QFINITY updates - publications and committee work
QFINITY · Updates

The latest from QFINITY and the field.

An overview of updates beyond events and projects: articles and publications, work in industry bodies and committees, awards, and our perspective on new regulations.

At a glance

Publications, committee work and more.

EMA-Workshop-Report zu Annex 22: sechs Ströme werden zu vier Linien und laufen zu einer Aussage zusammen (QFINITY)

In early October 2026 the EMA published the report on its expert workshop of 30 June 2026. In 15 pages, document EMA/156789/2026 records what the industry associations presented on six topics, and it contains one sentence that reaches beyond the workshop: the drafting group has discussed widening the scope of EU GMP Annex 22 to dynamic, adaptive, probabilistic and generative models. The condition would be a "fully documented, robust, risk-based control strategy". Here is our reading of what the report confirms and what it leaves open.

We followed the publicly broadcast workshop day and brought the signals from Barcelona, Boston and the workshop together in our August article Three Signals, One Line. With the report, a written account of the workshop by the EMA itself is available for the first time.

The sentence that matters

The 2025 consultation draft excludes generative AI and Large Language Models from its scope and, like dynamic and probabilistic models, does not provide for them in critical GMP applications. The report quotes that sentence in its introduction and sets the consultation feedback against it. The comments supported allowing such models in GMP applications, "whether critical or non-critical". The drafting group, the EMA writes, has therefore discussed widening the scope, "provided they comply with the requirements of the annex and are supported by a fully documented, robust, risk-based control strategy".

Two things belong to that sentence. First, it records a discussion, not a decision. As the next step, the report names the revision of the draft by the drafting group, without giving a date. Second, the question of which elements such a control strategy needs was the very reason for the workshop. The drafting group wanted to hear from experts whether a risk-based approach can be applied to generative AI and which control mechanisms would carry it.

Four lines across six topics

For each topic, the report gives the associations' positions and the regulators' questions. Each topic closes with key messages and a section on the potential impact on the annex text. Four lines run through the topics.

1
No prohibition by technology category. The consolidated industry position opposed categorical exclusions. Whether a model is acceptable should follow from intended use, decision consequence, model influence, uncertainty and complexity, and from whether the residual risk can be reduced to an acceptable level. The report records as a key message that existing quality risk management principles apply to adaptive and probabilistic models as well. A valid outcome of that assessment may still be not to use the model. That conclusion should be documented.
2
Human oversight rather than human-in-the-loop by default. The report distinguishes oversight as a lifecycle-wide objective from human-in-the-loop as one possible implementation, in which a process waits for a human action. Its key messages state that human-in-the-loop is not a default requirement for all AI uses, that oversight must be evidenced and periodically reviewed, and that it cannot compensate for inadequate validation. The regulators asked how automation bias can be managed and how the performance of the reviewing person can be monitored.
3
Control mechanisms need evidence. The report documents the presented layering of prevention at the input, detection in the model and containment at the output. It also notes that some of the five use cases were pilots or theoretical frameworks. Two points from the discussion are recorded. Controls designed for known failure modes do not by themselves cover unanticipated ones, and in the annex itself industry would prefer the term control mechanism over guardrail, because guardrails are technology-specific and transient. On that position, the annex should name objectives such as prevention, detection and containment, while technical methods belong in an updateable format.
4
Responsibility stays with the regulated company. That covers the use of the model as much as the management of suppliers and cloud providers. On the industry position reported, AI systems consist of data, model and hardware and therefore remain computerized systems. Annex 11 applies to them. The report refers to its chapter on outsourced activities; in the current Annex 11 the subject sits in section 3, in the 2025 draft in section 7. Whoever uses a third-party model through an interface needs access to the evidence with which its behavior can be measured. If the provider does not supply it, the use cannot be justified.

What has not been worked out yet

What the workshop left open is just as telling. Some of the use cases presented were, according to the report, not yet production systems but pilots or concepts. On the question of how independent test data can be preserved for a model that keeps learning in operation, the report records that the answer did not define one mandatory technical approach and that implementation for continuously learning systems needs clarification. And for the particular behaviors of generative models, hallucination, fabrication, overconfidence in the output, the workshop set no method for estimating rates or confidence. The revised draft will have to settle these questions, or hand them openly to the operator's risk assessment.

