
QFINITY · Updates
The latest from QFINITY and the field.
An overview of updates beyond events and projects: articles and publications, work in industry bodies and committees, awards, and our perspective on new regulations.
At a glance

An overview of updates beyond events and projects: articles and publications, work in industry bodies and committees, awards, and our perspective on new regulations.
EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI
In early October 2026 the EMA published the report on its expert workshop of 30 June 2026. In 15 pages, document EMA/156789/2026 records what the industry associations presented on six topics, and it contains one sentence that reaches beyond the workshop: the drafting group has discussed widening the scope of EU GMP Annex 22 to dynamic, adaptive, probabilistic and generative models. The condition would be a "fully documented, robust, risk-based control strategy". Here is our reading of what the report confirms and what it leaves open.
We followed the publicly broadcast workshop day and brought the signals from Barcelona, Boston and the workshop together in our August article Three Signals, One Line. With the report, a written account of the workshop by the EMA itself is available for the first time.
The sentence that matters
The 2025 consultation draft excludes generative AI and Large Language Models from its scope and, like dynamic and probabilistic models, does not provide for them in critical GMP applications. The report quotes that sentence in its introduction and sets the consultation feedback against it. The comments supported allowing such models in GMP applications, "whether critical or non-critical". The drafting group, the EMA writes, has therefore discussed widening the scope, "provided they comply with the requirements of the annex and are supported by a fully documented, robust, risk-based control strategy".
Two things belong to that sentence. First, it records a discussion, not a decision. As the next step, the report names the revision of the draft by the drafting group, without giving a date. Second, the question of which elements such a control strategy needs was the very reason for the workshop. The drafting group wanted to hear from experts whether a risk-based approach can be applied to generative AI and which control mechanisms would carry it.
Four lines across six topics
For each topic, the report gives the associations' positions and the regulators' questions. Each topic closes with key messages and a section on the potential impact on the annex text. Four lines run through the topics.
What has not been worked out yet
What the workshop left open is just as telling. Some of the use cases presented were, according to the report, not yet production systems but pilots or concepts. On the question of how independent test data can be preserved for a model that keeps learning in operation, the report records that the answer did not define one mandatory technical approach and that implementation for continuously learning systems needs clarification. And for the particular behaviors of generative models, hallucination, fabrication, overconfidence in the output, the workshop set no method for estimating rates or confidence. The revised draft will have to settle these questions, or hand them openly to the operator's risk assessment.
Our reading
For QFINITY, the report overlaps with the architecture we describe on our Annex 22 page and in Validation of AI in the GxP environment. The model is a component with its own evidence, and it is verified. The computerized system in which it works with control mechanisms, process and people is validated in its process. The report does not commit to this distinction. It uses "validation" for lifecycle and system questions as well and keeps the objects of evidence open side by side: in its outlook on the validation topic it writes "revalidation/re-verification" and names an "AI validation/qualification package" as a possible consequence, mirroring the industry presentation rather than stating a regulatory position. The conceptual core of what an operator should be able to show is nevertheless visible in the report: evidence of model performance, information on the training data, controls around input and output, and evidence that the system works as expected in operation. In substance that matches the evidence we have described since the GAMP workshop at the ISPE summit in Boston in June, on whose core team Frank Henrichmann worked for QFINITY: intended use in the company's own process, acceptance criteria, a test set kept separate from training, the supplier's model card, and the residual risk the operator carries.
On oversight, the report meets the line we presented in March at the GAMP D-A-CH Forum under the question Who Pushes Back When the System Speaks? and deepened in September for ISPE iSpeak under the title Human-in-the-Loop as an Illusion of Control? Human-in-the-loop alone does not establish control. Control comes about when the reviewing person understands the context of use, knows the limits of the model and is allowed to push back, and when that capability can be evidenced in operation. In the report, one speaker puts it this way: oversight provides knowledge, detection and triggers for action, and it is the action that reduces the risk.
Which of your AI-supported applications would you operate today on the basis of a documented, risk-based control strategy? And for which would the assessment conclude not to use them?
A checklist for operators
The revised draft has no date. Until then the 2025 consultation draft remains the reference for preparation, not an annex in force, and the report does not change its wording. Anyone planning an AI application in a GMP environment today can use the four lines of the report as a checklist. It starts with a criticality assessment that, beyond direct impact, takes in decision consequence, model influence, uncertainty and the detectability of errors. The form of oversight must fit the risk assessment, and its effectiveness must be demonstrable. The evidence for the control mechanisms rests on the overall package of controls rather than on each mechanism in isolation. Supplier agreements secure access to evidence, participation in change control and transparency of the controls. How this can be anchored in AI governance with human oversight is described on our page on the subject. We have also worked the state of the report into the three open questions on our Annex 22 page.
