{"id":17197,"date":"2026-10-02T16:52:03","date_gmt":"2026-10-02T14:52:03","guid":{"rendered":"https:\/\/q-finity.de\/?p=17197"},"modified":"2026-10-02T23:34:17","modified_gmt":"2026-10-02T21:34:17","slug":"ema-workshop-report-annex-22","status":"publish","type":"post","link":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/","title":{"rendered":"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI"},"content":{"rendered":"<p class=\"qf-abstract\">In early October 2026 the EMA published the report on its expert workshop of 30 June 2026. In 15 pages, document EMA\/156789\/2026 records what the industry associations presented on six topics, and it contains one sentence that reaches beyond the workshop: the drafting group has discussed widening the scope of <a href=\"https:\/\/q-finity.de\/en\/eu-gmp-annex-22\/\">EU GMP Annex 22<\/a> to dynamic, adaptive, probabilistic and generative models. The condition would be a \"fully documented, robust, risk-based control strategy\". Here is our reading of what the report confirms and what it leaves open.<\/p>\n<p>We followed the publicly broadcast workshop day and brought the signals from Barcelona, Boston and the workshop together in our August article <a href=\"https:\/\/q-finity.de\/en\/ai-gxp-regulators-one-line\/\">Three Signals, One Line<\/a>. With the report, a written account of the workshop by the EMA itself is available for the first time.<\/p>\n<div style=\"clear:both\"><\/div>\n<h2>The sentence that matters<\/h2>\n<p>The 2025 consultation draft excludes generative AI and Large Language Models from its scope and, like dynamic and probabilistic models, does not provide for them in critical GMP applications. The report quotes that sentence in its introduction and sets the consultation feedback against it. The comments supported allowing such models in GMP applications, \"whether critical or non-critical\". The drafting group, the EMA writes, has therefore discussed widening the scope, \"provided they comply with the requirements of the annex and are supported by a fully documented, robust, risk-based control strategy\".<\/p>\n<p>Two things belong to that sentence. First, it records a discussion, not a decision. As the next step, the report names the revision of the draft by the drafting group, without giving a date. Second, the question of which elements such a control strategy needs was the very reason for the workshop. The drafting group wanted to hear from experts whether a risk-based approach can be applied to generative AI and which control mechanisms would carry it.<\/p>\n<h2>Four lines across six topics<\/h2>\n<p>For each topic, the report gives the associations' positions and the regulators' questions. Each topic closes with key messages and a section on the potential impact on the annex text. Four lines run through the topics.<\/p>\n<div class=\"qf-gaplist\">\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">1<\/div>\n<div class=\"qf-gap-t\"><b>No prohibition by technology category.<\/b> The consolidated industry position opposed categorical exclusions. Whether a model is acceptable should follow from intended use, decision consequence, model influence, uncertainty and complexity, and from whether the residual risk can be reduced to an acceptable level. The report records as a key message that existing quality risk management principles apply to adaptive and probabilistic models as well. A valid outcome of that assessment may still be not to use the model. That conclusion should be documented.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">2<\/div>\n<div class=\"qf-gap-t\"><b>Human oversight rather than human-in-the-loop by default.<\/b> The report distinguishes oversight as a lifecycle-wide objective from human-in-the-loop as one possible implementation, in which a process waits for a human action. Its key messages state that human-in-the-loop is not a default requirement for all AI uses, that oversight must be evidenced and periodically reviewed, and that it cannot compensate for inadequate validation. The regulators asked how automation bias can be managed and how the performance of the reviewing person can be monitored.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">3<\/div>\n<div class=\"qf-gap-t\"><b>Control mechanisms need evidence.<\/b> The report documents the presented layering of prevention at the input, detection in the model and containment at the output. It also notes that some of the five use cases were pilots or theoretical frameworks. Two points from the discussion are recorded. Controls designed for known failure modes do not by themselves cover unanticipated ones, and in the annex itself industry would prefer the term control mechanism over guardrail, because guardrails are technology-specific and transient. On that position, the annex should name objectives such as prevention, detection and containment, while technical methods belong in an updateable format.<\/div>\n<\/div>\n<div class=\"qf-gap\">\n<div class=\"qf-gap-n\">4<\/div>\n<div class=\"qf-gap-t\"><b>Responsibility stays with the regulated company.