GxP news - QFINITY
QFINITY · News · Insights & Events

Shaping the regulated quality of tomorrow.

Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI - what is changing in the regulated environment, what it means in practice, and what is happening inside our company.

Latest articles

Events, case studies and insights.

Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop - QFINITY

Within seven months, three signals converged on how to assess AI in the GxP environment: the rapporteur of the EMA drafting group for EU GMP Annex 22 explained the draft’s criticality logic in Barcelona in December 2025, a National Expert at the US FDA made clear in Boston in June 2026 that the rules still hold, and at the EMA expert workshop on 30 June 2026 industry answered with a joint position. QFINITY followed all three, Barcelona and Boston on site, the EMA workshop via its public broadcast. The occasions were independent of one another, yet all of them arrive at the same five sentences. It is the line we ourselves presented at the GAMP D-A-CH Forum in Berlin in March 2026, with the question: who pushes back when the system speaks?

Taken in turn: in Barcelona the drafting group’s rapporteur spoke, in Boston a National Expert at the FDA, at the workshop industry addressed the EMA. At the end we put the three signals in perspective.

Barcelona, December 2025: How the drafting group thinks about criticality

At the 2025 ISPE Pharma 4.0 Conference (9 and 10 December 2025, Barcelona), the rapporteur of the Annex 22 drafting group, a representative of the Danish Medicines Agency, explained how the draft delimits its scope. The guiding question was: what effect would an error have, and would it be detected? Which technology is in use makes no difference to that classification, at least at first. An AI-supported application whose output passes through an expert review anyway, for example training material or SOP drafts, counts as non-critical. An application whose output feeds into the quality decision without further review, for example in quality control or automated visual inspection, counts as critical.

The rapporteur then explained the draft’s original regulatory intent. Within the critical area, the draft initially excludes certain technologies. On the slide this area sat in the top right, and as the “upper right-hand corner” it became a catchphrase among experts. Dynamic systems that keep learning in operation are left out, as are probabilistic systems where the same input and the same version do not guarantee the same result. Consequently, that also applies to large language models. Although this view starts from process and system design, it was in the end tied to technology. That became one of the main points of discussion across the industry. He had delivered the same message with the same slides in the GAMP D-A-CH community a few days earlier: on 4 December 2025 at the 2nd GAMP Conference “Künstliche Intelligenz trifft Pharma” in Mannheim. QFINITY was involved in leading the GAMP D-A-CH community for more than a decade and helped build the AI community in D-A-CH.

The second thought from Barcelona concerns evidence. A trained model cannot be proven out by a single deterministic test. The evidence takes a different form: test data that are themselves subject to requirements, and metrics that carry the evidence for control and effectiveness. That is how data scientists think, and it is at the same time the principle of quality risk management: decision under uncertainty. On evidence, then, Annex 22 imports no foreign logic into the GxP world; it applies the existing logic to models. On scope, by contrast, the draft draws the line a priori rather than judging a model type’s admissibility on the basis of the risk assessment. Industry would later take the discussion up from there.

Boston, June 2026: An FDA voice says the rules still apply

At the ISPE AI in Life Sciences Summit in Boston (22 and 23 June 2026), Seneca Toms, National Expert for Drugs at the US FDA, spoke about how industry is handling AI. Oliver Herrmann was in the room. Frank Henrichmann, as Chair of the GAMP Global Steering Committee, represented the “Powered by GAMP” side of the summit. What made the talk convincing was the clarity with which a regulator’s voice applied the old principles to the new technology. Safe and effective products, controlled processes, identified and managed risks, scientifically justified decisions: that held before AI, and it holds after. ISPE’s editorial team summarized the talk in an August iSpeak post. It notes explicitly that the summary has not been vetted by any of the agencies mentioned and does not represent an official agency position. We therefore present the thoughts that follow as a reflection on the talk, not as an FDA statement.

