Pharma

AI on the GMP Line: What the EU AI Act and Draft Annex 22 Now Ask You to Prove

2026Nextvise

Most AI regulation is written in the abstract: be fair, be transparent, keep a human in the loop. Then someone has to apply it to a batch of medicine on a real production line, and the abstractions have to become records. The EU's draft Annex 22 is what that looks like when regulators get specific, and for anyone running AI in GMP-regulated manufacturing, it is worth reading closely, because it reads almost exactly like a specification for a defensible system.

Two rulebooks converging on the same line

A pharma manufacturer using AI in production is now in the path of two instruments at once.

The EU AI Act is horizontal. AI used in the manufacture of medicinal products can fall into its high-risk tier, and the Act's evidence obligations follow: Article 12 requires high-risk systems to automatically record events over their lifetime, and Article 14 requires effective human oversight by a competent person with the authority to intervene. (We cover those in What Defensible AI Means in a Regulated Environment.)

Draft Annex 22 is vertical, the sector-specific one. Published for consultation on 7 July 2025, with the consultation closing on 7 October 2025 after roughly 1,300 comments, it is a proposed supplement to the EU GMP Guide dealing specifically with AI. It is still a draft, not yet legally binding, with a final version expected around the end of 2026, but its direction is unusually concrete.

What Annex 22 actually pins down

This is where it stops sounding like principles and starts sounding like a build spec.

Static models only, for anything critical. The draft draws a hard line between static models, locked after training so they do not change during operation, and adapting models that keep learning from new data in use. Adapting models are excluded from GMP-critical applications. The reason is the oldest one in GMP: a validated state has to stay put. A critical model has to be deterministic, the same input reliably producing the same output.

A named human stays accountable. A competent person remains accountable for AI-supported decisions, with the level of oversight scaled to risk. And responsibility does not offshore: the manufacturer remains responsible for GMP compliance regardless of which supplier provided the model.

Testing you can show. Systems are validated for their intended use. Acceptance criteria are set before testing, the model is tested on data independent from its training set, and performance measures, including confidence scores and decision thresholds, are documented.

Explainability, at the feature level. For predictive and classification models, you are expected to be able to show which input features drove a given output, and why those features are relevant.

ALCOA+ on every decision. Inputs, outputs, and decisions follow ALCOA+ data-integrity principles, with an audit trail capturing the model version, the inputs, the outputs, and any human override.

Read that list again

Model version. Inputs. Output. The human override. Per decision, on an audit trail, testable against independent data, explainable at the feature level. That is not a policy on a shelf, and it is not an annual certificate. It is a per-decision evidence record, and a regulator has all but written the schema.

Annex 22 is, in effect, defensibility made mandatory for a whole industry. A framework will not satisfy it. Only the record will: what the model was, what went in, what came out, and who could stop it.

The standard we build to

Nextvise is the infrastructure for Defensible AI. It validates every AI output against the requirements that govern it, returns it signed, and keeps a tamper-evident record, model version, inputs, output, and any human override, of exactly the kind Annex 22 describes, escalating anything that does not hold to a named human, on the record.

The EU AI Act tells you to log and to oversee. Annex 22 tells you what the log has to contain. A Nextvise record is that log, produced at runtime, not reconstructed before an inspection.

― basis: EU AI Act Art. 12 (record-keeping) & Art. 14 (human oversight) · EU GMP Annex 22 (Draft, published 7 July 2025; consultation closed 7 October 2025; final expected ~end 2026) · ALCOA+ data-integrity principles

Get Audit-Ready
← Back to Insights