Artificial intelligence is entering pharmaceutical production/quality processes, data analysis, process monitoring, and other controlled processes. Nonetheless, introducing AI into a GxP landscape raises a pivotal question: how do businesses apply AI while preserving product quality, patient safety, data integrity, and regulatory oversight?

To address pharmaceutical manufacturing and artificial intelligence, the EU GMO Annex 22 is being refined to cover AI. The 2025 draft proposed those expectations related to AI model selection, training, validation, performance, data quality, intended use, human oversight, change control, and ongoing monitoring. Annex 22, however, is still in development as of September 2026 and cannot yet be regarded as final, effective GMP guidance.

To pharmaceutical firms, that is no waiting around. Companies considering AI in GxP settings must already be developing risk-based governance, validation plans, data controls, lifecycle management, and teams with the expertise to show that AI is appropriate for its regulated application.

What Is EU GMP Annex 22 and Why Is It Being Developed?

The utilisation of AI by the pharmaceutical industry has resulted in challenges not always explicitly covered under the controls of traditional computerised systems. The conceptual EU GMF Annex 22 contains AI-specific advice, in addition to the more universal computerised-system framework, Annex 11.

A Dedicated Framework for Artificial Intelligence

In July 2025, the European Commission gave a draft copy of Annex 22 to stakeholders to discuss. It is the result of PIC/S replacing the EMA GMDP Inspectors Working Group collaboration with the wider updates to Annex 11 and Chapter 4.

The aim is to sustain technological innovation and maintain product quality and patient safety.

Focus on Pharmaceutical Manufacturing

The aim is to sustain technological innovation and maintain product quality and patient safety.

Dwelt upon Pharmaceutical Manufacturing.

The 2025 draft focuses on AI models used to make medicinal products and active substances, specifically on essential applications directly related to patient safety, product quality, or data integrity.

Firms must not, however, take Annex 22 as an omnipurpose manual on all the applications of AI within an enterprise.

Annex 22 Works Alongside Annex 11

The draft explains that Annex 22 provides further guidance on computer systems where AI models are integrated. Therefore, AI governance cannot be isolated of wider computerised-system lifecycle controls.

Other considerations include validation, data integrity, security, suppliers, changes and system management.

The Guidance Is Still Evolving

In October 2025, the 2025 consultation concluded. The EMA then held an expert workshop in June and July 2026 to gather more evidence on areas such as generative AI, probabilistic models, guardrails, cybersecurity, and off-the-shelf AI services.

Pharma organisations must remember to oversee the finalisation process instead of presuming that all of the provisions of the consultation draft will not be altered.

Preparation Should Begin Before Finalisation

The ethical implication of letting AI governance mature before creating it is that companies may be left scrambling to implement their own controls for technologies already integrated into regulated systems.

The new direction can instead be utilised by organisations to bolster AI inventories, intended-use assessment, risk management, validation plans, data governance, and lifecycle controls.

What Does Draft Annex 22 Mean for AI in GxP Environments?

The draft indicates that AI authentication cannot be reduced to demonstrating software functionality. Organisations should be aware of the model, how it is intended to be used, what kind of data will be utilised by it, how it will perform, and what the repercussions of inaccurate outputs are.

Clearly Define the Intended Use

Assurance activities should be based on the potential consequences of AI breakdown. Take potential harm to patient safety, product quality, and data integrity into account in risk assessment. The higher the potential impact, the higher the controls, testing, review, and lifecycle controls.

Understand and Assess GxP Risk

Assurance activities should be based on the potential consequences of AI breakdown.

Risk assessments should consider potential harm to patient safety, product quality, and data integrity. The higher the potential impact, the higher the controls, testing, review, and lifecycle controls.

Establish Appropriate Model Performance

AI is not worth using based on its output alone. Companies must set performance requirements aligned with the intended use and ensure benchmarks reflect that the model performs well against those requirements.

Maintain Human Oversight Where Necessary

Human discretion is especially necessary with AI outputs that may interfere with regulated decisions or with models that demonstrate uncertainties about making such decisions.

Depending on the intended use, system design, and risk involved, add the right level and type of oversight rather than treating it as an unintended approval step.

Control the AI Throughout Its Lifecycle

In pharmaceutical AI compliance, only initial validation is part of the initial validation. To monitor the performance of the models and manage changes, investigate issues, and make sure the AI remains within the approved and strictly used bounds, companies require mechanisms in these areas.

