Artificial Intelligence Governance
AI is already inside your operation. The question is whether you can demonstrate control over it.
The draft EU GMP Annex 22, released for consultation in 2025, is the first GMP text dedicated to artificial intelligence. Its scope is narrow: it applies where AI models are used in critical applications with direct impact on product quality, patient safety or data integrity — and in those applications it permits only static, deterministic models. Generative AI and LLMs are limited to non-critical uses under documented human oversight.
In practice AI rarely comes through the front door. It arrives by individual initiative: someone drafting a procedure, specification or analysis with an LLM, unrecorded and unreviewed. Without an inventory there is no way to assess that risk, let alone defend it in an inspection.
The FDA has already devoted a dedicated warning letter subsection to inappropriate AI use in pharmaceutical manufacturing, after a manufacturer generated specifications, procedures and master production records using AI agents without adequate Quality Unit review. This is no longer a forward-looking topic.
Deliverables cycle
AI usage inventory
A survey of AI tools in use across the operation, including undeclared adoption by staff, with GxP criticality classification for each identified use.
AI usage policy for GxP environments
A document defining permitted and prohibited uses, separating critical from non-critical applications, and establishing mandatory human review with a named qualified reviewer.
AI risk assessment
Use-case level risk analysis covering input data, model behaviour, human oversight and potential impact on product, patient and data integrity.
Output traceability model
A record structure linking every AI output used in a GxP document or decision to the tool, version, input, reviewer and approval — in auditable form.
Regulatory readiness plan
A roadmap toward Annex 22 and the Annex 11 revision, with milestones and owners, sized to the company profile and usage pattern.
How we run it
Map
Usage inventory, including informal adoption.
Classify
Separate critical from non-critical applications.
Govern
Policy, human review and output traceability.
Sustain
Monitoring, change control and regulatory readiness.
Applicable standards
Frequently asked questions
Is Annex 22 already in force?
No. The draft was released for consultation in July 2025 and the consultation closed in October 2025. The final text has not been adopted. The work now is preparation, not mandatory compliance.
Can I use generative AI in GxP processes?
The draft Annex 22 restricts generative AI to non-critical applications under documented human oversight. In critical applications it permits only static, deterministic models. That separation must be written down and demonstrable.
My team already uses AI with no policy. Where do I start?
With the inventory. Without knowing what is in use and at what criticality, any policy comes out generic. The mapping is usually the most revealing stage of the project.