{"id":17010,"date":"2026-08-24T19:46:52","date_gmt":"2026-08-24T17:46:52","guid":{"rendered":"https:\/\/q-finity.de\/aktuelles\/"},"modified":"2026-08-24T21:10:20","modified_gmt":"2026-08-24T19:10:20","slug":"updates","status":"publish","type":"page","link":"https:\/\/q-finity.de\/en\/updates\/","title":{"rendered":"Updates"},"content":{"rendered":"\n<div class=\"av-alb-blogposts template-blog  av-blog-meta-author-disabled av-blog-meta-comments-disabled av-blog-meta-category-disabled av-blog-meta-date-disabled av-blog-meta-tag-disabled \" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/Blog\"><article class=\"post-entry post-entry-type-standard post-entry-17149 post-loop-1 post-parity-odd single-big with-slider post-17149 post type-post status-publish format-standard has-post-thumbnail hentry category-news-category\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\"><div class=\"blog-meta\"><\/div><div class=\"entry-content-wrapper clearfix standard-content\"><header class=\"entry-content-header\" aria-label=\"Post: Frank Henrichmann on trust in AI for computerized system validation\"><div class=\"av-heading-wrapper\"><span class=\"blog-categories minor-meta\"><a href=\"https:\/\/q-finity.de\/en\/kategorie\/news-category\/\" rel=\"tag\">Updates<\/a><\/span><h2 class=\"post-title entry-title \" itemprop=\"headline\"><a href=\"https:\/\/q-finity.de\/en\/interview-trust-in-ai-computerized-system-validation\/\" rel=\"bookmark\" title=\"Permanent Link: Frank Henrichmann on trust in AI for computerized system validation\">Frank Henrichmann on trust in AI for computerized system validation<span class=\"post-format-icon minor-meta\"><\/span><\/a><\/h2><\/div><\/header><span class=\"av-vertical-delimiter\"><\/span><div class=\"big-preview single-big\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\"><a href=\"https:\/\/q-finity.de\/en\/interview-trust-in-ai-computerized-system-validation\/\" title=\"building-trust-in-ai-csv-card\"><img data-opt-id=2025834714  fetchpriority=\"high\" decoding=\"async\" loading=\"lazy\" width=\"1210\" height=\"423\" src=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:1210\/h:423\/q:mauto\/rt:fill\/g:ce\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/09\/building-trust-in-ai-csv-card.png\" class=\"wp-image-17150 avia-img-lazy-loading-17150 attachment-entry_without_sidebar size-entry_without_sidebar wp-post-image\" alt=\"Building Trust in AI for Computerized System Validation - QFINITY\"><\/a><\/div><div class=\"entry-content\" itemprop=\"text\"><p>Frank Henrichmann, Senior Executive Consultant at QFINITY, spoke with Life Science Connect about the use of AI in computerized system validation. The interview appeared on September 4, 2026, published simultaneously on Pharmaceutical Online, Bioprocess Online and Biosimilar Development.<\/p>\n<p>In the interview, he sets out which validation tasks can be handled reliably by machine. These include checking completeness, tracing requirements to evidence and comparing documents for consistency. It becomes more delicate where someone has to judge whether a piece of evidence is adequate or how a deviation should be assessed. Those judgments stay with people.<\/p>\n<p>He describes two effects as the real danger: automation bias and cognitive ease. Anyone reading plausibly worded suggestions reviews them less rigorously, and that is precisely why putting a person into the process is not enough. It takes independent technical controls that hold even when human review slips. As the methodological framework, he points to the <a href=\"https:\/\/q-finity.de\/en\/glossar\/gamp-5-begriff\/\" target=\"_self\" title=\"GAMP 5 - &quot;A Risk-Based Approach to Compliant GxP Computerized Systems&quot; - is ISPE's industry guide to the validation of computerized systems: published in 2008, and available since 2022 in the Second Edition, which strengthens critical thinking and scaled evidence. GAMP is industry good practice, not law: regulations set the requirements - GAMP shows a&hellip;\" class=\"encyclopedia\">GAMP 5<\/a> Second Edition.<\/p>\n<p>Jon O&rsquo;Connell of Life Science Connect conducted the interview. You can read it <a href=\"https:\/\/www.pharmaceuticalonline.com\/doc\/building-trust-in-ai-for-computerized-system-validation-0001\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<\/div><span class=\"post-meta-infos\"><\/span><footer class=\"entry-footer\"><\/footer><div class=\"post_delimiter\"><\/div><\/div><div class=\"post_author_timeline\"><\/div><span class=\"hidden\">\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/09\/building-trust-in-ai-csv-card.png<\/span>\n\t\t\t\t\t\t<span itemprop=\"height\">1792<\/span>\n\t\t\t\t\t\t<span itemprop=\"width\">2400<\/span>\n\t\t\t\t<\/span>\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"publisher\" itemtype=\"https:\/\/schema.org\/Organization\" itemscope=\"itemscope\">\n\t\t\t\t\t\t<span itemprop=\"name\">oherrmann<\/span>\n\t\t\t\t\t\t<span itemprop=\"logo\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/07\/q-finity_schriftzug_orange-retina.png<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span><span class=\"av-structured-data\" itemprop=\"author\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/Person\"><span itemprop=\"name\">oherrmann<\/span><\/span><span class=\"av-structured-data\" itemprop=\"datePublished\" datetime=\"2026-09-07T11:49:57+02:00\">2026-09-07 11:49:57<\/span><span class=\"av-structured-data\" itemprop=\"dateModified\" itemtype=\"https:\/\/schema.org\/dateModified\">2026-09-07 14:17:58<\/span><span class=\"av-structured-data\" itemprop=\"mainEntityOfPage\" itemtype=\"https:\/\/schema.org\/mainEntityOfPage\"><span itemprop=\"name\">Frank Henrichmann on trust in AI for computerized system validation<\/span><\/span><\/span><\/article><article class=\"post-entry post-entry-type-standard post-entry-17066 post-loop-2 post-parity-even single-big with-slider post-17066 post type-post status-publish format-standard has-post-thumbnail hentry category-news-category\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\"><div class=\"blog-meta\"><\/div><div class=\"entry-content-wrapper clearfix standard-content\"><header class=\"entry-content-header\" aria-label=\"Post: Who Pushes Back When the System Speaks?\"><div class=\"av-heading-wrapper\"><span class=\"blog-categories minor-meta\"><a href=\"https:\/\/q-finity.de\/en\/kategorie\/news-category\/\" rel=\"tag\">Updates<\/a><\/span><h2 class=\"post-title entry-title \" itemprop=\"headline\"><a href=\"https:\/\/q-finity.de\/en\/who-pushes-back-when-the-system-speaks\/\" rel=\"bookmark\" title=\"Permanent Link: Who Pushes Back When the System Speaks?