traqxGxP Compliance Software
EU AI Act

EU AI Act × GxP: what the AI Act means for regulated pharma quality

Reading time ~8 min · Daniel Herrmann · Updated

The EU AI Act (Regulation (EU) 2024/1689) is the EU's horizontal AI law. It does not replace GxP — it lays a second, parallel layer over AI systems, including those used in regulated pharma work. The good news: the governance principles overlap strongly (human oversight, traceability, data governance, logging). Whether a specific AI application falls under particular AI Act obligations is a legal question — this article frames the interface and shows sensible preparation; it makes no classification.

EU AI ACT × GxP GxPQuality + records EU AI ACTRole + AI governance SHARED CONTROL POINTHuman decisionSCOPE · EVIDENCE · OWNER
Two rulebooks, one way of working. Where they meet — and what you can do before the legal picture is final.

What the EU AI Act is — and what it is not

The EU AI Act (Regulation (EU) 2024/1689) is the EU's first comprehensive, horizontal AI regulation. Horizontal means it applies across industries to AI systems — not to pharma specifically, but to AI as a technology. It entered into force in 2024 and applies on a staggered timeline.

Digital Omnibus status: 19 July 2026. The European Parliament adopted its first-reading position on 16 June; the Council approved that position on 29 June, and the legislative act was signed on 8 July. The adopted text provides for the high-risk rules to apply from 2 December 2027 to stand-alone high-risk AI systems and from 2 August 2028 to high-risk AI systems embedded in products. On 19 July, EUR-Lex still listed the procedure as ongoing; publication in the Official Journal of the EU was still pending. The legislative act is to enter into force on the third day following that publication. These dates do not classify any specific GxP use.

The Act takes a risk-based approach and broadly distinguishes four tiers — from prohibited practices, through strictly regulated applications and transparency obligations, to largely unregulated uses. It addresses different roles, in particular providers (who develop / place an AI system on the market) and deployers (who put it to use).

An important point first, to avoid misunderstanding: the AI Act is not a GxP rulebook and replaces neither GMP, nor EU Annex 11, nor 21 CFR Part 11. It sits alongside your existing quality and validation obligations. For regulated teams this is not a replacement, but a second perspective on the same AI tools.

Why the AI law concerns GxP teams at all

AI is entering regulated work — from document drafting through review support to data analysis. As soon as an AI system is used, it can in principle fall within the scope of the AI Act — in addition to the GxP requirements that already apply to the regulated activity.

The result is a double lens on the same tool: the GxP world asks “Is the work valid, traceable and released?” The AI Act asks “Is the AI system appropriately controlled, transparent and supervised?” Both questions aim at control and demonstrability — only from a different angle.

In practice this means: anyone using AI in GxP should not dismiss the AI Act perspective as a foreign topic, but consider it as a second governance layer — early, not only once an auditor or authority asks about it.

The good news: the governance principles overlap strongly

The reassuring insight for quality and validation teams: the core principles of both rulebooks run largely in parallel. Take GxP governance seriously and you have already built in much of the AI Act posture. The recurring themes:

  • Human oversight. The AI Act stresses human control over AI outputs; GxP work requires professional review and, depending on the process, formal approval. The same idea: the AI proposes, the human decides.
  • Transparency & traceability. Both want to know how a result came about — sources, basis, traceability instead of a black box.
  • Data governance. Quality, origin and suitability of the data used is a topic in both worlds.
  • Logging & records. The AI Act thinks in logs and demonstrability; GxP in audit trail and records. Structurally the same need.
  • Risk management & accountability. Both require a deliberate look at risk and clear ownership of who is responsible for what.

In other words: a robust GxP way of working — sources first, AI as a suggestion, human review, a connected audit trail — feeds directly into the AI Act's governance expectations too. That is not a coincidence, but the same control logic in two rulebooks.

Take GxP governance seriously and you have already built in much of the AI Act posture.

Where the frameworks differ — and why you should not classify finally yourself

As large as the overlap is in principle, the rulebooks are not congruent:

  • Own scope and own definitions. The AI Act has its own terms (e.g. “AI system”, provider vs. deployer) and its own scope, which cannot be derived 1:1 from the GxP world.
  • Own risk taxonomy. The AI Act's risk tiers follow a different logic than GxP risk assessment (patient safety / product quality). A GxP classification is not an AI Act classification.
  • Role-dependent obligations. Whether you count as a provider or a deployer changes the obligations considerably — and depends on how you concretely use or provide an AI system.
  • Staggered, still maturing application. Parts of the Act apply only over time; accompanying guidelines and harmonized standards keep evolving.

This is exactly why the classification of a specific system is a legal question, not a marketing or gut-feel decision. The serious approach is to understand the interface, make the preparation that is sensible anyway — and settle the classification with qualified legal advice.

