QMSdesk

RegulationsEU GMP

EU GMP Annex 22 artificial intelligence: what the draft asks

EU GMP Annex 22 is a proposed new annex to the EU GMP Guide (EudraLex Volume 4) that would set expectations for artificial intelligence (AI) models used in critical GMP applications in the manufacture of medicinal products and active substances: those with a direct impact on patient safety, product quality or data integrity. The EMA GMP/GDP Inspectors Working Group drafted it with PIC/S, and the European Commission and PIC/S opened a joint consultation on it on July 7, 2025, alongside a revised Annex 11 and Chapter 4. As of September 24, 2026, it is a draft: it has not been adopted, and EMA is weighing the consultation feedback.

What the EU GMP Annex 22 artificial intelligence draft asks

01

Scope: which models it covers

The draft covers machine-learning models that learn their behavior from training data, used in critical GMP applications, for example to predict or classify data. It adds to Annex 11 for any computerized system with an AI model embedded. It covers only static models, which don't change as they're used, with deterministic output, where the same input always gives the same result.

02

What it excludes

Dynamic models that keep learning during use, and models with probabilistic output, fall outside the draft, and it says they should not be used in critical GMP applications. The same goes for generative AI and large language models. If such models are used in non-critical applications, qualified and trained people should stay responsible for checking that their output suits the intended use.

03

What it expects for a model in scope

  • Intended use. A detailed description of the task and the input data, including rare variations, known limits and possible bias, approved before acceptance testing. A process subject-matter expert is responsible for it.
  • Acceptance criteria. Test metrics suited to the task, with acceptance criteria set in advance by a process subject-matter expert. The criteria should be at least as high as the performance of the process the model replaces.
  • Test data. Representative, with verified labels, large enough for statistical confidence, and never used in developing, training or validating the model. Where test data is split from a shared pool, it is protected by access control and an audit trail.
  • Test execution. An approved test plan, with every deviation documented, investigated and justified, and all test documentation retained.
  • Explainability and confidence. During testing, records of the features that drove a classification or decision, reviewed as part of approving the results. Where applicable, a logged confidence score and a suitable threshold, with thought given to flagging very low-confidence results as undecided.
  • Operation. Change control and configuration control before deployment, ongoing performance monitoring, checks that input data still falls within the intended use, and records of human review where a person makes the final decision and testing of the model was reduced.
  • People and suppliers. Qualified personnel with defined responsibilities and access, activities scaled to the risk to patient safety, product quality and data integrity, and the regulated user reviewing the documentation even when a supplier provides the model.

Where QMSdesk stands: your quality decisions stay with people

QMSdesk™ puts no AI model in any regulated decision path. QMSdesk has no AI features. Quality decisions in it are made by people, and each one is attributable and recorded. Approvals, closures and other decisions that attest to something are e-signed.

Where QMSdesk acts on its own, it opens work for people, following rules written down in advance. A risk at a level you set as a CAPA trigger raises a linked CAPA automatically, once. An expired supplier certificate opens a risk. A document review more than 30 days overdue opens a risk. These are fixed rules, not learned behavior, so the same input gives the same result.

Every signature requires re-authentication, with multi-factor where you require it, and records what it means. The signature and the change it approves commit together. Every audit-trail entry is SHA-256 hash-chained to the one before it, and the database keeps the log insert-only.

QMSdesk embeds no AI model, so the draft's model-specific expectations have nothing inside QMSdesk to apply to. QMSdesk is still a computerized system, so when you use it for GMP-regulated work, EU GMP Annex 11 applies to how you validate and use it. QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA.

Running AI elsewhere? The draft Annex 22 clause-to-control map (July 2025 consultation draft, not adopted)

Annex 22 is still a draft, so the rows below are expectations it proposes, not adopted requirements. If you use an AI model in a critical GMP application, for example in visual inspection, the model lives in another system. The quality records around it can live in QMSdesk. Here's what QMSdesk carries, and what it doesn't. The map covers the main provisions of the draft, not every clause.

Draft provision (section, paraphrased) How QMSdesk supports it Evidence the system produces What you still own
§1 Scope: static, deterministic machine-learning models in critical GMP applications; generative AI and LLMs excluded Not applicable inside QMSdesk: it embeds no AI model. None. Deciding which of your models and applications fall in scope, and which are critical.
§2.1 Qualified personnel with defined responsibilities and access Training by acknowledgment, quiz, practical assessment or external certificate; competency assessments by qualified assessors; access set by permission keys. Training and competency records. Defining the team (subject-matter experts, QA, data scientists, IT) and its qualifications.
§2.2 Documentation for these activities available and reviewed by you, including when a supplier provides the model Supplier qualification by risk tier, with signed status decisions. Supplier documents held as reference documents with issuing body, version and issue date. Signed supplier decisions; reference documents with currency checks. Reviewing the documentation itself.
§2.3 Activities scaled to the risk to patient safety, product quality and data integrity A risk register built on ISO 14971 and ICH Q9(R1) principles, with signed assessments and signed residual risk. Signed risk records. The risk assessment of the model's use.
§3.1, §4.2 Intended use and acceptance criteria approved before acceptance testing Document control with signed authoring, review and approval by different people. Dated, signed approval, each signature with its meaning. The content, and the subject-matter expert accountable for it.
§3.3 Operator responsibility, training and performance, where a person makes the final call and model testing was reduced Training assigned automatically, with recurring refreshers and competency assessments. Training history per person. Monitoring each operator's ongoing performance.
§5, §6 Test data: representative, labeled, independent, access-controlled Outside QMSdesk's scope. QMSdesk is not a test-data repository. None. Your test datasets and the controls on them.
§7.2–7.4 Approved test plan; deviations investigated; documentation retained Document control for the test plan. A deviation record, with investigation and signed closure, for any departure from the plan. Retention floors of 7, 10, 15 or 30 years, and no hard deletion. Signed plan; deviation record; retained documents. Running the test and judging its results.
§8, §9 Explainability, confidence scores and thresholds Outside QMSdesk's scope. They belong to the AI system. None. Capturing and reviewing them.
§10.1 Change control for the model, its system and its process Change control with risk-based routing and verification by someone other than the implementer. Signed change records. Deciding whether to retest, and justifying any decision not to.
§10.2 Configuration control of the deployed model Outside QMSdesk's scope. None. Configuration control in the AI system.
§10.3–10.5 Performance and input monitoring; records of human review Outside QMSdesk's scope for the monitoring itself. When monitoring finds a problem, record it as a deviation and raise the CAPA it needs. A linked deviation and CAPA. The metrics, the monitoring and the review records.

Annex 22, Annex 11 and Chapter 4 belong together

The three drafts were published together. The draft revised Annex 11 covers computerized systems in general, including supplier oversight, audit trails, electronic signatures and security. The draft revised Chapter 4 covers documentation in every format. Annex 22 adds the model-specific layer on top. Read our EU GMP Annex 11 page for how Annex 11 applies when you use QMSdesk.

Kept current

What changed recently

  1. July 7, 2025

    The European Commission and PIC/S open a joint stakeholder consultation on draft Annex 22, the revised Annex 11 and revised Chapter 4, prepared by the EMA GMP/GDP Inspectors Working Group with PIC/S. Consultation page

  2. October 7, 2025

    The consultation closes. Consultation page

  3. June 30–July 1, 2026

    EMA holds a multistakeholder workshop to gather expert input for Annex 22, including on a risk-based approach and possible guardrails for AI in medicines manufacturing. EMA notes that consultation responses suggested support for potentially enabling generative AI and large language models, and says it is still considering the results. The exclusions summarized above may change in the final text. EMA workshop page

  4. Status on September 24, 2026

    Annex 22 does not appear in EudraLex Volume 4, which still lists Annex 11 (revision January 2011) and Chapter 4 (January 2011). EudraLex Volume 4

PDF and Excel

Regulation checklist

The tables from this page, with a column for your own evidence. No form to fill in.

EU GMP Annex 22 FAQ

Is EU GMP Annex 22 final?

No. As of September 24, 2026 it is a draft. The consultation closed on October 7, 2025, EMA held an expert workshop on June 30 and July 1, 2026, and no final text or date has been published.

Does Annex 22 ban generative AI and LLMs?

Not today. Annex 22 is a draft and is not binding. The July 2025 draft says generative AI and large language models, like dynamic and probabilistic models, should not be used in critical GMP applications. In non-critical ones, qualified people should check the output. EMA is now exploring guardrails that could allow some uses, so watch for the final text.

Does QMSdesk use AI?

No. QMSdesk puts no AI model in any regulated decision path, and it has no AI features. Its automation follows written rules, and quality decisions are made and signed by the people who make them.

Does Annex 22 apply to our eQMS?

As drafted, Annex 22 would apply where an AI model is embedded in a computerized system used in a critical GMP application. It is not adopted yet. QMSdesk embeds no AI model. Annex 11 applies when you use QMSdesk for GMP-regulated work, and the final Annex 22 may apply to other systems you run.

What does "human-in-the-loop" mean in Annex 22?

A person makes the decision, with the model's output as an input. Where testing of such a model has been reduced, the draft expects the operator's responsibility to be defined, their training and performance monitored, and records kept of the review.

Reviewed by a practitioner

Abdul Azam, Founder & CEO, 25 years in regulated life-sciences quality. Last reviewed September 26, 2026. Next review December 2026. This guide is general information, not legal or regulatory advice.

Primary sources

Bring one workflow. We'll show you QMSdesk running it.

Bring the change control for your next model update, or the deviation you'd raise if it underperformed. We'll show you QMSdesk running it, with the decisions signed by the people who make them.