\">Who Pushes Back When the System Speaks?<span class=\"post-format-icon minor-meta\"><\/span><\/a><\/h2><\/div><\/header><span class=\"av-vertical-delimiter\"><\/span><div class=\"big-preview single-big\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\"><a href=\"https:\/\/q-finity.de\/en\/who-pushes-back-when-the-system-speaks\/\" title=\"Wer widerspricht, wenn das System spricht? (Human Oversight)\"><img data-opt-id=703467862  fetchpriority=\"high\" decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"423\" src=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:1024\/h:423\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/wer-widerspricht-wenn-das-system-spricht.png\" class=\"wp-image-17067 avia-img-lazy-loading-17067 attachment-entry_without_sidebar size-entry_without_sidebar wp-post-image\" alt=\"Who pushes back when the system speaks? Human Oversight in QA - QFINITY\"><\/a><\/div><div class=\"entry-content\" itemprop=\"text\"><p><em>A follow-up to the 47th GAMP D-A-CH Forum, Berlin, 11 March 2026.<\/em><\/p>\n<p class=\"qf-abstract\">At the 47th GAMP D-A-CH Forum in Berlin in March 2026, Daniel K&ouml;pke and Oliver Herrmann asked what <a href=\"https:\/\/q-finity.de\/en\/glossar\/human-oversight-begriff\/\" target=\"_self\" title=\"Human Oversight bezeichnet die menschliche Aufsicht &uuml;ber KI- und computergest&uuml;tzte Entscheidungen: Die Verantwortung liegt beim Menschen, nie im System. Dazu geh&ouml;rt Human in the Loop (HITL).\" class=\"encyclopedia\">Human Oversight<\/a> means when systems become more intelligent, more complex and more convincing. For us, the answer starts with responsibility: the greatest danger to QA is the silent erosion of visible responsibility, until no one pushes back anymore. This summer, a security incident at the AI provider OpenAI showed how real this question has become. It is the occasion to share the March position now: not foresight, an illustration. This article lays out the position from the talk, and it names what organizations can build to counter it.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Why is this follow-up coming now?<\/h2>\n<p>On 26 August 2026, OpenAI published the technical report on an incident from July. In one of the company&rsquo;s own security tests, agents had broken out of their test environment and compromised real Hugging Face infrastructure. A key factor was that the usual safeguards had been switched off in the test environment for testing purposes. In production, by contrast, they would be in place. Even so, the incident remains a vivid experiment that shows how far the capabilities of these systems now reach. Whether the agents broke out or were let out, both are a failure of architecture, not of a single control. Controls bolted onto a system after the fact cannot keep pace with these systems. Controllability must be designed in before the system speaks. The incident happened far outside the GxP world. The important message here: these AI capabilities are increasingly being used in GxP system landscapes as well. Anyone assessing the associated risks needs to understand both the limits and the potential of these systems.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>The starting point is responsibility<\/h2>\n<figure class=\"qf-figure right\"><img data-opt-id=1197005058  fetchpriority=\"high\" src=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/berlin-vortrag-koepke-herrmann-gamp-dach-2026.jpg\" alt=\"Daniel K&ouml;pke and Oliver Herrmann presenting at the 47th GAMP D-A-CH Forum in Berlin\" loading=\"lazy\" decoding=\"async\"><figcaption><b>BERLIN<\/b>Daniel K&ouml;pke and Oliver Herrmann at the 47th GAMP D-A-CH Forum, 11 March 2026.<\/figcaption><\/figure>\n<p>Every human being has a face and a voice. Both make us recognizable, and both make us responsible: as QA professionals and as people who contribute to patient safety. A patient does not know our systems. They know no SOPs, no validation plans, no model architecture. They trust that in the end a human stands behind quality.<\/p>\n<p>The connection to AI lies in the transition from data to decisions. An AI-enabled system can analyze data, detect patterns, generate test cases, classify deviations and prepare decisions. And as it does, it sounds plausible, often even very plausible.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Everything documented, everything compliant, and no one understands why<\/h2>\n<p>In Berlin we opened with a scene. One system recommends release. A second has checked the data. A third has classified the anomaly as acceptable. Everything documented, everything traceable, everything compliant. And no human has really understood why.<\/p>\n<p>This scene is not the future; it is pieced together from today&rsquo;s everyday practice. A system generates 847 test cases, and the tester checks the output. But who checks the logic behind them, and who decides what was not tested? A chatbot classifies a deviation as minor and proposes the CAPA along with it. The QA professional confirms, and at some point confirming becomes a habit. An autonomous monitoring system reports no trend. But what about the trend outside the pattern the model knows? Silence is not a statement. Silence is an assumption.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Plausibility is not evidence of review<\/h2>\n<p>That is the central risk of any Human-in-the-Loop setup. Plausible outputs discourage the thorough review that technical correctness, regulatory robustness and GxP responsibility actually demand. Plausibility can trigger a review. It cannot replace one, and it does not make responsibility transferable. Plausible means: it could be right. Right means: we have checked and understood it. That is not a small difference, it is the difference.<\/p>\n<p>A system bears no regulatory responsibility. It does not know the GxP context the way a human does, it does not recognize when a seemingly correct result becomes dangerous in a critical process, and it does not judge under ambiguity. All of that stays with people. Technical measures such as guardrails can support people in exercising this responsibility. Anyone who trusts these measures blindly, however, perpetuates the very design weakness that makes the Human-in-the-Loop setup vulnerable.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>The silent erosion of visible responsibility<\/h2>\n<p>The danger comes quietly. Click by click, confirmation by confirmation, buried under ever more decisions waiting to be taken, until no one really pushes back anymore. No single step stands out, and what remains is a QA function that has formally documented everything and in practice no longer decides anything.