Wednesday, July 15, 2026

MHRA sets clear expectations for AI-assisted GxP inspection responses


Introduction MHRA sets expectations for AI-assisted GxP inspection responses, requiring accurate evidence, technical review, human approval and accountable CAPA development.

The UK Medicines and Healthcare products Regulatory Agency has published an important statement on the use of artificial intelligence when preparing responses following GxP inspections.

The MHRA confirmed that companies are already using AI tools to draft inspection responses. The regulator recognises that AI can help explain complex technical matters, improve consistency and accelerate routine drafting. However, it has also identified cases in which inappropriate AI use created real regulatory and patient-safety risks.

According to the MHRA, some AI-assisted inspection responses included references to guidance that did not exist, citations of inappropriate regulatory frameworks and inaccurate information. In one case, a response exceeded 90 pages but still failed to address the identified deficiencies. In another case involving a serious patient-safety concern, inaccurate AI-generated information increased the regulator’s review time from approximately four hours to more than 20 hours.

This is an important development because it moves the risk of AI hallucination in GxP documentation from theory into documented regulatory experience.

MHRA is not prohibiting AI

The MHRA’s position is not that companies should stop using AI. Its concern is whether information submitted to the regulator is accurate, verifiable, technically reviewed and prepared under appropriate oversight.

The regulator states that all inspection responses and related submissions must be:

  • factually accurate and verifiable;
  • technically reviewed by appropriately experienced personnel;
  • approved by a person with sufficient authority and accountability;
  • supported by evidence for factual claims;
  • appropriate to the specific regulatory and organisational context.

These expectations apply regardless of whether the document was prepared using AI, templates, consultants or conventional manual drafting.

Voluntary disclosure of AI use

The MHRA is also offering companies the option to disclose when AI has been used to support an inspection response. Disclosure is currently voluntary.

Where a company chooses to disclose AI use, the MHRA recommends:

  • including a brief statement at the beginning of the response;
  • identifying the sections in which AI assistance was used;
  • confirming that the content was verified and approved by humans.

The MHRA indicates that transparent disclosure, combined with effective verification, may demonstrate a mature and open quality culture.

This does not mean that disclosure compensates for inaccurate information. Responsibility remains with the organisation and the accountable personnel approving the response.

What may indicate inadequate AI oversight?

The MHRA identifies several warning signs that may indicate weak verification or quality-system controls:

  • incorrect statements or non-existent references;
  • generic language that does not address the specific deficiency;
  • lack of organisation-specific information;
  • citations of regulations without explaining their relevance;
  • inconsistent technical terminology;
  • excessively long responses that fail to address the issue clearly.

Where inspection responses are inaccurate, incomplete or unnecessarily verbose, the MHRA may reject them or return them for revision.

Weak responses may also affect the regulator’s assessment of the company’s CAPA system and future inspection risk. Serious or repeated problems may be referred for further regulatory action.

Practical implications for pharmaceutical companies

Companies using AI to prepare responses to inspections, audits or regulatory deficiencies should establish a controlled review process.

At minimum, this should include:

  • use of approved regulatory and company source documents;
  • verification of every cited regulation, guidance document and factual claim;
  • confirmation that the response addresses the specific observation;
  • technical review by subject-matter experts;
  • Quality Unit review and formal approval;
  • removal of generic or unsupported AI-generated statements;
  • retention of evidence supporting proposed CAPAs;
  • clear accountability for the final submitted response.

AI may help organise information and improve drafting efficiency, but it cannot replace root-cause analysis, technical understanding or knowledge of the company’s processes.

A well-written response that does not address the actual cause of a deficiency is not an effective CAPA response.

Key takeaway

The MHRA’s message is pragmatic and important: regulators do not need to prohibit AI to control its risks.

The regulatory expectation remains focused on outcomes. Inspection responses must be accurate, evidence-based, organisation-specific and approved by accountable personnel.

For pharmaceutical companies, this means that AI-assisted regulatory writing should be treated as a controlled quality process—not as an informal administrative shortcut.

Source:
https://mhrainspecto … stifling-innovation/

banner2.png

Saturday, July 11, 2026

EMA Annex 22 AI workshop: awaiting official conclusions, but the direction of discussion is important


Introduction EMA’s Annex 22 AI workshop highlights a possible shift from prohibiting GenAI and LLMs in GMP toward risk-based control using guardrails, human oversight, traceability, validation, lifecycle monitoring and pharmaceutical quality system governance.

Following the EMA GMP multistakeholder workshop organised on 30 June and 1 July 2026 on expert contributions to the development of EU GMP Annex 22 on Artificial Intelligence, the pharmaceutical industry is still awaiting official feedback, conclusions or a post-workshop report from EMA.

