top of page

Copy of: GMP seminar on computer systems and AI in Brno attracted 50 participants and sparked a lively discussion

7 hours ago
8 min read

A seminar on GMP, computer systems and artificial intelligence demonstrated that the topic of digital compliance in pharmaceutical manufacturing is no longer a niche specialism. On 17 September 2026, 50 participants gathered in Brno, where they asked specific questions throughout the programme regarding validation, data management, the risks of AI and forthcoming changes to European regulations.


The programme was led by three speakers (Marta Ugochukwu Monincová, MoCare; Pavel Říha, Orise and Richard Ficek, MoCare) specialising in GMP requirements, the validation of computerised systems and the regulated use of new digital tools. The main focus was on the revision of EU GMP Annex 11 and the topic of Annex 22, particularly in relation to the use of AI in environments where decisions regarding the quality of medicinal products are made.




The event brought together regulation, practice and manufacturing issues


The GMP seminar on computer systems and AI addressed the growing need for a better understanding of how regulated companies should prepare for changes to European requirements. The focus was on how to assess computerised systems that support manufacturing, quality control, documentation management, batch tracking and laboratory data management.

Participants did not simply come to listen to a lecture. Discussions began during the very first sessions and continued even during the breaks. The most frequently discussed topics were situations familiar to many pharmaceutical companies from their day-to-day practice:

• how to determine the scope of validation based on risk,

• how to assess changes to a system already in use,

• when it is necessary to involve the system supplier,

• how to document the use of AI tools,

• how to allocate responsibilities between IT, QA, manufacturing and the laboratory,

• how to demonstrate data integrity during automated processing.


It was precisely this practical focus that gave the seminar a clear structure. The topic of revising GMP annexes was not confined solely to regulatory requirements. The speakers repeatedly returned to explaining what must be evident in the documentation, in the change management process, during audits and in the decision-making of those responsible.


Why the revision of EU GMP Annex 11 was one of the main topics

Annex 11 is one of the key parts of the European GMP regulations for companies that use computerised systems in regulated processes. In practice, it affects validation, operation, access management, backups, audit trails, electronic records and supplier management.


The seminar therefore addressed how the requirements for computerised systems are changing as the technologies themselves evolve. Many companies now use cloud-based solutions, interconnected systems, automated data collection, electronic workflows and tools that support decision-making. All of this has a practical impact on validation and the quality of records.


Several recurring themes emerged from the discussion.


Validation cannot be a one-off document.

Participants kept returning to the question of how to maintain a validated state after the system has been deployed. It is not enough to have a signed validation report. The organisation must know how it monitors changes, incidents, configuration, user roles and regular reviews.

The risk-based approach must be specific.

Risk cannot be described in just a general statement.

For a system that affects product quality or data integrity, it must be clear which functions are critical and why. Only then does the scope of testing make sense.

The supplier does not relieve the client of responsibility.

With cloud-based and standard systems, the supplier’s documentation is often used.

Whilst this can be of significant help, it does not replace knowledge of one’s own processes. The company must know which system it is using, for what purpose, and how it verifies its suitability.



Artificial intelligence raised the most practical questions

The topic of AI sparked an exceptionally lively response during the seminar. Participants asked where standard automation ends and where a system begins that requires a different approach to risk management. Questions were also raised as to whether AI can be used for document review, classifying anomalies, data trend analysis or to support decision-making in the laboratory.

The speakers emphasised that, when it comes to AI tools, it is essential to understand their purpose. A tool that helps search through internal documents poses different risks to one that influences decisions on batch quality. There is also a difference between a system that works with public data and one that processes regulated manufacturing or laboratory data.



The most frequently raised questions concerned the following areas:

• the explainability of AI outputs,

• the quality of input data,

• the monitoring of model changes,

• the auditability of decisions,

• the protection of regulated and sensitive data,

• the role of humans in verifying results,

• documentation of the purpose of AI use.


Another important point was the scope of responsibility. When AI provides a proposal, recommendation or classification, it must be clear who checks the output and how it is used. In a GMP environment, responsibility cannot be hidden behind the technology. It must be described in the process, training and records.



Annex 22 was seen as a sign of further regulatory developments

The discussion on Annex 22 showed that regulated firms view AI not only as a technical innovation, but primarily as a topic for inspections, audits and quality management systems. Participants were interested in how new or amended requirements would tie in with the rules on system validation, data integrity and risk management.

From a practical perspective, the discussion centred on how to prepare the internal environment even before the requirements are fully incorporated into standard audit expectations. Organisations can start by mapping out where they are already using AI or advanced automation. This may involve officially implemented systems, but also tools used to support writing, searching, analysing or sorting information.