We pick up four thoughts from Boston because they apply directly to regulated companies. How deeply you test follows the decision a system supports: a tool that summarizes meeting notes needs a different level of assurance than a system that feeds into decisions on product quality or patient safety. Oversight begins with understanding; whoever approves a result without understanding it is not exercising Human Oversight. The greatest risk sits in trust. Toms described inspections where systems had not failed; people had simply stopped asking, because the systems had been running for years. It reflects an observation we also described in Berlin. We will come back to it below. With AI the pattern repeats as soon as recommendations are accepted because they are convenient or look credible. And the “current” in cGMP demands keeping pace. New tools are measured against today’s state, because paper, legacy systems, people and today’s means of controlling AI all have limits.

“You can outsource a lot of things, but you cannot outsource your common sense.” (Seneca Toms, US FDA, as quoted by ISPE iSpeak, 24 August 2026)

EMA expert workshop, 30 June 2026: Industry answers with one voice

One week after Boston, the EMA spent a day listening to industry. At the expert workshop on the draft EU GMP Annex 22, experts nominated by the associations presented their positions on six topics set by the EMA, the six pillars of the EMA’s guardrail architecture, from regulatory pathways for adaptive models through Human Oversight, validation and lifecycle to cybersecurity. We followed the publicly broadcast first day in full. The workshop followed the 2025 consultation, which drew 1,359 comments from 79 organizations; the call for a risk-based approach was its clearest theme. On the second, non-public day the drafting group took the input on board and continued its work on the text. The two-day sequence was set from the outset. For us, the signal lies in the tone of the public statement the EMA gave afterwards. It suggests that the ideas and concepts presented were received as helpful. A senior FDA official, too, publicly praised the workshop’s format and dialogue.

The associations had been asked to present divergent views as well. The outcome was nonetheless clear: their approaches agree, and they come down to how a quality-risk-based approach is interpreted. On the central question of scope, industry’s position departed from the draft. The draft excludes dynamic, probabilistic and generative models from critical applications. Industry countered that no model type is inadmissible or harmless per se. Admissibility is decided by the risk assessment in the specific use case. On Human Oversight, industry proposed replacing the Human-in-the-Loop mechanism fixed in the draft with a Human Oversight concept with several forms. The range runs from approval of every output to ongoing monitoring with intervention by exception. Which form is appropriate follows from the risk assessment. And on guardrails, industry drew the line itself: they reduce risk, they do not remove it, and a control that is meant to lower risk needs its own evidence of effectiveness.

From QFINITY’s point of view, the quiet highlight was an architecture diagram shown at the workshop: the AI subsystem of model, integration code and guardrails as a part inside the computerized system, which also includes process and people. That embedding is precisely the architecture behind our validation of AI in the GxP environment: the model is verified; the computerized system as a whole is validated in the process.

Five sentences all three share

Placed side by side, the three occasions leave a common core that none of the voices disputes:

1
Criticality is derived from the process and measured by impact and detectability, not by technology. Whether framed as impact and detectability, as the significance of the decision or as the risk assessment in the use case, all three describe the same axis. The particular traits of generative or dynamic models belong one level down, in the functional risk assessment, where guardrails come in as controls in the sense of quality risk management.
2
Human Oversight is a capability. Barcelona makes expert review the measure of criticality, the FDA voice from Boston demands understanding rather than mere approval, industry proposes replacing the fixed HITL mechanism with a Human Oversight concept with several forms, and all three presuppose that people can review effectively.
3
The form of evidence shifts to statistics, and it stays within GxP logic. A model is verified with test data that carry their own requirements, with metrics and with confidence levels, and that follows the principle of decision under uncertainty.
4
Oversight applies to the whole lifecycle. It runs from planning and design through initial verification and the whole period of use to decommissioning. That includes adjusting the form of oversight, and it includes monitoring. Confidence in a system is not established once and then left alone.
5
Accountability stays with the operating company. No model and no service provider relieves you of it. Toms said it from the FDA’s perspective, industry presented it as consensus at the workshop, and your next inspection will assume it.

Our position from Berlin: Who pushes back when the system speaks?