The workshop was organised to support the development of Annex 22 and to collect expert input on the possible use of artificial intelligence in medicines manufacturing. The first day was available as a live broadcast and included expert opinions on the future use of generative AI, large language models and other probabilistic or adaptive AI models in GMP environments.

One important message emerging from the expert discussion was that a simple, general prohibition of GenAI or LLMs in pharmaceutical GMP environments may not be the most effective or future-proof regulatory approach. Such a prohibition could quickly become outdated, especially as AI models, control mechanisms, guardrails, validation methods and monitoring tools continue to improve.

At the same time, this does not mean that GenAI or LLMs should be freely accepted in critical GMP applications. The more balanced and practical direction appears to be a risk-based approach: AI should be considered according to its intended use, GMP impact, patient risk, level of human oversight, data quality, traceability, model behaviour, validation evidence and lifecycle controls.

This is particularly important because the original draft Annex 22 indicated that dynamic, adaptive and probabilistic models, including GenAI and LLMs, should not be used in critical GMP applications. However, stakeholder feedback showed support for potentially enabling these technologies in medicines manufacturing if adequate control and mitigation measures can be demonstrated.

For pharmaceutical companies, the practical message is clear: the discussion is moving from “AI should be prohibited” toward “under what conditions can AI be controlled well enough for GMP use?”

The key control areas are likely to include:

  • clear definition of intended use;
  • GMP impact and patient-risk assessment;
  • approved and controlled source data;
  • model/version control;
  • guardrails and their verification;
  • human oversight and accountability;
  • traceability of AI outputs;
  • detection of hallucinations or incorrect recommendations;
  • incident escalation and prevention of GMP impact;
  • performance monitoring and drift detection;
  • supplier qualification and cloud-service oversight;
  • change control for model updates, retraining and configuration changes;
  • documented validation or qualification evidence.

One of the most important concepts discussed in the context of GenAI and LLMs in GMP is the use of “guardrails”. What could “guardrails” mean for AI in GMP?

In simple terms, guardrails are predefined controls built around an AI system to keep its use within safe, intended and acceptable boundaries.

In GMP language, guardrails can be understood as technical, procedural and human controls that prevent AI from being used in the wrong way, reduce the risk of incorrect or unsupported outputs, and stop AI-generated conclusions from becoming GMP decisions without appropriate human review.

Guardrails do not make AI perfect. They do not remove the need for validation, qualification, human oversight or quality risk management. Their purpose is to ensure that AI remains a controlled support tool, not an uncontrolled authority.
Guardrails are predefined technical, procedural and organizational controls that define what an AI system is allowed to do, what it must not do, how it should behave under uncertainty, and how its outputs are reviewed before they affect GMP activities, records or decisions.

Examples of AI guardrails in GMP

  • Intended-use limitation – the AI system may only be used for defined and approved purposes. For example, an AI tool may summarize SOP content, but may not approve a deviation, assign final root cause or make a batch disposition decision.
  • Source grounding – the AI must generate answers only from approved and controlled sources, such as current SOPs, specifications, batch records, validation reports, quality agreements or approved regulatory guidance.
  • Refusal rules – the AI must not guess when evidence is missing. For example, the system should state: “Insufficient information is available to conclude product impact” instead of generating an unsupported conclusion.
  • Output constraints – the AI output should be limited to predefined sections or fields, such as facts identified, source references, missing information, potential questions for review and recommended human follow-up. It should not create final GMP conclusions unless this is explicitly validated and approved for the intended use.
  • Human review gate – AI-generated outputs should be reviewed by qualified personnel before they are used in GMP records or decisions. For example, QA should review an AI-generated deviation summary before it is entered into the official investigation record.
  • Access control – only trained and authorized users should be able to use AI functions with potential GMP impact. For example, a batch review assistant should be available only to trained QA or manufacturing reviewers.
  • Audit trail – the system should retain evidence of AI use, including prompt, output, source documents, model or knowledge-base version, reviewer edits and final approval.
  • Change control – changes to the AI model, prompts, configuration, guardrails or knowledge base should be assessed for GMP impact. A new model version or major knowledge-base update may require impact assessment and requalification.
  • Performance monitoring – AI performance should be monitored in routine use. Examples include tracking false citations, unsupported claims, reviewer corrections, repeated failure modes and cases where AI output was rejected by users.

Practical example: AI support for deviation investigations

For an AI tool supporting deviation investigations, guardrails could be defined as follows:

The AI may identify relevant facts, summarize the event chronology, list missing information, identify potentially similar historical deviations and suggest questions for the investigator to consider. The AI must use only approved QMS records and controlled source documents. It must not assign the final root cause, conclude product impact, determine CAPA effectiveness or recommend batch disposition. If the available information is insufficient, the AI must clearly state that no conclusion can be made. Any AI-generated text must be reviewed, corrected where needed and approved by the investigation owner and QA before inclusion in the GMP record.

