
Note: Annex 22 is available as a draft (as of 5 October 2026). This content is not legal, regulatory or compliance advice.
Short answer
Today, AI in the QC lab can mainly prepare, structure and recalculate. The decision stays with a qualified person. The EU GMP Annex 22 draft excludes generative AI and LLMs from critical GMP applications. There is plenty of room for support with human review, as long as the roles are clearly assigned.
What "human in the loop" means in the QC lab
Human in the loop means: a qualified person checks the AI result before it becomes a GMP relevant decision. Responsibility stays with the company and the persons in charge. The Irish regulator HPRA also stressed in 2026 that testing and confirming the outputs is key wherever AI is used.
For this to work day to day, each use case needs three things defined:
- What the AI does: prepare, suggest, recalculate. Not: release, reject, decide.
- Who checks: a named role with the expertise for exactly this check.
- How the check is recorded: so that you can later show what the AI delivered and what the human did with it.
Five use cases with a clear division of roles
The following examples describe support, not critical decisions made by an AI. Whether a use case counts as GMP critical in your organisation is for your own risk assessment to decide.
1. Trend evaluation of stability data
- AI: an assistant organises stability data, runs the regression in a calculation tool and flags values that deviate noticeably from the trend.
- Human: QC analytics checks the flags, assesses them scientifically and decides whether to open an out-of-trend investigation.
More on the scientific background in Out-of-trend and OOS in stability data.
2. HPLC method development
- AI: suggestions for column choice, gradient and starting conditions based on the molecular structure and the literature.
- Human: method development plans the experiments, assesses the results and decides on the method, which is then validated in the usual way.
Background: HPLC column selection in method development.
3. Identifying unknown impurities
- AI: candidate structures are proposed from mass spectrometry data and the corresponding masses are recalculated.
- Human: analytics checks the candidates against further data and decides which structure is considered established.
Background: Identifying unknown impurities with LC-MS.
4. ICH M7 pre-assessment
- AI: a first assessment of potentially mutagenic impurities with a rationale, plus a flag when a structure lies outside a model's applicability domain.
- Human: toxicology or QA checks the classification and enters it into their own assessment.
Background: ICH M7 classes 1 to 5 with examples and Applicability domain in QSAR.
5. Drafting documentation
- AI: drafts of deviation descriptions, report sections or summaries of measurement series.
- Human: as with any draft: review, correction and approval in the existing document process.
Why computation and language belong apart
The same pattern runs through all five examples. The language model understands the task, plans the steps and writes up the result. The numbers that matter do not come from the language model but from a tool that returns the same result for the same input. The article Tool calling vs fine-tuning describes why this works better than a model that does everything itself.
CovaSyn connects LLMs with reproducible chemistry tools. The language model plans, the tools compute, every step is traceable. CovaSyn is a tool for research and the lab, not validated GMP software and not compliance advice.
Common mistakes when introducing AI
- Overlooking unofficial use: chat assistants are often used before any rule exists. They belong in the inventory.
- Review without a record: "someone looked at it" is not enough. The review needs a trail.
- Unclear responsibility: if nobody is named, in the end nobody checks.
- Forgetting AI literacy: since 2 February 2025, the EU AI Act has required sufficient AI literacy among staff (Art. 4), independently of Annex 22.
Frequently asked questions
What does "human in the loop" mean in practice?
A qualified person checks the AI result before it becomes a GMP relevant decision. Responsibility stays with the company and the persons in charge.
May an AI release a batch?
No. Batch release is a decision with a direct effect on patient safety and stays with the responsible person. AI can prepare the documents for it.
Is a chat assistant in the lab an AI application in the sense of Annex 22?
It is certainly an AI application that belongs in the inventory. Whether it falls within the scope of the final Annex 22 depends on what it is used for.
Next step
With the Annex 22 Readiness Check, you check where your lab stands in 14 questions. In the workshop module AI in the GxP lab, you work through your own use cases with your team. The pillar page AI in the GxP Lab and EU GMP Annex 22 gives the full overview.
Sources
- EMA, multistakeholder workshop on Annex 22: ema.europa.eu
- HPRA, presentation at the QP Forum 2026: tcd.ie (PDF)
- Regulation (EU) 2024/1689 (AI Act), Art. 4 and Art. 113: eur-lex.europa.eu
Annex 22 is available as a draft (as of 5 October 2026). This content is not legal, regulatory or compliance advice.
