Artificial intelligence is entering pharmaceutical production/quality processes, data analysis, process monitoring, and other controlled processes. Nonetheless, introducing AI into a GxP landscape raises a pivotal question: how do businesses apply AI while preserving product quality, patient safety, data integrity, and regulatory oversight?
To address pharmaceutical manufacturing and artificial intelligence, the EU GMO Annex 22 is being refined to cover AI. The 2025 draft proposed those expectations related to AI model selection, training, validation, performance, data quality, intended use, human oversight, change control, and ongoing monitoring. Annex 22, however, is still in development as of September 2026 and cannot yet be regarded as final, effective GMP guidance.
To pharmaceutical firms, that is no waiting around. Companies considering AI in GxP settings must already be developing risk-based governance, validation plans, data controls, lifecycle management, and teams with the expertise to show that AI is appropriate for its regulated application.
The utilisation of AI by the pharmaceutical industry has resulted in challenges not always explicitly covered under the controls of traditional computerised systems. The conceptual EU GMF Annex 22 contains AI-specific advice, in addition to the more universal computerised-system framework, Annex 11.
In July 2025, the European Commission gave a draft copy of Annex 22 to stakeholders to discuss. It is the result of PIC/S replacing the EMA GMDP Inspectors Working Group collaboration with the wider updates to Annex 11 and Chapter 4.
The aim is to sustain technological innovation and maintain product quality and patient safety.
The aim is to sustain technological innovation and maintain product quality and patient safety.
Dwelt upon Pharmaceutical Manufacturing.
The 2025 draft focuses on AI models used to make medicinal products and active substances, specifically on essential applications directly related to patient safety, product quality, or data integrity.
Firms must not, however, take Annex 22 as an omnipurpose manual on all the applications of AI within an enterprise.
The draft explains that Annex 22 provides further guidance on computer systems where AI models are integrated. Therefore, AI governance cannot be isolated of wider computerised-system lifecycle controls.
Other considerations include validation, data integrity, security, suppliers, changes and system management.
In October 2025, the 2025 consultation concluded. The EMA then held an expert workshop in June and July 2026 to gather more evidence on areas such as generative AI, probabilistic models, guardrails, cybersecurity, and off-the-shelf AI services.
Pharma organisations must remember to oversee the finalisation process instead of presuming that all of the provisions of the consultation draft will not be altered.
The ethical implication of letting AI governance mature before creating it is that companies may be left scrambling to implement their own controls for technologies already integrated into regulated systems.
The new direction can instead be utilised by organisations to bolster AI inventories, intended-use assessment, risk management, validation plans, data governance, and lifecycle controls.
The draft indicates that AI authentication cannot be reduced to demonstrating software functionality. Organisations should be aware of the model, how it is intended to be used, what kind of data will be utilised by it, how it will perform, and what the repercussions of inaccurate outputs are.
Assurance activities should be based on the potential consequences of AI breakdown. Take potential harm to patient safety, product quality, and data integrity into account in risk assessment. The higher the potential impact, the higher the controls, testing, review, and lifecycle controls.
Assurance activities should be based on the potential consequences of AI breakdown.
Risk assessments should consider potential harm to patient safety, product quality, and data integrity. The higher the potential impact, the higher the controls, testing, review, and lifecycle controls.
AI is not worth using based on its output alone. Companies must set performance requirements aligned with the intended use and ensure benchmarks reflect that the model performs well against those requirements.
Human discretion is especially necessary with AI outputs that may interfere with regulated decisions or with models that demonstrate uncertainties about making such decisions.
Depending on the intended use, system design, and risk involved, add the right level and type of oversight rather than treating it as an unintended approval step.
In pharmaceutical AI compliance, only initial validation is part of the initial validation. To monitor the performance of the models and manage changes, investigate issues, and make sure the AI remains within the approved and strictly used bounds, companies require mechanisms in these areas.
AI performance depends heavily on data. This makes training, test, and operational data key components of an effective Annex 22 compliance strategy, not just technical concerns for data science teams.
Organisations need confidence that data used to train a model is appropriate for its intended application.
Poor-quality, unrepresentative, incorrectly labelled, or insufficient data can undermine model performance even when the underlying algorithm appears technically sophisticated.
Validation should provide an independent assessment of performance rather than simply demonstrating how well a model handles information it has effectively already encountered.
Appropriate management of test data is therefore an important part of generating meaningful evidence.
Cleaning, transformation, feature selection, labelling, exclusion, and other processing activities can influence model behaviour.
Companies need visibility and control over the data pipeline, not just the finished AI model.
Accuracy alone may not adequately describe whether an AI model is suitable.
Metrics should reflect the intended use and consequences of different failure types. The organization should be able to explain why selected metrics and acceptance criteria provide meaningful assurance.
Data considerations do not disappear after deployment. Operational inputs, data shifts, quality problems, and changing process conditions can affect AI performance and should therefore form part of ongoing oversight.
A competent Annex 22 AI strategy must link existing GxP validation disciplines to AI-related risks. The idea is not to have documentation of AI once it is developed but to develop confidence throughout its full lifecycle.
Firstly, organisations must have an idea of where AI is actually in use. An inventory can identify AI-enabled applications, models, suppliers, intended use, business owners, GxP relevance, and potential impact. This ensures ungoverned AI does not enter vital processes unnoticed.
Base validation effort on intended use and the consequences of failure.
There is more evidence, controls, testing and monitoring needed in higher risk models. Lower-risk applications can warrant an alternate assurance approach in having a documented assessment.
Before an AI model can be released as controlled, it needs acceptance criteria, performance measures, a test strategy, data requirements, limitations, and responsibilities. Retrospective validation can make it much harder to recreate defensible evidence.
