If you operate in multiple regulatory jurisdictions — and most life sciences companies do — you need to understand what each regulator expects from AI in GxP environments. The problem is that nobody has published a clean side-by-side comparison. FDA, EMA, and MHRA each approach AI through different regulatory instruments, at different levels of specificity, with different emphases. This article maps what each authority has actually published, where they converge, and where your compliance strategy must address genuine differences.
FDA: risk-based assurance through existing frameworks
The FDA has not published a dedicated GxP AI regulation. Instead, it extends existing frameworks:
- Computer Software Assurance (CSA) draft guidance (2023). Replaces CSV for software validation. Core principle: assurance effort proportional to risk. For AI systems, this means high-risk AI (batch release, process control) gets deep validation while low-risk AI (document formatting, scheduling) gets proportionally lighter assurance. CSA's emphasis on critical thinking over scripted testing is particularly relevant for non-deterministic AI systems.
- AI/ML SaMD framework. For AI used in medical devices, FDA has published the AI/ML Software as a Medical Device Action Plan, the Predetermined Change Control Plan (PCCP) framework, and draft guidance on marketing submission recommendations. PCCP is notable: it allows manufacturers to pre-define the types of model changes that are permissible without new regulatory submission — a practical accommodation for models that learn continuously.
- GMLP principles. FDA, Health Canada, and MHRA jointly published Good Machine Learning Practice principles: data quality, model transparency, clinical evaluation, performance monitoring. These are principles, not binding requirements — but they signal the direction of future regulation.
- 21 CFR Part 11. Electronic records and signatures requirements apply to AI-generated content that becomes part of regulated records. No AI-specific modifications — the same Part 11 requirements apply. 21 CFR Part 11 in GxP Copilot ensures Part 11 compliance for AI-generated and human-reviewed documents.
FDA's emphasis: Risk-proportionate assurance, continuous performance monitoring, clinical evidence of effectiveness, and human oversight of AI decisions.
EMA / EU GMP: Annex 22 and explicit AI requirements
The EMA's approach is more prescriptive than the FDA's, primarily through EU GMP Annex 22:
- EU GMP Annex 22 (effective August 2025). Explicitly addresses AI and machine learning in GMP environments. Requires six specific assurance elements: (1) Published AI governance policy, (2) Documented safeguards, (3) Human-in-the-loop policy, (4) Fallback mechanism when AI fails, (5) Evaluation framework for AI model performance, (6) Performance monitoring plan. These are not recommendations — they are inspectable requirements. Annex 11 / 22 in GxP Copilot implements all six.
- EU GMP Annex 11. Computerised systems requirements — applies to AI systems as it does to any computerised system. Covers: validation, data integrity, access control, audit trail, change control, business continuity.
- EU AI Act. Not GxP-specific, but relevant: AI systems used in medical devices or healthcare are likely to be classified as high-risk under the AI Act, triggering additional requirements for risk management, transparency, human oversight, and conformity assessment.
- EMA reflection paper on AI. Published guidance on the use of AI in the medicinal product lifecycle — covering drug discovery, clinical trials, manufacturing, and pharmacovigilance. Emphasises: data quality, model validation, explainability, and human oversight.
EMA's emphasis: Explicit, prescriptive requirements (especially Annex 22), AI governance as a mandatory framework, and the intersection of AI Act obligations with GMP requirements.
MHRA: aligned with EU principles, emphasis on post-market
Post-Brexit, MHRA has charted a partially independent path:
- AI as a Medical Device (AIaMD) roadmap. MHRA has published a phased roadmap for regulating AI in medical devices, with planned legislation covering pre-market assessment, post-market surveillance, and change management for learning systems.
- GMLP participation. MHRA co-authored the GMLP principles with FDA and Health Canada. MHRA treats these as the foundation for future regulatory requirements.
- Software and AI as a Medical Device guidance. MHRA has published guidance on how existing medical device regulations apply to AI, including requirements for clinical evidence, ongoing performance monitoring, and manufacturer responsibilities for model updates.
- GMP alignment. For manufacturing AI, MHRA currently follows EU GMP Annex 11 and has signalled alignment with Annex 22 principles — but has not formally adopted Annex 22. MHRA inspectors are expected to assess AI systems against Annex 22-equivalent criteria.
MHRA's emphasis: Post-market surveillance, continuous performance monitoring, and manufacturer accountability for model behaviour over the product lifecycle.
Where the three converge
- Risk-based approach. All three authorities expect assurance effort proportional to the risk the AI system poses. High-risk AI (patient safety, product quality) requires deeper validation, more human oversight, and more intensive monitoring than low-risk AI.
- Human oversight. All three require documented human decision authority over critical AI outputs. The operator, not the AI, is responsible for regulated decisions.
- Continuous monitoring. All three expect ongoing performance monitoring for deployed AI systems, not just point-in-time validation. Drift detection and periodic re-qualification are emerging as universal expectations.
- Data quality. All three hold AI training and operational data to existing data integrity standards (ALCOA+ or equivalent). Data provenance, quality, and integrity are foundational requirements.
- Audit trail. All three require audit trails for AI systems that feed regulated records. The audit trail must capture inputs, outputs, model versions, and human review decisions.
Where they differ — and what to do about it
The key differences and how to handle them for a global compliance programme:
- Annex 22 specificity. EMA requires explicit Annex 22 artefacts; FDA and MHRA do not (yet). Strategy: build Annex 22 artefacts for all AI systems regardless of jurisdiction. They are good practice and will satisfy all three authorities. Annex 22 assurance in GxP Copilot generates these artefacts by default.
- AI Act obligations. The EU AI Act adds requirements beyond GMP. For AI systems classified as high-risk under the AI Act, additional conformity assessment, transparency, and risk management obligations apply. Strategy: assess your AI use cases against AI Act risk categories and build the additional documentation where required. This is an EU-only obligation for now.
- PCCP framework. FDA's Predetermined Change Control Plan is unique to the US regulatory context. It allows pre-approved model changes — a practical advantage for continuously learning systems. Strategy: use PCCP where applicable for FDA-regulated AI, but maintain full change control for EMA/MHRA jurisdictions where equivalent frameworks do not yet exist.
Building a single compliance architecture for all three
The practical approach is to build to the most stringent standard (currently EMA with Annex 22 and the AI Act) and demonstrate compliance with all three from a single evidence base. GxP Copilot is designed for this: Annex 22 assurance artefacts satisfy EMA requirements and exceed FDA and MHRA expectations; Part 11 compliance satisfies FDA and aligns with Annex 11; and continuous monitoring with documented performance evidence satisfies all three authorities' post-market expectations. book a demo to discuss your specific multi-jurisdiction AI compliance needs.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
