Resources

The Annex 11 revision explained

Written by Entelion | Aug 6, 2026, 9:00:00 AM

This article outlines the Annex 11 revision and what it means for validation teams working with computerized and AI-driven systems.

Annex 11 has not changed in a meaningful way since 2011. In that time, GxP systems moved to the cloud, validation shifted from on-premise servers to SaaS platforms nobody in the room actually controls the infrastructure for, and AI went from a research topic to something showing up inside the tools quality teams use every day. The rulebook stayed still while everything it was supposed to govern kept moving. That gap is what the current revision is trying to close.

In July 2025, the European Commission opened a public consultation on a revised Chapter 4 (Documentation), a revised Annex 11 (Computerised Systems), and — for the first time — a new Annex 22 dedicated to artificial intelligence. The three documents were developed jointly by the EMA GMP/GDP Inspectors Working Group and PIC/S, and the consultation closed on 7 October 2025. Final versions are expected in 2026, most likely with a grace period of six to twelve months before they become fully operative. Nothing here is law yet. But the draft is detailed enough, and the direction consistent enough across chapter and annex, that treating it as a preview rather than a rumor is the right call for anyone planning validation work into next year.

What's actually changing in Annex 11

The revised Annex 11 keeps its familiar chapter structure but adds substantial depth to almost every section, and a few entirely new ones. A handful of shifts matter more than the rest for how validation teams will actually work.

Quality management gets pulled further up the org chart: senior management is expected to regularly review the elements that affect whether computerised systems keep operating properly, not just sign off on deviations after the fact. Risk management is explicitly tied to ICH Q9 and threaded through IT security decisions rather than treated as a separate exercise. A new section on external IT services sets out, in detail, what oversight of outsourced and cloud providers actually has to look like — audits, contracts, documented responsibilities — which matters enormously for any team that no longer owns the servers its GxP systems run on.

Data integrity gets sharper teeth: manual data entry is flagged as a specific risk relative to electronic interfaces, and encryption expectations show up for the first time. Access control adds a requirement that will surprise some sites — shared or shareable smart cards are explicitly out, and segregation of duties between administrators and users has to be demonstrable, not assumed. Audit trails, already a familiar topic, get a much more structured set of expectations around technical configuration and, critically, timely review — an audit trail nobody looks at is treated as barely better than no audit trail at all. Periodic review becomes its own dedicated section with real substance behind it, and a new section on data archiving borrows structure from the OECD's GLP guidance to cover ground the 2011 version left largely untouched. IT security itself — firewalls, patching, disaster recovery, penetration testing for critical systems — moves from implied good practice to explicit requirement.

None of this is a rewrite of what validation is for. It is a much more prescriptive answer to a question the 2011 version left vague: what does it actually take to keep a computerised system in a validated state for as long as it's in use, not just on the day it goes live.

Annex 22: a companion for AI

The new Annex 22 is where the revision gets most interesting, and most restrictive. It draws a firm line between two kinds of AI: models that are locked after training and produce deterministic, repeatable output, and models that keep learning or generating in ways that make their output harder to pin down. Only the first kind is permitted in GMP-critical applications. Generative AI and large language models are explicitly excluded from critical decisions — they may still support non-critical work under human direction, but they don't get to touch anything that affects product quality or patient safety without a human confirming the outcome.

For the AI a site is allowed to use critically, Annex 22 asks for the same rigor validation teams already apply elsewhere, made specific to how models actually fail: a documented intended use and performance criteria, test data kept independent from training data, explainability measures so a reviewer can understand why the model produced a given output, and change control over model versions the same way a site already controls software versions. Performance monitoring in operation isn't optional — a model that was accurate at validation and has since drifted is treated as a control that has failed, not a detail to note at the next periodic review.

What this means for validation teams right now

Two things worth planning for, whether or not the final text moves before mid-2026. First, the supplier and cloud oversight expectations in Annex 11 are specific enough that a gap assessment against current vendor contracts and audit records is worth doing well before enforcement starts, not after. Second, any AI or ML tool already touching a GxP process — including tools used to support validation itself — is worth checking against the static-versus-adaptive line Annex 22 draws, because "we'll figure out the documentation later" is exactly the posture that periodic reviews and inspections are being redesigned to catch.

The throughline across both documents is the same one validation teams have been circling for a while: a system is not validated because a report says so once. It's validated for as long as there's current, reviewable evidence that it still behaves the way the report said it would — evidence someone actually looked at, on a system someone can show they're still overseeing. Annex 11's revision doesn't invent that idea. It just stops leaving it optional.