If you searched "AI Annex 11" hoping to find a document by that name, I want to save you some time: it doesn't exist yet. What exists is EU GMP Annex 11, "Computerised Systems," a regulation written in 2011 that never uses the word "artificial intelligence," sitting next to a draft annex that will. Understanding the gap between those two documents, and what to do while it closes, is the real question behind the search term.
I'm Jared Clark, JD, MBA, RAC, Principal Consultant at Certify Consulting. Quality and regulatory teams have been bringing me this exact question since the draft Annex 22 consultation opened, so I want to walk through what current Annex 11 already requires of AI systems, what's changing, and what to do before the new text is final.
Annex 11 is part of EudraLex Volume 4, the European Commission's compiled Good Manufacturing Practice guidance, and it has governed computerised systems in GMP-regulated manufacturing since it took effect on 30 June 2011. The Pharmaceutical Inspection Co-operation Scheme adopted it word for word as PE 009-15, so the same text controls inspections across more than 50 PIC/S member countries, not just the EU. It was written for validated software, servers, and databases. It was not written with machine learning models in mind, and it shows.
That's changing. The European Medicines Agency published a concept paper for revising Annex 11 on 16 November 2022, and one of its explicit gaps was regulatory expectations for AI and machine learning, particularly around the data used to train and operate these systems. Since then, the EMA's GMDP Inspectors Working Group and PIC/S have gone further than a simple revision: they're drafting an entirely new annex, Annex 22, dedicated to artificial intelligence. That's the document most people typing "AI Annex 11" are actually looking for.
What Annex 11 Actually Covers
Annex 11 organizes computerised systems compliance around seventeen numbered sections built on a single governing principle: risk management applied across the full system lifecycle, proportionate to patient safety, data integrity, and product quality. The sections that matter most for anyone running AI inside a GMP environment are risk management (clause 1), validation (clause 4), data (clause 5), audit trails (clause 9), security (clause 12), and electronic signature (clause 14).
None of those clauses were drafted with a large language model or a predictive quality-control algorithm in view. But none of them say "software" in a way that excludes AI, either. Regulators have made clear, through the concept paper and the reflection papers that followed, that they read Annex 11's existing scope as already covering AI-enabled tools. The absence of the word "AI" in the 2011 text is not the same as an exemption from it.
Does Annex 11 Already Apply to AI Systems?
This is the question that actually needs answering today, because Annex 22 won't be finalized for a while yet. The honest answer is yes, with real friction at the edges.
Here's how each core clause maps onto an AI-enabled system, and where it starts to strain.
| Annex 11 Clause | What It Requires | The AI-Specific Question It Raises |
|---|---|---|
| 1. Risk Management | Risk management applied across the system lifecycle, scaled to patient safety, data integrity, and product quality | Has the risk assessment accounted for model drift, training-data bias, and non-deterministic outputs, none of which a traditional validated system produces? |
| 4. Validation | Documented evidence the system is fit for its intended purpose before use | Can a continuously learning model be validated once at go-live, or does validation need to become continuous verification? |
| 5. Data | Data must be secured against accidental or deliberate change and checked for integrity | Where do training datasets, synthetic data, and fine-tuning corpora sit inside GMP data-integrity controls that were built for transactional records? |
| 9. Audit Trails | An audit trail is required wherever GMP-relevant data can be changed or deleted, capturing what changed, who changed it, and when | Does a model's inference process generate a reconstructable record of how a given output was produced, or is it a black box the audit trail can't reach? |
| 12. Security | Physical and logical controls restrict system access to authorized individuals | Who counts as "authorized" to retrain, fine-tune, or adjust the weights of a model already in production use? |
| 14. Electronic Signature | Electronic signatures must be equivalent to handwritten ones, uniquely linked to the signatory and to the specific content signed | Can a quality professional meaningfully sign off on an AI-generated batch release recommendation they did not derive and cannot fully trace? |
That last row generates the most follow-up questions. A signature is supposed to mean a human reviewed a specific decision and takes responsibility for it. When the decision came out of a model whose reasoning isn't fully inspectable, the signature still has to mean something, and Annex 11 doesn't say how to make that true. That's the gap Annex 22 is being written to close.
