SeerPharma Blog

AI Adoption: Why Risk and Control matters in GxP Industries

Written by SeerPharma | Sep 4, 2026, 1:55:59 AM

Artificial intelligence is becoming ubiquitous, with organisations using it to improve productivity, analyse information faster, support decision-making, and find new ways of working.

This is particularly relevant across pharmaceuticals, biotechnology, medical devices, and other regulated industries, where organisations are exploring how AI can improve efficiency without compromising quality, safety, or compliance.

But adopting AI is only one part of the challenge.

Unlike many traditional digital tools, AI can introduce risks that are not always obvious at the beginning of a project. These can relate to the data being used, reliability and explainability of outputs, cybersecurity, legal requirements, ethics, model performance, or simply whether the technology is being applied appropriately.

Regulators and industry bodies are also paying closer attention.

Internationally, the regulatory landscape is also evolving. In July 2025, PIC/S and the European Medicines Agency (EMA) released a draft new GMP Annex 22 – Artificial Intelligence, alongside proposed revisions to Annex 11 on Computerised Systems and Chapter 4 on Documentation. The draft Annex 22 reflects an increasingly lifecycle-based approach to AI, including considerations around intended use, model performance, change control, ongoing monitoring, and human oversight.

While Annex 22 remains draft guidance, its development is an important signal of where GMP expectations are heading: AI used in regulated environments needs to be governed, assessed and controlled throughout its lifecycle, rather than treated simply as another software implementation.
Industry guidance is evolving alongside the regulatory landscape. The ISPE GAMP® Guide: Artificial Intelligence, published in 2025, provides a holistic framework for developing and using AI-enabled computerised systems in GxP environments. It extends the risk-based principles of GAMP® into areas such as AI lifecycle management, system design, development, operation, monitoring and maintenance, with a focus on patient safety, product quality and data integrity.

In Australia, the Therapeutic Goods Administration (TGA) has clarified how AI-enabled software may fall within medical device regulation depending on its intended purpose, with manufacturers expected to demonstrate appropriate evidence of safety and performance.

For regulated organisations, these developments reinforce an important principle: AI adoption needs to be considered not only from an innovation perspective, but also from a risk, quality and governance perspective.

This is where platforms such as AIQURIS can help.

AIQURIS provides a structured way for organisations to examine an AI use case before and during deployment. It considers risks across areas including safety, security, ethics, legal requirements, performance, and sustainability, helping teams identify potential concerns and the controls needed to manage them.

Importantly, the aim is not to replace existing quality or compliance systems. Rather, AI governance should work alongside established QMS, risk management, validation and data governance processes, providing greater visibility and structure around risks that are specific to AI.

As the regulatory and industry landscape continues to evolve, organisations that build AI risk and control framework into AI adoption from the beginning will be better placed to innovate confidently while maintaining the standards expected in regulated environments.

AI innovation does not need to be slowed by such a framework. Done well, AI Risk and Control frameworks can be what enables responsible innovation at scale.

Click here to start your journey in developing an AI Risk and Control framework for your organisation, and to learn more about AIQURIS.