If your organization has already digitized its electronic batch record (eBR), or is in the process of doing so, there is a regulatory shift underway that changes the very architecture of the system. This is not a minor wording update: it is the first deep revision of EudraLex Annex 11 since 2011, and it arrives with a critical companion — an entirely new annex dedicated to artificial intelligence.
The timeline: where things stand
On July 7, 2025, the European Commission and PIC/S released coordinated drafts of Chapter 4 (Documentation), Annex 11 (Computerised Systems), and Annex 22 (AI in GxP).
The comment period closed in October 2025 and the final version is expected by mid-2026, but the draft is already the roadmap. The document has grown from 5 pages to nearly 19, reorganized into 17 chapters. For anyone operating under GAMP 5 and Part 11, waiting for the final text is an operational risk. Gaps in access control, supplier management, and audit trails don’t close with a software patch on publication day — they require design and process changes.
The end of “static validation” in Annex 11
The Annex 11 draft marks a definitive shift from point-in-time validation to lifecycle management. There are four places where an eBR typically fails today:
1. Audit trail: recording the “birth” of the data
Until now, most systems only logged the change or the deletion. The new standard requires traceability of the creation event itself. If an operator logs a temperature reading, the act of recording that data point must be audited. It’s not enough to know who changed it — you have to prove how and when the data was born.
How we solve it: the eBR systems we design audit the creation event from the first field filled on the floor, not just later edits. It’s a system architecture decision, not a module bolted on afterward to pass an inspection.
2. Validated state is not permanent
Under the 2011 framework, a well-executed IQ/OQ/PQ qualification was often enough for years. The draft breaks that: it requires evidence of a periodic, documented review of validated state. The system is no longer “validated and forgotten” — it needs a review schedule with formal reports demonstrating it remains fit for its intended use.
3. Suppliers: from commercial agreement to technical commitment
Supplier management stops being a contract appendix and becomes an explicit requirement. Written agreements on service levels are demanded, and above all, a formal assessment of supplier capability. Anyone relying blindly on a supplier’s “certification” without their own qualification dossier will be exposed at the next inspection.
4. Cybersecurity as a GMP requirement
The draft folds cybersecurity (patching, pentesting, network segmentation) into GMP compliance itself. An eBR hosted on the client’s own infrastructure, with full control over continuity and security, has a significant competitive advantage over multi-tenant SaaS solutions where the client has no real visibility into patch management.
How we solve it: we always deploy inside the client’s own infrastructure, never on multi-tenant SaaS. Your regulatory evidence never leaves your network, and the patch and segmentation gap assessment stays under your own control.
Annex 22: the hard limit on AI
Annex 22 is arguably the most disruptive document, since it’s the first GMP guidance to set limits on AI in critical processes.
The scope is surgical: it applies only to static, deterministic models — ones that don’t learn in real time and always produce the same output for the same input. That deliberately excludes generative models and LLMs from any classification or prediction application with an impact on product quality or patient safety.
The golden rule for eBR design: any AI component that sits on the critical path — deciding whether a value is in specification, approving a step, or releasing a batch — is unacceptable to the regulator.
AI has a place on the floor, but it stays outside the decision. It can help search across thousands of records or draft a justification for a deviation, but it can never fill in a field, approve a step, or decide on quality. Sign-off and release remain human and deterministic; AI is, at best, a post-facto lookup assistant.
Annex 22 · where AI can operate in an eBR
How we solve it: we design the sign-off and batch-release layer to be deterministic by definition, with no AI components on the critical path. It’s the same philosophy behind our AI systems in other sectors: AI assists, but the decision and the signature always stay on the human side.
The multi-region angle: design once, comply everywhere
A revised EU Annex 11 and Annex 22 don’t just matter to companies selling into Europe. Regulators across Latin America, the Gulf, and Asia-Pacific routinely model their own GxP frameworks — Central America’s RTCA 11.03.42:07 among them — on whichever international standard is currently strictest, usually EU GMP or the FDA. That makes the practical strategy simple regardless of where you manufacture or sell: design the system against the most demanding framework in force (today, the EU draft or FDA guidance), and map local or regional compliance downstream from it. It is never efficient to build a separate system per jurisdiction; it is efficient to build one system that clears the highest bar and document the mapping to each local regulation your batches need to satisfy.
The auditor’s checklist: is your system ready?
If your Quality or Validation team wants to get ahead of this, these are the questions they should already be able to answer:
- Data creation: does the audit trail capture the data creation event, or only modifications?
- Lifecycle: do we have a periodic review schedule for validated state, or do we rely only on initial qualification?
- Technical SLA: does the supplier agreement include technical service levels and a formal capability assessment?
- Decision sovereignty: does any AI algorithm decide the approval or rejection of a process step?
- Regional mapping: does the compliance dossier cover your local/regional framework, or only Part 11?
We’ve built a detailed checklist for each of these points, including how to evidence them to an inspector. You can request it at the end of this article.
Official references
- European Commission public consultation on EudraLex Volume 4: Chapter 4, Annex 11 and new Annex 22
- PIC/S news on the joint stakeholder consultation revising Chapter 4, Annex 11 and Annex 22
Does your validation team want to review the full checklist against the Annex 11 and Annex 22 drafts?
Request it through our contact form and our team will send it directly to your inbox.