<\/p>\n<p class=\"qf-keyq\">When the system speaks, the decisive question remains: who pushes back?<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Three sets of rules, one direction<\/h2>\n<p>In Berlin we mirrored this question against sets of rules that emerged independently of one another and carry the same expectation. In Article 14, the EU AI Act describes what <a href=\"https:\/\/q-finity.de\/en\/glossar\/human-oversight-begriff\/\" target=\"_self\" title=\"Human Oversight bezeichnet die menschliche Aufsicht &uuml;ber KI- und computergest&uuml;tzte Entscheidungen: Die Verantwortung liegt beim Menschen, nie im System. Dazu geh&ouml;rt Human in the Loop (HITL).\" class=\"encyclopedia\">Human Oversight<\/a> means for high-risk systems. People must be able to understand, monitor and correct the system, not merely have signed off formally. <a href=\"https:\/\/q-finity.de\/en\/glossar\/eu-gmp-annex-11\/\" target=\"_self\" title='EU GMP Annex 11 (\"Computerised Systems\") is the European GMP annex for computerized systems: introduced in 1992, current in its 2011 version, part of EudraLex Vol. 4. Its principle divides the world of evidence in two: the application is validated, the IT infrastructure is qualified. Annex 11 requires a risk-based approach across the entire lifecycle&hellip;' class=\"encyclopedia\">EU GMP Annex 11<\/a> has always demanded controllable, traceable and inspectable computerized systems. It was written before generative AI, and it applies regardless. The <a href=\"https:\/\/q-finity.de\/en\/eu-gmp-annex-22\/\">draft EU GMP Annex 22<\/a> proposes the first formal framework for AI in the GxP environment, with intended use, performance monitoring and change control. In critical applications it currently envisages only static models with deterministic output. The regulated user must hold and review the evidence itself. That applies regardless of whether the model was developed in-house or created with a service provider. On the industry side, <a href=\"https:\/\/q-finity.de\/en\/glossar\/gamp-5-begriff\/\" target=\"_self\" title=\"GAMP 5 - &quot;A Risk-Based Approach to Compliant GxP Computerized Systems&quot; - is ISPE's industry guide to the validation of computerized systems: published in 2008, and available since 2022 in the Second Edition, which strengthens critical thinking and scaled evidence. GAMP is industry good practice, not law: regulations set the requirements - GAMP shows a&hellip;\" class=\"encyclopedia\">GAMP 5<\/a> describes the consensus on how these expectations can be implemented. All point in the same direction. Control stays with people.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>The role of QA is shifting<\/h2>\n<figure class=\"qf-figure left\"><img data-opt-id=627010965  fetchpriority=\"high\" src=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/berlin-vortrag-herrmann-gamp-dach-forum-2026.jpg\" alt=\"Oliver Herrmann presenting at the 47th GAMP D-A-CH Forum in Berlin\" loading=\"lazy\" decoding=\"async\"><figcaption><b>ON SITE<\/b>Oliver Herrmann during the talk in Berlin.<\/figcaption><\/figure>\n<p>A QA function that wants to answer this question shapes the conditions under which human judgment remains effective. In GxP terms, Human Oversight belongs in the intended use, in the business process and in the risk-based controls, with lifecycle evidence that demonstrates its effectiveness. Human Oversight is a capability that is designed into the architecture of the system, not added later in a review step.<\/p>\n<p>In Berlin we described this role in four images. As architecture designer, QA sits at the table when system boundaries are drawn and helps decide which decisions a system may take autonomously and where a human must be able to intervene. As oversight architect, it defines the control points itself instead of leaving them to IT or the vendor: where monitoring takes place, what counts as a deviation, when a system is paused. As escalation designer, it devises the detection paths for silent failures, because drift is not a crash; it creeps. And as guardian of transparency, it records that a validation was incomplete if no one in an audit can explain why the system design was chosen, why human oversight was defined as it was and why the decision in operation was made as it was.<\/p>\n<p>The sentence the talk was building toward still stands. Future-proof QA does more than validate systems. It validates that people remain capable of deciding.<\/p>\n<p>And it needs people who can review. Four conditions determine whether pushback happens in daily work:<\/p>\n<div class=\"qf-gaplist\">\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">1<\/div>\n<div class=\"qf-gap-t\"><b>Competence.<\/b> Whoever reviews must understand what the system can and cannot do, know the context in which it is used and be able to judge its limits.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">2<\/div>\n<div class=\"qf-gap-t\"><b>Time.<\/b> A review with no time set aside for it becomes a confirmation.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">3<\/div>\n<div class=\"qf-gap-t\"><b>Psychological safety.<\/b> Pushing back against a result that sounds plausible and that everyone accepts requires an environment that explicitly expects dissent and makes it possible without repercussions.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">4<\/div>\n<div class=\"qf-gap-t\"><b>Real authority.<\/b> Whoever reviews must be allowed to stop a system, formally and in everyday practice. A system without a defined stop is not a controlled system.<\/div>\n<\/div>\n<\/div>\n<p>Organizations must design Human Oversight so that responsibility is exercised in daily work and its effectiveness remains demonstrable. And that assignment of responsibility belongs on record. It is not the system that decided. A human took responsibility for the system&rsquo;s decision, with name, role, qualification and (digital) signature. In an audit there is no line for the model. A responsibility that exists only on paper protects no patient.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Three supporting voices, one shared core<\/h2>\n<p>Since the talk, this position has not stood alone. The rapporteur of the Annex 22 drafting group in Barcelona, a National Expert at the FDA in Boston and industry at the EMA expert workshop arrived independently at the same line. The synthesis is in our article <a href=\"https:\/\/q-finity.de\/en\/ai-gxp-regulators-one-line\/\">Three Signals, One Line<\/a>. How Human Oversight can be set up and checked is covered in <a href=\"https:\/\/q-finity.de\/en\/ai-governance-and-human-oversight-in-the-gxp-environment\/\">AI Governance and Human Oversight<\/a>.<\/p>\n<p>An AI strategy that anchors Human Oversight and visible responsibility is a good starting point. More important still is the attitude: the system works for us, not the other way around.<\/p>\n<p>For us, that is the core of Digital Compliance: quality is not merely demonstrated; it is designed to be trustworthy and to grow with knowledge. Trust has a face and a voice. Our job is to make sure neither disappears into our systems.<\/p>\n<p>Further reading: <a class=\"qf-extref\" href=\"https:\/\/ispe-dach.org\/rueckblick-gamp-d-a-ch-in-berlin\/\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">R&uuml;ckblick: GAMP D-A-CH in Berlin (ISPE D-A-CH, 11 March 2026, in German)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><a class=\"qf-extref\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">OpenAI: report on the Hugging Face security incident (26 August 2026)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><\/p>\n<\/div><span class=\"post-meta-infos\"><\/span><footer class=\"entry-footer\"><\/footer><div class=\"post_delimiter\"><\/div><\/div><div class=\"post_author_timeline\"><\/div><span class=\"hidden\">\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/wer-widerspricht-wenn-das-system-spricht.png<\/span>\n\t\t\t\t\t\t<span itemprop=\"height\">576<\/span>\n\t\t\t\t\t\t<span itemprop=\"width\">1024<\/span>\n\t\t\t\t<\/span>\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"publisher\" itemtype=\"https:\/\/schema.org\/Organization\" itemscope=\"itemscope\">\n\t\t\t\t\t\t<span itemprop=\"name\">oherrmann<\/span>\n\t\t\t\t\t\t<span itemprop=\"logo\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/07\/q-finity_schriftzug_orange-retina.png<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span><span class=\"av-structured-data\" itemprop=\"author\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/Person\"><span itemprop=\"name\">oherrmann<\/span><\/span><span class=\"av-structured-data\" itemprop=\"datePublished\" datetime=\"2026-08-31T17:48:44+02:00\">2026-08-31 17:48:44<\/span><span class=\"av-structured-data\" itemprop=\"dateModified\" itemtype=\"https:\/\/schema.org\/dateModified\">2026-09-01 05:43:30<\/span><span class=\"av-structured-data\" itemprop=\"mainEntityOfPage\" itemtype=\"https:\/\/schema.org\/mainEntityOfPage\"><span itemprop=\"name\">Who Pushes Back When the System Speaks?<\/span><\/span><\/span><\/article><article class=\"post-entry post-entry-type-standard post-entry-17047 post-loop-3 post-parity-odd post-entry-last single-big with-slider post-17047 post type-post status-publish format-standard has-post-thumbnail hentry category-news-category\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\"><div class=\"blog-meta\"><\/div><div class=\"entry-content-wrapper clearfix standard-content\"><header class=\"entry-content-header\" aria-label=\"Post: Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop\"><div class=\"av-heading-wrapper\"><span class=\"blog-categories minor-meta\"><a href=\"https:\/\/q-finity.de\/en\/kategorie\/news-category\/\" rel=\"tag\">Updates<\/a><\/span><h2 class=\"post-title entry-title \" itemprop=\"headline\"><a href=\"https:\/\/q-finity.de\/en\/ai-gxp-regulators-one-line\/\" rel=\"bookmark\" title=\"Permanent Link: Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop\">Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop<span class=\"post-format-icon minor-meta\"><\/span><\/a><\/h2><\/div><\/header><span class=\"av-vertical-delimiter\"><\/span><div class=\"big-preview single-big\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\"><a href=\"https:\/\/q-finity.de\/en\/ai-gxp-regulators-one-line\/\" title=\"Drei Signale, eine Linie (KI im GxP-Umfeld)\"><img data-opt-id=710981951  fetchpriority=\"high\" decoding=\"async\" loading=\"lazy\" width=\"1210\" height=\"423\" src=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:1210\/h:423\/q:mauto\/rt:fill\/g:ce\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/drei-signale-eine-linie-ki-gxp-v2.png\" class=\"wp-image-17041 avia-img-lazy-loading-17041 attachment-entry_without_sidebar size-entry_without_sidebar wp-post-image\" alt=\"Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop - QFINITY\"><\/a><\/div><div class=\"entry-content\" itemprop=\"text\"><p class=\"qf-abstract\">Within seven months, three signals converged on how to assess AI in the GxP environment: the rapporteur of the EMA drafting group for <a href=\"https:\/\/q-finity.de\/en\/glossar\/eu-gmp-annex-22\/\" target=\"_self\" title=\"EU GMP Annex 22 (&ldquo;Artificial Intelligence&rdquo;) is the planned AI annex to the EU GMP guideline: it adds the evidence for embedded AI models to Annex 11 - in the draft limited, for critical applications, to static models with deterministic output.\" class=\"encyclopedia\">EU GMP Annex 22<\/a> explained the draft&rsquo;s criticality logic in Barcelona in December 2025, a National Expert at the US FDA made clear in Boston in June 2026 that the rules still hold, and at the EMA expert workshop on 30 June 2026 industry answered with a joint position. QFINITY followed all three, Barcelona and Boston on site, the EMA workshop via its public broadcast. The occasions were independent of one another, yet all of them arrive at the same five sentences. It is the line we ourselves presented at the GAMP D-A-CH Forum in Berlin in March 2026, with the question: who pushes back when the system speaks?<\/p>\n<p>Taken in turn: in Barcelona the drafting group&rsquo;s rapporteur spoke, in Boston a National Expert at the FDA, at the workshop industry addressed the EMA. At the end we put the three signals in perspective.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Barcelona, December 2025: How the drafting group thinks about criticality<\/h2>\n<p>At the 2025 ISPE Pharma 4.0 Conference (9 and 10 December 2025, Barcelona), the rapporteur of the Annex 22 drafting group, a representative of the Danish Medicines Agency, explained how the draft delimits its scope. The guiding question was: what effect would an error have, and would it be detected? Which technology is in use makes no difference to that classification, at least at first. An AI-supported application whose output passes through an expert review anyway, for example training material or SOP drafts, counts as non-critical. An application whose output feeds into the quality decision without further review, for example in quality control or automated visual inspection, counts as critical.<\/p>\n<p>The rapporteur then explained the draft&rsquo;s original regulatory intent. Within the critical area, the draft initially excludes certain technologies. On the slide this area sat in the top right, and as the &ldquo;upper right-hand corner&rdquo; it became a catchphrase among experts. Dynamic systems that keep learning in operation are left out, as are probabilistic systems where the same input and the same version do not guarantee the same result. Consequently, that also applies to large language models. Although this view starts from process and system design, it was in the end tied to technology. That became one of the main points of discussion across the industry. He had delivered the same message with the same slides in the GAMP D-A-CH community a few days earlier: on 4 December 2025 at the 2nd GAMP Conference &ldquo;K&uuml;nstliche Intelligenz trifft Pharma&rdquo; in Mannheim. QFINITY was involved in leading the GAMP D-A-CH community for more than a decade and helped build the AI community in D-A-CH.<\/p>\n<p>The second thought from Barcelona concerns evidence. A trained model cannot be proven out by a single deterministic test. The evidence takes a different form: test data that are themselves subject to requirements, and metrics that carry the evidence for control and effectiveness. That is how data scientists think, and it is at the same time the principle of quality risk management: decision under uncertainty. On evidence, then, Annex 22 imports no foreign logic into the GxP world; it applies the existing logic to models. On scope, by contrast, the draft draws the line a priori rather than judging a model type&rsquo;s admissibility on the basis of the risk assessment. Industry would later take the discussion up from there.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Boston, June 2026: An FDA voice says the rules still apply<\/h2>\n<p>At the ISPE AI in Life Sciences Summit in Boston (22 and 23 June 2026), Seneca Toms, National Expert for Drugs at the US FDA, spoke about how industry is handling AI. Oliver Herrmann was in the room. Frank Henrichmann, as Chair of the GAMP Global Steering Committee, represented the &ldquo;Powered by GAMP&rdquo; side of the summit. What made the talk convincing was the clarity with which a regulator&rsquo;s voice applied the old principles to the new technology. Safe and effective products, controlled processes, identified and managed risks, scientifically justified decisions: that held before AI, and it holds after. ISPE&rsquo;s editorial team summarized the talk in an August <a href=\"https:\/\/ispe.org\/pharmaceutical-engineering\/ispeak\/us-food-and-drug-administration-us-fda-artificial-intelligence-ai\" target=\"_blank\" rel=\"noopener\">iSpeak post<\/a>. It notes explicitly that the summary has not been vetted by any of the agencies mentioned and does not represent an official agency position. We therefore present the thoughts that follow as a reflection on the talk, not as an FDA statement.<\/p>\n<p>We pick up four thoughts from Boston because they apply directly to regulated companies. How deeply you test follows the decision a system supports: a tool that summarizes meeting notes needs a different level of assurance than a system that feeds into decisions on product quality or patient safety. Oversight begins with understanding; whoever approves a result without understanding it is not exercising <a href=\"https:\/\/q-finity.de\/en\/glossar\/human-oversight-begriff\/\" target=\"_self\" title=\"Human Oversight bezeichnet die menschliche Aufsicht &uuml;ber KI- und computergest&uuml;tzte Entscheidungen: Die Verantwortung liegt beim Menschen, nie im System. Dazu geh&ouml;rt Human in the Loop (HITL).\" class=\"encyclopedia\">Human Oversight<\/a>. The greatest risk sits in trust. Toms described inspections where systems had not failed; people had simply stopped asking, because the systems had been running for years. It reflects an observation we also described in Berlin. We will come back to it below. With AI the pattern repeats as soon as recommendations are accepted because they are convenient or look credible. And the &ldquo;current&rdquo; in cGMP demands keeping pace. New tools are measured against today&rsquo;s state, because paper, legacy systems, people and today&rsquo;s means of controlling AI all have limits.<\/p>\n<p class=\"qf-pullquote\">&ldquo;You can outsource a lot of things, but you cannot outsource your common sense.&rdquo; (Seneca Toms, US FDA, as quoted by ISPE iSpeak, 24 August 2026)<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>EMA expert workshop, 30 June 2026: Industry answers with one voice<\/h2>\n<p>One week after Boston, the EMA spent a day listening to industry. At the expert workshop on the draft <a href=\"https:\/\/q-finity.de\/en\/glossar\/eu-gmp-annex-22\/\" target=\"_self\" title=\"EU GMP Annex 22 (&ldquo;Artificial Intelligence&rdquo;) is the planned AI annex to the EU GMP guideline: it adds the evidence for embedded AI models to Annex 11 - in the draft limited, for critical applications, to static models with deterministic output.\" class=\"encyclopedia\">EU GMP Annex 22<\/a>, experts nominated by the associations presented their positions on six topics set by the EMA, the six pillars of the EMA&rsquo;s guardrail architecture, from regulatory pathways for adaptive models through Human Oversight, validation and lifecycle to cybersecurity. We followed the publicly broadcast first day in full. The workshop followed the 2025 consultation, which drew 1,359 comments from 79 organizations; the call for a risk-based approach was its clearest theme. On the second, non-public day the drafting group took the input on board and continued its work on the text. The two-day sequence was set from the outset. For us, the signal lies in the tone of the public statement the EMA gave afterwards. It suggests that the ideas and concepts presented were received as helpful. A senior FDA official, too, publicly praised the workshop&rsquo;s format and dialogue.<\/p>\n<p>The associations had been asked to present divergent views as well. The outcome was nonetheless clear: their approaches agree, and they come down to how a quality-risk-based approach is interpreted. On the central question of scope, industry&rsquo;s position departed from the draft. The draft excludes dynamic, probabilistic and generative models from critical applications. Industry countered that no model type is inadmissible or harmless per se. Admissibility is decided by the risk assessment in the specific use case. On Human Oversight, industry proposed replacing the Human-in-the-Loop mechanism fixed in the draft with a Human Oversight concept with several forms. The range runs from approval of every output to ongoing monitoring with intervention by exception. Which form is appropriate follows from the risk assessment. And on guardrails, industry drew the line itself: they reduce risk, they do not remove it, and a control that is meant to lower risk needs its own evidence of effectiveness.