Guide: what the draft Annex 22 requires of AI in GMPRead the guide

Artificial intelligence an inspector can review

We bring AI models into the company's processes and deliver the evidence that they do what they claim: what they are used for, how they were tested, which version is in production and who approved each proposal.

  • Intended use defined and approved
  • Model version under change control
  • A person always decides

Reading, classification and drafting work

What a model does well today.

AI pays off where qualified staff spend hours reading, comparing and filling in forms. In every case the model prepares and a person decides, and the system keeps a record of both.

  • The model prepares
  • A person decides
  • Recorded in the trail
  1. InOpen deviations GMPComplete batch record GMPProcedure and revised standard GxPEmail, form or literature GVPSource data RegulatoryA change to the system CSV
  2. The model preparesgroups the ones describing the same problem and finds similar past casesreads all of it and shows only what went out of range or doesn't add upcompares them and lists the gaps with the exact clauseextracts the case, proposes MedDRA coding and detects duplicatesdrafts dossier sections with the reference for each data pointstates which evidence is affected and which isn't
  3. ProposalDraft investigation, with its sources citedBatch exceptions, with its sources citedGaps with their clause, with its sources citedCoded case, with its sources citedDraft section, with its sources citedAffected evidence, with its sources cited
  4. A person decidesQuality assurance: accepts, corrects or rejectsThe Qualified Person: accepts, corrects or rejectsThe process owner: accepts, corrects or rejectsThe case assessor: accepts, corrects or rejectsRegulatory affairs: accepts, corrects or rejectsThe validation lead: accepts, corrects or rejects
  5. Audit trailwhat the model proposed, with which version; what the person accepted, corrected or rejectedwhat the model proposed, with which version; what the person accepted, corrected or rejectedwhat the model proposed, with which version; what the person accepted, corrected or rejectedwhat the model proposed, with which version; what the person accepted, corrected or rejectedwhat the model proposed, with which version; what the person accepted, corrected or rejectedwhat the model proposed, with which version; what the person accepted, corrected or rejected

Deviations and CAPA

Groups deviations that describe the same problem in different words, searches the history for similar cases and how they were closed, and proposes a draft investigation with its sources cited.

GMP

Decides: quality assurance.

Batch review by exception

Reads the complete batch record and presents only what went out of range, what is missing and what doesn't match previous batches.

GMP

Decides: the Qualified Person who certifies the batch.

Procedures and regulatory changes

Compares your procedures with a revised standard and lists the gaps with the exact clause. Turns a paper procedure into guided execution steps.

GxP

Decides: the process owner.

Pharmacovigilance

Extracts the data of a case from email, the form or the literature, proposes the MedDRA coding, detects duplicates and translates the original text. The reporting clock starts at receipt.

GVP

Decides: the case assessor.

Registration and regulatory affairs

Drafts dossier sections from the source data, with a reference for each data point, and finds in earlier dossiers how a similar question from the agency was answered.

Regulatory

Decides: regulatory affairs.

System validation

Proposes requirements, test cases and the traceability matrix, and when something changes it shows which evidence is affected and which is not.

CSV

Decides: the validation lead.

The seven pieces of evidence of a validated model

What we deliver for each model.

A model is not validated like a spreadsheet formula. Its output is probabilistic and its provider releases new versions. That is why the documentation of a system with AI includes pieces a conventional system doesn't need. Together they make up the model documentation: the evidence package you show in an inspection.

Intended use
What task the model performs, on what data, and what is out of scope. Everything else is measured against this definition.
Level of autonomy
Whether the model suggests, drafts or executes with approval. It is decided according to the risk to the patient and the product, and the decision is justified in writing.
Test data
Real, representative cases, kept separate from those used to tune the system. The acceptance criterion is set before testing.
Sources for each proposal
Each proposal shows which documents or records it comes from, so the reviewer can check it.
Version under change control
The model, its version, the instructions and the configuration are part of the validated system. A new version from the provider doesn't reach production without going through change control.
Recorded oversight
The audit trail keeps what the model proposed, with which version, and what the person accepted, corrected or rejected; that person is trained to understand the output and challenge it.
Monitoring in production
The share of proposals that get corrected or rejected is measured continuously. If it rises, the system flags it before an audit finds it.

Layered controls

Prevent, detect and contain.

No control is perfect on its own, so we combine them in three layers. Each one is tied to a specific failure mode and a measurable acceptance criterion, and the risk assessment is updated when an unforeseen failure mode appears.

  • At the input: checking that the case is within the intended use before it reaches the model
  • In the model: cited sources for each proposal and a confidence score
  • At the output: thresholds, review by a person and a return to a safe state, with a defined escalation path, when something fails

Your data doesn't train third-party models

Data and model provider.

Nor does it leave the European Union or the country your regulations require, whether the system runs on your infrastructure or we run it for you.

  • We don't resell any model or any platform: we choose the one that suits the case
  • The system is ready to switch models, under change control and without being rebuilt
  • If the model comes from a third party, it has to provide the evidence needed to control it, such as logs and the rationale for its outputs: GMP accountability stays with your company

Where we don't use AI

What a person always decides.

Certifying a batch, deciding to notify an authority, approving a change and deciding the disposition of an out-of-specification result belong to people with a name and accountability. The model can prepare the information for those decisions, but it doesn't make them.

The draft Annex 22 to the EU GMP Guide currently restricts critical applications to static, deterministic models and leaves generative models for non-critical uses, with a person reviewing the output. Since the consultation, the European Medicines Agency has been considering allowing them with a risk-based control strategy, and the report of its latest workshop stresses that accountability stays with people and cannot be delegated to AI. The final text has not been published yet, and we design so the system can adapt to it without being rebuilt. We explain it section by section in the Annex 22 guide.

And if the risk assessment concludes that a model's uncertainty cannot be controlled, the conclusion is not to use it, and that conclusion is documented.

Where could a model help you?

We start from a real case in your process and tell you whether a model adds enough to justify validating it.