Orientation, not legal advice

Whether a specific AI application falls under particular AI Act obligations, and which risk tier it belongs to, is a legal assessment of your individual case. This article makes no classification — engage qualified legal advice for the classification.

What you can practically do now — without waiting for the final legal picture

The good message: the most effective preparation is classification-independent. It is good GxP practice and at the same time AI-Act-compatible — you can start it before the legal picture is settled:

  • Keep an AI inventory. Where is AI actually used in regulated work today — and for what purpose? No overview, no control.
  • Secure human review. For every GxP-relevant AI output, professional review remains mandatory; named approval follows where the process requires it. AI prepares, AI does not approve.
  • Carry the source binding and audit trail. Every relevant statement stays connected to its source and version; who decided what on which basis stays traceable.
  • Document data governance. Which data may the AI use, where does it come from, what is excluded?
  • Name responsibilities. Who is accountable for use, monitoring and stopping an AI tool?

None of these points weaken your GxP compliance — they reinforce it and at the same time create the substance an eventual AI Act assessment can build on. This is exactly the way of working traqx reflects: AI drafts, your team reviews and decides, sources/versions/audit trail stay connected — Ground. Generate. Verify. Human Review. That is a control architecture, not a compliance promise.

The honest limits

Finally, the necessary sobriety:

  • This is not legal advice. The contextualization does not replace an assessment of your specific scope by qualified legal counsel.
  • No risk classification. This article classifies neither traqx nor your applications into an AI Act risk tier — that is deliberately reserved for legal assessment.
  • The framework keeps maturing. Application, guidelines and harmonized standards are evolving; statements made today are a snapshot.
  • GxP remains in force. The AI Act complements, but does not replace, GMP, Annex 11 or Part 11. Both layers apply side by side.

What this article does not do

No legal advice, no classification of your systems, no guarantee of AI Act or GxP conformity. The AI Act applies on a staggered timeline and its guidelines keep maturing; your obligations depend on role and individual case. GxP remains fully in force regardless.

Frequently asked questions

Does the EU AI Act replace GxP rules like GMP, Annex 11 or 21 CFR Part 11?

No. GMP, Annex 11 and 21 CFR Part 11 remain fully in force. The EU AI Act (Regulation (EU) 2024/1689) is a horizontal AI law and, where it applies to the specific AI use, lays a second layer over your existing quality and validation obligations. It sits alongside the GxP requirements; it does not replace them.

Does the EU AI Act affect AI software in pharma quality?

Yes, it can apply as soon as an AI system is used in regulated work — for example in document drafting or review support. The AI Act is horizontal and applies across industries to AI as a technology, in addition to the GxP requirements that already apply to the regulated activity. Whether a specific application falls under particular obligations depends on the individual case.

Is an AI system used in GxP work high-risk under the EU AI Act?

This is a legal question and depends on your individual case. The AI Act uses its own risk taxonomy of broadly four tiers, which follows a different logic than GxP risk assessment; a GxP classification does not carry over to the AI Act. Your role as provider or deployer also affects the obligations. This article makes no classification; engage qualified legal advice for it.

What can GxP teams prepare now for the EU AI Act?

The most effective preparation is classification-independent and at the same time good GxP practice, so you can start before the legal picture is settled. Keep an AI inventory, secure professional human review for every GxP-relevant AI output and named approval where the process requires it, carry source binding and audit trail, document your data governance, and name clear responsibilities. These points strengthen your GxP compliance and create the substance an eventual AI Act assessment can build on.

Key takeaways

  • The EU AI Act is a horizontal, parallel AI layer — not a GxP replacement. GMP, Annex 11 and Part 11 remain fully in force.
  • The governance principles overlap strongly: human oversight, transparency/traceability, data governance, logging, risk management.
  • Classifying a specific AI system is a legal question — own scope, own risk taxonomy, role-dependent obligations. Engage qualified legal advice for it.
  • The most effective preparation is classification-independent: AI inventory, human review, process-specific approval, source binding + audit trail, data governance, clear responsibilities.
  • A robust GxP way of working (sources first, AI as a suggestion, human decides) feeds directly into AI Act governance — without any conformity promise.

Sources

Author

Daniel Herrmann

Daniel Herrmann is Co-Founder and CEO of traqx and has worked for years at the intersection of GxP validation, quality assurance and AI-supported tools for regulated teams. This article summarizes publicly accessible regulation (EU AI Act, EMA reflection paper, EU Annex 11/22) in his own contextualization. It is orientation, not legal or compliance advice, makes no risk classification and does not replace an assessment for your specific scope. Where traqx is mentioned, the text describes the provable way of working — sources first, AI as a suggestion, the human decides, the audit trail remains — and no effect promise beyond that.