EU GMP Annex 22 Explained: What Pharma Quality Teams Must Do Before AI Rules Become Final in 2026

AI has moved from slide decks to the shop floor. Cameras now inspect vials. Models flag deviations before anyone opens a batch record. And regulators have noticed. 

EU GMP Annex 22 is the first set of EU GMP rules written specifically for artificial intelligence in medicine manufacturing. If your quality team uses AI, or plans to, this draft affects you.

The good news? The rules are not final yet. That gives you a rare window to prepare. This article explains what Annex 22 is, what it asks for, and exactly what to do before it lands in 2026.

What Is EU GMP Annex 22?

EU GMP Annex 22 is a new appendix to the EU Good Manufacturing Practice guidelines. It sets out how AI and machine learning may be used in regulated pharmaceutical manufacturing.

The draft was published on 7 July 2025. It was written by the European Medicines Agency’s inspectors, working with PIC/S. The FDA and UK MHRA joined as observers, which signals a push toward global alignment.

In short, Annex 22 is becoming the “Annex 11 for AI.” Where Annex 11 governs computerised systems, Annex 22 adds rules built for how AI actually behaves. You can review the official consultation on the European Commission health portal.

GMP Annex 22

Why Annex 22 Matters Now

AI adoption in pharma is accelerating fast. In a 2025 industry survey of top-20 pharma companies, 85% of respondents called AI an immediate priority. The technology arrived faster than the rules to govern it.

Annex 22 closes that gap. However, it is still a draft. The public consultation closed on 7 October 2025 and drew roughly 1,300 comments. A final version is expected by the end of 2026, with enforcement likely to follow in 2027 or 2028.

So why act now? Because a draft cannot trigger an inspection finding, but it clearly shows regulatory direction. The core principles are unlikely to reverse. Teams that prepare early will need only small adjustments later, not a full redesign.

What Does Annex 22 Actually Cover?

Annex 22 takes a risk-based approach. Only high-impact AI faces the strictest rules. That means models affecting product quality, patient safety, or data integrity.

Importantly, the July 2025 draft is narrow about scope:

  • Static models only. AI that does not change during use is considered suitable for critical GMP tasks.
  • Deterministic outputs preferred. The same input should give the same output.
  • Generative AI and LLMs excluded. These are not allowed in critical GMP applications. They may still support non-critical tasks like drafting or training, with human oversight.

This is a key point many teams miss. If you hoped to use a generative AI tool to make batch-release decisions, the draft says no. For now, that door stays closed.

The Real Problems Quality Teams Face

Let us be honest about the pain this creates on the ground. These are the problems compliance and QA teams are wrestling with right now.

Problem 1: Nobody Knows Where the AI Is

AI has crept into operations quietly. A vision system here, a predictive maintenance model there. Many teams cannot produce a full list of the AI touching GMP processes. Without that inventory, compliance is impossible.

Problem 2: Test Data Is Not Independent

Annex 22 demands independent test data, never used in training or validation. In practice, teams often reuse data. That risks overfitting, where a model looks accurate in testing but fails on real, varied inputs.

Problem 3: The “Black Box” Cannot Explain Itself

Regulators now expect explainability. A model must show which features drove its decision. Many off-the-shelf AI tools cannot do this. A model that rejects a tablet based on background lighting, not a real defect, is a serious risk.

Problem 4: Human Accountability Is Unclear

Annex 22 insists a human stays accountable. Yet in many setups, it is unclear who reviews AI outputs, when, and how. If an operator rubber-stamps AI decisions, that is not real oversight.

Problem 5: No Monitoring for Drift

AI performance decays quietly over time. This is called drift. Without ongoing monitoring, a model can slowly go wrong while everyone assumes it still works. That is a data integrity failure waiting to happen.

Is Anyone Solving These Problems?

Yes, but slowly and unevenly. Some larger manufacturers have built AI governance frameworks and validation playbooks. Vendors are adding explainability tools like SHAP and LIME, and confidence scoring, to their platforms.

However, many mid-size companies are still stuck. They lack the in-house mix of QA, data science, and CSV expertise that Annex 22 quietly demands. This skills gap is the biggest barrier to readiness.

