Pharmaceutical manufacturing and regulated technology environments are increasingly shifting toward artificial intelligence, but implementing an AI model is only one part of the problem.
Firms must also show that the technology is appropriate for its intended use, has been sufficiently tested, is properly controlled, and is continuously monitored. This is where Annex 22 AI validation is becoming increasingly important.
The proposed EU GMO Annex 22 sets AI-related expectations for critical applications that are directly applicable to pharmaceutical production, especially when AI can directly affect patient safety, product quality, or data integrity.
Although Annex 22 is still being developed as of September 2026, it creates a strong opportunity for pharmaceutical organisations to prepare their systems before the requirements are finalised.
Companies can start AI inventory, intended use, data quality, model performance, risk management, testing, human oversight, change control, and lifecycle monitoring assessments today, establishing a more robust basis for compliant AI use.
AI validation cannot be performed the same way as software validation. Data and model training create machine-learning functionality and require further considerations for model behaviour, data quality, performance, explainability, and further control.
Any GxP AI validation strategy must start with intended use. Companies must specify what the model is, where it will run, what information it consumes, what its output is, and whether that output will affect a regulated process or decision. Meaningful validation is hard without a clear intended use.
Organisations should evaluate an AI application’s potential to directly or indirectly impact patient safety, product quality, or data integrity.
The greater the potential impact, the more validation, testing, governance, and oversight the application is likely to require.
Validation teams must understand the model, its inputs, outputs, constraints, dependencies, and anticipated behaviour.
The complexity of the technology behind an AI application does not mean it should be made a black box to comply.
Set performance criteria before validation testing, not after reviewing the results. Acceptance criteria must reflect intended usage and effects of faulty predictions or classifications.
AI does not operate independently of the application in which it is embedded. Proper assurance is also required in the surrounding computerised system, interfaces, access controls, electronic records, data flows, infrastructure, and lifecycle controls.
The draft EU GMP Annex 22 AI framework places heavy emphasis on demonstrating model performance through proper data, testing, controls, and evidence. Companies preparing today must apply these principles to their AI projects.
AI performance quality depends on the data used to build the model. Organisations need to understand the relevance of training data, whether it is representative enough and prepared accordingly, and whether it is suitable for use with the model.
Validation should independently challenge model performance. Appropriate separation between test data and data used to train or optimise the model should then be made to ensure testing yields meaningful evidence and does not merely repeat known performance.
Companies should define performance metrics and acceptance criteria, followed by formal validation.
The measures chosen must be sensible for the particular AI application rather than a generic accuracy percentage that can conceal significant failures.
Testing must show model performance under intended-use conditions. Test procedures, data, results, deviations, and conclusions should provide adequate evidence to justify the validation decision.
Where relevant to the model and use case, organizations must decide whether outputs are comprehensible enough and whether confidence information can be used to make the appropriate interpretation and human decision-making.
AI cannot be validated with the same effort because the technology is novel. The level of assurance for intended use and the consequences of failure should be based on sound AI risk management in pharma.
Firms are advised to consider AI failure modes. Examples include wrong classifications, unreliable predictions, unexpected inputs, poor-quality data, inappropriate recommendations, performance degradation, or operating outside the tested use case.
All major failure scenarios must be assessed based on the impact that they may have on the product quality, patient safety, data integrity, and regulated processes. This relates technical AI risks to pharmaceutical quality risk management.
Functions that are more at risk may need more rigorous testing, restrictions, human checks, monitoring, or other precautions.
Controls should address the identified risks rather than being introduced to meet a documentation template.
Where human review is part of the control strategy, companies should clearly define who reviews AI outputs, when intervention is required, and what happens when an output is questionable.
Human oversight must be an actual control, not a nominal approval process.
Validation should also cover risks left behind by the controls.
The organization must be capable of justifying why the rest of the risk is acceptable to the use of the model in GxP.
Preparing for Annex 22 compliance must start with the current technology environment, not wait until a new AI project is validated. Companies should have visibility into where AI currently lives and how those applications are managed.
Determine AI or machine learning applications in controlled manufacturing. Document the system, model, purpose of use, owner, supplier, GxP impact, data dependencies, current validation status, and lifecycle-related responsibilities.
Compare current AI controls with the new demands for intended use, data, testing, performance, explainability, risk, human control, change control, and monitoring.
This can expose weaknesses before they become larger remediation projects.
AI cannot exist outside of pre-established CSV, CSA, Quality, change control, and computerized-system governance.
Instead, organisations should identify which existing controls remain suitable and where AI-specific assurance is needed.
Most AI functions will be provided by vendors, SaaS apps, cloud services, or third parties providing models.
Organisations must understand supplier duties, model modifications, accessible validation data, data management, service plans, and how suppliers communicate the significance of modifications.
Validation decisions should be traceable and defensible. Teams should be able to explain intended use, risks, data selection, testing, acceptance criteria, performance, limitations, human oversight, and ongoing controls without reconstructing the story after an inspector asks.
