigen Sie Hilfe bei der Auswahl des richtigen Labors?
Aurora TIC verbindet Hersteller und Marken mit akkreditierten Prüflaboratorien — schnell, kostenlos und auf Ihr Produkt zugeschnitten.
Kostenloses Angebot anfordern