This example illustrates the practical meaning of guardrails: the AI can support the process, but it cannot replace GMP responsibility. The final decision remains with qualified personnel and must be justified by evidence.

The final Annex 22 position is not yet known. However, the workshop confirms that regulators are actively considering how to balance innovation with GMP control. For industry, this is a strong signal to start preparing practical AI governance frameworks now, rather than waiting until the final Annex 22 text is published.

AI in GMP should not be treated as an informal tool or uncontrolled black box. If AI supports or influences regulated manufacturing, quality or compliance decisions, it should be governed within the pharmaceutical quality system.

Previous note on the planned EMA workshop:
https://www.aiforpha … ment-of-ai-annex-22/

EMA workshop page:
https://www.ema.euro … development-annex-22

Friday, July 10, 2026

Digital standards and machine-readable compendial methods may become a key enabler for AI in QC laboratories


Introduction Machine-readable compendial methods and digital standards may become key enablers for AI-ready pharmaceutical QC laboratories by improving traceability, version control, GMP data integrity and integration with LIMS, LES and ELN systems.

A recent Pharmaceutical Technology article discusses how digital standards can modernise pharmaceutical quality assurance without compromising confidence. This follows the launch of USP MethodConnect, a machine-readable library of USP-NF test methods designed for integration into LIMS, LES and ELN systems.

This may look like a laboratory informatics topic, but it is highly relevant to AI in pharma. AI and automation depend on reliable, structured and controlled data. If compendial methods are manually retyped from PDF or paper into laboratory systems, there is a risk of transcription errors, inconsistent interpretation and weak traceability.

Machine-readable standards reduce that risk by allowing trusted quality requirements to be integrated directly into digital laboratory workflows. This creates a stronger foundation for automation, advanced analytics and future AI-supported QC processes.

Why this matters for pharma and GMP:

  • AI-ready laboratories need structured, trusted and machine-readable quality data.
  • Manual transcription of compendial methods into digital systems creates compliance risk.
  • Digital standards can improve traceability, version control and consistency.
  • Machine-readable methods can support LIMS, LES, ELN and automated review workflows.
  • Trusted digital standards may help AI systems remain anchored to approved scientific and compendial sources.

Practical takeaway:

For QC laboratories, AI readiness is not only about buying AI software. It is also about building a controlled digital foundation.

Companies should assess:

  • how compendial methods are transferred into laboratory systems;
  • how method versions are controlled;
  • whether manual transcription creates data integrity risks;
  • whether LIMS, LES, ELN and CDS systems can use structured method content;
  • how future AI tools will access controlled and approved source information;
  • whether digital standards can reduce ambiguity during method execution, review and inspection.

The long-term message is important: reliable AI in QC will depend on reliable digital standards. If the source content is controlled, machine-readable and traceable, AI-supported workflows become easier to justify and govern.

Source:
https://www.pharmtec … promising-confidence

Additional source on USP MethodConnect:
https://www.labmanag … y-to-the-bench-35443

Tuesday, July 7, 2026

New open-access paper proposes an integrated validation and lifecycle framework for AI in GxP applications


Introduction AI Implementation and Validation in GxP: New Framework for GMP, Ethics and Lifecycle Governance

Image7lip.png

A new open-access review published in AI and Ethics discusses validation, ethics and lifecycle governance of AI and machine learning in GxP applications.

This is one of the most relevant recent publications for GMP and pharma quality teams because it directly addresses the gap between high-level AI principles and practical implementation in regulated environments.

The paper compares regulatory approaches from FDA, EMA and the EU AI Act, including expectations related to AI in GxP, the draft EU GMP Annex 22, FDA’s AI credibility framework, data integrity, validation, lifecycle management, human oversight and generative AI risks.

The authors propose an Integrated Validation, Ethics and Lifecycle framework, called IVEL. The framework is not presented as an official standard, but as a structured way to organize AI validation and governance activities across the lifecycle.

Why this matters for pharma and GMP:

  • AI validation cannot be treated as a one-time software test.
  • AI systems require defined intended use, risk assessment, data governance, performance qualification, lifecycle monitoring and change control.
  • Generative AI creates specific risks, including hallucination, prompt sensitivity, factual inconsistency and unclear reproducibility.
  • AI outputs used in GxP decisions must remain traceable to data, model version, system configuration and human review.
  • The paper reinforces that AI systems should be governed within the pharmaceutical quality system when they influence regulated processes.

Practical takeaway:

Pharmaceutical companies should start converting AI governance principles into practical SOPs and validation templates. For each AI use case, companies should define the context of use, risk level, data sources, model versioning approach, human review process, performance monitoring plan and requalification triggers.

This paper is especially useful for teams preparing internal AI policies, AI validation approaches, Annex 22 readiness plans or AI risk-assessment templates.

Source:
html: https://link.springe … 7/s43681-026-01218-9

pdf: https://rdcu.be/fs3qh