<\/b> That covers the use of the model as much as the management of suppliers and cloud providers. On the industry position reported, AI systems consist of data, model and hardware and therefore remain computerized systems. Annex 11 applies to them. The report refers to its chapter on outsourced activities; in the current Annex 11 the subject sits in section 3, in the 2025 draft in section 7. Whoever uses a third-party model through an interface needs access to the evidence with which its behavior can be measured. If the provider does not supply it, the use cannot be justified.<\/div>\n<\/div>\n<\/div>\n<h2>What has not been worked out yet<\/h2>\n<p>What the workshop left open is just as telling. Some of the use cases presented were, according to the report, not yet production systems but pilots or concepts. On the question of how independent test data can be preserved for a model that keeps learning in operation, the report records that the answer did not define one mandatory technical approach and that implementation for continuously learning systems needs clarification. And for the particular behaviors of generative models, hallucination, fabrication, overconfidence in the output, the workshop set no method for estimating rates or confidence. The revised draft will have to settle these questions, or hand them openly to the operator's risk assessment.<\/p>\n<h2>Our reading<\/h2>\n<p>For QFINITY, the report overlaps with the architecture we describe on our <a href=\"https:\/\/q-finity.de\/en\/eu-gmp-annex-22\/\">Annex 22 page<\/a> and in <a href=\"https:\/\/q-finity.de\/en\/validation-of-ai\/\">Validation of AI in the GxP environment<\/a>. The model is a component with its own evidence, and it is verified. The computerized system in which it works with control mechanisms, process and people is validated in its process. The report does not commit to this distinction. It uses \"validation\" for lifecycle and system questions as well and keeps the objects of evidence open side by side: in its outlook on the validation topic it writes \"revalidation\/re-verification\" and names an \"AI validation\/qualification package\" as a possible consequence, mirroring the industry presentation rather than stating a regulatory position. The conceptual core of what an operator should be able to show is nevertheless visible in the report: evidence of model performance, information on the training data, controls around input and output, and evidence that the system works as expected in operation. In substance that matches the evidence we have described since the GAMP workshop at the ISPE summit in Boston in June, on whose core team Frank Henrichmann worked for QFINITY: intended use in the company's own process, acceptance criteria, a test set kept separate from training, the supplier's model card, and the residual risk the operator carries.<\/p>\n<p>On oversight, the report meets the line we presented in March at the GAMP D-A-CH Forum under the question <a href=\"https:\/\/q-finity.de\/en\/who-pushes-back-when-the-system-speaks\/\">Who Pushes Back When the System Speaks?<\/a> and deepened in September for ISPE iSpeak under the title <a href=\"https:\/\/q-finity.de\/en\/company\/publications\/human-in-the-loop-illusion-of-control\/\">Human-in-the-Loop as an Illusion of Control?<\/a> Human-in-the-loop alone does not establish control. Control comes about when the reviewing person understands the context of use, knows the limits of the model and is allowed to push back, and when that capability can be evidenced in operation. In the report, one speaker puts it this way: oversight provides knowledge, detection and triggers for action, and it is the action that reduces the risk.<\/p>\n<p class=\"qf-keyq\">Which of your AI-supported applications would you operate today on the basis of a documented, risk-based control strategy? And for which would the assessment conclude not to use them?<\/p>\n<h2>A checklist for operators<\/h2>\n<p>The revised draft has no date. Until then the 2025 consultation draft remains the reference for preparation, not an annex in force, and the report does not change its wording. Anyone planning an AI application in a GMP environment today can use the four lines of the report as a checklist. It starts with a criticality assessment that, beyond direct impact, takes in decision consequence, model influence, uncertainty and the detectability of errors. The form of oversight must fit the risk assessment, and its effectiveness must be demonstrable. The evidence for the control mechanisms rests on the overall package of controls rather than on each mechanism in isolation. Supplier agreements secure access to evidence, participation in change control and transparency of the controls. How this can be anchored in <a href=\"https:\/\/q-finity.de\/en\/ai-governance-and-human-oversight-in-the-gxp-environment\/\">AI governance with human oversight<\/a> is described on our page on the subject. We have also worked the state of the report into the three open questions on our Annex 22 page.