AI in GxP governance
"AI is arriving, and no one can tell me how to validate something that learns." Governance is the answer, and it has to come before the first model goes live.
Monitoring
Drift, performance and human oversight watched after go-live, because AI does not stay put.
Validation master plan
Model-specific and sized to the risk tier, not a one-size template.
Governance operating model
An AI Governance Board, a RACI, decision rights and reclassification triggers.
Four-tier risk classification
The most consequential hour in a model's life. Get the tier right and every control follows.
Reference architecture
Data, model, workflow, record and audit trail, mapped end to end.
Regulatory spine
Annex 11, the draft Annex 22, 21 CFR Part 11, FDA CSA and the FDA-EMA principles.
No GxP impact
Light-touch. Documented intended use, minimal controls.
GxP, low impact
Standard validation with documented human oversight.
GxP, high impact
Full validation, drift monitoring, human-in-the-loop.
Critical / high autonomy
Heaviest controls; adaptive models restricted under the draft Annex 22.
The problem in your words
Traditional CSV assumes four things: a fixed expected result, a system that stays put, behaviour that is independent of data, and failure that is visible. AI breaks all four. Results are probabilistic, the model can change, behaviour depends on training data, and failure is often silent. The guidance is still catching up, the Annex 22 (AI) draft is in consultation, and you are being asked to approve deployments anyway.
How I approach it
Governance precedes validation. The AI Governance Stack builds from the bottom up: the regulatory spine (Annex 11, the draft Annex 22, 21 CFR Part 11, FDA CSA, the FDA-EMA principles), then a reference architecture covering data, model, workflow, record and audit trail, then four-tier risk classification, then a governance operating model with an AI Governance Board and clear decision rights, then a model-specific validation master plan, and at the top, monitoring for drift, performance and human oversight.
The most consequential hour in an AI system's life is its classification. Get the tier right and every downstream control follows. I bring that judgment from having sat on the regulator side of the draft, and my clause-level reading of it is in What the Annex 22 (AI) draft asks of you.
Decision integrity is the new layer on top of data integrity. Classify first; monitoring is not optional, because AI does not stay put and failure can be silent.
What you get
- An AI inventory with a documented intended use and risk tier for every use case.
- A governance operating model: the board, the RACI, the decision rights, the reclassification triggers.
- A validation master plan sized to risk, and a monitoring regime that proves ongoing state of control.
- An evidence pack mapped to the draft Annex 22, ready for the inspector who has never seen your model.
Built on where the rules are going
EU GMP Annex 22 (AI) draft FDA CSA, final and updated Annex 11 21 CFR Part 11 ISPE AI Maturity Model
I build to where these rules are heading, so the governance you stand up now still holds when the drafts are finalised.
Related services
Questions leaders ask
Can AI be used in GxP-regulated processes?
Yes. Under the draft EU GMP Annex 22, static or deterministic AI models that are locked and validated are acceptable even in critical GxP applications. Adaptive and generative models are restricted to non-critical uses with documented human oversight. The work is in classification, validation to the right risk tier, and monitoring.
What is EU GMP Annex 22?
EU GMP Annex 22 is the first dedicated GMP guideline for artificial intelligence, in draft consultation during 2026. It sets expectations for validating AI in manufacturing and quality: intended use, data and model lifecycle controls, human oversight, and ongoing monitoring.
How do you validate AI in pharma quality?
Classify the use case first on impact and autonomy, then validate to that tier: training-data lineage, intended use, model-specific test evidence, human-in-the-loop review, and a monitoring plan for drift. Decision-integrity records, capturing input, output, reviewer and disposition, are what inspectors ask to see. Done this way, AI in live GxP quality has passed Health Authority inspection with zero compliance observations.
Put governance in before you scale.
Take the AI-in-GxP Readiness Index, or book a conversation.
Request a conversation Take the readiness indexWant a deeper first step? The Inspection-Readiness Review is a paid 90-minute senior session that pressure-tests your AI-in-GxP position before an inspector does.