Do not target ideal inputs in testing. Examples of things teams should consider in the context of model risk include anticipated operating conditions, edge cases, predictable failures, incorrect inputs, and other scenarios that may apply to the model.
The organisation ought to be in a position to clarify why the AI is deemed fit to be utilised in the desired GxP application. A coherent validation story should include risk assessments, testing, data controls, performance evidence, approvals, limitations, and lifecycle arrangements.
The necessity to be particularly careful in regards to the perpetuation of model performance is among the most significant distinctions between AI assurance and traditional thinking in software. GMP AI needs lifecycle management, not a single time validation.
In their operation, organisations must have the relevant mechanisms that will be used to find out whether the AI is still performing as per the expectations that were initially set.
Model behavior can change due to changes in input data, processes, operating conditions, or other factors.
Evaluate any modifications to models, configurations, data pipelines, surrounding applications, or intended use, as they may affect GxP.
The evaluation should determine whether further testing, validation, approval, or other controls are necessary.
When the management strategy involves human control, clarify responsibilities.
Staff need relevant knowledge to appraise outputs rather than blindly following an AI-generated recommendation just because the robot created it.
Failure to meet expectations in performance, unexpected results, data issues, or other failures must be addressed through proper investigation and a quality response.
The underlying causes should be addressed by corrective actions and the amendment given to the possible potential influence to the regulated activities.
Third-party AI technologies will be adopted by many organizations instead of creating every model in-house.
Suppliers’ capabilities, responsibilities, visibility of changes, data management, service contracting, and potential evidence should all be viewed in the context of the overlaying AI control strategy.
In this regard, firms must take extra care when interpreting the draft EU GMP AI specifications, as the regulatory discourse is changing.
The consultation draft addressed using machine-learning models with deterministic outcomes in critical GMPs. It also omitted dynamic models that learn continuously when used and opined that probabilistic models must not be employed in challenging GMP applications.
The 2025 draft also did not mention generative AI and large language models as key GMP uses. For non-critical purposes, it emphasised the role of humans in ensuring that outputs are appropriate towards their intended application.
The June-July 2026 workshop of EMA was a specific discussion on whether technologies, including generative AI, LLMs, dynamic models, and probabilistic systems, could be facilitated by appropriate controls.
The EMA workshop looked at the evidence required to prove that AI guardrails are effective, such as validation evidence, stress testing and failure analysis, human supervision, and continuous control.
The workshop discussion should not be perceived by organisations as a go-ahead to implement GenAI in very serious GMP settings.
The use cases of AI must also be cautiously categorised, risk-examined, managed, and contrasted to present and potential requirements based on the existing requirements and new guidelines until the local regulatory stance has been settled upon.
Data scientists are not the only ones who are required to prepare AI regulatory compliance in pharma. Organisations should find professionals who are able to reach the AI technology to CSV, CSA, quality risk management, GxP software testing, data integrity, validation, and lifecycle adherence.
Pharma Connections helps pharmaceutical and life sciences organisations design risk-based strategies to validate AI-enabled GxP applications based on their intended use, impact, technology, and relevant compliance standards.
Companies that are preparing for emerging EU GMP Annex 22 expectations can boost AI inventories, risk assessment, validation strategy, testing, documentation, lifecycle controls, and governance prior to the actual requirements coming into effect.
Pharma Connections supports CSV, CSA, risk-based testing, software assurance, validation documentation, and GxP application testing to supplement larger AI validation programs.
Companies with inadequate internal skills can outsource their quality, Validation, IT, and compliance departments to dedicated sources on AI and other GxP technology endeavours.
Pharma Connections trains specialists in CSV, CSA, GxP software testing, risk-based validation, and new AI validation concepts too, contributing to the establishment of a useful capabilities base to pharmaceutical companies, MNCs, consulting firms, and other employers in the life sciences.
AI can create significant opportunities for pharmaceutical operations, but regulated adoption requires confidence that technology remains controlled, validated, monitored, and suitable for its intended use.
Although EU GMP Annex 22 is still under development, its direction makes several priorities clear: AI governance, intended use, risk assessment, data quality, model validation, performance criteria, human oversight, change control, and lifecycle monitoring deserve attention now.
Pharma Connections helps pharmaceutical and life sciences organisations prepare for this changing compliance environment through AI validation, Annex 22 readiness, CSV, CSA, GxP software testing, validation resources, and staff augmentation.
Don’t wait until AI systems are deeply embedded in regulated operations to decide how to control them.
Connect with Pharma Connections to assess your AI-enabled GxP applications, strengthen validation strategies, and prepare your teams and systems for emerging Annex 22 expectations.
EU GMP Annex 22 is proposed guidance focused on artificial intelligence used in pharmaceutical manufacturing. As of September 2026, it remains under development and should not be described as a finalised, effective GMP annex.
The 2025 draft addresses areas including AI intended use, model selection, training and validation, data quality, performance metrics, testing, human oversight, change control, and ongoing performance monitoring.
The 2025 consultation draft excluded generative AI and LLMs from critical GMP applications. However, EMA continued discussing potential approaches for GenAI, probabilistic, and dynamic models during its 2026 expert workshop, so companies should monitor the final guidance.
Companies can begin by identifying GxP AI use cases, defining intended use, performing risk assessments, strengthening data governance, establishing validation and testing strategies, defining human oversight, and implementing lifecycle monitoring and change controls.
Yes. Pharma Connections supports pharmaceutical and life sciences organisations with AI validation readiness, CSV, CSA, GxP software testing, validation resources, staff augmentation, and preparation for emerging AI-related GxP expectations.
Pharma Connections, Established on February 14, 2019, A Product of Eduteq Connections Pvt Ltd (An ISO 9001:2015 certified company), is dedicated to providing training and upskilling opportunities for Life science Professionals.
Read More