GxP Insights

EMA Annex 22 and AI in GMP: What Applies Today—and How to Prepare

Annex 22 is not final EU GMP. Current Annex 11 remains the baseline. Here is a practical readiness framework for AI use cases in pharmaceutical manufacturing.

G GuideGxP 5 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Fumetto GuideGxP: un output di IA viene valutato rispetto all’attuale Annex 11 e alla bozza di Annex 22 prima di una decisione GMP responsabile.

Annex 22 is not final EU GMP. Current Annex 11 remains the baseline. Here is a practical readiness framework for AI use cases in pharmaceutical manufacturing.

Annex 22 is not current EU GMP

The first decision point is simple: do not treat Annex 22 as operative law.

Status checked: 26 July 2026. The published text remains the July 2025 consultation draft. It is not an operative EU GMP annex.

It would therefore be wrong to say that EU GMP now permits, requires or has accepted a specific validation approach for adaptive, probabilistic or generative AI in critical GMP applications.

Waiting passively is also the wrong response. EMA’s June–July 2026 workshop gathered expert input on whether, and how, adaptive, probabilistic and generative AI might be addressed in future guidance. The questions raised included validation, guardrails, human oversight, drift, cybersecurity and outsourced or cloud-based services.

If future guidance creates a pathway, what evidence, boundaries and lifecycle controls would your site need to show that an AI system is understood and controlled?

The current GMP baseline remains Annex 11

For EU human-medicines GMP, the current baseline for computerised systems used in GMP-regulated activities remains Annex 11, supported where applicable by Annex 15, Chapter 1 and Chapter 7.

Under Annex 11, the application should be validated and IT infrastructure should be qualified. The extent of validation and data-integrity controls should follow a justified, documented risk assessment considering patient safety, data integrity and product quality.

Lifecycle expectations also include controlled change, periodic evaluation, incident management, security, data retention and, where relevant, audit trails and business continuity. An AI label does not remove a system from that lifecycle. The material issue is intended use and GMP impact.

What the draft Annex 22 proposed—and what it did not do

The July 2025 consultation draft proposed additional AI-specific guidance for data-trained AI or machine-learning models embedded in computerised systems when their use directly affects patient safety, product quality or data integrity.

Those proposals included intended use, input sample space, independent test data, predefined performance criteria, explainability where applicable, confidence thresholds, change control and ongoing monitoring.

The draft also proposed that dynamic or adaptive models, probabilistic-output models, generative AI and large language models should not be used in critical GMP applications. Those are draft positions, not current operative prohibitions. The 2026 workshop did not replace them or create a permission pathway; it gathered evidence for possible future guidance.

A practical readiness approach under current Annex 11

A high average model score is not enough for GMP decision support. The site needs to define the decision being informed, understand the conditions in which the model may be unreliable and decide how the process responds when those conditions arise.

1. Define intended use and the decision-rights boundary

Be precise about the input, output, user, process point and accountable decision-maker. Also state what the system does not do.

“Supports quality decisions” is too broad. A tighter boundary might state that a model prioritises environmental-monitoring records for analyst review, but does not determine excursions, approve investigations, disposition product or release a batch.

2. Assess GMP risk and the failure response

Use the current risk-based approach to identify foreseeable failure conditions, including incorrect output, low confidence, unsuitable input, unavailability and unassessed change.

For each material condition, define detection, escalation, fallback and reassessment proportionate to the potential impact on patient safety, product quality and data integrity.

3. Set the data boundary and use independent testing

Document the type, source, quality and limits of the data the model is expected to receive: its approved input sample space.

Keep development data separate from independent, representative test data. Record out-of-boundary conditions and what the process must do when they occur.

4. Predefine performance and uncertainty criteria

Set case-appropriate performance measures and minimum acceptance criteria before evaluation.

For probabilistic outputs, do not rely only on a headline average. Consider relevant subgroups and error types, then define the operational response to uncertainty: flag, escalate, suppress the recommendation, abstain or continue only under defined human review.

5. Make human review a real control

Human oversight is a control, not a substitute for controlled design, testing or lifecycle management.

Define who reviews, what information they see, when escalation is required, what they may override and how the final GMP decision is recorded. A person placed after the model is not automatically an effective control.

6. Govern monitoring, changes and suppliers

Initial testing does not end the control strategy. Identify events that trigger assessment, such as a data-pipeline change, an altered input population, a supplier model update, retraining, material performance drift, recurring low-confidence output, a security incident or a changed human-review workflow.

Where a supplier, cloud provider or external guardrail provider supports the system, formal third-party agreements must exist. Supplier documentation may inform the assessment, but it does not transfer GMP accountability.

Compact AI readiness checklist

Area What to document now
Intended useThe decision informed, process point, user and accountable human decision-maker.
Decision boundaryWhat the model does and explicitly does not do.
GMP riskImpact on patient safety, product quality and data integrity.
Input boundaryApproved input sample space, data sources and out-of-boundary conditions.
TestingIndependent test-data rationale and case-appropriate performance criteria.
Uncertainty controlConfidence or abstention rule, escalation path and manual fallback.
Human oversightReviewer role, override rules and final GMP record design.
Lifecycle triggersChange, drift, retraining, outages, disagreements and reassessment events.
Third partiesSupplier and cloud dependencies, agreements and oversight plan.

A common mistake to avoid

“A person reviews the output” is not enough by itself.

That statement does not explain which outputs require review, what the reviewer must assess, how uncertainty is shown, what happens when the model and reviewer disagree or how the final decision is recorded.

Monday action: map one AI use case

Record the decision the system informs or automates, its direct impact on patient safety, product quality and data integrity, and the accountable human decision-maker.

  • Separate intended use from model characteristics.
  • Record the approved input sample space and uncertainty rule.
  • Define manual fallback, audit records and reassessment triggers.

FAQ

Is Annex 22 current EU GMP?

No. As of 26 July 2026, the published text remains consultation draft guidance and is not an operative EU GMP annex.

What currently applies to AI used in GMP activities?

Current computerised-system controls remain grounded in Annex 11, supported where applicable by Annex 15, Chapter 1 and Chapter 7.

Should sites wait for final Annex 22 guidance?

No. Sites can already document intended use, decision boundaries, GMP risk, data boundaries, testing, uncertainty controls, human accountability and lifecycle reassessment triggers.

Does human review make an AI system compliant?

Not by itself. Human review must be a designed control with defined information, authority, escalation, override and recording requirements.

Official sources

Need a stronger Annex 11 validation baseline?

The Operational Guide to Computer System Validation (CSV) in the GxP Environment provides a practical lifecycle foundation for validating computerised systems, defining evidence and preparing for audits.

Explore the CSV guide on GuideGxP →

Subscribe to The Pragmatic GMP newsletter →

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP