Does Annex 22 Close the Door on GenAI in Validation?

Ryan Chen

Author

Ryan Chen

Product Strategist

ValGenesis

LinkedIn

Published on October 1, 2026
Reading time: -- minutes
Last updated on October 1, 2026
Reviewed by: Lisa Weeks

Summary

Draft EU GMP Annex 22 draws clear boundaries around artificial intelligence (AI) use in critical GMP applications, but those boundaries should not be interpreted as a blanket rejection of generative AI (GenAI) in validation. This article explores what Annex 22 means for AI-enabled validation, why intended use and risk matter, and how life sciences organizations can begin preparing for governed AI adoption.

Key Takeaways

  • Annex 22 sets boundaries, not a blanket ban on AI. The draft distinguishes between critical and non-critical applications and places clear limitations on GenAI, LLMs, and other probabilistic technologies in critical GMP applications.

  • AI governance should reflect intended use and risk. An assistive AI use case reviewed by qualified personnel presents a different risk profile from AI independently influencing a critical GMP decision.
     
  • AI extends the conversation from data integrity to decision integrity. As AI becomes part of validation activities, organizations need to demonstrate not only that data are trustworthy, but also that AI-assisted outputs and the decisions they inform are controlled, traceable, and accountable. 

Who is this for

  • CQV, validation, and CSV/CSA professionals evaluating where and how AI can be responsibly applied within GxP validation activities

  • Validation and quality leaders assessing the implications of draft Annex 22 for AI use, human oversight, risk management, and inspection readiness

  • Digital transformation leaders developing strategies for introducing and scaling AI responsibly across regulated processes

  • Quality systems and AI governance leaders establishing the controls, accountability, traceability, and lifecycle governance needed for AI use in regulated environments 
featured image

Does draft EU GMP Annex 22 mean generative AI (GenAI) has no place in GxP validation? The answer depends in large part on how and where AI is being used. 

Annex 22 is still evolving, and so is the broader regulatory conversation around AI. For validation leaders, the more useful question may therefore be less about whether AI is simply “allowed” or “not allowed” and more about where AI is being used, what it is being asked to do, what risk that creates, and what controls are needed to govern it responsibly.

 

What Does Annex 22 Actually Say About GenAI?

Draft Annex 22 focuses on AI used in critical GMP applications that directly impact patient safety, product quality, or data integrity. Within that scope, the draft centers on static AI and machine learning models that produce deterministic outputs. Dynamic models that continuously learn during use, probabilistic outputs, GenAI, and large language models (LLMs) fall outside the covered model class for critical GMP applications.   

That is an important boundary, but it is not the same as saying these technologies have no place in GxP environments. The draft explicitly contemplates non-critical use where qualified personnel remain accountable for determining whether the output is suitable for its intended purpose. This distinction shifts the conversation from the technology alone to its intended use and potential impact (European Commission, 2025).

 

The Regulatory Conversation Is Still Evolving

Public feedback on Annex 22 reflects the same tension. Industry groups have broadly welcomed AI-specific GMP guidance while questioning whether broad exclusions based on model type could become too restrictive as the technology evolves. BioPhorum and the International Society of Quality Assurance have both advocated, in different ways, for approaches that place greater emphasis on quality risk management (QRM), appropriate controls, and practical implementation (BioPhorum, 2025; International Society of Quality Assurance, 2025). 

The European Medicines Agency’s (EMA) June 2026 multistakeholder workshop adds useful context. The discussion examined how GenAI and LLMs might be responsibly governed in medicines manufacturing, including QRM, data governance, model evaluation, lifecycle controls, transparency, cybersecurity, accountability, and human oversight. This does not mean critical GenAI use is already permitted under Annex 22. Rather, it shows that the conversation continues to explore what evidence and controls may be necessary to govern these technologies appropriately (EMA, 2026).

 

Not Every AI Use Case Carries the Same Risk

Consider the difference between using AI to draft validation content from approved source information and allowing AI to independently make a critical GMP decision. In the first scenario, a qualified validation professional can review, correct, and approve the content before it becomes part of the controlled record. In the second, an incorrect AI output could directly affect a critical decision without qualified human intervention. 

Both scenarios involve AI, but treating them as equivalent overlooks a fundamental principle of QRM: the level of control should reflect the intended use and potential consequence. For AI, that means asking what task the technology is performing, what happens if it is wrong, whether an error can be detected or reversed, who reviews the output, and whether that output directly influences a GMP decision or record. The underlying idea is straightforward: greater reliance on AI requires stronger evidence and control (ICH, 2023).

