
Artificial intelligence is finding its way into pharmaceutical manufacturing, from image analysis in visual inspection to the prediction of process deviations. Until now, a specific GMP framework for this has been lacking. With the draft of EU GMP Annex 22, it is becoming apparent how regulatory authorities intend to classify the use of AI in the GxP environment.
Published as a draft for consultation, Annex 22 addresses the use of AI and machine-learning models in GMP-critical applications, that is, wherever a malfunction could jeopardise product quality, patient safety or data integrity. As a draft, the text is not yet final and may change; the direction, however, is already clearly discernible and warrants early engagement.
A central idea of the draft is the restriction of critical applications to deterministic models that are frozen after training. Models that continue to evolve on their own during operation, as well as generative approaches and large language models, are considered unsuitable for critical GMP decisions as long as their behaviour cannot be demonstrated reproducibly. Above all stands human oversight: responsibility for a decision remains with qualified personnel, not with the model.
An AI model in the GMP environment must not only be good, but demonstrably and reproducibly good.
Not every AI application is subject to the same expectations. A pattern recognition that supports a human reviewer but does not replace them carries a different risk than a model that helps decide on the release of a batch. The first step is therefore always the same question of Computer System Validation: what influence does the system have on product quality and data integrity? The depth of testing follows from the answer.
The draft transfers familiar validation principles to the particularities of machine learning. At the centre are:
Annex 22 does not stand alone. It fits into the risk-based approach of GAMP 5 and the principles of Computer System Validation. Anyone who already masters these does not need to rethink AI entirely, but only to add the additional questions of data quality, explainability and model drift. Data integrity in accordance with ALCOA+ remains the foundation for training and input data as well.
In practice, it helps to keep two levels apart: the IT infrastructure on which a model runs is qualified like any other computerised system; the model itself is additionally validated for its functional performance. Anyone who conflates the two levels regularly underestimates the effort required to assess model quality.
The draft of Annex 22 makes it clear: AI is welcome in the GxP environment, but only under the same principles of evidence, control and responsibility that apply to every other critical system. Anyone who starts today with clean validation and clear human oversight is prepared for the framework to come. Vispact supports the validatable introduction of such systems, technically sound and regulatorily compatible.
If a topic from this article is currently on your plant's agenda, we will discuss it concretely in an initial consultation.
30 minutes, no obligation. Reply within one working day, directly from engineering.