How RxCloud Approaches These Problems

At RxCloud, we work on exactly this intersection of quality, validation, and technology. So these problems are not abstract to us. Here is how our approach maps to what Annex 22 asks for:

  • Risk-based CSV and CSA. We focus validation on the systems that truly affect data integrity and patient safety, which mirrors the risk-based logic of Annex 22. Learn more on our Computer System Validation services.
  • Audit readiness built in. With extensive GxP audit experience, we help teams find and close the exact gaps inspectors look for.
  • Validated automation. We apply test automation inside validated platforms, keeping every change inside GMP boundaries.

We would rather understate this than oversell it. Annex 22 readiness works only on top of solid quality fundamentals. That is the part we focus on first.

What Pharma Quality Teams Must Do Before 2026

You do not need the final text to start. In fact, waiting is the costly option. Here is a practical, six-step plan.

Step 1: Build a Complete AI Inventory

List every AI model touching a GMP process. Note what it does, how critical it is, and who owns it. Annex 11 already expects a system inventory. Simply extend it to include AI.

Step 2: Define Intended Use and Criticality

For each model, document its precise intended use. Include common cases, edge cases, and likely errors. A process subject matter expert must approve this before any testing.

Step 3: Fix Your Test Data

Secure independent, representative test data. It must cover real-world variation, such as different suppliers, shifts, and equipment. Document any data cleaning or exclusions clearly.

Step 4: Add Explainability and Confidence

For critical models, capture the features driving each decision. Log a confidence score for each output. If confidence is very low, route the result to a human instead of acting on it.

Step 5: Document Human Oversight

Make accountability explicit. Define who reviews outputs, when, and how. Record the operator’s responsibilities. This keeps AI as a support tool, not the final decision-maker.

Step 6: Set Up Ongoing Monitoring

Plan how you will watch each model for drift and bias over time. Monitoring is not optional. It is how you prove the model still works long after go-live.

Annex 22 vs Annex 11: Quick Comparison

AspectAnnex 11Annex 22
FocusComputerised systemsAI and ML models
ScopeSoftware and infrastructureStatic, deterministic AI in critical use
Key demandValidation and audit trailsTest data, explainability, drift monitoring
Human roleSystem controlDocumented human oversight of AI
StatusIn forceDraft, final expected end of 2026

The Cost of Waiting

Some teams will delay until the rules are final. That is a mistake. The preparation work, inventory, intended use, test data, and oversight, takes months, not weeks.

Moreover, the core principles are already visible. They align closely with existing GMP and the FDA and EMA guiding principles on good AI practice issued in January 2026. Building now means a smooth transition later, not a scramble.

Frequently Asked Questions

Is EU GMP Annex 22 legally binding yet?

No. Annex 22 is still a draft. The consultation closed in October 2025, and a final version is expected by the end of 2026. A draft cannot be the basis of an inspection finding. However, it shows clear regulatory direction, so early preparation is wise.

Does Annex 22 allow generative AI or LLMs?

Not for critical GMP tasks. The July 2025 draft excludes generative AI and large language models from critical applications. They may still be used for non-critical work, such as drafting documents or training, as long as humans review the output.

What types of AI does Annex 22 cover?

It focuses on static, deterministic AI and machine-learning models used in GMP-critical applications. These are models that do not change during use and give consistent outputs for the same input.

How is Annex 22 different from Annex 11?

Annex 11 governs computerised systems in general. Annex 22 adds AI-specific rules on top, covering test data independence, explainability, confidence scoring, human oversight, and drift monitoring. Think of it as the AI layer above Annex 11.

When should we start preparing?

Now. Building an AI inventory, defining intended use, and fixing test data takes months. Starting early means only small adjustments when the final text arrives, rather than a full redesign under time pressure.

Conclusion: Prepare Now, Not Later

EU GMP Annex 22 marks a turning point. For the first time, EU GMP rules speak directly to AI. The message for quality teams is clear. AI is welcome in pharma, but only under real control.

The draft is not final, and that is your advantage. Use this window to map your AI, fix your data, and document oversight. Teams that prepare now will meet 2026 with confidence, not panic.

Need help getting audit-ready for AI in your quality systems? Our team at RxCloud is happy to compare notes. Get in touch with us here.