Data Quality and AI Model Validation Under Annex 22

AI performance depends heavily on data. This makes training, test, and operational data key components of an effective Annex 22 compliance strategy, not just technical concerns for data science teams.

Training Data Must Be Suitable

Organisations need confidence that data used to train a model is appropriate for its intended application.

Poor-quality, unrepresentative, incorrectly labelled, or insufficient data can undermine model performance even when the underlying algorithm appears technically sophisticated.

Training and Test Data Need Separation

Validation should provide an independent assessment of performance rather than simply demonstrating how well a model handles information it has effectively already encountered.

Appropriate management of test data is therefore an important part of generating meaningful evidence.

Data Processing Needs Control

Cleaning, transformation, feature selection, labelling, exclusion, and other processing activities can influence model behaviour.

Companies need visibility and control over the data pipeline, not just the finished AI model.

Performance Metrics Need Context

Accuracy alone may not adequately describe whether an AI model is suitable.

Metrics should reflect the intended use and consequences of different failure types. The organization should be able to explain why selected metrics and acceptance criteria provide meaningful assurance.

Data Governance Extends Into Operation

Data considerations do not disappear after deployment. Operational inputs, data shifts, quality problems, and changing process conditions can affect AI performance and should therefore form part of ongoing oversight.

How Should Pharma Companies Approach Annex 22 AI Validation?

A competent Annex 22 AI strategy must link existing GxP validation disciplines to AI-related risks. The idea is not to have documentation of AI once it is developed but to develop confidence throughout its full lifecycle.

Start With AI Inventory and Classification

Firstly, organisations must have an idea of where AI is actually in use. An inventory can identify AI-enabled applications, models, suppliers, intended use, business owners, GxP relevance, and potential impact. This ensures ungoverned AI does not enter vital processes unnoticed.

Perform Risk-Based AI Validation

Base validation effort on intended use and the consequences of failure.

There is more evidence, controls, testing and monitoring needed in higher risk models. Lower-risk applications can warrant an alternate assurance approach in having a documented assessment.

Define Validation Before Deployment

Before an AI model can be released as controlled, it needs acceptance criteria, performance measures, a test strategy, data requirements, limitations, and responsibilities. Retrospective validation can make it much harder to recreate defensible evidence.

Test Realistic and Challenging Scenarios

Do not target ideal inputs in testing. Examples of things teams should consider in the context of model risk include anticipated operating conditions, edge cases, predictable failures, incorrect inputs, and other scenarios that may apply to the model.

Document Validation Decisions

The organisation ought to be in a position to clarify why the AI is deemed fit to be utilised in the desired GxP application. A coherent validation story should include risk assessments, testing, data controls, performance evidence, approvals, limitations, and lifecycle arrangements.

Maintaining AI Compliance After Go-Live

The necessity to be particularly careful in regards to the perpetuation of model performance is among the most significant distinctions between AI assurance and traditional thinking in software. GMP AI needs lifecycle management, not a single time validation.

Monitor Model Performance

In their operation, organisations must have the relevant mechanisms that will be used to find out whether the AI is still performing as per the expectations that were initially set.

Model behavior can change due to changes in input data, processes, operating conditions, or other factors.

Apply Formal Change Control

Evaluate any modifications to models, configurations, data pipelines, surrounding applications, or intended use, as they may affect GxP.

The evaluation should determine whether further testing, validation, approval, or other controls are necessary.

Define Human Review Procedures

When the management strategy involves human control, clarify responsibilities.

Staff need relevant knowledge to appraise outputs rather than blindly following an AI-generated recommendation just because the robot created it.

Investigate AI Failures and Deviations

Failure to meet expectations in performance, unexpected results, data issues, or other failures must be addressed through proper investigation and a quality response.

The underlying causes should be addressed by corrective actions and the amendment given to the possible potential influence to the regulated activities.

Maintain Supplier Oversight

Third-party AI technologies will be adopted by many organizations instead of creating every model in-house.

Suppliers’ capabilities, responsibilities, visibility of changes, data management, service contracting, and potential evidence should all be viewed in the context of the overlaying AI control strategy.

What About Generative AI, LLMs and Dynamic Models?

In this regard, firms must take extra care when interpreting the draft EU GMP AI specifications, as the regulatory discourse is changing.

The 2025 Draft Was Restrictive

The consultation draft addressed using machine-learning models with deterministic outcomes in critical GMPs. It also omitted dynamic models that learn continuously when used and opined that probabilistic models must not be employed in challenging GMP applications.