The five sentences match the position Daniel Köpke and Oliver Herrmann presented at the 47th GAMP D-A-CH Forum in Berlin on 11 March 2026. They asked what Human Oversight means when systems become more intelligent, more complex and more convincing. The starting point was responsibility: a patient knows neither SOPs nor validation plans; they trust that in the end a human stands behind quality. An AI-enabled system can analyze data, detect patterns, classify deviations and prepare decisions, and it sounds plausible while doing so. That is exactly where the risk lies: plausibility is not evidence of review. It can trigger a review, it cannot replace one, and it does not make responsibility transferable.

The biggest danger to QA is therefore not AI. It is the silent erosion of visible responsibility: click by click, confirmation by confirmation, until no one pushes back anymore. The role of QA shifts accordingly: it does not just validate systems, it shapes the conditions under which human judgment remains effective. Human Oversight belongs embedded in intended use, business process, data integrity, risk-based controls and lifecycle evidence, so that responsibility is not merely documented but exercised, and its effectiveness stays demonstrable. The full version of this position is in Who Pushes Back When the System Speaks?

What conditions do you need to create today so that in three years someone will still challenge a recommendation the system has delivered without complaint all along?

What follows for regulated companies

The convergence has a practical side. Anyone working by these five sentences today is unlikely to have to rebuild for the final Annex 22, whether the EMA follows industry’s risk principle or keeps the exclusion of certain model classes. The draft’s evidence logic, from intended use through independent test data to monitoring, holds in every outcome of the revision. And it holds before an FDA inspection too, because what counts there is what Toms named in Boston: understanding, risk, lifecycle, accountability. That evidence logic is just as necessary for systems to deliver the expected performance and, with or without an AI label, make a tangible contribution to relief and value.

The entry point is the criticality question: which AI-supported applications deliver results that feed without further review into quality decisions that touch patient safety, product quality or data integrity? The effectiveness of Human Oversight follows from there. What matters is less whether a review step is documented than whether the reviewing person understands the context of use, knows the system’s limits and is free to disagree. How that can be checked is described under AI Governance and Human Oversight. This includes the question of whether dissent still occurs in day-to-day operation.

What comes next

For Annex 22, a workshop report has been announced first; a revised draft is expected afterwards. Our Annex 22 page sets out in three questions what the final text will turn on; as soon as the report is available, we will measure it against them. Until then, the position is a plain one: the computerized system is validated under Annex 11, quality risk management guides how deep the evidence needs to go, and Toms describes no different expectation from inspections. For QFINITY, the three signals from regulators and industry confirm the path we presented in Berlin: AI continues the line of CSV and CSA. That is how we described it in Pharmaceutical Engineering in January, and that is how we read this year’s regulator and industry signals.

Further reading: US FDA on AI, Critical Thinking, and the Enduring Principles of Quality (ISPE iSpeak, 24 August 2026)Human-in-the-Loop as an Illusion of Control? (Herrmann and Henrichmann, ISPE iSpeak, 4 September 2026)Chapter 4, Annex 11, Annex 22: Three Drafts, One Control System (QFINITY)

AI in Pharma 2026 Kraków - ISPE Poland GAMP CoP conference - QFINITY

On October 26 and 27, 2026, ISPE Poland and its GAMP Community of Practice host the English-language conference AI in Pharma 2026 at the Novotel Kraków Centrum, the fourth edition of the format. Two days are devoted to AI in pharmaceutical practice, across four tracks from “Trusted, Safe & Regulated AI” to “Sustainable & Responsible AI”. A student hackathon at AGH Kraków opens the event on October 25, built around real cases from pharmaceutical manufacturing.

QFINITY is on the program on the first conference day: Frank Henrichmann, Sr. Executive Consultant and Chair of the global GAMP Steering Committee, speaks in the “Trusted, Safe & Regulated AI” track on “AI-Enabled Computerized System Validation – Vision and Reality” (October 26, 10:30 am). The talk measures the vision of AI-supported validation against what actually holds up in regulated environments today.