<\/p>\n<div class=\"qf-offer-teaser\">\n<div class=\"qf-offer-teaser-text\">\n<span class=\"qf-offer-teaser-eyebrow\">Entry offer<\/span><br>\n<span class=\"qf-offer-teaser-name\">Readiness Assessment and Roadmap: Chapter&nbsp;4, Annex&nbsp;11 &amp;&nbsp;22<\/span>\n<p>In the AI module we assess your AI applications along the four lines of the report: criticality, form of oversight, evidence for control mechanisms, supplier agreements.<\/p>\n<\/div>\n<dl class=\"qf-offer-teaser-facts\">\n<div>\n<dt>Modules<\/dt>\n<dd><a href=\"https:\/\/q-finity.de\/en\/glossar\/data\/\" target=\"_self\" title=\"Data generally denotes facts, values (numerical or otherwise) or recordable findings, such as those obtained by measurements or observation.\" class=\"encyclopedia\">Data<\/a>, systems, AI<\/dd>\n<\/div>\n<div>\n<dt>Duration<\/dt>\n<dd>Three to six weeks<\/dd>\n<\/div>\n<div>\n<dt>Result<\/dt>\n<dd>Control map, gap list, roadmap<\/dd>\n<\/div>\n<\/dl>\n<p><a class=\"btn btn-secondary\" href=\"https:\/\/q-finity.de\/en\/readiness-assessment-chapter-4-annex-11-22\/\">View the offer &rarr;<\/a>\n<\/p><\/div>\n<p>Further reading: <a class=\"qf-extref\" href=\"https:\/\/www.ema.europa.eu\/en\/documents\/report\/report-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22_en.pdf\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">EMA: Report of the multistakeholder workshop on expert contributions to AI guidance development (Annex 22), EMA\/156789\/2026<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><a class=\"qf-extref\" href=\"https:\/\/www.ema.europa.eu\/en\/events\/good-manufacturing-practice-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22\" target=\"_blank\" rel=\"noopener\"><span class=\"qf-extref-text\">EMA: workshop page with agenda and report<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><a class=\"qf-extref\" href=\"https:\/\/q-finity.de\/en\/ai-gxp-regulators-one-line\/\"><span class=\"qf-extref-text\">Three Signals, One Line: AI in the GxP environment between Barcelona, Boston and the EMA workshop (QFINITY)<\/span><span class=\"qf-extref-arrow\">&#8599;<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In early October 2026 the EMA published the report on its expert workshop of 30 June 2026. In 15 pages, document EMA\/156789\/2026 records what the industry associations presented on six topics, and it contains one sentence that reaches beyond the workshop: the drafting group has discussed widening the scope of EU GMP Annex 22 to [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":17213,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[39],"tags":[],"class_list":["post-17197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-category"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.5 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>EMA Workshop Report on Annex 22: Opening to Generative AI | QFINITY<\/title>\n<meta name=\"description\" content=\"The EMA has published the report on its Annex 22 expert workshop. The drafting group has discussed admitting generative AI under a risk-based control strategy. QFINITY&#039;s reading.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EMA Workshop Report on Annex 22: Opening to Generative AI\" \/>\n<meta property=\"og:description\" content=\"The drafting group has discussed admitting generative AI under a risk-based control strategy. What the report confirms and which common lines emerge.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/\" \/>\n<meta property=\"og:site_name\" content=\"QFINITY\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-02T14:52:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-02T21:34:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"oherrmann\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"oherrmann\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/\"},\"author\":{\"name\":\"oherrmann\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/person\\\/f9dc643267b45b803521d7382f1283b4\"},\"headline\":\"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI\",\"datePublished\":\"2026-10-02T14:52:03+00:00\",\"dateModified\":\"2026-10-02T21:34:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/\"},\"wordCount\":1461,\"publisher\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/ema-workshop-report-annex-22-sechs-vier-eins.jpg\",\"articleSection\":[\"Updates\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/\",\"name\":\"EMA Workshop Report on Annex 22: Opening to Generative AI | QFINITY\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/ema-workshop-report-annex-22-sechs-vier-eins.jpg\",\"datePublished\":\"2026-10-02T14:52:03+00:00\",\"dateModified\":\"2026-10-02T21:34:17+00:00\",\"description\":\"The EMA has published the report on its Annex 22 expert workshop. The drafting group has discussed admitting generative AI under a risk-based control strategy. QFINITY's reading.