What's Changing: The Concept Paper and Draft Annex 22
The 2022 concept paper laid out 33 points for the Annex 11 revision, organized around the existing structure of the annex. Two developments stood out as needing new regulatory language: the handling of "data in motion" and "data at rest" in modern IT architectures, and the validation of AI and machine learning systems, with particular attention to the provenance and quality of training data. That paper was the starting gun.
What came out the other end was more ambitious than a simple update. The EMA GMDP Inspectors Working Group, in cooperation with PIC/S, is now drafting a revised Chapter 4 (Documentation), a revised Annex 11 (Computerised Systems), and an entirely new Annex 22 (Artificial Intelligence) as a package. Draft Annex 22 adds model-specific expectations for data-trained AI and machine learning systems embedded in applications with a direct impact on patient safety, product quality, or data integrity.
Public consultation on the draft ran from 7 July to 7 October 2025 and drew roughly 1,300 comments, which the working group is still processing. The EMA's current Inspectors Working Group plan targets the fourth quarter of 2026 for delivering final text to the European Commission. A multistakeholder workshop was also held on 30 June and 1 July 2026, specifically to gather expert input on regulatory pathways for adaptive, probabilistic, and generative AI models. None of this is settled law yet, but the direction of travel is clear even before the text is final.
Annex 22 Is Not a Replacement for Annex 11
This question comes up often, so let me be direct: Annex 22 does not replace Annex 11, and it will not let you skip Annex 11's requirements once your system involves a model. The two are additive. Annex 11 remains the baseline for every computerised system in a GMP environment, validated software, LIMS, MES, the works. Annex 22 sits on top of that baseline and adds requirements specific to AI and machine learning models where those models are doing something Annex 11's drafters never had to think about: learning from data rather than executing fixed logic.
If your AI tool is deterministic, rules-based, and doesn't change its behavior after deployment, Annex 11 alone may be doing most of the work already. If it's a model that gets retrained, fine-tuned, or produces probabilistic outputs, expect Annex 22 to add a second layer of expectations around training data governance, ongoing performance monitoring, and explainability once it's finalized.
How Annex 11 and Annex 22 Fit Alongside Other AI Guidance
Annex 11 and its coming AI annex aren't the only regulatory documents reshaping this space, and manufacturers with US operations or global supply chains need to track more than one at once.
| Document | Issuing Body | Status as of August 2026 | Scope | Core Mechanism |
|---|---|---|---|---|
| EU GMP Annex 11 (Computerised Systems) | European Commission / PIC/S | In force since 30 June 2011; revision drafted jointly with Annex 22 | All GMP computerised systems | Lifecycle risk management, validation, audit trail, electronic signature |
| Draft Annex 22 (Artificial Intelligence) | EMA GMDP Inspectors Working Group / PIC/S | Draft; consultation closed 7 October 2025; final text targeted Q4 2026 | AI/ML models embedded in GMP-critical applications | Model-specific expectations for training data, monitoring, and use |
| EMA Reflection Paper on AI (EMA/CHMP/CVMP/83833/2023) | EMA, CHMP and CVMP | Finalized and published 30 September 2024 | Full medicinal product lifecycle, from discovery through post-authorization | Non-binding regulatory considerations, not manufacturing-specific |
| FDA Draft Guidance on AI for Regulatory Decision-Making (Docket FDA-2024-D-4689) | FDA, CDER and CBER | Draft published 7 January 2025; comment period closed 7 April 2025 | AI models used in nonclinical, clinical, post-marketing, and manufacturing contexts to support regulatory decisions | Risk-based credibility assessment tied to a defined "context of use" |
| ISPE GAMP Guide: Artificial Intelligence | ISPE | Published July 2025 | AI/ML-enabled computerised systems in GxP environments | Extends GAMP 5's Appendix D11 into a standalone validation lifecycle framework |
Notice what these documents don't do: none of them contradict each other on the fundamentals. Every one lands on the same core idea, that AI's risk to patient safety and product quality has to be assessed and controlled across the full lifecycle of the model, not just at the moment it goes live. The FDA's "context of use" concept and the EMA's model-specific risk lens are answering the same question from different sides of the Atlantic. Annex 22 is where the EU side will formalize its answer for manufacturing specifically.
