
Annex 22 & AI in the Laboratory: What the New EU GMP Guideline Means for Your Day-to-Day Laboratory Operations
.png)
The pharmaceutical industry is at a turning point:Annex 22 to EU-GMP-LeitlinieIt introduces clear rules for AI in the lab for the first time. While many companies alreadyArtificial intelligence in the laboratoryWhether using or planning to use the new regulations, there is uncertainty about the new regulatory requirements.
The good news first: The new draft is not a list of prohibitions, but a guidepost for theGxP compliantThe use of Large Language Models (LLMs) and other AI technologies in regulated environments.
What exactly is Annex 22 and why is it important?
Annex 22complements the provenAnnex 11-Guideline with specific provisions for AI-based systems. While Annex 11 covers traditional computer-based systems, the new draft addresses the specific challenges of modern AI-based systems.AI assistance systems.
The focus is on systems that:
- Changing their functionality through machine learning
- Perform complex data analyses without explicit programming.
- Decision support in thepharmaceutical quality assurance offer
It is important to understand that Annex 22 is still in the public consultation phase. The final version may change, but the basic principles are already apparent.
[[image-1]]
Critical or non-critical: The key distinction
The core of Annex 22 is the differentiation betweencritical application and non-critical applicationof AI and GMP systems. This classification determines the required validation effort.
When is AI classified as critical?
This is a key weakness of Annex 22: The guideline does not provide a precise definition for critical applications. This ambiguity leads to room for interpretation and uncertainty in practice.
The draft only mentions general criteria, which, however, leave plenty of room for different interpretations:
- Direct impact on product quality or patient safety
- Automated decisions without sufficient human oversight
- Lack of traceability or reversibility
- GMP-relevant process control
Important:This ambiguity does not mean that all AI applications should automatically be considered critical! Rather, it requires a thoughtful, risk-based assessment of each individual case.
Possible approaches to criticality assessment:
Approach 1: Depth of intervention
- Does the AI only give recommendations (uncritically)?
- Does she make autonomous (potentially critical) decisions?
- Does it directly interfere with GMP processes (critically)?
Approach 2: Default risk
- What happens when AI produces incorrect results?
- Are the consequences reversible?
- Are there safety nets and control mechanisms in place?
Approach 3: Regulatory Relevance
- Does AI influence GMP-documented processes?
- Does it affect validated systems?
- Does it influence batch records or release decisions?
Examples for guidance:
- Probably critical:Automatic batch release, AI-driven analysis result evaluation
- Probably uncritical:Literature research, training support, maintenance planning
- Grey area:Trend analyses with recommendations for action, automated report generation
The lack of a clear distinction necessitates a careful, documented approach.GxP risk assessmentfor every use case – ideally in coordination with quality assurance and regulatory experts.
Non-critical AI: More flexibility in everyday laboratory work
However, most AI applications in laboratories fall into the categoryAI not subject to validationThese supporting systems can be operated with reduced requirements:
- Document-based AIfor information search
- LLMs for training purposes and knowledge transfer
- Data analysis tools for trend identification
- Automated reports without direct GMP relevance
The decisive factor: The final decision always remains with the human, and all actions are transparently documented.
[[whitepaper]]
AI Validation: What is really required?
Also non-critical applicationsThey must meet certain standards. Annex 22 defines clear control mechanisms:
Technical requirements:
- Audit Trail: Complete logging of all inputs and outputs
- Model fixation: Use of defined, tested versions
- Access control: Restriction to authorized users
- Human-in-the-loopHuman surveillance and decision-making authority
Organizational measures:
- Documented risk assessment for each use case
- Clear responsibilities and escalation channels
- Regular review of AI performance
- User training
Practical example: How Thunder AI meets the requirements
ModernAI in GMP-regulated laboratories How Thunder AIThey demonstrate how a balance between innovation and compliance can be achieved. Such systems offer:
- Document-based answers with verifiable sources
- Strict data separation and access control
- Complete audit logs for all interactions
- Human-in-the-loop principle in all recommendations
This way, laboratories can benefit from AI support withoutRegulatory requirements for AIto injure.
Strategic recommendations for laboratory managers
1. Conduct an inventory
Record all currently used AI tools and assess them according to the criteria of Annex 22. Not every use of ChatGPT for research purposes is automatically critical.
2. Implement risk assessment
Develop a systematic approach to GxP risk assessment of new AI applications. This creates legal certainty and enables informed decisions.
3. Document processes
Create clear SOPs for AI deployment, define responsibilities, and establish audit mechanisms.
4. Train employees
Raise your teams' awareness of theregulatory requirementsand raise awareness about the correct use of AI tools.
The future: AI as an opportunity, not a risk
Annex 22 does not signal the end of AI innovation in laboratories, but rather its professionalization. Companies that act proactively now can secure significant advantages:
- Innovation advantagethrough compliant AI integration
- Efficiency gainswith simultaneous compliance
- Competitive advantagesthrough structured digitization
- Future securityfor upcoming regulatory developments
Conclusion
The new Annex 22 presents an opportunity for the systematic and compliant integration ofArtificial intelligence in the laboratoryCompanies that act now can successfully combine AI innovation with GMP compliance and secure important competitive advantages.
FAQ: The Most Important Questions About Annex 22 and AI in the Laboratory
Do I need to remove all AI tools from my lab now?
No, definitely not. Annex 22 does not ban AI, but rather regulates its use. Most supporting AI applications can continue to be used with appropriate control measures in place. The key is to distinguish between critical and non-critical applications.
What is the difference between Annex 11 and Annex 22?
Annex 11 governs traditional computerized systems, while Annex 22 is specifically focused on AI and machine learning systems. Annex 22 complements Annex 11 and accounts for the unique characteristics of learning systems, such as non-determinism and evolving model parameters.
What documentation do I need for non-critical AI applications?
Even non-critical applications require a documented risk assessment, clear usage policies, and a functional audit trail. However, the requirements are significantly lower than those for critical systems.
How do I determine if my AI application requires validation?
The validation requirement depends on the criticality of the application. Ask yourself: Does the AI have a direct impact on product quality or patient safety? Does it make automated decisions without human oversight? Is it GMP-relevant? If so, full validation is required.
How do I prepare my laboratory for the final version of Annex 22?
Start by taking stock of all AI applications and implementing a systematic GxP risk assessment and establishing the recommended control mechanisms now. This ensures you are prepared when the final version comes into effect.

Why holistic knowledge management is the key to successful laboratory automation

The Untapped Power of Your Instrument Logbook — Recognizing and Realizing Its Potential


