Over the past few years, Artificial Intelligence has moved from being an emerging technology to becoming an increasingly tangible reality in the Life Sciences industry. From assistants for document generation to predictive models, decision-support systems, and tools for process optimization, use cases continue to grow and adoption now seems inevitable.
However, as the technology evolves at great speed, so do the questions we must ask ourselves as Quality, Compliance, and Validation professionals.
In this article, Anna Dachs Soler, Life Sciences Business Strategy Manager & Senior GxP Consultant, Auditor & Trainer at Ambit Iberia, shares her key reflections on how the use of Artificial Intelligence in GxP environments is evolving and the challenges it raises for the industry.
Questions we need to ask in GxP environments
Following my recent participation in the Good Manufacturing Practice Multistakeholder Workshop: Expert Contributions to Artificial Intelligence Guidance Development (Annex 22), organized by the European Medicines Agency (EMA), I would like to share some of the most relevant ideas for the evolution of GxP systems.
The aim of the workshop was not to present a new regulatory draft or communicate what companies will be required to do in the future. EMA brought together representatives from the pharmaceutical industry, AI solution providers, associations such as ISPE (International Society for Pharmaceutical Engineering), Quality experts, and regulatory authorities to hear different perspectives and better understand which aspects should be considered in the development of the future Annex 22.
It was there that the discussion focused on key questions:
-
How can we ensure that an Artificial Intelligence-based system remains reliable over time?
-
How can we demonstrate that it continues to be fit for its intended use?
-
What controls will be necessary when a model evolves?
-
How far should human oversight go?
-
How will we generate the evidence needed to demonstrate that the process remains under control?
However, the goal was not to provide answers. It was to build them together. And there was one question that remained present throughout almost every conversation, and that all companies are beginning to ask:
“What does an organization really need in order to use Artificial Intelligence in a GxP environment with confidence?”
AI does not change GxP principles; it changes how we apply them
"I thought the conversation would revolve around algorithms, foundation models, LLMs, or new Artificial Intelligence capabilities. However, the reality was very different. What appeared repeatedly throughout the workshop sessions were concepts that every GxP professional has known for years: Risk Management, Intended Use, Lifecycle Management, Change Control, Monitoring, Evidence, Human Oversight, Responsibilities, and Periodic Review. And it was then that I understood what the real paradigm shift was: Artificial Intelligence is not replacing GxP principles. It is forcing us to reinterpret them for a technology that behaves differently from traditional software."
When we talk about Artificial Intelligence, it is easy to think that we are entering completely new territory. However, many of the questions raised during the workshop have far more to do with classic Quality principles than with algorithms.
- The risk-based approach remains the central pillar.
- The definition of intended use remains critical.
- Lifecycle management retains all of its relevance.
- The need for evidence remains unquestionable.
- And controlled change remains an essential requirement.
What changes is the object to which we apply those principles.
We are no longer talking only about deterministic applications whose behavior remains stable after validation. We are now talking about models capable of working with uncertainty, evolving, adapting, or behaving probabilistically. And this forces us to rethink how we demonstrate that they remain fit for their intended use throughout their entire useful life. It does not mean abandoning GxP principles. It means adapting them to a new technological reality.
Figure 1. From traditional software to AI Governance

