EU GMP Annex 22 and the revised Annex 11: what the drafts ask of AI systems

In brief
EU GMP Annex 22, published as a draft for consultation on July 7, 2025 alongside revised drafts of Annex 11 and Chapter 4, is the first GMP text written specifically for artificial intelligence. It applies to static AI models used in critical GMP applications, says generative AI and large language models should not be used in those applications, and requires a qualified person to check outputs where AI is used in non-critical ones. The consultation closed on October 7, 2025, and as of September 2026 none of the three documents had been adopted.
Key takeaways
- The European Commission published draft Annex 22, revised Annex 11 and revised Chapter 4 for consultation from July 7 to October 7, 2025, and all three were still drafts as of September 2026.
- Draft Annex 22 covers static models only; dynamic, continuously learning models and models with probabilistic outputs should not be used in critical GMP applications.
- The draft says generative AI and large language models should not be used in critical GMP applications; in non-critical ones, qualified personnel are responsible for checking outputs.
- For critical applications, the draft requires acceptance criteria at least as high as the process being replaced, independent test data, explainability, and a confidence score logged for each prediction.
- The revised Annex 11 and Chapter 4 drafts strengthen lifecycle management, quality risk management, and data integrity for computerized systems and for paper, digital, and hybrid records.g Principles of Good AI Practice in Drug Development, which explicitly include manufacturing.
What was published, and its status
| Document | What it covers | Status (Sept. 2026) |
|---|---|---|
| Annex 22, Artificial Intelligence (new) | AI models used in the manufacture of medicines and active substances | Draft; consultation July 7 to October 7, 2025 |
| Annex 11, Computerised Systems (revised) | Lifecycle, risk management, data integrity, and security for computerized systems | Draft; the 2011 version remains in force |
| Chapter 4, Documentation (revised) | Paper, digital, and hybrid documentation and data governance | Draft; the 2011 version remains in force |
What draft Annex 22 covers
The scope section sets the boundaries. The draft applies to static models, ones that do not change once deployed, with deterministic outputs. It says dynamic models that keep learning in use, and models whose outputs are probabilistic and not identical for the same input, should not be used in critical GMP applications. It says the document does not apply to generative AI and large language models, and that such models should not be used in critical GMP applications.
A critical application is one with a direct impact on patient safety, product quality, or data integrity. For non-critical applications, the draft allows other kinds of models, including generative AI, provided qualified personnel are responsible for checking the outputs. This is sometimes described as a ban on generative AI in GMP. It is narrower than that: it keeps generative AI out of critical decisions and puts a qualified person in charge of it elsewhere.
What it requires for critical applications
- Intended use. A description of what the model does, the data it works on, and the responsibilities of the human operator.
- Acceptance criteria. Performance criteria at least as high as the performance of the process the model replaces.
- Independent test data. Test data kept separate from training data, and people who have seen the test data not involved in training.
- Explainability. A record of the features that drove a decision, for example through methods such as SHAP, LIME, or heat maps.
- Confidence. A confidence score logged for each prediction, so low-confidence outputs can be handled appropriately.
- Controlled change. A retrained or changed model introduced only through change control, with an impact assessment.
What the revised Annex 11 and Chapter 4 add
The revised Annex 11 draft strengthens lifecycle management for computerized systems, makes quality risk management mandatory throughout and adds data integrity and security controls. The revised Chapter 4 draft covers documentation across paper, digital, and hybrid formats and introduces risk-based data governance. Together they update the ground Annex 22 sits on: any AI system is also a computerized system, and its outputs are documentation.
What it means for AI used near GMP work
For systems that assemble evidence, draft records, or answer questions for a qualified person to check, the draft points in a clear direction:
- Decide, for each use, whether it is a critical application in the Annex 22 sense, and document why.
- Where generative AI is involved, keep it to non-critical uses, and define the qualified person who checks each output.
- Record how each output was produced, from which sources, so the check is meaningful.
- Surface uncertainty rather than hiding it; the draft's confidence requirement reflects the same principle.
- Put changes to models, prompts, and workflow steps under change control.
These are the controls agentic solutions must be built around: approved sources, source lineage, execution records, surfaced uncertainty, and expert approval as a defined step. Agentic AI in GxP environments: a practical guide covers them in more detail.
Questions
- Is EU GMP Annex 22 in force?
- No. It was published as a draft for consultation from July 7 to October 7, 2025, and as of September 2026 it had not been adopted. Check the EudraLex Volume 4 page for the current status.
- Does Annex 22 ban generative AI in pharmaceutical manufacturing?
- Not entirely. The draft says generative AI and large language models should not be used in critical GMP applications. In non-critical applications, they can be used with qualified personnel responsible for checking the outputs.
- What counts as a critical GMP application?
- In the draft, one with a direct impact on patient safety, product quality, or data integrity. Each operation should document its own classification for each use.
- How does Annex 22 relate to FDA's draft AI guidance?
- FDA's January 2025 draft addresses the credibility of AI used to support regulatory decisions and excludes internal operational uses that do not affect patient safety. Annex 22 addresses AI used in GMP manufacturing and quality operations directly. Both were drafts as of September 2026.
Sources
- Stakeholders' consultation on EudraLex Volume 4, Chapter 4, Annex 11 and new Annex 22., European Commission, July 1, 2025
- Draft Annex 22: Artificial Intelligence, European Commission, July 1, 2025
- Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products. Draft guidance., U.S. FDA, January 1, 2025
Read next
Document Intelligence
Turns records from suppliers, CROs, CDMOs and your labs into contextualized, source-linked data.
See How It Works