Our reading

For QFINITY, the report overlaps with the architecture we describe on our Annex 22 page and in Validation of AI in the GxP environment. The model is a component with its own evidence, and it is verified. The computerized system in which it works with control mechanisms, process and people is validated in its process. The report does not commit to this distinction. It uses "validation" for lifecycle and system questions as well and keeps the objects of evidence open side by side: in its outlook on the validation topic it writes "revalidation/re-verification" and names an "AI validation/qualification package" as a possible consequence, mirroring the industry presentation rather than stating a regulatory position. The conceptual core of what an operator should be able to show is nevertheless visible in the report: evidence of model performance, information on the training data, controls around input and output, and evidence that the system works as expected in operation. In substance that matches the evidence we have described since the GAMP workshop at the ISPE summit in Boston in June, on whose core team Frank Henrichmann worked for QFINITY: intended use in the company's own process, acceptance criteria, a test set kept separate from training, the supplier's model card, and the residual risk the operator carries.

On oversight, the report meets the line we presented in March at the GAMP D-A-CH Forum under the question Who Pushes Back When the System Speaks? and deepened in September for ISPE iSpeak under the title Human-in-the-Loop as an Illusion of Control? Human-in-the-loop alone does not establish control. Control comes about when the reviewing person understands the context of use, knows the limits of the model and is allowed to push back, and when that capability can be evidenced in operation. In the report, one speaker puts it this way: oversight provides knowledge, detection and triggers for action, and it is the action that reduces the risk.

Which of your AI-supported applications would you operate today on the basis of a documented, risk-based control strategy? And for which would the assessment conclude not to use them?

A checklist for operators

The revised draft has no date. Until then the 2025 consultation draft remains the reference for preparation, not an annex in force, and the report does not change its wording. Anyone planning an AI application in a GMP environment today can use the four lines of the report as a checklist. It starts with a criticality assessment that, beyond direct impact, takes in decision consequence, model influence, uncertainty and the detectability of errors. The form of oversight must fit the risk assessment, and its effectiveness must be demonstrable. The evidence for the control mechanisms rests on the overall package of controls rather than on each mechanism in isolation. Supplier agreements secure access to evidence, participation in change control and transparency of the controls. How this can be anchored in AI governance with human oversight is described on our page on the subject. We have also worked the state of the report into the three open questions on our Annex 22 page.

Entry offer
Readiness Assessment and Roadmap: Chapter 4, Annex 11 & 22

In the AI module we assess your AI applications along the four lines of the report: criticality, form of oversight, evidence for control mechanisms, supplier agreements.

Modules
Data, systems, AI
Duration
Three to six weeks
Result
Control map, gap list, roadmap

View the offer →

Further reading: EMA: Report of the multistakeholder workshop on expert contributions to AI guidance development (Annex 22), EMA/156789/2026↗EMA: workshop page with agenda and report↗Three Signals, One Line: AI in the GxP environment between Barcelona, Boston and the EMA workshop (QFINITY)↗

Frank Henrichmann von QFINITY auf der Buehne der Vimachem Pharma Digitization and AI Conference 2026 in Athen - QFINITY

On 24 September 2026, Vimachem invited around 50 manufacturers, partners and experts to the Pharma Digitization & AI Conference at the Conrad Athens. The ISPE Greece and Cyprus Affiliate supported the conference. The agenda covered the draft EU GMP Annex 22, the ISPE GAMP Guide on artificial intelligence and case studies from manufacturing. Frank Henrichmann, Chair of the ISPE GAMP Global Steering Committee, spoke on behalf of QFINITY about how to validate AI-supported computerized systems in GMP. His starting point was that validation does not start from scratch. It builds on the principles that GAMP 5 already describes today.

Talk card by Vimachem: From guide to practice, validating AI-enabled systems in GMP, Frank Henrichmann, 24 September 2026
TALK CARDVimachem announced the talk with this card: “From guide to practice: validating AI-enabled systems in GMP” (source: Vimachem).

