Annex 22 is the first EU GMP standard designed specifically to govern artificial intelligence and machine learning within regulated pharmaceutical environments. Once finalized, it will apply directly to manufacturers of active substances and medicinal products operating under GxP.
What Is GMP Annex 22?
For years, AI-driven systems operated in something of a regulatory blind spot within pharmaceutical manufacturing. Annex 11 addressed computerized systems broadly, but it never accounted for the specific challenges of machine learning models — their probabilistic outputs, the risk of model drift, or the complexities tied to training data. Annex 22 exists precisely to close that gap.
The European Commission released the draft for public consultation in mid-2025, and the drafting process is still ongoing. Throughout 2026, the European Medicines Agency has continued gathering expert input through stakeholder workshops focused on AI governance in GMP settings. Annex 22 doesn’t replace Annex 11 — it builds on it, adding specific requirements for computerized systems that embed AI or ML models. Combined with the revised Chapter 4 of EudraLex Volume 4, these documents form a coherent regulatory framework for the digital pharmaceutical sector.
Who Falls Under Annex 22 Requirements?
The regulation targets any organization in the EU that manufactures medicinal products or active substances and uses AI or ML systems in GMP-regulated processes. This scope covers pharmaceutical manufacturers, biotech companies, and medical device producers operating in GxP environments alike.
Annex 22 isn’t limited to systems running on the production floor. It extends across the entire drug lifecycle wherever AI models influence critical decisions — from raw material quality checks, through manufacturing process monitoring, to batch release. Organizations that don’t rely on AI at any of these stages simply fall outside its direct scope.

Core Requirements Under Annex 22
The main concept running through the entire document is its intended use. Every AI model deployed in a GMP setting needs an approved intended-use specification that defines both its operational purpose and the boundaries within which its outputs can be trusted. Without this documentation, a model cannot legally operate in a regulated environment — a meaningful shift away from ad hoc AI adoption toward a rigorously documented process.
Annex 22 also draws a firm line between critical and non-critical applications:
- In critical applications with a direct impact on patient safety or product quality, only static, deterministic models are permitted. Dynamic, adaptive models and generative AI systems — including large language models (LLMs) — are explicitly excluded from these use cases.
- In non-critical applications, generative AI models can be used, but only under continuous human oversight, commonly referred to as Human-In-the-Loop (HITL). This is the approach behind LISC Risk Assessment, which uses AI to prepare structured FMEA drafts while leaving contextual evaluation, decision-making, and formal approval with qualified experts.
What Does Managing the AI Model Lifecycle Involve?
Annex 22 frames the entire AI model lifecycle as a sequence of controlled stages:
- defining the intended use;
- training data preparation;
- building and testing the model;
- running a parallel validation deployment;
- formal release of the model for production use;
- continuous monitoring of performance post-deployment.
Every stage requires its own documentation and formal sign-off. Data quality receives particular emphasis, namely, training data must meet GxP standards for integrity and traceability, and any anomalies or inconsistencies must be identified and resolved before training begins. In reality, this means production data can rarely be fed directly into a model without prior preparation and cleansing.
Risk Management and Validation
Validating an AI model under Annex 22 differs meaningfully from standard software validation. Confirming that the system runs correctly from a technical standpoint isn’t enough — organizations are also obliged to demonstrate that the model consistently hits defined performance metrics using test data that satisfies GxP requirements.
Tools such as LISC can support this preparation stage by structuring inputs from URS, process descriptions, and technical documentation into review-ready risk assessment material; expert review remains essential before the output is used within a validation project.
Learn more: CQV: Planning Commissioning, Qualification, and Validation
For critical applications, a parallel deployment phase is mandatory. This means the AI model runs alongside the existing process, with qualified personnel reviewing its outputs before any decisions are made based on them. Only when the results consistently match specific expectations can the model be formally released for independent use in a GMP environment.
Change Control for AI Models
Any modification to an AI model — whether to training data, parameters, architecture, or the computing environment — must go through a formal change control process. This involves assessing how the change affects the model’s intended use, updating documentation accordingly, and, where warranted, revalidating the model entirely. Every model version must carry a clear identifier and remain fully reproducible, so the organization always knows exactly which version is running in production and on what data it was trained.
Annex 22 also mandates ongoing monitoring after deployment. Over time, real-world production data can diverge enough from the original training data that a model’s accuracy degrades — a phenomenon known as model drift. If performance drops below a predefined threshold, the organization must either revalidate the model or withdraw it from use.

Annex 22 and QMS Integration
Annex 22 requirements don’t exist in isolation from the rest of an organization’s compliance infrastructure. AI models operating in a GMP environment need to be integrated with a Quality Management System (QMS). Any deviation from defined performance parameters should automatically trigger the relevant QMS workflows, including CAPA. The audit trail must capture not just user actions, but also model outputs and every decision made by the company’s staff regarding their acceptance.
For organizations that deploy AI, a SaaS-based QMS built for GxP environments becomes a non-negotiable piece of compliance infrastructure. Integration alone, however, isn’t sufficient to satisfy Annex 22 — 3 specific areas need proper configuration and documentation:
- Logging deviations and incidents tied to model behavior
- Managing change control for any modification to the model or its training data
- Monitoring model performance over time and reporting results
Annex 22 as a Catalyst for Digital Transformation
New regulatory requirements push organizations to formalize processes that often ran informally in the past. It’s a demanding operational shift, but it drives real improvements in data quality, documentation, and oversight of digital systems. Companies that handle Annex 22 as a mere compliance checkbox are likely to implement it at the bare minimum and miss out on the broader value this transformation can deliver.
See also: Digital Transformation in GxP-Regulated Life Sciences
Organizations that approach compliance with long-term operational value in mind end up building data and process infrastructure capable of supporting increasingly sophisticated AI applications. Annex 22 sets the regulatory floor, but it also lays the groundwork for responsible, scalable AI adoption across the pharmaceutical industry.
Preparing Your Organization for Annex 22
If your organization already uses or plans to use AI/ML systems within GMP-regulated processes, Annex 22 will have a direct impact on your operations. Rather than treating it purely as a compliance burden, use it as the trigger to bring structure to your data, processes, and documentation. eLife Sciences helps pharmaceutical and biotech companies design, validate, and oversee digital systems across GxP environments — from intended use strategy and data architecture to SaaS QMS deployment, AI-supported risk assessment, paperless validation, and inspection readiness.
Contact us to discuss where your organization stands on Annex 22 readiness and plan your next steps.

FAQs
Does Annex 22 affect manufacturers outside the EU?
Annex 22 applies directly to manufacturing for the EU market, but its influence extends further. It was developed with PIC/S, whose members include non‑EU regulators, making it a likely reference globally. Any company exporting to the EU must already meet EU GMP standards. While the US still relies on existing cGMP and 21 CFR Part 11 frameworks plus non‑binding AI guidances, Annex 22 remains the most detailed AI manufacturing standard and a useful benchmark worldwide.
When Is Annex 22 Coming Into Force?
Annex 22 is still going through the EU legislative process. A draft was released for public consultation in 2025, and expert work has continued since then. The European Commission has not yet announced a final adoption date or a transition period for companies to align their GMP operations with the new requirements.
Do small and mid-sized pharmaceutical companies also have to comply with Annex 22?
Yes. Annex 22 applies based on how AI/ML is used in GMP-governed processes, not on company size. Even a smaller manufacturer using a predictive algorithm in quality control will fall under Annex 22 requirements once the guideline comes into force.