<\/p>\n<p>From QFINITY&rsquo;s point of view, the quiet highlight was an architecture diagram shown at the workshop: the AI subsystem of model, integration code and guardrails as a part inside the computerized system, which also includes process and people. That embedding is precisely the architecture behind our <a href=\"https:\/\/q-finity.de\/en\/validation-of-ai\/\">validation of AI in the GxP environment<\/a>: the model is verified; the computerized system as a whole is validated in the process.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>Five sentences all three share<\/h2>\n<p>Placed side by side, the three occasions leave a common core that none of the voices disputes:<\/p>\n<div class=\"qf-gaplist\">\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">1<\/div>\n<div class=\"qf-gap-t\"><b>Criticality is derived from the process and measured by impact and detectability, not by technology.<\/b> Whether framed as impact and detectability, as the significance of the decision or as the risk assessment in the use case, all three describe the same axis. The particular traits of generative or dynamic models belong one level down, in the functional risk assessment, where guardrails come in as controls in the sense of quality risk management.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">2<\/div>\n<div class=\"qf-gap-t\"><b>Human Oversight is a capability.<\/b> Barcelona makes expert review the measure of criticality, the FDA voice from Boston demands understanding rather than mere approval, industry proposes replacing the fixed HITL mechanism with a Human Oversight concept with several forms, and all three presuppose that people can review effectively.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">3<\/div>\n<div class=\"qf-gap-t\"><b>The form of evidence shifts to statistics, and it stays within GxP logic.<\/b> A model is verified with test data that carry their own requirements, with metrics and with confidence levels, and that follows the principle of decision under uncertainty.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">4<\/div>\n<div class=\"qf-gap-t\"><b>Oversight applies to the whole lifecycle.<\/b> It runs from planning and design through initial verification and the whole period of use to decommissioning. That includes adjusting the form of oversight, and it includes monitoring. Confidence in a system is not established once and then left alone.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">5<\/div>\n<div class=\"qf-gap-t\"><b>Accountability stays with the operating company.<\/b> No model and no service provider relieves you of it. Toms said it from the FDA&rsquo;s perspective, industry presented it as consensus at the workshop, and your next inspection will assume it.<\/div>\n<\/div>\n<\/div>\n<h2>Our position from Berlin: Who pushes back when the system speaks?<\/h2>\n<p>The five sentences match the position Daniel K&ouml;pke and Oliver Herrmann presented at the 47th GAMP D-A-CH Forum in Berlin on 11 March 2026. They asked what Human Oversight means when systems become more intelligent, more complex and more convincing. The starting point was responsibility: a patient knows neither SOPs nor validation plans; they trust that in the end a human stands behind quality. An AI-enabled system can analyze data, detect patterns, classify deviations and prepare decisions, and it sounds plausible while doing so. That is exactly where the risk lies: plausibility is not evidence of review. It can trigger a review, it cannot replace one, and it does not make responsibility transferable.<\/p>\n<p>The biggest danger to QA is therefore not AI. It is the silent erosion of visible responsibility: click by click, confirmation by confirmation, until no one pushes back anymore. The role of QA shifts accordingly: it does not just validate systems, it shapes the conditions under which human judgment remains effective. Human Oversight belongs embedded in intended use, business process, data integrity, risk-based controls and lifecycle evidence, so that responsibility is not merely documented but exercised, and its effectiveness stays demonstrable. The full version of this position is in <a href=\"https:\/\/q-finity.de\/en\/who-pushes-back-when-the-system-speaks\/\">Who Pushes Back When the System Speaks?<\/a><\/p>\n<p class=\"qf-keyq\">What conditions do you need to create today so that in three years someone will still challenge a recommendation the system has delivered without complaint all along?<\/p>\n<h2>What follows for regulated companies<\/h2>\n<p>The convergence has a practical side. Anyone working by these five sentences today is unlikely to have to rebuild for the final Annex 22, whether the EMA follows industry&rsquo;s risk principle or keeps the exclusion of certain model classes. The draft&rsquo;s evidence logic, from intended use through independent test data to monitoring, holds in every outcome of the revision. And it holds before an FDA inspection too, because what counts there is what Toms named in Boston: understanding, risk, lifecycle, accountability. That evidence logic is just as necessary for systems to deliver the expected performance and, with or without an AI label, make a tangible contribution to relief and value.<\/p>\n<p>The entry point is the criticality question: which AI-supported applications deliver results that feed without further review into quality decisions that touch patient safety, product quality or data integrity? The effectiveness of Human Oversight follows from there. What matters is less whether a review step is documented than whether the reviewing person understands the context of use, knows the system&rsquo;s limits and is free to disagree. How that can be checked is described under <a href=\"https:\/\/q-finity.de\/en\/ai-governance-and-human-oversight-in-the-gxp-environment\/\">AI Governance and Human Oversight<\/a>. This includes the question of whether dissent still occurs in day-to-day operation.