The conference centered on a question that has been on the agenda of the GAMP committees since the July 2025 draft of Annex 22. What does AI change about validation, and what does it leave unchanged? The title of the talk follows the vocabulary of the ISPE GAMP Guide, which refers to AI-enabled computerized systems. In our reading, the distinction runs one level deeper: The model is verified against its specification. The AI-supported computerized system is validated in its process, against the intended use. This separation allows the tools described in GAMP 5 to remain in use. The only addition is the layer for the specific properties of the model.

Four moves from GAMP 5 to operation

The talk followed four moves, as the slide behind the speaker showed: start with the foundations from GAMP 5, add what AI brings, spend most of the time on the part that decides whether it works, and carry it all into operation.

A
The foundations from GAMP 5. A risk-based approach, a documented intended use, supplier assessment and maintenance of the validated state across the lifecycle continue to apply unchanged. They are the starting point for every AI-supported computerized system in GMP.
B
The AI-specific layer. The model is trained on data, its performance can drift in operation, and a vendor update changes the validated state. That is why the model is verified against acceptance criteria using independent test data, as provided for in the draft Annex 22.
C
Human-in-the-Loop in practice. The talk focused on Human Oversight. It is a control only if the human can actually catch an error. That requires detectable errors, triage by the model’s uncertainty and a limited review volume.
D
Operation after go-live. Performance monitoring, defined triggers for re-verification and logging of every exception keep the performance of the model within its verified range.

The test for the third move: Would the reviewer notice an error made by the model, or merely confirm the result put in front of them?

Context: Annex 22, the GAMP AI Guide and the regulators’ position

Frank Henrichmann of QFINITY on stage at the Vimachem Pharma Digitization and AI Conference in Athens with the slide Where We're Headed
ON STAGEFrank Henrichmann spoke at the Conrad Athens on 24 September 2026 with the slide “Where We’re Headed” behind him: four moves from the foundations in GAMP 5 to operation after go-live.

The draft EU GMP Annex 22 was published in July 2025 and open for consultation until October 2025. For static models in critical applications, it provides for a documented intended use, acceptance criteria, independent test data and monitoring in operation. For generative AI, it provides for use outside critical applications only, as long as qualified personnel take responsibility for the results. The ISPE GAMP AI Guide supplies the accompanying methodology. Both documents were on the agenda in Athens. The draft signals the direction of the requirements on the model. The guide describes how a company implements them across the lifecycle.

The joint EMA and FDA guiding principles of 14 January 2026 assess the system as a whole, including the interaction between humans and AI. The third move of the talk takes up this approach.

QFINITY in Athens

QFINITY has worked on these questions for years in GAMP committees and in projects involving AI applications in GxP, as well as in its own publications. We set out our position on Human Oversight in detail in the September 2026 iSpeak article “Human-in-the-Loop as an Illusion of Control?”. Our service page describes how we validate AI-supported systems.

Frank Henrichmann is Chair of the ISPE GAMP Global Steering Committee and Senior Executive Consultant at QFINITY. Our thanks go to Vimachem and the ISPE Greece and Cyprus Affiliate for the invitation and the expert discussions on AI in manufacturing.

Conference page at Vimachem (vimachem.com)↗

Building Trust in AI for Computerized System Validation - QFINITY

Frank Henrichmann, Senior Executive Consultant at QFINITY, spoke with Life Science Connect about the use of AI in computerized system validation. The interview appeared on September 4, 2026, published simultaneously on Pharmaceutical Online, Bioprocess Online and Biosimilar Development.

In the interview, he sets out which validation tasks can be handled reliably by machine. These include checking completeness, tracing requirements to evidence and comparing documents for consistency. It becomes more delicate where someone has to judge whether a piece of evidence is adequate or how a deviation should be assessed. Those judgments stay with people.

He describes two effects as the real danger: automation bias and cognitive ease. Anyone reading plausibly worded suggestions reviews them less rigorously, and that is precisely why putting a person into the process is not enough. It takes independent technical controls that hold even when human review slips. As the methodological framework, he points to the GAMP 5 Second Edition.

Jon O’Connell of Life Science Connect conducted the interview. You can read it here.