Skip to content
CovaSyn
Book an initial call

Guide

AI in the GxP Lab and EU GMP Annex 22: What Works Today

Annex 22 is a draft. What it means for AI in the GxP lab, why LLMs are excluded from critical use and what labs can already do today.

Dr. Oliver Kraft12 min read

All Articles
AI in the GxP Lab and EU GMP Annex 22: What Works Today

Note: Annex 22 is available as a draft (as of 5 October 2026). This content is not legal, regulatory or compliance advice.

Short answer

EU GMP Annex 22 ("Artificial Intelligence") is the first GMP text that addresses AI directly. It was published as a draft for consultation in July 2025, is currently being revised and is not in force. The draft targets static models with deterministic outputs and excludes generative AI and LLMs from critical GMP applications. For labs, this means: list your AI applications now, classify them by criticality and decide where a human checks the result.

What Annex 22 covers and what it does not

On 7 July 2025, the European Commission and PIC/S opened a consultation on three drafts: a revised Chapter 4 (Documentation), a revised Annex 11 (Computerised Systems) and the new Annex 22 (Artificial Intelligence). They were prepared by the EMA GMP/GDP Inspectors Working Group together with PIC/S. The consultation ran until 7 October 2025.

The three texts belong together. Annex 11 covers computerised systems in general: validation, access rights, data integrity and audit trails for any software in a GMP environment. Chapter 4 covers documentation. Annex 22 adds the requirements that only arise with AI models. It replaces neither Annex 11 nor Chapter 4. Anyone running an AI model in a GMP environment therefore still has to meet everything that applies to computerised systems, plus what Annex 22 requires for the model itself.

Annex 11 shows how much the overall framework is moving: the revised draft grows from 5 to 19 pages. The article Annex 11 vs Annex 22: What Applies to What? explains the difference between the two annexes in detail.

One point matters for context: Annex 22 is a draft. Until it is adopted, it is not part of the binding EU GMP Guide (EudraLex Volume 4).

What the draft is about

The draft describes what an AI model in a GMP environment needs before it may be used. The core points include:

  • a written intended use that states what the model is for and what it is not for
  • test data that is kept separate from the training data
  • monitoring of performance in operation, so that degradation is noticed
  • human oversight, meaning a clear rule on who checks results and who is accountable

None of these points is entirely new to a QC lab. They carry over what method validation and computer system validation have required for years to a new kind of software.

Static models and generative AI

The draft draws a clear line. In scope are static models that are frozen after training and return the same result for the same input. Dynamic models that keep learning in operation, as well as probabilistic models such as generative AI and LLMs, should not be used in critical GMP applications.

The reason lies in the logic of validation. A result can only be validated if it is reproducible. An LLM can give different answers to the same question. It can also produce a plausible sounding number that is wrong. For a release decision, an OOS assessment or a specification, that is not acceptable.

What the EMA is reassessing

The 2025 consultation, however, showed support for potentially enabling generative AI and LLMs under certain conditions. The EMA therefore held an expert workshop on 30 June and 1 July 2026 to develop a risk-based approach to generative AI. The focus was on control and mitigation measures, so-called guardrails.

According to a presentation by the Irish regulator HPRA at the QP Forum 2026, the draft is under revision, with further targeted consultations scheduled for 2026. Where AI is used, testing and confirming the outputs is key, for example through a human in the loop.

What the final text will look like is open. A prediction would not be serious at this point. The article Generative AI in GMP: Where the EMA Stands summarises the current state of the discussion.

What already works in the lab today

The draft does not mean that AI is off limits in the lab. It concerns critical GMP applications, those with a direct effect on product quality, patient safety or data integrity. Beyond that, there is a lot of work where AI can help, as long as a human checks the result and makes the decision:

  • Preparing evaluations: an assistant structures raw data, suggests evaluation steps or runs a plausibility check that a qualified person then assesses.
  • Drafting documentation: drafts of reports, deviation descriptions or SOP sections, which are reviewed and approved like any other draft.
  • Supporting method work: research, comparison of method variants, suggestions for experimental designs in research and development.

The line is drawn where the AI itself decides. A batch release, an OOS decision or a specification stays with people. The article AI in the QC Lab: Use Cases With a Human in the Loop shows concrete examples with a clear division of roles.

The architecture principle: the LLM plans, the tools compute

The core problem of generative AI in the lab is not language but numbers. A language model writes well, plans well and understands a question. It does not compute reliably. A molar mass, a shelf life extrapolation or a limit from a model based on probabilities is worthless in a regulated environment as long as nobody knows how the number came about.