Readiness Assessment and Roadmap: Chapter 4, Annex 11 & 22
In the AI module we assess your AI applications along the four lines of the report: criticality, form of oversight, evidence for control mechanisms, supplier agreements.
View the offer →
Further reading: EMA: Report of the multistakeholder workshop on expert contributions to AI guidance development (Annex 22), EMA/156789/2026↗EMA: workshop page with agenda and report↗Three Signals, One Line: AI in the GxP environment between Barcelona, Boston and the EMA workshop (QFINITY)↗
From Guide to Practice: QFINITY at the Vimachem Pharma Digitization & AI Conference in Athens
On 24 September 2026, Vimachem invited around 50 manufacturers, partners and experts to the Pharma Digitization & AI Conference at the Conrad Athens. The ISPE Greece and Cyprus Affiliate supported the conference. The agenda covered the draft EU GMP Annex 22, the ISPE GAMP Guide on artificial intelligence and case studies from manufacturing. Frank Henrichmann, Chair of the ISPE GAMP Global Steering Committee, spoke on behalf of QFINITY about how to validate AI-supported computerized systems in GMP. His starting point was that validation does not start from scratch. It builds on the principles that GAMP 5 already describes today.
The conference centered on a question that has been on the agenda of the GAMP committees since the July 2025 draft of Annex 22. What does AI change about validation, and what does it leave unchanged? The title of the talk follows the vocabulary of the ISPE GAMP Guide, which refers to AI-enabled computerized systems. In our reading, the distinction runs one level deeper: The model is verified against its specification. The AI-supported computerized system is validated in its process, against the intended use. This separation allows the tools described in GAMP 5 to remain in use. The only addition is the layer for the specific properties of the model.
Four moves from GAMP 5 to operation
The talk followed four moves, as the slide behind the speaker showed: start with the foundations from GAMP 5, add what AI brings, spend most of the time on the part that decides whether it works, and carry it all into operation.
The test for the third move: Would the reviewer notice an error made by the model, or merely confirm the result put in front of them?
Context: Annex 22, the GAMP AI Guide and the regulators’ position
The draft EU GMP Annex 22 was published in July 2025 and open for consultation until October 2025. For static models in critical applications, it provides for a documented intended use, acceptance criteria, independent test data and monitoring in operation. For generative AI, it provides for use outside critical applications only, as long as qualified personnel take responsibility for the results. The ISPE GAMP AI Guide supplies the accompanying methodology. Both documents were on the agenda in Athens. The draft signals the direction of the requirements on the model. The guide describes how a company implements them across the lifecycle.
The joint EMA and FDA guiding principles of 14 January 2026 assess the system as a whole, including the interaction between humans and AI. The third move of the talk takes up this approach.
QFINITY in Athens
QFINITY has worked on these questions for years in GAMP committees and in projects involving AI applications in GxP, as well as in its own publications. We set out our position on Human Oversight in detail in the September 2026 iSpeak article “Human-in-the-Loop as an Illusion of Control?”. Our service page describes how we validate AI-supported systems.
Frank Henrichmann is Chair of the ISPE GAMP Global Steering Committee and Senior Executive Consultant at QFINITY. Our thanks go to Vimachem and the ISPE Greece and Cyprus Affiliate for the invitation and the expert discussions on AI in manufacturing.
Conference page at Vimachem (vimachem.com)↗
Frank Henrichmann on trust in AI for computerized system validation
Frank Henrichmann, Senior Executive Consultant at QFINITY, spoke with Life Science Connect about the use of AI in computerized system validation. The interview appeared on September 4, 2026, published simultaneously on Pharmaceutical Online, Bioprocess Online and Biosimilar Development.
In the interview, he sets out which validation tasks can be handled reliably by machine. These include checking completeness, tracing requirements to evidence and comparing documents for consistency. It becomes more delicate where someone has to judge whether a piece of evidence is adequate or how a deviation should be assessed. Those judgments stay with people.
He describes two effects as the real danger: automation bias and cognitive ease. Anyone reading plausibly worded suggestions reviews them less rigorously, and that is precisely why putting a person into the process is not enough. It takes independent technical controls that hold even when human review slips. As the methodological framework, he points to the GAMP 5 Second Edition.
Jon O’Connell of Life Science Connect conducted the interview. You can read it here.