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#primaryimage\",\"url\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/ema-workshop-report-annex-22-sechs-vier-eins.jpg\",\"contentUrl\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/ema-workshop-report-annex-22-sechs-vier-eins.jpg\",\"width\":2560,\"height\":1440,\"caption\":\"EMA-Workshop-Report zu Annex 22: sechs Str\u00f6me werden zu vier Linien und laufen zu einer Aussage zusammen (QFINITY)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/ema-workshop-report-annex-22\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/q-finity.de\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"name\":\"QFINITY\",\"description\":\"Qualit\u00e4tsmanagement &amp; - sicherung\",\"publisher\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/q-finity.de\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\",\"name\":\"QFINITY\u221e\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/mlsqau6zetur.i.optimole.com\\\/cb:frAi.c2d9\\\/w:512\\\/h:512\\\/q:mauto\\\/f:best\\\/https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/cropped-cropped-signet_PAN_orange.png\",\"contentUrl\":\"https:\\\/\\\/mlsqau6zetur.i.optimole.com\\\/cb:frAi.c2d9\\\/w:512\\\/h:512\\\/q:mauto\\\/f:best\\\/https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/cropped-cropped-signet_PAN_orange.png\",\"width\":512,\"height\":512,\"caption\":\"QFINITY\u221e\"},\"image\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/q-finity-quality-management\\\/\",\"https:\\\/\\\/www.instagram.com\\\/qfinity_official\\\/\",\"https:\\\/\\\/www.wikidata.org\\\/wiki\\\/Q141257555\"],\"founder\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#founder\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#\\\/schema\\\/person\\\/f9dc643267b45b803521d7382f1283b4\",\"name\":\"oherrmann\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g\",\"caption\":\"oherrmann\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#founder\",\"name\":\"Oliver Herrmann\",\"jobTitle\":\"Founder & CEO\",\"url\":\"https:\\\/\\\/q-finity.de\\\/en\\\/\",\"worksFor\":{\"@id\":\"https:\\\/\\\/q-finity.de\\\/en\\\/#organization\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/olherrmann\\\/\",\"https:\\\/\\\/virtual.ispe.org\\\/b\\\/sp\\\/oliver-herrmann-4399\",\"https:\\\/\\\/www.wikidata.org\\\/wiki\\\/Q141257562\"],\"knowsAbout\":[\"GxP-Compliance\",\"Computer System Validation\",\"Computer Software Assurance\",\"Data Integrity\",\"ALCOA++\",\"AI Governance\",\"GAMP 5\"],\"image\":\"https:\\\/\\\/q-finity.de\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/oliver-herrmann-qfinity-ceo-scaled.jpg\",\"description\":\"Founder and CEO of QFINITY, GAMP Europe Chair, qualified GAMP 5 and GAMP Data Integrity trainer, GQMA auditor and international speaker. Co-author of several ISPE GAMP guides, including the GAMP 5 Guide (2nd Edition).\",\"memberOf\":{\"@type\":\"Organization\",\"name\":\"International Society for Pharmaceutical Engineering (ISPE)\",\"url\":\"https:\\\/\\\/ispe.org\"},\"hasCredential\":[{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"degree\",\"name\":\"Graduate Computer Scientist (Dipl.-Inf.)\"},{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"certification\",\"name\":\"Microsoft Certified Systems Engineer (MCSE)\"},{\"@type\":\"EducationalOccupationalCredential\",\"credentialCategory\":\"certification\",\"name\":\"SAFe (Scaled Agile Framework)\"}]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"EMA Workshop Report on Annex 22: Opening to Generative AI | QFINITY","description":"The EMA has published the report on its Annex 22 expert workshop. The drafting group has discussed admitting generative AI under a risk-based control strategy. QFINITY's reading.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/","og_locale":"en_US","og_type":"article","og_title":"EMA Workshop Report on Annex 22: Opening to Generative AI","og_description":"The drafting group has discussed admitting generative AI under a risk-based control strategy. What the report confirms and which common lines emerge.","og_url":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/","og_site_name":"QFINITY","article_published_time":"2026-10-02T14:52:03+00:00","article_modified_time":"2026-10-02T21:34:17+00:00","og_image":[{"width":2560,"height":1440,"url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg","type":"image\/jpeg"}],"author":"oherrmann","twitter_card":"summary_large_image","twitter_title":"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI","twitter_misc":{"Written by":"oherrmann","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#article","isPartOf":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/"},"author":{"name":"oherrmann","@id":"https:\/\/q-finity.de\/en\/#\/schema\/person\/f9dc643267b45b803521d7382f1283b4"},"headline":"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI","datePublished":"2026-10-02T14:52:03+00:00","dateModified":"2026-10-02T21:34:17+00:00","mainEntityOfPage":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/"},"wordCount":1461,"publisher":{"@id":"https:\/\/q-finity.de\/en\/#organization"},"image":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#primaryimage"},"thumbnailUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg","articleSection":["Updates"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/","url":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/","name":"EMA