An AI model that meets acceptance criteria before deployment can still pose future risk. AI life cycle management thus emerges as a key component in ensuring an approved and regulated GxP system.
Organisations should set up appropriate mechanisms to check whether deployed models remain within acceptable boundaries.
Model behaviour may be influenced by changes in the operational data or process conditions.
Monitoring should help pinpoint serious deterioration or unforeseen behaviour early enough to prevent an intolerable GxP effect.
Use specific limits to trigger escalation, investigation, and intervention when performance exceeds acceptable levels.
Apply appropriate change control to updates to models, configurations, datasets, interfaces, infrastructure, or intended use. Consider the potential validation impact before implementation.
Not all changes need revalidation, but major changes may require further testing or confirmation. Base the amount of revalidation on the severity of the change and the risk involved.
Unexpected model behaviour, incorrect outputs, data problems, monitoring alerts, and other significant incidents should enter appropriate investigation and Quality processes. This helps ensure AI system adherence during operation, not just at initial release.
Organisations need not wait for Annex 22 to be published to strengthen AI governance. An organised readiness system can help teams identify existing gaps and remain flexible as regulations change.
Establish responsibility in quality, validation, IT, data science, system owners, process owners, cybersecurity, and suppliers.
All parties must know who is responsible for validation decisions and long-term AI control.
Determine the intended use, risk evaluations, performance expectations, testing methods, acceptance criteria, and the evidence to use before deployment.
Validation must prove appropriateness, not merely produce documentation.
Establish training controls, testing controls, operational data controls, data processing controls, data quality controls, data integrity controls, data lineage controls, and data change controls.
It is hard to give AI assurance without trust in the data the model is based on.
Identify monitoring, human control, incident control, change control, periodic review and revalidation triggers. These controls help sustain the proven state once deployed.
Make evidence current, organised, retrieved, and understandable. System owners and validation teams must be ready to document why the AI application remains appropriate for its approved GxP use.
Technical model development is not the only way to comply with AI. Companies need validation professionals who understand how AI risk, computerised systems, Quality, testing, and GxP lifecycle controls interact.
Pharma Connection helps pharmaceutical and life sciences companies build AI-ready GxP systems aligned with future Annex 22 requirements.
Pharma Connections may assist with Annex 22 AI validation preparedness through intended-use assessment, AI risk evaluation, validation strategy, testing, documentation, gap assessment, and lifecycle-control planning, all aligned with the specific application.
AI-based applications can still be found in broader computerised-system settings. Pharma Connections supports CSV and CSA to help organisations bridge AI-specific validation with existing GxP system assurance.
We offer risk-based GxP application testing, validation testing, test evidence, traceability, and software assurance services to regulated technology projects.
Pharma Connections helps companies assess validation evidence, identify compliance gaps, strengthen documentation, and enable AI-based and other GxP applications to pass regulatory audits and inspections.
Any organisation that requires extra skills can access CSV, CSA, GxP testing, validation, and emerging AI validation solutions to expand internal Quality, IT, and compliance teams for individual projects.
Annex 22 AI validation will shift AI assurance from a single technical test to a managed GxP lifecycle based on intended use, data quality, risk, model performance, testing, human oversight, change management, and ongoing monitoring.
Although EU GMO Annex 22 is still in progress, the overall direction of AI systems can help pharmaceutical companies assess current controls, address validation loopholes, and build stronger compliance foundations now.
Pharma Connections assists pharmaceutical and life sciences organisations to prepare for AI validation, Annex 22 preparation, CSV and CSA services, GxP software testing, audit and inspection support, and specialised validation resources.
As AI enters your regulated tech space, compliance planning can’t wait until the last annex.
Pharma Connections can connect to evaluate your AI-enabled GxP systems and develop a risk-based Annex 22 readiness plan with a practical approach.
Annex 22 AI validation is the process of documenting confidence that AI models in applicable GMO applications are appropriate for their intended use through relevant risk assessment, data controls, performance testing, performance evaluation, and lifecycle management.
Annex 22 is still in development as of September 2026. The 2025 consultation is complete, and in 2026, the EMA resumed collecting expert evidence to update the guidance, which is evolving.
Companies should consider intended use, GxP impact, model risks, training and test data, performance criteria, test evidence, explainability where applicable, human oversight, change control, monitoring, and lifecycle management.
Firms can adopt AI-powered GxP software, conduct gap analyses, strengthen data management, develop risk-based validation approaches, audit suppliers, implement lifecycle controls, and prepare evidence.
Yes. Pharma Connections assists pharmaceutical and life sciences companies with AI validation preparation, CSV, CSA, GxP software testing, validation documentation, audit and inspection preparation, and validation resource supplementation.
Pharma Connections, Established on February 14, 2019, A Product of Eduteq Connections Pvt Ltd (An ISO 9001:2015 certified company), is dedicated to providing training and upskilling opportunities for Life science Professionals.
Read More