What Regulated Manufacturers Should Do Now
Waiting for Annex 22's final text before doing anything is the wrong call. The draft has been stable enough in its direction since the 2022 concept paper that acting on Annex 11's existing principles today puts you ahead rather than caught flat-footed later. A few concrete steps:
- Inventory every AI-enabled system touching GMP data or decisions. You can't apply a risk-based framework to systems you haven't listed. Include vendor tools with embedded AI features you may not have flagged as "AI" internally. Quality software with predictive maintenance features is a common blind spot.
- Apply Annex 11's clause 1 risk management to each one now, and document where the assessment breaks down under AI-specific conditions like drift or non-determinism. That documentation becomes the foundation of your Annex 22 readiness file later.
- Treat validation as continuous, not a one-time event, for any model that learns from new data after deployment. Static, point-in-time validation evidence won't hold up under a regulator reading Annex 22's expectations once it's final.
- Build the audit trail question into procurement, not after the fact. Ask vendors directly whether their model's outputs can be reconstructed and explained. Retrofitting explainability into a system you've already validated is far more expensive than requiring it up front.
- Track the consultation outcomes, not just the final text. What changes in the working group's public output between now and Q4 2026 will shape what your internal framework needs to absorb, and organizations that follow it incrementally adjust more easily than those waiting for one final version.
For a closer look at how machine learning specifically fits inside validated pharmaceutical systems today, our guide on GxP-compliant AI and governing machine learning in validated pharmaceutical systems walks through the validation lifecycle question in more depth. And if your systems touch FDA-regulated processes alongside EU ones, our breakdown of FDA's approach to machine learning covers the domestic side of the same problem.
Frequently Asked Questions
Is "AI Annex 11" an official document? No. There's no regulation titled "AI Annex 11." The term reflects a relationship between two separate documents: the 2011 EU GMP Annex 11, which governs computerised systems generally, and the new draft Annex 22, which is being written to address AI and machine learning specifically. Searchers usually mean one or both.
What happens to a company that treats current Annex 11 as not applying to its AI tools? It's a mistake regulators have already addressed. Inspectors reading Annex 11's clause 1 on risk management don't carve out an exception for machine learning; a validated system is a validated system regardless of whether its logic is fixed or learned. Skipping risk assessment, audit trail review, or access control on an AI tool because "the annex doesn't say AI" is a finding waiting to happen, not a defensible gap.
What's the practical difference between Annex 11's audit trail clause and what Annex 22 is expected to add? Annex 11 clause 9 requires a record of what changed, who changed it, and when, which works cleanly for a transactional database. Draft Annex 22 is expected to extend that expectation to a model's inference behavior itself, meaning not just what data changed but why a specific output was produced. That's a materially harder technical problem for anything more complex than a rules engine, and it's the part of the draft manufacturers ask about most.
How is Annex 22 different from the EMA's reflection paper on AI? The EMA Reflection Paper on the use of AI in the medicinal product lifecycle (EMA/CHMP/CVMP/83833/2023, finalized 30 September 2024) covers the full product lifecycle from drug discovery through post-authorization and is non-binding. Draft Annex 22 is narrower and manufacturing-specific, adding enforceable GMP expectations for AI/ML systems embedded in applications with a direct impact on patient safety, product quality, or data integrity.
Will Annex 22 replace Annex 11 for AI systems? No. Annex 11 remains the baseline requirement for every computerised system in a GMP environment. Annex 22 adds AI-specific requirements on top of that baseline for systems involving trained models. It doesn't substitute for Annex 11 compliance at any point.
Last updated: 2026-08-18
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.