What should the Qualified Person (QP) know about Artificial Intelligence (AI)?
The increasing use of artificial intelligence in the GMP sector raises fundamental questions regarding the activities and responsibilities of the Qualified Person (QP). During the pre-conference session as part of the Qualified Person Forum 2025, these aspects were addressed from technical, practical and legal perspectives. In addition, participants were surveyed on the topic of artificial intelligence; the results of this survey are presented in the following section.
Survey results
The survey of 61 participants in the roles of Qualified Person, Quality Assurance/Quality Control and Compliance, Pharmacovigilance and Responsible Person yielded the following results:
- 30% are considering the use of AI in their own company, 10% are in the project planning phase, 25% are in an ongoing implementation phase, and 35% already have AI in use.
- With regard to establishing a company-wide AI strategy, 60% stated that this had already been done. 20% do not yet have an AI strategy, whilst for a further 20% this topic was new.
- 2% are very familiar with the EU AI Regulation1, 10% have read parts of it, 70% have heard of it and 20% were unaware of it.
- 21% have already read the draft of EU GMP Annex 22 - AI (in conjunction with EU GMP Annex 11) in part, 60% have heard of it and 20% were unaware of it.
- 12% use AI operationally in GMP processes, approx. 30% plan to use AI, and 58% use AI outside GMP-relevant processes.
- Microsoft Copilot is currently the most widely used AI tool, followed by ChatGPT/GPT models (internal or external) and DeepL (for translations).
- AI applications are used, amongst other things, in visual inspection systems, internal ChatGPT clones, document comparison tools, LIMS-related AI functions, RCA automation (root cause analysis for deviations), as well as QMS document search and automated data analysis.
Conclusion: Companies are at different stages of development and implementation in the field of AI. Despite limited regulatory knowledge to date and low levels of operational use of AI in the GMP sector, there is high demand.

Recommendation
Copenhagen, Denmark25 August 2026
Raw Data - Understanding, Defining and Managing
Markus Roemer: AI Projects, Validation and Implementation
In the context of current AI applications, a distinction is made between discriminative (classifying) and generative (content-generating) systems (see EU Annex 113). In addition, there are various deployment models. AI can analyse data, generate content or prepare decisions, thereby directly influencing GMP-relevant processes.
Whilst traditional software or source code ('if-then-else') operates deterministically, AI generalises from data sources - with consequences for validation, reproducibility and data integrity. Traditional software is based on defined validation concepts and procedural control. In contrast, AI governance requires ongoing validation, monitoring of performance and data drift, formal explainability and structured human oversight to address new risks and uncertainties. An effective governance framework combines both approaches to address the challenges posed by deterministic software and AI systems.
The relevant regulatory frameworks are the EU AI Regulation1, the EU Machinery Regulation and the draft versions (2025) of EU GMP Annex 11 and Annex 222, although the currently valid version of Annex 113 must be applied. The provisions of the EU AI Regulation can be systematically mapped to the requirements of EU GMP Annex 113.
The classification of AI as a machine-based system that transforms inputs into outputs links the EU AI Regulation to the Machinery Regulation (EU) 2023/1230, including CE marking requirements for high-risk systems. The draft of EU GMP Annex 222 is regarded as critical, as there has so far been a lack of alignment with the AI Regulation and the planned Annex 112, technological openness is limited, and ambiguities in the content are apparent.
Beyond the regulatory framework, the organisational implementation of AI, the harmonisation of ISO/IEC 420014 (AI Quality System) with the existing PQS and QMS structure, and the further development of validation methodology towards 'digital validation' are required. As AI projects are to be classified as innovation projects, additional procedural challenges arise. For the successful deployment of AI, an AI-capable organisation, project methodology, data management and appropriate validation concepts are of central importance.
Cheryl Chia: A QP's Perspective
For the use of AI in GMP organisations, robust 'master data governance', clean and consistent data, and clearly defined datasets suitable for AI models are essential. At the process level, it must be precisely defined which steps are to be performed by AI and how human oversight is to be structured. This includes mechanisms for detecting erroneous AI results, as well as structured methods for investigating the causes of such errors. In addition, the established regulatory requirements for the validation of computerised systems apply.