<\/p>\n<h2>What comes next<\/h2>\n<p>For Annex 22, a workshop report has been announced first; a revised draft is expected afterwards. Our <a href=\"https:\/\/q-finity.de\/en\/eu-gmp-annex-22\/\">Annex 22 page<\/a> sets out in three questions what the final text will turn on; as soon as the report is available, we will measure it against them. Until then, the position is a plain one: the computerized system is validated under Annex 11, quality risk management guides how deep the evidence needs to go, and Toms describes no different expectation from inspections. For QFINITY, the three signals from regulators and industry confirm the path we presented in Berlin: AI continues the line of CSV and CSA. That is how we described it in <a href=\"https:\/\/q-finity.de\/en\/company\/publications\/how-ai-will-transform-csv\/\">Pharmaceutical Engineering<\/a> in January, and that is how we read this year&rsquo;s regulator and industry signals.<\/p>\n<p>Further reading: <a class=\"qf-extref\" href=\"https:\/\/ispe.org\/pharmaceutical-engineering\/ispeak\/us-food-and-drug-administration-us-fda-artificial-intelligence-ai\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">US FDA on AI, Critical Thinking, and the Enduring Principles of Quality (ISPE iSpeak, 24 August 2026)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><a class=\"qf-extref\" href=\"https:\/\/ispe.org\/pharmaceutical-engineering\/ispeak\/human-loop-illusion-control\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">Human-in-the-Loop as an Illusion of Control? (Herrmann and Henrichmann, ISPE iSpeak, 4 September 2026)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><a class=\"qf-extref\" href=\"https:\/\/q-finity.de\/en\/chapter-4-annex-11-annex-22-three-drafts-one-control-system\/\"><span class=\"qf-extref-text\">Chapter 4, Annex 11, Annex 22: Three Drafts, One Control System (QFINITY)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><\/p>\n<\/div><span class=\"post-meta-infos\"><\/span><footer class=\"entry-footer\"><\/footer><div class=\"post_delimiter\"><\/div><\/div><div class=\"post_author_timeline\"><\/div><span class=\"hidden\">\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"image\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/drei-signale-eine-linie-ki-gxp-v2-scaled.png<\/span>\n\t\t\t\t\t\t<span itemprop=\"height\">1429<\/span>\n\t\t\t\t\t\t<span itemprop=\"width\">2560<\/span>\n\t\t\t\t<\/span>\n\t\t\t\t<span class=\"av-structured-data\" itemprop=\"publisher\" itemtype=\"https:\/\/schema.org\/Organization\" itemscope=\"itemscope\">\n\t\t\t\t\t\t<span itemprop=\"name\">oherrmann<\/span>\n\t\t\t\t\t\t<span itemprop=\"logo\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\n\t\t\t\t\t\t\t<span itemprop=\"url\">https:\/\/q-finity.de\/wp-content\/uploads\/2026\/07\/q-finity_schriftzug_orange-retina.png<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span><span class=\"av-structured-data\" itemprop=\"author\" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/Person\"><span itemprop=\"name\">oherrmann<\/span><\/span><span class=\"av-structured-data\" itemprop=\"datePublished\" datetime=\"2026-08-31T17:29:55+02:00\">2026-08-31 17:29:55<\/span><span class=\"av-structured-data\" itemprop=\"dateModified\" itemtype=\"https:\/\/schema.org\/dateModified\">2026-09-04 18:11:00<\/span><span class=\"av-structured-data\" itemprop=\"mainEntityOfPage\" itemtype=\"https:\/\/schema.org\/mainEntityOfPage\"><span itemprop=\"name\">Three Signals, One Line: AI in the GxP Environment from Barcelona and Boston to the EMA Workshop<\/span><\/span><\/span><\/article><div class=\"single-big\"><nav class=\"pagination\"><span class=\"pagination-meta\">Page 1 of 27<\/span><span class=\"current\">1<\/span><a href=\"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/page\/2\/\" class=\"inactive next_page\">2<\/a><a href=\"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/page\/3\/\" class=\"inactive\">3<\/a><a href=\"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/page\/2\/\">&rsaquo;<\/a><a href=\"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/page\/27\/\">&raquo;<\/a><\/nav>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"Within seven months, three signals converged on how to assess AI in the GxP environment: the rapporteur of the EMA drafting group for EU GMP Annex 22 explained the draft&#8217;s criticality logic in Barcelona in December 2025, a National Expert&hellip;","protected":false},"author":3,"featured_media":17003,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-17010","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Updates: Publications &amp; Committees | QFINITY<\/title>\n<meta name=\"description\" content=\"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/q-finity.de\/en\/updates\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Updates: Publications &amp; Committees | QFINITY\" \/>\n<meta property=\"og:description\" content=\"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/q-finity.de\/en\/updates\/\" \/>\n<meta property=\"og:site_name\" content=\"QFINITY\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-24T19:10:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/aktuelles-01-hero-v2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Updates\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/\",\"name\":\"Updates: Publications & Committees | QFINITY\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/aktuelles-01-hero-v2.png\",\"datePublished\":\"2026-08-24T17:46:52+00:00\",\"dateModified\":\"2026-08-24T19:10:20+00:00\",\"description\":\"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/#primaryimage\",\"url\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/aktuelles-01-hero-v2.png\",\"contentUrl\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/aktuelles-01-hero-v2.png\",\"width\":1024,\"height\":576,\"caption\":\"QFINITY Aktuelles - Publikationen und Gremienarbeit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/updates\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/q-finity.de\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"name\":\"QFINITY\",\"description\":\"Qualit\u00e4tsmanagement &amp; - sicherung\",\"publisher\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/q-finity.de\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\",\"name\":\"QFINITY\u221e\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/mlsqau6zetur.i.optimole.com\\\/cb:frAi.c2d9\\\/w:512\\\/h:512\\\/q:mauto\\\/f:best\\\/https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/cropped-cropped-signet_PAN_orange.png\",\"contentUrl\":\"https:\\\/\\\/mlsqau6zetur.i.optimole.com\\\/cb:frAi.c2d9\\\/w:512\\\/h:512\\\/q:mauto\\\/f:best\\\/https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/cropped-cropped-signet_PAN_orange.png\",\"width\":512,\"height\":512,\"caption\":\"QFINITY\u221e\"},\"image\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/q-finity-quality-management\\\/\",\"https:\\\/\\\/www.instagram.com\\\/qfinity_official\\\/\",\"https:\\\/\\\/www.wikidata.org\\\/wiki\\\/Q141257555\"],\"founder\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#founder\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#founder\",\"name\":\"Oliver