Draft EU GMP update

Cybersecurity Requirements for GMP Systems (Annex 11 and New Annex 22)

Revision of Good Manufacturing Practice (GMP) Guidelines Chapter 4 (Documentation), Annex 11 (Computerised Systems), and new Annex 22 (Artificial Intelligence). This pillar page explains the draft expectations and how medicinal product and active substance manufacturers can prepare with Hunto AI.

Consultation

Closed Oct 7, 2025

Scope

EU GMP Volume 4

Focus

Docs, systems, AI

What is changing and why it matters now

The European Commission is revising the EU GMP guidance to keep pace with advanced digital systems and AI adoption in regulated manufacturing. The consultation covers Chapter 4 (Documentation), a revised Annex 11 (Computerised Systems), and a new Annex 22 for Artificial Intelligence. The draft updates elevate risk management, data integrity, and lifecycle control of computerized and AI systems.

For official sources, see the EU stakeholder consultation page, Annex 11 draft, and Annex 22 draft.

Chapter 4 Documentation: data governance becomes central

The draft Chapter 4 revision emphasizes that documentation is not a clerical step. It is a controlled system tied to data governance. Records can be text, image, video, or audio, and must remain accurate, complete, legible, and available throughout their lifecycle. This expands expectations for electronic records, e-signatures, audit trails, and hybrid documentation models.

  • Document lifecycle controls apply equally to paper, digital, and hybrid records.
  • Risk management principles are required for documentation systems.
  • Consistency with Annex 11 data integrity and system controls is expected.

Annex 11: computerized systems lifecycle and supplier oversight

The updated Annex 11 expands requirements for lifecycle management of computerized systems. Quality risk management must be applied throughout requirements, validation, operation, change control, and retirement. Suppliers and service providers are explicitly in scope, and data integrity controls are reinforced across audit trails, access management, and security.

  • Defined and maintained system requirements with traceability.
  • Validated systems with documented change control and periodic review.
  • Supplier qualification, monitoring, and contractual controls.
  • Data integrity by design, with security and auditability built in.

Annex 22: AI lifecycle controls for GMP use cases

Annex 22 introduces explicit requirements for AI and machine learning used in GMP processes. It expects clear intended use, model governance, quality of training data, validation and performance metrics, and ongoing monitoring with human oversight and change control. This affects AI used in process control, deviation detection, quality analytics, and predictive maintenance.

  • Define intended use, model boundaries, and performance metrics.
  • Training and test data must be controlled, traceable, and representative.
  • Model changes require controlled updates and impact assessment.
  • Human review is required for high-impact decisions.

Practical compliance roadmap for manufacturers

The drafts are not final, but regulators and inspectors will expect that organizations are already aligning their systems, governance, and evidence with the new direction. Use this roadmap to begin preparation.

  1. Map all GMP-relevant computerized and AI systems to product impact.
  2. Review documentation practices against data integrity and lifecycle rules.
  3. Update validation and change control procedures for AI systems.
  4. Assess supplier and cloud provider controls for Annex 11 expectations.
  5. Implement monitoring, audit trails, and role-based access controls.
  6. Prepare evidence packages and inspection-ready documentation.

How Hunto AI helps you get compliant

Hunto AI accelerates compliance readiness by mapping your systems to Annex 11 and Annex 22 requirements, generating validation evidence, and tracking readiness gaps across documentation, data integrity, and AI governance. We provide continuous control monitoring so your GMP systems stay inspection-ready as the drafts become enforceable guidance.

Coverage

Annex 11 and 22 control mapping

Evidence

Validation artifacts and audit trails

AI Governance

Model lifecycle and monitoring

Readiness

Inspection-ready evidence packs

FAQs

Are the Annex 11 and Annex 22 drafts already enforceable?

The drafts are not yet legally binding, but they signal the direction of enforcement. Regulators often expect early alignment, especially for critical systems and AI use cases that affect product quality and patient safety.

What GMP systems are typically in scope for Annex 11?

Systems that impact product quality or data integrity are in scope, including LIMS, MES, ERP integrations, electronic batch records, laboratory instruments, and any system that generates or stores GMP records.

How does Annex 22 affect AI used for analytics?

Annex 22 requires AI models to have defined intended use, validated performance, controlled training data, and continuous monitoring. Even analytics models need governance if they influence quality decisions or process controls.

What evidence will inspectors expect?

Inspectors will look for validation evidence, traceable requirements, audit trails, data integrity controls, supplier oversight records, and documented AI model lifecycle governance, including change control and performance reviews.

How can Hunto AI accelerate compliance?

Hunto AI maps GMP systems to control requirements, automates evidence collection, and provides a real-time readiness view across Annex 11 and Annex 22. This reduces manual audit prep and strengthens continuous compliance.

Is this guidance relevant outside the EU?

While the drafts are EU focused, GMP practices are globally harmonized. Many multinational manufacturers align with EU GMP to satisfy PIC/S expectations and to maintain consistent global quality systems.

Prepare your GMP systems for the Annex 11 and Annex 22 shift

Get a tailored readiness plan, validation evidence mapping, and AI governance controls aligned to the draft GMP updates.

© 2026 Hunto AI. Copyright. All Rights Reserved