The One Signature AI Is Not Allowed To Give
Brussels has drafted the first Good Manufacturing Practice rules written specifically about AI. They turn on one person’s signature, and the software being bought this year will still be running when they land.
Somewhere in every European medicines factory there is a person who can stop your product reaching a patient, and you cannot overrule them. Brussels has now drafted rules for what happens when a machine tries to help them decide.
The role is called the Qualified Person (the named individual who carries personal legal responsibility for certifying each batch before it reaches a patient). Nothing in any North American cannabis market prepares an operator for it.
No batch of a finished medicinal product reaches a patient in the European Union until a Qualified Person certifies it. Their name is listed on the manufacturing authorisation. Their qualifications are set in law. The responsibility is personal rather than corporate, which means that when something goes wrong it is that individual who answers for it, not a department. Their independence from the company is the entire point of the job. A QP who refuses to release a batch has refused, and the board cannot vote on it.
For the bulk of German medical cannabis flower the same function operates one step earlier. The flower is usually treated as a starting material that pharmacies later prepare as magistral preparations. Importers and manufacturers hold manufacturing authorisations and must name a Sachkundige Person under the German Medicines Act, the person who performs the Qualified Person function. That person certifies the batch for release into the distribution chain before the material reaches the pharmacy. The personal liability and independence of the role remain the same.
Operators arriving from Colorado or Ontario tend to hear this and reach for the nearest equivalent, usually a compliance manager. It is not the same. A compliance manager reports to operations. A Qualified Person is a check on operations, and the law built them that way deliberately.
Understand that one role and most of the rest of European pharmaceutical regulation stops looking arbitrary. Every record, every audit trail, every locked-down system exists to give one person enough evidence to sign their name.
Software that starts making those decisions raises an obvious problem.
What a QP is actually signing
Not that the product is good. That the product was made and tested the way it was supposed to be, and that this can be demonstrated.
The distinction matters more than it sounds. A batch can be perfectly clean and still fail release, because the evidence of how it was made is incomplete. The pharmaceutical world uses the data-integrity convention known as ALCOA: records must be attributable to a person, legible, contemporaneous, original and accurate.
Contemporaneous is the one that catches people. Batch records written up on Friday covering a week of work fail, however accurate they are. A system that lets a supervisor quietly correct an entry fails too, because the original is gone.
Cannabis track-and-trace systems answer a question about custody. Where is this material now, where has it been. They answer it well, and it is not the question a QP is asking. A QP needs proof of history, including the history of every correction.


Now put AI in the room
On 7 July 2025 the European Commission opened a consultation on three linked documents: a rewritten Chapter 4 on documentation, a rewritten Annex 11 on computerised systems, and a new Annex 22 on artificial intelligence. All three were drafted by the European Medicines Agency’s inspectors working group with PIC/S (the Pharmaceutical Inspection Co-operation Scheme, the international network of GMP inspectorates). The consultation closed on 7 October 2025 and drew about 1,300 comments according to secondary reports of the process.
Annex 22 is the first text in Good Manufacturing Practice written specifically about AI, and its central rule is sharper than most people expect.
Where an AI model sits in a critical application (one with direct impact on product quality, patient safety or data integrity), the draft permits only static models. A static model is locked after training and returns the same output for the same input, every time. Models that keep learning in production are excluded from critical applications. So are generative models and large language models.
They may support non-critical work, with human oversight. They may not sit inside a critical decision.
| What the model does | Where the draft puts it |
|---|---|
| Locked model, same input gives same output, validated for a defined purpose | Permitted in critical applications |
| Model that retrains on new production data | Not permitted in critical applications |
| Generative model or large language model | Not permitted in critical applications |
| Any of the above supporting non-critical work | Permitted with human oversight |
The reasoning follows directly from the QP. A person carrying personal liability has to be able to say why a decision was made. A model that produces a different answer this month than last month, for reasons nobody can reconstruct, cannot give them that. Neither can a model that produces plausible language rather than a traceable result.
This is not hostility to AI. It is a requirement that the machine be explainable to the human who has to answer for it.
Frozen does not mean finished
The obvious objection is that no business can accept software that never gets better. Pharma has been answering that objection for decades, and the answer is not that the model never improves. It is that the model never improves quietly.
The version running in production is locked. The next version is not. You keep collecting data, you train a better model away from the production line, and when it is ready you put it through the same process any change to a validated system goes through.
The steps are the same ones a factory already uses to approve a new piece of equipment or a new test method:
- Write down what better means, before you start. What the new version has to achieve, measured how, and what result counts as a pass.
- Train and test it offline, against those criteria, on data that represents what the model will actually meet.
- Put it through change control. A formal review asks what has changed, what the risk is, and how much retesting the change demands.
- Validate it to the extent that review requires.
- Approve and release it as a new version, with a record of why the change was made and how it was checked.
- Keep the old versions on file, so anyone can establish which version produced any given output on any given day.