In this section, the seminar did not focus on theoretical debates about the future of AI. The key issue was how to establish controls so that the technology would be helpful without undermining the reliability of records and decisions.


Data integrity remains the common thread

Whether the discussion centred on Annex 11, Annex 22, AI or validation, the topic of data integrity kept coming up. In the pharmaceutical sector, it is not simply a question of whether data exists. What matters is whether it is complete, legible, correctly attributed, authentic and accessible for the entire required period.

In computer systems, this requires clear rules governing access, audit trails, backups, recovery, archiving and the management of electronic records. If a system allows manual intervention, editing or the addition of data, it must be clear who made the change, when, why and what the impact was.




During the practical session, participants also asked about older systems. Many companies still use equipment or software that was not designed to meet today’s expectations regarding audit trails and electronic signatures. The trainers pointed out that, even with such systems, a company must be aware of the risks and take appropriate measures. These may include technical solutions, procedural controls or a plan to replace the system.

The issue of review frequency was also important. A system that was validated years ago may not automatically correspond to its current use. The process, regulatory expectations, supplier, infrastructure or number of users may have changed. Regular reviews help to identify these changes before they become a problem during an audit.



Three speakers offered different perspectives on the same topic

A key benefit of the seminar was the combination of the three speakers’ perspectives. As a result, the individual topics were not limited to a mere explanation of the requirements. Participants also heard about the practical implications for documentation, technical system management and day-to-day decision-making within companies.

One of the key points was the relationship between QA and IT. A computer system in a GMP environment is not merely a technical tool. It is part of a process that can influence product quality. IT understands infrastructure, security and operations. QA understands regulation, documentation and the impact on quality. The process owner knows how the system is used in practice. If any part is missing, a gap arises.

The seminar therefore repeatedly demonstrated that effective management of computerised systems relies on collaboration between these roles. It is not enough for one department to prepare validation in isolation. Similarly, it is not enough for IT to operate the system without considering its GMP implications.



Questions from the audience highlighted where companies face the greatest uncertainty


The number of questions was one of the most striking features of the entire event. The questions were not general in nature. Participants often described specific types of situation – without revealing confidential information – and sought guidance on how to handle them correctly from a GMP perspective.

The greatest uncertainty arose in three areas.


How far should documentation go?

Companies want to document sufficiently, but do not want to create unnecessary red tape. It emerged from the discussion that the answer lies in the impact of the system. The higher the risk to quality, the patient or data integrity, the clearer the justification, testing and monitoring must be.



How to work with common tools

The seminar also addressed tools that are not primarily pharmaceutical in nature but are used in supporting processes. For these, it is essential to determine whether they have an impact on GMP. If so, they must be managed in a manner appropriate to their use.

How to prepare a company for AI

AI often finds its way into companies faster than internal policies can keep up. The seminar highlighted the need for a basic framework. This should specify when the use of AI is permitted, when it requires approval, what data must not be fed into the tool, and who monitors the outputs.




What the participants from Brno took away

The Brno seminar confirmed that the regulation of computer systems and AI will increasingly affect the day-to-day work of pharmaceutical companies. It is not just about new technologies. It is about the ability to demonstrate that the systems used in GMP processes are fit for purpose, managed and under control.

The main practical conclusions included several points:

  • map computer systems that have an impact on GMP,

  • identify the owner and purpose of use for each system,

  • review critical functions from a risk perspective,

  • verify that audit trails and access rights are managed,

  • check the rules for changes and reviews,

  • establish basic rules for the use of AI,

  • involve QA, IT and process owners in joint management.


The seminar also demonstrated that many issues cannot be resolved with a single, universal answer. The same type of system can have a different impact in different companies, depending on how it is used. This is precisely why a risk-based approach makes sense, provided it is specific, documented and regularly reviewed.


The next step is to translate the discussion into internal policies


The value of such events only becomes apparent once participants return to their own teams. The topics discussed in Brno can serve as a basis for an internal review of the current situation. When it comes to computer systems, it is worth starting with an overview that highlights where the greatest risks lie and which systems require more detailed attention.


When it comes to AI, it is advisable not to wait for the first audit findings. Even a simple internal rule can prevent regulated data from ending up in an unsuitable tool or AI output from being used without verification. Particularly in a GMP environment, new technology must have a clearly defined purpose, scope and accountability.

The seminar held on 17 September 2026 in Brno was therefore not merely a summary of regulatory changes. It was a practical discussion on how to manage digital systems in an environment where trust in data is directly linked to trust in the quality of medicines. The fifty participants and the lengthy discussions during the programme confirmed that the topic of computer systems and AI will remain one of the most important in the GMP sector in the years to come.


 
 
 

Comments


bottom of page