 

AI Extends Data Integrity Into Decision Integrity

Life sciences organizations already understand the importance of data integrity. Records must be complete, accurate, attributable, and traceable. But as AI begins to draft content, identify gaps, interpret evidence, compare information, or flag anomalies, the integrity question starts to extend beyond the underlying data. 

Organizations also need to understand what happened around an AI-assisted output. What information was used? What was the AI expected to do? Why was its output accepted, changed, rejected, or escalated? Who remained accountable for the decision? This broader concept can be described as decision integrity: the ability to reconstruct and defend how an AI-assisted recommendation, classification, exception, or action was handled.   

This does not replace data integrity. It extends the same discipline into AI-assisted work. As AI becomes more deeply embedded in validation processes, demonstrating that the surrounding decision process was understood, controlled, and reviewable may become increasingly important to inspection readiness.

 

Govern AI According to Risk, Not Hype

A practical path forward does not require organizations to choose between unrestricted AI adoption and waiting until every regulatory question has been answered. Organizations can begin with clearly bounded applications, define what AI is and is not allowed to do, control the information available to it, maintain source traceability, keep qualified people accountable, and monitor how the technology performs over time. 

Importantly, these controls do not make a probabilistic model deterministic. They make the process surrounding AI use more bounded, reconstructable, and governed. This distinction matters because responsible AI adoption is ultimately about more than the model itself. It is about whether the organization can demonstrate that AI operates within a controlled process appropriate to its intended use and risk(European Medicines Agency/ICH, 2023).

 

Annex 22 Readiness Can Start Today

The final Annex 22 may differ from today’s draft, but organizations do not need to wait to start building readiness. Validation leaders can begin by understanding where AI is already being used, classifying use cases by intended use and criticality, establishing clear boundaries and human oversight, and determining what evidence would be needed before greater reliance on AI could be justified. 

That reframes the Annex 22 conversation around a more practical question. Rather than asking only, “Can we use AI in validation?” organizations should ask, “Can we demonstrate that the way we use AI is controlled, evidence-based, accountable, and appropriate for the risk?” Building that foundation now can help organizations prepare not only for Annex 22, but for the broader shift toward governed AI across GxP environments.

 

 

 

Citations

1

BioPhorum. (2025). https://www.biophorum.com/download/analysis-and-response-to-annex-22/

Analysis and response to Annex 22. Accessed Date: 30 September 2026.

2

European Commission. (2025). https://health.ec.europa.eu/document/download/5f38a92d-bb8e-4264-8898-ea076e926db6_en?filename=mp_vol4_chap4_annex22_consultation_guideline_en.pdf

Draft guidelines: New Annex 22—Artificial intelligence. Accessed Date: 30 September 2026.

3

European Medicines Agency. (2026). https://www.ema.europa.eu/en/events/good-manufacturing-practice-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22

Good manufacturing practice: Multistakeholder workshop on expert contributions to AI guidance development (Annex 22). Accessed Date: 30 September 2026.

4

International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. (2023). https://www.ema.europa.eu/en/ich-q9-quality-risk-management-scientific-guideline

ICH Q9(R1) guideline on quality risk management. Accessed Date: 30 September 2026.

5

International Society of Quality Assurance. (2025). https://sqa.org/common/Uploaded%20files/1-regulatory%20resources/regulatory%20communications/2021%20-/RRT_EMA-PICs_Annex22_FINAL_2025-10-06.pdf

Submission of comments on Annex 22 artificial intelligence. Accessed Date: 30 September 2026.

The opinions, information and conclusions contained within this blog should not be construed as conclusive fact, ValGenesis offering advice, nor as an indication of future results.

FAQs

Deterministic AI produces repeatable outputs under the same conditions, while probabilistic AI can produce variable outputs based on statistical inference. Draft Annex 22 focuses critical GMP use on static models with deterministic outputs, while GenAI, LLMs, and other probabilistic models fall outside that covered model class. 

AI controls should be proportionate to the intended use and risk. Key controls include defined use boundaries, controlled data and knowledge sources, traceability, appropriate testing, qualified human oversight, auditability, and lifecycle monitoring.

No. Human oversight is an important control, but it does not by itself establish that a GenAI use case is appropriate for GxP validation. Organizations must also consider intended use, criticality, data quality, testing, traceability, reviewer competence, and the potential impact of incorrect AI outputs.

Related Blog Posts