EU Annex 22 and GxP AI: Why Pharma Needs On Premise Models It Can Fully Control
Annex 22 asks for an AI system a regulator can inspect, and the cheapest way to give it one is to own the model.

Draft Annex 22 asks for AI in GMP that a regulator can inspect: a static model, an explanation for every output, and a validation trail that holds up. The cheapest way to give it one is to own the model. Pharma GxP AI under Annex 22 runs on premise, on your own hardware, where the validated system data never leaves the plant, the model version is frozen at a point you choose, and there is no per token cloud meter to feed as usage grows.
Why pharma GxP AI under Annex 22 belongs on premise
The pressure is regulatory, and it is close. The EU opened a consultation on draft Annex 22 to its GMP guide on 7 July 2025, and industry reporting notes the consultation closed on 7 October 2025. Commentary describes it as the first GMP guidance written specifically for AI and machine learning in critical applications, those that touch patient safety, product quality or data integrity. The draft is not final and carries no implementation date yet, but its direction is settled. Models in critical GMP use should be static and deterministic, every output should be explainable, and the whole system should be validated and monitored for drift. A model you rent in the cloud is a poor fit for that, because the vendor can retrain and ship a new version without asking you, which quietly resets your validated state. A model you own, you can freeze.
What GxP AI validation costs you today
Today the bill has two halves. The first is the cloud AI subscription itself, charged per seat and per token, on a model that was never packaged for GxP validation, so it cannot supply the evidence an inspector will want to see. The second is the external validation and computer systems validation consultants brought in to wrap process around that tool, charged by the day, and charged again every time the vendor updates the model underneath you. Add the separate governance, risk and compliance subscriptions that track the controls, and a single AI use case in a regulated plant can carry three recurring lines before it has produced one validated output.
How Nomos runs Annex 22 governance on your own hardware
Nomos is our compliance studio, a ready made application inside one system that runs a data protection impact assessment and a live crosswalk across frameworks such as GDPR, HIPAA, DORA, ITAR and PCI, produces control gap assessments, and seals a regulator ready audit trail, all fully offline. For Annex 22 it does the same job around the AI system itself. The model runs on the plant's own hardware, pinned to a version you choose. The validated system data, the batch records, the analytical results, the deviations, stays inside the building and never crosses a cloud boundary. Nothing is metered per token, because nothing leaves.
The mechanism maps directly onto what the draft asks for:
- Pin the model to a static, deterministic version and record its intended use, so the validated state does not move under you
- Keep test data independent from training data, and record how the model performs across the subgroups that matter
- Produce an explainability note for each output, showing which inputs drove the result and why they are relevant
- Hold the decision logic as versioned decision tables a reviewer can read, rather than a black box
- Monitor confidence and drift, with revalidation triggers you own rather than a vendor's release schedule
- Seal every run to the Open Audit Record, so the inspection file is assembled as work happens, not reconstructed afterwards
The evidence Annex 22 asks for, sealed as you go
This is where owning the system pays back twice. An inspector under Annex 22 will want to see intended use, validation evidence, explainability and change control, and will want them to be contemporaneous. Because every action in Nomos is sealed under post-quantum cryptography into a signed record, the Open Audit Record, the evidence is generated as the work is done, not commissioned as a report months later. The explainability note, the decision table version, the test data lineage and the drift check all sit in one trail on hardware you control. When the model is frozen and the record is sealed, revalidation becomes a scheduled event you plan, not an emergency triggered by a vendor push you did not authorise. To be precise about the boundary: the system produces evidence that supports a GxP inspection, it does not hand you a certificate, and that distinction is exactly what an inspector expects to hear.
What you replace, and what you save
| What you run today | What it costs you | With Mickai |
|---|---|---|
| Cloud GenAI subscription | Per seat and per token fees, on a model with no GxP validation package | Offline model on owned hardware, no per token meter |
| External validation and CSV consultants | Day rates to validate, and to revalidate after each vendor update | Validation and explainability evidence generated in house by the studio |
| GRC and audit tooling (OneTrust, Vanta, Drata, LogicGate) | Annual per seat subscription to track the controls | Nomos crosswalk and control gap on hardware you own |
| A vendor model that updates on its own schedule | Forced revalidation and a validated state you did not choose to lose | A pinned static version you freeze and revalidate on your plan |
| Cloud processing of validated system data | Cross border transfer risk and extra legal review | Data stays in the plant, nothing crosses a cloud boundary |
None of this rests on a headline savings figure, because the honest saving is a mechanism, not a percentage. You stop paying a per token meter on a model you do not control, you stop paying consultant days to revalidate a tool that keeps changing underneath you, and you fold the governance tracking into the same owned system. The money moves from three recurring subscriptions into one capability you keep.
Frequently asked questions
Is Annex 22 in force yet?
Not yet. The EU opened its consultation on draft Annex 22 on 7 July 2025, industry reporting puts the close at 7 October 2025, and the text remains a draft with no confirmed implementation date. The direction, however, is clear enough to prepare against now, and building on a system you own is cheaper than retro-fitting validation around a cloud tool later.
Does Annex 22 allow AI that learns on its own?
The draft direction favours static, deterministic models for critical GMP applications and restricts adaptive or probabilistic behaviour in that setting. Owning the model and pinning it to a fixed version is the simplest way to hold a static state and prove it has not moved between validations.
Can an on premise model really produce inspection ready evidence?
Yes, that is the point of running it in Nomos. The explainability note, the versioned decision tables, the test data lineage and the drift checks are all captured and sealed to the Open Audit Record as the work happens, so the inspection file is contemporaneous rather than reconstructed. The system produces evidence that supports the inspection, it does not claim a certification you have not earned.
What does Mickai actually replace here?
The cloud AI subscription, the external validation and CSV consultant days spent wrapping process around it, and the separate GRC subscription that tracks the controls. Those three recurring lines collapse into one owned system running on your own hardware, where the validated system data never leaves the plant.