← Back to all posts

EU AI Act 2026: What Pharma QA Teams Do Now That Enforcement Has Started

The EU AI Act's main compliance date — 2 August 2026 — has now passed. For pharma QA Directors, Validation Managers, and CSV Specialists, that changes the question. It is no longer "should we prepare for this." It is "our AI governance is now measured against a law that is in force, not a deadline on a calendar." If your organisation is using AI for SOP search, deviation support, validation document review, training, or quality decision support, the obligations that apply to your use case are live today.

For DACH pharma companies, the practical challenge has not changed: AI governance cannot sit separately from quality governance. If an AI tool touches regulated records, influences GMP decisions, or supports users operating under SOPs and quality systems, the compliance model must align with existing validation and data integrity expectations. That is still where AI projects fail most often — treating AI governance as an IT policy issue rather than a quality system issue.

The safest approach for QA teams is to assume that any AI supporting GxP work must be governed to a standard that is auditable, risk-based, and fully documented — and to be able to show that governance today, not describe a plan for it.

What's actually enforceable as of today

Most AI systems used in pharma compliance work — document-drafting copilots, SOP search assistants, deviation and CAPA support tools — are not classified as "high-risk" under Annex III of the Act. They don't fall into the eight enumerated categories (biometric ID, critical infrastructure, employment access, essential services, law enforcement, migration, justice/democratic processes), and they aren't safety components of a regulated medical device. That means the Act's heaviest machinery — formal risk-management documentation, third-party conformity assessment, CE marking, EU database registration — does not apply to most GxP AI copilots as a mandatory baseline.

What does apply regardless of risk tier, effective now:

  • Article 50(1) transparency. Unless it's obvious from context, users interacting with an AI system must be told so. A persistent, explicit disclosure in the tool's interface is the safe reading — not just marketing copy elsewhere on the site.
  • GPAI-deployer due diligence. If your AI tool is built on a general-purpose model (Claude, GPT, Gemini, etc.), you are a deployer of that model and are expected to retain the provider's documentation — model card, known limitations, the pinned model version and why.

Even where a use case is not formally high-risk, the Act still raises the bar on transparency, provider documentation, user oversight, data governance, and post-market monitoring — and under GMP, "the AI gave inaccurate guidance with no traceability" was already a problem before the Act existed. The Act adds scrutiny; it doesn't invent the underlying risk.

Why "we're not high-risk" isn't the end of the conversation

Some pharma QA teams are more conservative than the strict legal text, and reasonably so — a regulator or auditor may ask you to justify your classification, not just assert it. That means two things are worth having ready even for a minimal-risk tool:

  • A written classification rationale. Why your use case doesn't fall into Annex III, walked through category by category, not just claimed.
  • An honest self-assessment against the higher bar anyway. Record-keeping and human-oversight controls (Articles 12 and 14) are usually where a well-built GxP AI tool is already strong — audit trails and draft-labeling are standard practice. Risk management, data governance, and technical documentation (Articles 9-11) are more often partial: the underlying behavior exists, but it isn't written up in the shape an AI Act auditor expects yet.

We publish our own working version of this exercise for ComplianceGxP — classification, role table, what we've built, and an honest gap list against the higher bar — at our EU AI Act position page. It is not legal advice, and it should not be the last word for your own tool. But it's a usable template for the shape a QA team's own classification memo should take.

Where AI Act expectations meet Annex 11 and Part 11

The Act does not replace existing pharmaceutical compliance requirements — it sits alongside them. Teams still need a harmonised control framework across EU GMP Annex 11 (computerised systems), 21 CFR Part 11 (electronic records and signatures), GAMP5 Second Edition (risk-based lifecycle control), ICH Q7/Q10 (pharmaceutical quality systems), and ALCOA+ data integrity principles. Building AI governance separately from these frameworks still produces duplicate documentation, inconsistent ownership, and gaps at inspection.

Consider the same recurring use case: an AI assistant answers a QA specialist's question about deviation handling, grounded in internal SOPs. If that answer feeds a GMP workflow, an inspector will ask the questions they always ask, now with an AI Act lens layered on:

  • What approved content is the answer based on, and can the user verify the cited source?
  • How are document updates reflected, and who approved the intended use?
  • What prevents unsupported or fabricated guidance, and what happens when the system can't answer reliably?
  • How are incidents, changes, and periodic reviews documented — and is the fact that this is an AI system disclosed to the person using it?

These sit directly at the intersection of Annex 11's risk-management and accuracy-check clauses, Part 11's trustworthy-electronic-systems expectations, GAMP5 lifecycle thinking, and the Act's Article 50 transparency requirement.

Practical implications for DACH manufacturers and CDMOs

DACH organisations often carry mature SOP landscapes, multilingual documentation, and complex supplier networks — which sharpens three specific risks now that enforcement is live:

  • Language consistency. If German SOPs, English validation templates, and corporate policies coexist, the AI must retrieve from the correct controlled versions and avoid mixing superseded content.
  • Client segregation in CDMOs. Multi-tenant environments require strict logical separation of data, permissions, and retrieval scope — an assistant that leaks one client's procedures into another client's answer is unacceptable under GMP and now under AI Act data-governance expectations too.
  • Hybrid IT/OT environments. Where AI interacts with MES, historian, SCADA, or batch documentation contexts, intended use and system boundaries must be tightly defined. Even "read-only" assistance influences operator behaviour and requires control.

What to check this quarter, now that enforcement has started

If your organisation did the "assess and prepare" work before August, this quarter is about verifying it holds up in practice. If it didn't happen yet, the work is the same — it's just no longer ahead of a deadline, it's remediation against a standard already in force.

  • Confirm your AI system inventory is current. Include vendor tools, embedded AI features in existing platforms (QMS, MES, office suites), and internal prototypes — these are the ones most often missed.
  • Check every AI surface has an explicit user-facing disclosure. Not "it's obvious from the branding" — a persistent, written statement in the interface itself.
  • Verify supplier qualification documentation actually covers AI. Model hosting, training-data boundaries, retention, access controls, change notification, performance monitoring.
  • Re-read your risk assessment against real usage, not the projected usage from when it was written. Has scope crept into decision-support territory that the original classification didn't anticipate?
  • Confirm human-oversight rules are enforced, not just documented. Can the AI actually not approve records or replace QA review, or is that only true in the SOP?
  • Check that change control has actually fired for any model updates, retrieval-logic changes, or prompt configuration updates since your last review.

The organisations in the best position now are not the ones who moved fastest before August. They're the ones who built AI governance into the existing pharmaceutical quality system, so "the deadline passed" didn't require a scramble — it just meant the same controls kept running.

The goal was never to prohibit AI. It's to run it in a way that preserves traceability, human oversight, document control, and inspection readiness — a standard that doesn't change whether the calendar says July or September.

See how ComplianceGxP handles this in practice: See how it works → · read our own EU AI Act position.

Running compliance on manual search? See how ComplianceGxP handles this.

See How It Works