The draft requires that the model, its surrounding system and the process it supports go under change control before deployment, so that any later change, whether retraining, a parameter tweak or a new server, triggers a formal decision about retesting before it goes live.
Think of it as product versions rather than a product that learns. Version one runs the line. Version two is being built, tested and approved in the background. When version two is signed off, it replaces version one and the batch records show exactly when that happened.
There is a second requirement that answers the other half of the objection. A frozen model gets worse over time if the world it sees stops resembling the world it was trained on. So the draft asks for measurements that detect when production data is drifting away from the training data. When it drifts far enough, you retrain, revalidate, or stop using the model.
Drift monitoring is what tells you it is time for the next version. The system still learns from experience. A person decides when that learning goes live.

The collision nobody in cannabis has named
Yield prediction models improve by retraining on every harvest. That is the selling point. Vendors describe it as the system learning your facility. Under the draft annex, a model that retrains in production is a dynamic model, and if its output feeds a decision with quality impact it does not belong in that decision.
The same applies to environmental control systems that adapt, to anomaly detection that tunes itself, and to anything marketed on the promise that it gets smarter the longer you run it.
None of this makes those products unusable. It draws a line through the middle of them, and the line falls exactly where the vendor’s marketing is strongest.
The rule is not settled, and the industry is pushing back
None of this is final, and the part being argued over hardest is the ban itself.
The draft sorts every AI use into one of two boxes: critical or not critical. ISPE, the main international body for pharmaceutical engineering, published its response and said two boxes are too few. Risk runs on a scale, not a switch, and a rule that treats it as a switch will block safe uses and wave through risky ones.
Its second point matters more for anyone selling AI. ISPE argued that smarter models should be allowed in critical work where a company can show, with evidence, that the risk is managed. The reason the draft bans them is that the old ways of measuring whether a model is reliable do not fit models that generate language. ISPE’s answer is that newer measurements do fit, and the rule should require good measurement rather than ban the technology.
Reported summaries of the consultation say this was the point most of the feedback converged on, across ISPE, the Parenteral Drug Association (PDA), the European Federation of Pharmaceutical Industries and Associations (EFPIA) and individual manufacturers.

The regulators appear to be listening. When EMA held its workshop on 30 June and 1 July 2026, one question on the table was whether adaptive and generative models could be allowed in GMP work under risk-based safeguards. That is an open question rather than a decided change, but a ban being reconsidered twelve months after it was drafted is a ban worth watching rather than planning around.
Nothing here is in force. As of mid-July 2026 the official EudraLex page (the collection of EU pharmaceutical legislation and guidance) still listed Annex 11 in its 2011 revision and no final Annex 22 had been published. EMA’s inspectors working group has targeted the final quarter of 2026 for delivering text to the Commission, which is a target rather than a publication date, and no implementation period has been announced.

Where the line falls in your building
One more distinction is worth getting straight.
Growing the plant runs under Good Agricultural and Collection Practice. Everything after harvest runs under Good Manufacturing Practice: drying, trimming, milling, blending, testing, packaging, release. People arriving from adult-use markets picture that boundary as a door the product passes through once. It runs through the middle of the building, and the documentation expectations on either side of it have almost nothing in common.
The AI question sits mostly on the GMP side, which is also the side where the QP is standing.
Five questions for anyone selling you AI for an EU facility
- Is the model static or does it retrain in production?
- If it retrains, what triggers it, and is there a record of every version that has ever produced an output?
- Given the same inputs, does the model return the same answer today as it did six months ago? Can you show that?
- Does any output from this system feed a decision with quality, safety or data integrity impact?
- What can you give a Qualified Person that lets them explain this system’s output to an inspector?
Question five is the one that separates vendors who have read Annex 22 from vendors who have heard of it.
The reason to care now is that software bought this year will still be running when it lands.

This article reports the regulatory framework as it stood in mid-2026. Annex 22 remains a draft. It is not legal or regulatory advice.
Sources
EMA multistakeholder workshop on Annex 22, 30 June–1 July 2026: https://www.ema.europa.eu/en/events/good-manufacturing-practice-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22
EudraLex Volume 4: https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
Stakeholders’ Consultation on Chapter 4, Annex 11 and new Annex 22: https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
German Medicines Act (Arzneimittelgesetz – AMG) §§ 14–15 (Sachkundige Person / Qualified Person): https://www.gesetze-im-internet.de/amg_1976/
Directive 2001/83/EC, Articles 48 and 51 (Qualified Person requirements)

