Here's the question EU inspectors are starting to ask about AI in GMP processes: not "does it work," but "who's on the hook if it doesn't."
EU GMP Annex 22 has been in draft since July 2025. The public consultation closed in October 2025, and as of today it isn't a requirement. But it's the clearest signal yet of where regulators are heading on artificial intelligence in GxP environments. We call this space GxP Decision Intelligence: AI that supports a GxP decision without ever making it for you. Quality, compliance, and digital transformation teams are already reading the draft as a preview of what's coming.
The draft leans on five ideas. Each one is worth turning into a question you ask about your own AI tools before a regulator asks it for you.
Annex 22 asks manufacturers to define, in writing, exactly what decision a model is allowed to touch and where that boundary sits. A model that flags a temperature excursion for human review is doing something different than a model that decides, on its own, whether a shipment ships. The draft treats those as two different risk categories, not two versions of the same tool.
The question to ask: What decision is this model allowed to touch, and what is it explicitly not allowed to touch?
This is where Annex 22 overlaps most directly with the world quality teams already work in under Annex 11's computer system validation requirements. A model validated on clean, idealized data doesn't tell you how it behaves on a real lane, a real packaging configuration, or a real excursion profile. The draft's expectation is that validation data has to resemble the operating environment the model will actually run in.
The question to ask: Was this tested on lanes, packaging, and excursion profiles that look like mine, or on a dataset built to make the model look good?
A model that was accurate at validation isn't guaranteed to still be accurate six months later. Carriers change routes, packaging changes, seasons change. Annex 22 expects ongoing performance monitoring after deployment, not a one-time validation event.
The question to ask: How do I know this model still works six months in, and how would I know if it started to drift, hallucinate, or develop a bad habit?
If a system recommends holding a shipment, releasing it, or investigating a deviation, someone has to be able to reconstruct what it evaluated and why. Annex 22 treats this as close to an audit trail requirement: the reasoning has to be retrievable, not just the output.
The question to ask: Can I reconstruct what the system evaluated and why it recommended what it did, and does that reasoning hold up when I explain it to an auditor?
None of the first four points matter if there's no name attached to the final call. Annex 22 keeps the decision, and the record of who made it, with a person. AI can narrow the options and surface the evidence; it doesn't sign the release.
The question to ask: Who made this decision, and where is that recorded?
The current draft is deliberately conservative about AI as the final decision-maker in critical GMP applications. Static, deterministic models are in scope. Continuously learning systems and generative models are steered away from critical use, at least for now.
That's a sound line to build on. AI that analyzes risk, surfaces recommendations, and speeds up a decision, while the evidence trail and the human sign-off stay intact, is a different category of tool than AI that makes the GMP decision for you. Annex 22 is drawing that line explicitly, but it's the same line quality teams already draw when they decide what belongs in a validated system versus a decision-support tool.
This is GxP Decision Intelligence, the territory PAXAFE has been building in from the start. The AI supports GxP quality and cold chain decisions with visible, auditable reasoning, not blind trust in a black box. Annex 22 doesn't change that approach. It's confirmation of it.
See how PAXAFE keeps a human-reviewable audit trail in CONTXT all the way through your product release.
The draft and full consultation record are available on the European Commission's website — read the draft Annex 22 text and consultation summary.
What is EU GMP Annex 22? EU GMP Annex 22 is a draft annex to EudraLex Volume 4, the EU's GMP guidelines, that sets out expectations for using artificial intelligence in GMP-regulated decisions. It addresses intended use, validation, performance monitoring, explainability, and accountability for AI systems used in pharmaceutical manufacturing and quality.
What is GxP Decision Intelligence? GxP Decision Intelligence is PAXAFE's term for AI that supports GxP decisions surfacing risk, evidence, and recommendations while keeping the evidence trail auditable and the final sign-off with a person. It's the practical middle ground Annex 22 is drawing a regulatory line around: AI that speeds up a decision without becoming the decision-maker.
Is EU GMP Annex 22 a legal requirement yet? Not yet. The draft was published in July 2025 and the public consultation closed in October 2025. As of now it is not in force, but it signals the direction EU regulators are taking on AI in GxP environments.
Does Annex 22 allow AI to make GMP decisions on its own? No. The current draft is deliberately conservative about AI as a final decision-maker in critical GMP applications. Static, deterministic models are in scope for supporting decisions; continuously learning and generative systems are steered away from critical use. A named person remains accountable for the final decision.
How does Annex 22 relate to Annex 11? Annex 11 governs computerized systems and validation in GMP environments today. Annex 22 is expected to sit alongside it, applying similar validation and accountability principles specifically to AI and machine learning systems.
What should quality and compliance teams do now, before Annex 22 is finalized? Start asking the five questions the draft is built on: what decisions a given AI tool is allowed to touch, whether it was validated on representative data, how its performance is monitored over time, whether its reasoning is explainable and auditable, and who is accountable for the final decision. Teams that can already answer these won't be caught off guard when the annex is finalized.