Recommendation
Copenhagen, Denmark26-28 August 2026
Data Integrity Master Class
Key issues concern the impact of AI on product quality, patient safety and the safety of supply, as well as its influence on batch release and the evidence of system reliability. QPs must understand how well the underlying process was already controlled prior to the introduction of AI and what changes the tool brings about. A key distinction is that between static and dynamic systems: whilst static systems remain stable after validation, learning models continue to evolve - raising questions regarding continuous monitoring, revalidation and ensuring the original intended purpose. Finally, it must be clearly defined how the performance of the AI tool is monitored during operation and which criteria determine when a tool is still considered reliable. A key challenge is that the Qualified Person must understand, comprehend and master the AI.
Monika Hupfauf: The Legal Framework for AI in the GMP Context
The EU AI Regulation1 establishes, for the first time, a comprehensive European regulatory framework for artificial intelligence. It adopts a strictly risk-based approach with four risk levels. Of particular relevance to the pharmaceutical industry are the 'high risk' and 'limited risk' categories, as a wide range of AI applications in GMP processes - such as in quality assurance, data analysis or decision support - are potentially classified as high risk. The AI Regulation sets out comprehensive obligations for providers and users, including risk assessments, robust datasets, documentation, traceability, human oversight and continuous monitoring; at the same time, certain AI practices are completely prohibited.
Another key issue is the lack of harmonisation between the EU AI Regulation1 and the drafts of EU GMP Annex 11 and Annex 222. Different terminology, divergent risk definitions and unclear interfaces complicate practical implementation. Whilst the Regulation constitutes a horizontal, cross-technology regulatory framework, EU GMP Annexes 11 and 22 function as sector-specific GMP regulations. Without clear coordination, there is a risk of duplicate requirements, conflicting interpretations and uncertainties during inspections. Particularly problematic with regard to Annex 22 appears to be (i) the failure to adopt key terminology (e.g. from the AI Regulation) whilst simultaneously introducing new definitions, (ii) the restriction to static, deterministic AI models that produce consistent output, and (iii) the explicit exclusion of dynamic/adaptive AI models, probabilistic AI models and generative AI models & LLMs in critical GMP applications. These significant uncertainties and restrictions in the (draft) Annex 22 considerably limit the potential applications of AI models in real-world GMP contexts.
The draft of Annex 22 is currently under review and is therefore not yet a reliable guideline.
Conclusion
Given the rapid evolution of artificial intelligence and the still limited practical experience, there remains a significant need for clarification, which calls for ongoing professional dialogue. The implementation of AI systems requires the coordinated involvement of all stakeholders, taking into account their concerns, qualifications and expertise. Ultimately, it seems advisable to base AI implementation on a comprehensive and considered approach, so that the best possible outcome can be achieved within the GMP environment and not only patients and companies, but also quality decision-makers such as the Qualified Person, can benefit from AI technology without risk.
| The topic of Artificial Intelligence will also be on the agenda at |
About the Authors
Markus Roemer is Managing Director of comes compliance services and Consultant, Auditor and Trainer.
Dr Monika Hupfauf from Koch/Hupfauf Attorneys is Lawyer specialising in the development of medicinal products and medical devices through to market launch.
References
1 EU KI Regulation: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024; Internet: https://eur-lex.europa.eu/eli/reg/2024/1689/oj?eliuri=eli%3Areg%3A2024%3A1689%3Aoj&locale=en
2 EU GMP Annex 11 and Annex 22 - Draft Version - 7 July 2025; Stakeholders' Consultation on EudraLex Volume 4 - Good Manufacturing Practice Guidelines: Chapter 4, Annex 11 and New Annex 22; Internet: https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
3 EudraLex - Volume 4 - Good Manufacturing Practice (GMP) guidelines (currently valid); among others Annex 11, Annex 16, Annex 1 PQS; Internet: https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
4 ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system; 2023; Internet: https://www.iso.org/standard/42001
