AI has moved from slide decks to the shop floor. Cameras now inspect vials. Models flag deviations before anyone opens a batch record. And regulators have noticed.
EU GMP Annex 22 is the first set of EU GMP rules written specifically for artificial intelligence in medicine manufacturing. If your quality team uses AI, or plans to, this draft affects you.
The good news? The rules are not final yet. That gives you a rare window to prepare. This article explains what Annex 22 is, what it asks for, and exactly what to do before it lands in 2026.
EU GMP Annex 22 is a new appendix to the EU Good Manufacturing Practice guidelines. It sets out how AI and machine learning may be used in regulated pharmaceutical manufacturing.
The draft was published on 7 July 2025. It was written by the European Medicines Agency’s inspectors, working with PIC/S. The FDA and UK MHRA joined as observers, which signals a push toward global alignment.
In short, Annex 22 is becoming the “Annex 11 for AI.” Where Annex 11 governs computerised systems, Annex 22 adds rules built for how AI actually behaves. You can review the official consultation on the European Commission health portal.

AI adoption in pharma is accelerating fast. In a 2025 industry survey of top-20 pharma companies, 85% of respondents called AI an immediate priority. The technology arrived faster than the rules to govern it.
Annex 22 closes that gap. However, it is still a draft. The public consultation closed on 7 October 2025 and drew roughly 1,300 comments. A final version is expected by the end of 2026, with enforcement likely to follow in 2027 or 2028.
So why act now? Because a draft cannot trigger an inspection finding, but it clearly shows regulatory direction. The core principles are unlikely to reverse. Teams that prepare early will need only small adjustments later, not a full redesign.
Annex 22 takes a risk-based approach. Only high-impact AI faces the strictest rules. That means models affecting product quality, patient safety, or data integrity.
Importantly, the July 2025 draft is narrow about scope:
This is a key point many teams miss. If you hoped to use a generative AI tool to make batch-release decisions, the draft says no. For now, that door stays closed.
Let us be honest about the pain this creates on the ground. These are the problems compliance and QA teams are wrestling with right now.
AI has crept into operations quietly. A vision system here, a predictive maintenance model there. Many teams cannot produce a full list of the AI touching GMP processes. Without that inventory, compliance is impossible.
Annex 22 demands independent test data, never used in training or validation. In practice, teams often reuse data. That risks overfitting, where a model looks accurate in testing but fails on real, varied inputs.
Regulators now expect explainability. A model must show which features drove its decision. Many off-the-shelf AI tools cannot do this. A model that rejects a tablet based on background lighting, not a real defect, is a serious risk.
Annex 22 insists a human stays accountable. Yet in many setups, it is unclear who reviews AI outputs, when, and how. If an operator rubber-stamps AI decisions, that is not real oversight.
AI performance decays quietly over time. This is called drift. Without ongoing monitoring, a model can slowly go wrong while everyone assumes it still works. That is a data integrity failure waiting to happen.
Yes, but slowly and unevenly. Some larger manufacturers have built AI governance frameworks and validation playbooks. Vendors are adding explainability tools like SHAP and LIME, and confidence scoring, to their platforms.
However, many mid-size companies are still stuck. They lack the in-house mix of QA, data science, and CSV expertise that Annex 22 quietly demands. This skills gap is the biggest barrier to readiness.
At RxCloud, we work on exactly this intersection of quality, validation, and technology. So these problems are not abstract to us. Here is how our approach maps to what Annex 22 asks for:
We would rather understate this than oversell it. Annex 22 readiness works only on top of solid quality fundamentals. That is the part we focus on first.

You do not need the final text to start. In fact, waiting is the costly option. Here is a practical, six-step plan.
List every AI model touching a GMP process. Note what it does, how critical it is, and who owns it. Annex 11 already expects a system inventory. Simply extend it to include AI.
For each model, document its precise intended use. Include common cases, edge cases, and likely errors. A process subject matter expert must approve this before any testing.
Secure independent, representative test data. It must cover real-world variation, such as different suppliers, shifts, and equipment. Document any data cleaning or exclusions clearly.
For critical models, capture the features driving each decision. Log a confidence score for each output. If confidence is very low, route the result to a human instead of acting on it.
Make accountability explicit. Define who reviews outputs, when, and how. Record the operator’s responsibilities. This keeps AI as a support tool, not the final decision-maker.
Plan how you will watch each model for drift and bias over time. Monitoring is not optional. It is how you prove the model still works long after go-live.
| Aspect | Annex 11 | Annex 22 |
| Focus | Computerised systems | AI and ML models |
| Scope | Software and infrastructure | Static, deterministic AI in critical use |
| Key demand | Validation and audit trails | Test data, explainability, drift monitoring |
| Human role | System control | Documented human oversight of AI |
| Status | In force | Draft, final expected end of 2026 |
The Cost of Waiting
Some teams will delay until the rules are final. That is a mistake. The preparation work, inventory, intended use, test data, and oversight, takes months, not weeks.
Moreover, the core principles are already visible. They align closely with existing GMP and the FDA and EMA guiding principles on good AI practice issued in January 2026. Building now means a smooth transition later, not a scramble.
No. Annex 22 is still a draft. The consultation closed in October 2025, and a final version is expected by the end of 2026. A draft cannot be the basis of an inspection finding. However, it shows clear regulatory direction, so early preparation is wise.
Not for critical GMP tasks. The July 2025 draft excludes generative AI and large language models from critical applications. They may still be used for non-critical work, such as drafting documents or training, as long as humans review the output.
It focuses on static, deterministic AI and machine-learning models used in GMP-critical applications. These are models that do not change during use and give consistent outputs for the same input.
Annex 11 governs computerised systems in general. Annex 22 adds AI-specific rules on top, covering test data independence, explainability, confidence scoring, human oversight, and drift monitoring. Think of it as the AI layer above Annex 11.
Now. Building an AI inventory, defining intended use, and fixing test data takes months. Starting early means only small adjustments when the final text arrives, rather than a full redesign under time pressure.
EU GMP Annex 22 marks a turning point. For the first time, EU GMP rules speak directly to AI. The message for quality teams is clear. AI is welcome in pharma, but only under real control.
The draft is not final, and that is your advantage. Use this window to map your AI, fix your data, and document oversight. Teams that prepare now will meet 2026 with confidence, not panic.
Need help getting audit-ready for AI in your quality systems? Our team at RxCloud is happy to compare notes. Get in touch with us here.