This leads to an architecture principle that fits well with the logic of Annex 22: the language model does the planning, reproducible tools do the computing. Every calculation step runs in a tool that returns the same result for the same input and whose result can be checked. The LLM calls these tools, combines their results and explains them. At the end, a human checks.

CovaSyn connects LLMs with reproducible chemistry tools. The language model plans, the tools compute, every step is traceable. That is how AI in the lab can be used today and built to fit the requirements Annex 22 is bringing.

It is important to be clear about what this does not mean: CovaSyn is a tool for research and the lab, not validated GMP software and not compliance advice. Whether and how a tool is used in a GMP process is decided and validated by the company that operates it. We only document which properties of individual tools are established for such an assessment once they have been reviewed by an expert.

Data integrity and audit trail: questions a lab should ask

For every AI application in the lab, critical or not, a short set of questions is worth asking. They come from what Annex 11 and the Annex 22 draft require together:

  • For each result, can you trace which model version and which inputs produced it?
  • Does the system return the same result for the same input?
  • Is there an audit trail that shows who triggered or changed what, and when?
  • Does the system detect when an input lies outside its scope (applicability domain)?
  • Is there a rule for how uncertain or contradictory results are handled?
  • Where is the data processed and stored, and who has access?

We have bundled these and eight more questions into a checklist that you can go through with your team in 20 minutes: the Annex 22 Readiness Check for labs.

Running it in-house as an option for data sovereignty

Many QA and IT departments ask one question first: where does our data end up? For labs with sensitive method or product data, it can make sense to run tools in their own network rather than in someone else's cloud. CovaSyn offers running it in-house as an option. Whether that is necessary for a use case depends on the data, the risk and the existing infrastructure, and can be clarified in a conversation.

What you can do now, regardless of the final text

Whether the final Annex 22 allows generative AI under conditions or not, four steps are worth taking in any case, and none of them is wasted.

  • Inventory your use cases. Record all AI applications in the lab, including the unofficial ones. A chat assistant that someone uses to rephrase a deviation is an AI application.
  • Assess criticality. Classify each application: does it affect a GMP relevant decision or not? This determines which controls are needed.
  • Define the human in the loop. For each application, decide who checks the result before it is used further, and how that check is documented.
  • Build AI literacy. Since 2 February 2025, the EU AI Act (Art. 4) has required deployers of AI systems to ensure sufficient AI literacy among their staff. This obligation applies independently of Annex 22, so it applies today.

If you are also looking for guidance on validation: the second edition of GAMP 5 includes Appendix D11, a dedicated appendix on AI and machine learning.

Frequently asked questions

Is Annex 22 already binding?

No. Annex 22 is a draft. It was published for consultation in July 2025 and is currently being revised. Until it is adopted, it is not part of the binding EU GMP Guide. Many companies are preparing now anyway, because the basic direction has been stable since the draft.

May LLMs such as ChatGPT or Claude be used in GMP processes?

The draft excludes generative AI and LLMs from critical GMP applications. For non-critical support, such as drafts, research or evaluation suggestions with human review, this does not apply in the same way. Since 2026, the EMA has been examining under which controls generative AI could be permitted more broadly.

What is the difference between Annex 11 and Annex 22?

Annex 11 covers computerised systems in general. Annex 22 adds requirements specific to AI models, for example a defined intended use, test data, performance monitoring and human oversight. Annex 22 does not replace Annex 11.

What does "human in the loop" mean in practice?

A qualified person checks the AI result before it becomes a GMP relevant decision. Responsibility stays with the company and the persons in charge.

How does CovaSyn fit in?

At CovaSyn, the language model plans the workflow and the calculations run in reproducible chemistry tools. Every step is traceable and a human checks the results. CovaSyn is a tool for research and the lab, not validated GMP software and not compliance advice.

What can we do now, before Annex 22 is final?

Record your AI use cases, classify them by criticality, decide where a human checks, and train your staff. The AI literacy obligation under the EU AI Act has applied since February 2025.

Does Annex 22 also cover research and development?

Annex 22 is part of the GMP Guide and targets the manufacture and quality control of medicinal products and active substances. Research outside GMP is not directly covered. But anyone who later transfers methods into GMP benefits from building in traceability early.

Next steps

Sources

Annex 22 is available as a draft (as of 5 October 2026). This content is not legal, regulatory or compliance advice.

Next step

Compute it instead of guessing.

Create an account, get your API key, use the tools in Claude, ChatGPT or Cursor.