Generative AI Was Outside the Critical-Use Scope

The 2025 draft also did not mention generative AI and large language models as key GMP uses. For non-critical purposes, it emphasised the role of humans in ensuring that outputs are appropriate towards their intended application.

Regulatory Discussion Has Continued

The June-July 2026 workshop of EMA was a specific discussion on whether technologies, including generative AI, LLMs, dynamic models, and probabilistic systems, could be facilitated by appropriate controls.

Guardrails Are Becoming an Important Question

The EMA workshop looked at the evidence required to prove that AI guardrails are effective, such as validation evidence, stress testing and failure analysis, human supervision, and continuous control.

Companies Should Avoid Premature Assumptions

The workshop discussion should not be perceived by organisations as a go-ahead to implement GenAI in very serious GMP settings.

The use cases of AI must also be cautiously categorised, risk-examined, managed, and contrasted to present and potential requirements based on the existing requirements and new guidelines until the local regulatory stance has been settled upon.

How Pharma Connections Supports AI Validation and Annex 22 Readiness

Data scientists are not the only ones who are required to prepare AI regulatory compliance in pharma. Organisations should find professionals who are able to reach the AI technology to CSV, CSA, quality risk management, GxP software testing, data integrity, validation, and lifecycle adherence.

AI Validation Support

Pharma Connections helps pharmaceutical and life sciences organisations design risk-based strategies to validate AI-enabled GxP applications based on their intended use, impact, technology, and relevant compliance standards.

Annex 22 Readiness

Companies that are preparing for emerging EU GMP Annex 22 expectations can boost AI inventories, risk assessment, validation strategy, testing, documentation, lifecycle controls, and governance prior to the actual requirements coming into effect.

CSV, CSA, and GxP Software Testing

Pharma Connections supports CSV, CSA, risk-based testing, software assurance, validation documentation, and GxP application testing to supplement larger AI validation programs.

AI Validation Resources and Staff Augmentation

Companies with inadequate internal skills can outsource their quality, Validation, IT, and compliance departments to dedicated sources on AI and other GxP technology endeavours.

Training Professionals for AI-Enabled GxP Environments

Pharma Connections trains specialists in CSV, CSA, GxP software testing, risk-based validation, and new AI validation concepts too, contributing to the establishment of a useful capabilities base to pharmaceutical companies, MNCs, consulting firms, and other employers in the life sciences.

Conclusion

AI can create significant opportunities for pharmaceutical operations, but regulated adoption requires confidence that technology remains controlled, validated, monitored, and suitable for its intended use.

Although EU GMP Annex 22 is still under development, its direction makes several priorities clear: AI governance, intended use, risk assessment, data quality, model validation, performance criteria, human oversight, change control, and lifecycle monitoring deserve attention now.

Pharma Connections helps pharmaceutical and life sciences organisations prepare for this changing compliance environment through AI validation, Annex 22 readiness, CSV, CSA, GxP software testing, validation resources, and staff augmentation.

Don’t wait until AI systems are deeply embedded in regulated operations to decide how to control them.

Connect with Pharma Connections to assess your AI-enabled GxP applications, strengthen validation strategies, and prepare your teams and systems for emerging Annex 22 expectations.

FAQs

1. What is EU GMP Annex 22?

EU GMP Annex 22 is proposed guidance focused on artificial intelligence used in pharmaceutical manufacturing. As of September 2026, it remains under development and should not be described as a finalised, effective GMP annex.

2. What does draft Annex 22 cover?

The 2025 draft addresses areas including AI intended use, model selection, training and validation, data quality, performance metrics, testing, human oversight, change control, and ongoing performance monitoring.

3. Does Annex 22 apply to generative AI and LLMs?

The 2025 consultation draft excluded generative AI and LLMs from critical GMP applications. However, EMA continued discussing potential approaches for GenAI, probabilistic, and dynamic models during its 2026 expert workshop, so companies should monitor the final guidance.

4. How should pharmaceutical companies prepare for Annex 22 compliance?

Companies can begin by identifying GxP AI use cases, defining intended use, performing risk assessments, strengthening data governance, establishing validation and testing strategies, defining human oversight, and implementing lifecycle monitoring and change controls.

5. Does Pharma Connections provide AI validation support?

Yes. Pharma Connections supports pharmaceutical and life sciences organisations with AI validation readiness, CSV, CSA, GxP software testing, validation resources, staff augmentation, and preparation for emerging AI-related GxP expectations.

Post a comment

Your email address will not be published.

Related Posts