---
title: "AI in GMP Is Not Banned. Here Is What Regulators Actually Expect."
description: "AI is not prohibited in GMP environments. Learn how intended use, risk, human oversight and existing quality controls determine compliant AI use."
url: https://qbdgroup.com/en/blog/ai-in-gmp-regulatory-expectations
type: "Blog post"
language: en
published: 2026-10-01
author: "Elias Muys & Jan Appelmans"
category: "Software Solutions & Services"
publisher: "QbD Group"
citation: "QbD Group, \"AI in GMP Is Not Banned. Here Is What Regulators Actually Expect.\", https://qbdgroup.com/en/blog/ai-in-gmp-regulatory-expectations"
---
# AI in GMP Is Not Banned. Here Is What Regulators Actually Expect.
> AI is not prohibited in GMP environments. Learn how intended use, risk, human oversight and existing quality controls determine compliant AI use.

**Many GMP teams still treat AI as a grey zone.**

Some wait for Annex 22 before doing anything. Others let employees experiment quietly.

**Both approaches carry risk.**

The regulatory message is clearer than many teams assume. Current GMP regulations do not prohibit the use of generative AI. However, its use must be evaluated within existing quality and risk management frameworks.

The responsibility for decisions and GMP-relevant content remains with qualified personnel, regardless of how that content was generated.

Expectations around data integrity, security, confidentiality and documented controls continue to apply.

In other words, the question is not simply whether AI is allowed in a GMP environment.

It is whether a specific use of AI can be appropriately controlled.

**In This Blog Post**

- Why AI itself is not the determining factor for GMP risk
- Why intended use matters more than the technology
- What "human in the loop" should mean in a GMP environment
- How existing QMS processes can govern AI-generated content
- Why organisations do not need to wait for AI-specific guidance to start building appropriate controls

## AI Risk in GMP Depends on the Intended Use

The same AI model can carry a completely different risk profile depending on what it is used for.

Using an AI tool to summarise supplier emails is one thing.

Using it to classify the severity of a deviation that drives a CAPA is another.

The technology may be identical.

**The GMP impact is not.**

That is why the question is no longer:

"Can we use AI?"

It is:

**"Which AI, for which purpose, under which controls?"**

That shift matters.

Instead of trying to classify AI as inherently compliant or non-compliant, organisations should assess the **intended use** and **associated risk** of each application.

The greater the potential impact on product quality, patient safety, data integrity or GMP decision-making, the stronger the controls and oversight need to be. This risk-based distinction is at the heart of the author's argument.

## Human in the Loop Means Expert in the Loop

AI cannot be held accountable.

If something goes wrong, a person answers for it, not a model.

Even agents checking other agents only move the human further along the process. **They never remove them.**

The real test is therefore not simply whether a human appears somewhere in the workflow.

It is whether a **subject matter expert with the right knowledge and authority** reviews the output before it is used for a GMP-relevant purpose.

That distinction is important.

A human clicking "approve" does not automatically constitute meaningful human oversight.

The reviewer needs to be capable of understanding the output, identifying potential errors and taking responsibility for the resulting decision.

## What Does AI Use in GMP Look Like in Practice?

Consider a straightforward example.

An LLM is used to draft a Standard Operating Procedure (SOP).

The subject matter expert responsible for the SOP reviews the draft, corrects it where necessary and ensures that the content accurately reflects the intended process.

The document then follows the organisation's normal QMS review and approval route.

The use of AI has changed **how the first draft was produced**.

It has not changed who is accountable for the document or how that document becomes approved GMP content.

**Oversight has not changed.**

Depending on the intended use and the outcome of the risk assessment, the introduction of AI may therefore not necessarily introduce a significant new GMP risk.

## You Do Not Need to Wait for AI-Specific GMP Rules

The temptation to wait for AI-specific regulatory guidance is understandable.

But organisations already have many of the principles they need.

The same risk-based, lifecycle thinking applied to computerised systems provides a useful starting point:

1. **Define the intended use.** Be clear about what the AI system will and will not be used for.
2. **Assess the risk.** Consider the potential impact on product quality, patient safety, data integrity and GMP decisions.
3. **Define appropriate controls.** Determine what validation, documentation, access controls and human oversight are proportionate to that risk.
4. **Keep qualified people accountable.** AI can support GMP activities, but responsibility for GMP-relevant decisions remains with the appropriate personnel.
5. **Apply lifecycle thinking.** Reassess the system and its controls when the model, intended use or underlying process changes.

And then, as the original contribution puts it:

**Use common sense.**

## From AI Uncertainty to Controlled Use

AI does not require GMP organisations to abandon the quality principles they already know.

Quite the opposite.

Intended use, risk assessment, documented controls, qualified oversight and lifecycle management already provide a framework for deciding where AI can be used responsibly.

The challenge is therefore not to decide whether your organisation is "for" or "against" AI.

**It is to understand where AI is being used, what risk each use creates and whether the controls are proportionate to that risk.**

Waiting indefinitely carries its own risk.

So does allowing uncontrolled experimentation.

The more practical path lies between the two: **controlled, risk-based adoption within the quality framework you already have.**

## Build a Risk-Based Approach to AI in GMP

QbD Group helps life sciences organisations translate emerging technologies into practical, compliant quality systems.

From AI governance and computerised system validation to data integrity, quality risk management and GMP processes, our experts can help you assess where AI fits within your organisation and establish controls proportionate to its intended use and risk.

**Exploring AI in a GMP-regulated environment? [Get in touch with our experts](/en/contact) to build a practical, risk-based approach that supports innovation without losing control.**
---
Source: https://qbdgroup.com/en/blog/ai-in-gmp-regulatory-expectations — © QbD Group. Quote freely with attribution and a link back.