From validation project to continuous control
Another aspect that particularly caught my attention was seeing how the conversation is evolving from one-off validation toward the continuous generation of evidence. For years, we have become accustomed to asking questions such as:
- Is the system validated?
- Have the tests been executed?
- Has it been approved for production?
However, when we talk about Artificial Intelligence, these questions no longer seem sufficient. Other, far more relevant ones now emerge:
- How do we know the model is still performing as expected?
- How do we detect a loss of performance?
- How do we identify changes in the data or in the context of use?
- Which indicators should we monitor? When should we reassess the model?
- How do we justify that it remains fit for its intended use?
Ultimately, validation stops being an endpoint and becomes a continuous process of generating evidence. And this is probably one of the greatest differences compared with the traditional paradigm.
AI guardrails role
One of the most frequently repeated concepts during the meeting was that of guardrails (mechanisms designed to control the behavior of an AI system). However, they should not be understood as the final objective.
Guardrails are only one part of the control system. Their function is to reduce risks, detect unforeseen situations, or limit certain model behaviors. But on their own, they do not guarantee that a system is under control.
That control still depends on much broader aspects:
- proper risk assessment
- clear definition of intended use
- an appropriate monitoring strategy
- effective change management
- human oversight proportional to the level of risk
- a governance model that makes it possible to maintain trust throughout the entire lifecycle.
In other words, guardrails are a tool. They do not replace a quality system.
A shared responsibility
Another aspect I found especially enriching about the workshop was the diversity of the participant profiles. It was not only representatives from regulatory authorities or pharmaceutical companies who were present. Developers of Artificial Intelligence-based solutions also took part and shared how they are addressing these challenges from within the technology development process itself.
I believe this perspective is especially relevant because trust will not depend solely on the user implementing AI. It will also depend on the developer creating it. Developers will need to be able to demonstrate how they design, control, and monitor their solutions. Regulated organizations, for their part, will need to understand those solutions sufficiently to assess their suitability within their own GxP context.
Responsibility, therefore, is no longer concentrated in a single actor. It becomes a collaborative model in which developers, users, and regulators share a common goal: ensuring that Artificial Intelligence can be used with confidence.
Figure 2. The AI Governance ecosystem

AI Governance: much more than validating models
If I had to summarize one of the main conclusions I took away from the workshop, it would probably be this:
“Artificial Intelligence is not replacing GxP principles. It is accelerating the shift toward a more continuous management model, based on risk, evidence, and constant adaptation.”
This does not mean that concepts such as continuous monitoring, periodic review, change management, or continuous improvement are new.
All of them have been part of the lifecycle of computerized systems for years, as well as methodologies that many organizations have already begun to adopt, especially in Agile environments or under Computer Software Assurance (CSA). What changes with AI is that this approach stops being merely advisable and becomes a necessity.
Unlike traditional software, an Artificial Intelligence-based system may see its performance affected by changes in the data, in the context of use, or even in the environment in which it operates, without the application code necessarily having changed.
Therefore, trust can no longer rest solely on initial validation. It must be built and maintained through a continuous process of risk assessment, monitoring, evidence generation, human oversight, and change management.
It is precisely this evolution that, in my view, represents the true meaning of AI Governance.
Figure 3. AI accelerates the evolution of the GxP lifecycle

The ongoing management of risk, evidence, and change is not a new concept in GxP. However, the dynamic nature of Artificial Intelligence makes this approach even more relevant for maintaining a state of control throughout the entire system lifecycle.
Responding to AI through GxP principles
If I had to summarize the main lesson I am taking away from this workshop, it would be the following: Artificial Intelligence is not creating a completely new discipline for GxP professionals. It is forcing us to reinterpret many of the principles we have been applying for decades in order to respond to a technology with a different kind of behavior.
And, in a way, that is good news. Because it means we already have a very solid foundation on which to build. Risk management, lifecycle thinking, evidence generation, change control, and human oversight will remain just as important. What will change is the way we apply them.
I believe the real challenge will not be to incorporate more Artificial Intelligence. It will be to demonstrate, continuously, that we know how to use it responsibly, that we understand its limitations, and that we are capable of keeping it under control throughout its entire lifecycle. And that is probably where one of the greatest opportunities for Quality and Compliance will lie in the years ahead.
*This article gathers my main personal reflections after attending the EMA workshop on the development of the future Annex 22 for Artificial Intelligence. It is not intended to summarize the content of the presentations, but rather to share the ideas that I consider most relevant for the evolution of GxP systems.
At Ambit Iberia, we have been experts for more than 20 years in the development of IT strategies and solutions. We help the pharmaceutical, medical device, and IVD (in vitro diagnostics) sectors comply with regulation throughout the entire product lifecycle. We design and implement innovative infrastructures through a broad portfolio of services that acts as an enabler of digital transformation. If you need support, contact us.
Cuéntanos tu opinión