Workshop Report on Annex 22: Opening to Generative AI | QFINITY","isPartOf":{"@id":"https:\/\/q-finity.de\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#primaryimage"},"image":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#primaryimage"},"thumbnailUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg","datePublished":"2026-10-02T14:52:03+00:00","dateModified":"2026-10-02T21:34:17+00:00","description":"The EMA has published the report on its Annex 22 expert workshop. The drafting group has discussed admitting generative AI under a risk-based control strategy. QFINITY's reading.","breadcrumb":{"@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#primaryimage","url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg","contentUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/10\/ema-workshop-report-annex-22-sechs-vier-eins.jpg","width":2560,"height":1440,"caption":"EMA-Workshop-Report zu Annex 22: sechs Str\u00f6me werden zu vier Linien und laufen zu einer Aussage zusammen (QFINITY)"},{"@type":"BreadcrumbList","@id":"https:\/\/q-finity.de\/en\/ema-workshop-report-annex-22\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/q-finity.de\/en\/home\/"},{"@type":"ListItem","position":2,"name":"EMA Workshop Report on Annex 22: The Drafting Group Has Discussed Opening the Scope to Generative AI"}]},{"@type":"WebSite","@id":"https:\/\/q-finity.de\/en\/#website","url":"https:\/\/q-finity.de\/en\/","name":"QFINITY","description":"Qualit\u00e4tsmanagement &amp; - sicherung","publisher":{"@id":"https:\/\/q-finity.de\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/q-finity.de\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/q-finity.de\/en\/#organization","name":"QFINITY\u221e","url":"https:\/\/q-finity.de\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/q-finity.de\/en\/#\/schema\/logo\/image\/","url":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:frAi.c2d9\/w:512\/h:512\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2021\/03\/cropped-cropped-signet_PAN_orange.png","contentUrl":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:frAi.c2d9\/w:512\/h:512\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2021\/03\/cropped-cropped-signet_PAN_orange.png","width":512,"height":512,"caption":"QFINITY\u221e"},"image":{"@id":"https:\/\/q-finity.de\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/q-finity-quality-management\/","https:\/\/www.instagram.com\/qfinity_official\/","https:\/\/www.wikidata.org\/wiki\/Q141257555"],"founder":{"@id":"https:\/\/q-finity.de\/en\/#founder"}},{"@type":"Person","@id":"https:\/\/q-finity.de\/en\/#\/schema\/person\/f9dc643267b45b803521d7382f1283b4","name":"oherrmann","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cae5b85c326b5a3c48b0ab3a60d56a3ee443233962ae9b9c3ccf7df578f76f40?s=96&d=mm&r=g","caption":"oherrmann"}},{"@type":"Person","@id":"https:\/\/q-finity.de\/en\/#founder","name":"Oliver Herrmann","jobTitle":"Founder & CEO","url":"https:\/\/q-finity.de\/en\/","worksFor":{"@id":"https:\/\/q-finity.de\/en\/#organization"},"sameAs":["https:\/\/www.linkedin.com\/in\/olherrmann\/","https:\/\/virtual.ispe.org\/b\/sp\/oliver-herrmann-4399","https:\/\/www.wikidata.org\/wiki\/Q141257562"],"knowsAbout":["GxP-Compliance","Computer System Validation","Computer Software Assurance","Data Integrity","ALCOA++","AI Governance","GAMP 5"],"image":"https:\/\/mlsqau6zetur.i.optimole.com\/cb:mN7M.c4bb\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/q-finity.de\/wp-content\/uploads\/2026\/06\/oliver-herrmann-qfinity-ceo-scaled.jpg","description":"Founder and CEO of QFINITY, GAMP Europe Chair, qualified GAMP 5 and GAMP Data Integrity trainer, GQMA auditor and international speaker. Co-author of several ISPE GAMP guides, including the GAMP 5 Guide (2nd Edition).","memberOf":{"@type":"Organization","name":"International Society for Pharmaceutical Engineering (ISPE)","url":"https:\/\/ispe.org"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","name":"Graduate Computer Scientist (Dipl.-Inf.)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"certification","name":"Microsoft Certified Systems Engineer (MCSE)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"certification","name":"SAFe (Scaled Agile Framework)"}]}]}},"_links":{"self":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/posts\/17197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/comments?post=17197"}],"version-history":[{"count":11,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/posts\/17197\/revisions"}],"predecessor-version":[{"id":17231,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/posts\/17197\/revisions\/17231"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/media\/17213"}],"wp:attachment":[{"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/media?parent=17197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/categories?post=17197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/q-finity.de\/en\/wp-json\/wp\/v2\/tags?post=17197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}