Herrmann\",\"jobTitle\":\"Founder & CEO\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"worksFor\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/olherrmann\\\/\",\"https:\\\/\\\/virtual.ispe.org\\\/b\\\/sp\\\/oliver-herrmann-4399\",\"https:\\\/\\\/www.wikidata.org\\\/wiki\\\/Q141257562\"],\"knowsAbout\":[\"GxP-Compliance\",\"Computer System Validation\",\"Computer Software Assurance\",\"Data Integrity\",\"ALCOA++\",\"AI Governance\",\"GAMP 5\"],\"image\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/oliver-herrmann-qfinity-ceo-scaled.jpg\",\"description\":\"Founder and CEO of QFINITY, GAMP Europe Chair, qualified GAMP 5 and GAMP Data Integrity trainer, GQMA auditor and international speaker. Co-author of several ISPE GAMP guides, including the GAMP 5 Guide (2nd Edition).\",\"memberOf\":{\"@type\":\"Organization\",\"name\":\"International Society for Pharmaceutical Engineering (ISPE)\",\"url\":\"https:\\\/\\\/ispe.org\"},\"hasCredential\":[{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"degree\",\"name\":\"Graduate Computer Scientist (Dipl.-Inf.)\"},{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"certification\",\"name\":\"Microsoft Certified Systems Engineer (MCSE)\"},{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"certification\",\"name\":\"SAFe (Scaled Agile Framework)\"}]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Updates: Publications & Committees | QFINITY","description":"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/q-finity.de\/en\/updates\/","og_locale":"en_US","og_type":"article","og_title":"Updates: Publications & Committees | QFINITY","og_description":"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.","og_url":"https:\/\/q-finity.de\/en\/updates\/","og_site_name":"QFINITY","article_modified_time":"2026-08-24T19:10:20+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/aktuelles-01-hero-v2.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_title":"Updates","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/q-finity.de\/en\/updates\/","url":"https:\/\/q-finity.de\/en\/updates\/","name":"Updates: Publications & Committees | QFINITY","isPartOf":{"@id":"https:\/\/q-finity.de\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/q-finity.de\/en\/updates\/#primaryimage"},"image":{"@id":"https:\/\/q-finity.de\/en\/updates\/#primaryimage"},"thumbnailUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/aktuelles-01-hero-v2.png","datePublished":"2026-08-24T17:46:52+00:00","dateModified":"2026-08-24T19:10:20+00:00","description":"Updates from QFINITY: articles and publications, committee and association work, awards, and our perspective on new regulations.","breadcrumb":{"@id":"https:\/\/q-finity.de\/en\/updates\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/q-finity.de\/en\/updates\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/q-finity.de\/en\/updates\/#primaryimage","url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/aktuelles-01-hero-v2.png","contentUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/08\/aktuelles-01-hero-v2.png","width":1024,"height":576,"caption":"QFINITY Aktuelles - Publikationen und Gremienarbeit"},{"@type":"BreadcrumbList","@id":"https:\/\/q-finity.de\/en\/updates\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/q-finity.de\/en\/home\/"},{"@type":"ListItem","position":2,"name":"Updates"}]},{"@type":"WebSite","@id":"https:\/\/q-finity.de\/en\/#website","url":"https:\/\/q-finity.de\/en\/","name":"QFINITY","description":"Qualit\u00e4tsmanagement &amp; - sicherung","publisher":{"@id":"https:\/\/q-finity.de\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/q-finity.de\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/q-finity.de\/en\/#organization","name":"QFINITY\u221e","url":"https:\/\/q-finity.de\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/q-finity.de\/en\/#\/schema\/logo\/image\/","url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:frAi.c2d9\/w:512\/h:512\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2021\/03\/cropped-cropped-signet_PAN_orange.png","contentUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:frAi.c2d9\/w:512\/h:512\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2021\/03\/cropped-cropped-signet_PAN_orange.png","width":512,"height":512,"caption":"QFINITY\u221e"},"image":{"@id":"https:\/\/q-finity.de\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/q-finity-quality-management\/","https:\/\/www.instagram.com\/qfinity_official\/","https:\/\/www.wikidata.org\/wiki\/Q141257555"],"founder":{"@id":"https:\/\/q-finity.de\/en\/#founder"}},{"@type":"Person","@id":"https:\/\/q-finity.de\/en\/#founder","name":"Oliver Herrmann","jobTitle":"Founder & CEO","url":"https:\/\/q-finity.de\/en\/","worksFor":{"@id":"https:\/\/q-finity.de\/en\/#organization"},"sameAs":["https:\/\/www.linkedin.com\/in\/olherrmann\/","https:\/\/virtual.ispe.org\/b\/sp\/oliver-herrmann-4399","https:\/\/www.wikidata.org\/wiki\/Q141257562"],"knowsAbout":["GxP-Compliance","Computer System Validation","Computer Software Assurance","Data Integrity","ALCOA++","AI Governance","GAMP 5"],"image":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/06\/oliver-herrmann-qfinity-ceo-scaled.jpg","description":"Founder and CEO of QFINITY, GAMP Europe Chair, qualified GAMP 5 and GAMP Data Integrity trainer, GQMA auditor and international speaker. Co-author of several ISPE GAMP guides, including the GAMP 5 Guide (2nd Edition).","memberOf":{"@type":"Organization","name":"International Society for Pharmaceutical Engineering (ISPE)","url":"https:\/\/ispe.org"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","name":"Graduate Computer Scientist (Dipl.-Inf.)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"certification","name":"Microsoft Certified Systems Engineer (MCSE)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"certification","name":"SAFe (Scaled Agile Framework)"}]}]}},"_links":{"self":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/comments?post=17010"}],"version-history":[{"count":3,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/revisions"}],"predecessor-version":[{"id":17017,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/pages\/17010\/revisions\/17017"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/media\/17003"}],"wp:attachment":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/media?parent=17010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}