The topic sits at the core of our work: how AI is changing the validation of computerized systems is the subject of our topic area Artificial Intelligence in GxP; the regulatory frame for AI in GMP comes from the draft EU GMP Annex 22.

Program and tickets at AI in Pharma (aiinpharma.pl)

Joining in Kraków and keen to talk about AI in a GxP environment? Frank looks forward to the conversation on site. Or book a call directly.

Oliver Herrmann at the lectern of the main conference of the Biopharmaceutical Bioprocess Development Summit in Shanghai

One conference day in Shanghai, packed and inspiring in equal measure: a keynote and a panel at the Biopharmaceutical Bioprocess Development Summit, plus the deep-dive AI session at the AI for Pharma 2026 running in parallel. The question raised on the panel is one we currently meet in projects and committees alike: how do the three European drafts Chapter 4, Annex 11 and Annex 22 work together? This article shares the reading we gave on stage and looks into the background of shifting responsibilities, authority cases and criticality, as a working hypothesis based on the drafts and our observations.

Oliver Herrmann and Martin Heitmann under the entrance arch of AI for Pharma 2026 in Shanghai
TWO INVITATIONSInvited independently, on stage together: Oliver Herrmann and Martin Heitmann at the venue in Shanghai.

The occasion was unusual enough to be worth telling: a CMC and bioprocess summit put EU GMP regulation on its keynote program, and the AI for Pharma 2026 running in parallel booked the matching AI deep dive. Martin Heitmann and I had been invited independently of each other and only discovered it during preparation. Companies there want to know the criteria while there is still time to design for them. One day on site, tightly scheduled, and on the main conference panel the question that carries this article: how do all these data integrity requirements actually fit together?

The order behind the three drafts

Keynote slide: One Delivery, Three Rule Books - delivery, cargo, truck, autopilot and driver as an image for Chapter 4, Annex 11 and Annex 22
KEYNOTE SLIDEOne picture, three rule books: the cargo is the data (Chapter 4), the truck is the application and the road the qualified infrastructure (Annex 11), autopilot and guardrails belong to Annex 22, and a human stays at the wheel, carrying responsibility.

Our answer on the panel starts with where the legal act sits. Chapter 4 lives in the main part of the EU GMP Guide, and that is also where batch certification takes place: the Qualified Person certifies the batch on the basis of the records. That is not a system function but a legal act, and it is now meant to rest entirely on records, beyond documents in the traditional sense. This is why Chapter 4 addresses the data and its governance.

Annex 11 is the technical implementation. Its job is to give this legal act technical and functional trust: the computerized system in which the records are created, validated against its intended use and operated in a validated state. Annex 22, finally, inherits from both. It governs AI in critical GMP applications and presupposes the data and system control that Chapter 4 and Annex 11 have built. In the end, the three texts have to add up to a coherent control system, or one of them has not done its job.

One caveat belongs to every one of these statements: all three texts are drafts from the consultation. What will finally be published is open. Until then, this reading is a working hypothesis, based on our observations in the industry and on the EMA’s communication.

As early as 2022, the EMA concept paper on the Annex 11 revision announced that the FDA guidance on Computer Software Assurance, then available as a draft, would be examined: "This guidance and any implication will be considered with regards to aspects of potential regulatory relevance for GMP Annex 11." A guidance from the medical device world, written for production and quality system software and final in the meantime, is thus explicitly on the radar of the pharma revision. The convergence reaches across the Atlantic.

Exhibit 1: The person who moved

To test the ordering formula, follow the Qualified Person through the texts. The Annex 11 of 2011 named them explicitly: "…only Qualified Persons [to] certify the release of the batches". In the 2025 draft, they no longer appear. Instead, they now stand in the Chapter 4 draft: "All records should be available to the Qualified Person at the time of the release decision."

The move confirms the order: certification rests on the records, so the Qualified Person belongs in the chapter that governs the records. The system-side execution, meaning the signature in the system and the workflow behind it, remains a matter for Annex 11. On stage, we made the point in a single sentence:

The QP did not leave. The annex stopped being about them.

Exhibit 2: The numbers

The second test is quantitative. We measured the drafts against the 2011 versions, on the primary texts themselves:

1
Annex 11 grows from 5 to 19 pages. A statement of principles becomes a catalog of requirements that increasingly describes what control has to look like.
2
Chapter 4 grows from 9 to 17 pages and from 32 to 85 clauses. Both clause series are numbered without gaps; the chapter is still called "Documentation".
3
Four terms that appeared exactly zero times in 2011 now carry the chapter. Counted in the text: "governance" 19 times, "data integrity" more than twenty times, "lifecycle" 15 times, "criticality" 7 times.

The unassailable core of this measurement is the zero: a documentation chapter builds its foundation on terms it did not even know in 2011. The numbers show the direction, away from the document as a container, toward the data and its lifecycle as the object of control.

The test question both drafts ask: how strongly do these data influence the decision resting on them, and would you even notice an error?

Exhibit 3: Criticality has three readings and two axes

"Critical" appears several times across the drafts and does not mean the same thing three times over. The Chapter 4 draft defines data criticality in its glossary as "the degree of influence that data have on product safety as well as the regulatory compliance of processes, decisions and product quality". The same draft adds a second axis, detectability: would you see it if the data were wrong? The Annex 22 draft, in turn, calls applications critical when they have a "direct impact on patient safety, product quality or data integrity".

The third reading we took from a conference presentation: at the ISPE Pharma 4.0 conference in Barcelona in 2025, the EMA rapporteur explained the intention behind the critical-application concept along two axes, direct impact and detectability of the error. Detectability thus stands in both drafts, in Chapter 4 as in Annex 11 ("the likelihood of detection"), and additionally in the explained intention behind Annex 22; a single find becomes a pattern.

In practice, both converge on ALCOA++: criticality drives the rigor with which the ten attributes are demonstrated. And the second plus, Traceable, is the attribute-side counterpart of the detectability axis: it makes an error findable after the fact.

Exhibit 4: Existing requirements already apply to the use of AI

Anyone who considers the drafts a distant prospect should read two authority cases from this year. In April 2026, the FDA charged a manufacturer in a warning letter with "overreliance on artificial intelligence for your drug manufacturing operations". And in June 2026, the MHRA described AI-written inspection responses in its Inspectorate blog with "references to MHRA guidance that doesn’t exist", and drew the line that matters: "our concern isn’t whether you use AI; it’s whether your submissions are accurate, verifiable, and prepared under appropriate oversight".

Both authorities check the same thing: whether the evidence is accurate, verifiable and produced under appropriate oversight. The use of AI as such is not in question in either case. That is exactly the logic of the three drafts, applied before their finalization.

What follows from this

Oliver Herrmann at the microphone on the main conference panel in Shanghai
THE PANELThe question about the interplay of the requirements came from the main conference panel. This article’s answer is the worked-out version.

The consequence of our observations: the culture these drafts presuppose can be built today, with a data inventory, assigned criticality and a governance that puts the cross-cutting questions where they belong. Someone has to start, and what the first one builds sets the measure for every system that follows. That is exactly why these foundations belong at the overarching QA level: laid out once there, they carry across all systems instead of emerging by chance in whichever project comes first. QFINITY has supported this build-up since the ERES programs of the Part 11 era and from the core team of GAMP 5 Second Edition; we read the drafts before they become the rule.

And the sentence that drew the strongest reaction in Shanghai belongs at the end, because it explains why this control architecture exists in the first place:

Our industry is not machines serving patients. It is people serving people. The colleague who runs the bioreactor today may be the patient waiting for the vial tomorrow.

More on the foundation of this reading: our pages on the Annex 11 revision and the EU GMP Annex 22 track the state of the two drafts, and our analysis of PIC/S recommendation PI 006-4 shows how the same movement reaches the production level.