EU Annex 11 Revision: What Labs Need to Prepare (2026)

EU Annex 11

The draft revision published on 7 July 2025 is the most significant rewrite of Annex 11 since 2011 — expanding the guideline from 5 pages to 19, restructured into 17 chapters, and elevating computerised systems from supporting tools to GMP-controlled assets in their own right. For laboratories, four changes matter most: audit trails must now capture data creation, not only changes and deletions; audit trail review moves to a defined risk-based frequency; supplier and service management carries mandatory contract elements; and cybersecurity becomes a core GMP requirement with its own extensive chapter. A companion Annex 22 restricts AI in GMP-critical applications to static, deterministic models — explicitly excluding generative AI and large language models. The final text has not yet been published as of August 2026, and estimates for its arrival diverge. The gap assessment, however, should not wait.


Where the revision actually stands

Accuracy about status matters here, because a lot of published commentary states timelines with more confidence than the evidence supports.

What is certain: On 7 July 2025, the European Commission published draft revisions to three interconnected parts of EudraLex Volume 4 — a comprehensive revision of Annex 11 (Computerised Systems), a brand-new Annex 22 (Artificial Intelligence), and an updated Chapter 4 (Documentation). The revision was drafted jointly with PIC/S. The public consultation closed on 7 October 2025.

What is not certain: the publication date of the final text. Multiple sources published through mid-2026 anticipated the final version “mid-2026.” As of early August 2026 it has not appeared. One tracker notes that because the draft was released in July 2025 rather than the December 2024 originally scheduled in the EMA concept paper, implementation is now estimated for Q1 2027 — while also stating plainly that no renewed timetable has been published by EMA.

The honest position is therefore: the final text is imminent but undated, and any article asserting a firm effective date is guessing. Since these are drafts, specific provisions may change before adoption — so treat the details below as the direction of travel rather than settled law, and verify against the final text when it lands. Anyone with EU market exposure should check the European Commission’s EudraLex Volume 4 pages directly for current status.

That uncertainty is not a reason to wait. The consultation is closed, the direction is clear, and the remediation work most labs will need — audit trail reconfiguration, supplier contract renegotiation, security evidence — takes longer than the notice period will allow.

Why the rewrite happened

The current Annex 11 took effect on 30 June 2011, when it was itself a response to growing reliance on computerised systems. Fourteen years later, technological innovation has far outpaced those expectations. Cloud services, SaaS deployment models, machine learning, and a threat landscape that barely existed in 2011 all sat outside the guideline’s frame.

The result is not a patch but a paradigm shift toward comprehensive digital governance, now explicitly covering all computerised systems including cloud services and AI/ML systems, with enhanced cybersecurity requirements. The draft is roughly four times the length of the version it replaces, organized into 17 chapters plus a glossary, built on eight overarching principles.

The scope is broad and worth stating plainly for lab readers: any software touching a GMP, GDP or GLP process falls within it — ERP, LIMS, MES, batch release systems, temperature monitoring platforms. If your LIMS influences a batch outcome, a release decision, or a GMP record, Annex 11 applies to it.

The changes that matter most for laboratories

1. Audit trails: creation events now in scope

This is the change with the most immediate practical consequence for lab systems. Under the draft, audit trails must capture data creation events, not only changes and deletions. The draft devotes ten subsections to audit trails — a signal of how central they have become.

Many LIMS and instrument systems were configured on the older assumption that logging modifications and deletions was sufficient. If yours was, this is a configuration gap that will need identifying, remediating, and revalidating. It is also, in our experience of what labs actually overlook, the single most likely place to find a gap.

The draft also formalizes audit trail review frequency on a risk basis rather than leaving it to interpretation — reporting on the draft indicates monthly review for high-risk systems, quarterly for routine ones, and always before a batch release decision that the data supports. Labs that have treated audit trail review as an annual or ad-hoc exercise should expect to build a documented, recurring process.

Our guides to ALCOA+ data integrity and 21 CFR Part 11 cover the underlying principles that both frameworks share.

2. Risk management across the full lifecycle

Risk management remains the central pillar, but the emphasis shifts from broad guidance to a systemic, continuous approach across the entire system lifecycle. The draft acknowledges that risks are dynamic and requires proactive, documented, continuous assessment: at selection and design, through ongoing monitoring during operation, and in a final review when the system is taken out of use.

That last point deserves attention because it is easy to miss — decommissioning is now part of the regulated lifecycle. Labs planning to replace a legacy system should build risk review into that project explicitly; our guide to migrating from one LIMS to another covers the surrounding data and retention obligations.

3. Supplier and service management with mandatory contract terms

The draft introduces supplier and service management with nine mandatory contract elements. For laboratories running cloud or SaaS LIMS, this converts a commercial relationship into a documented compliance dependency.

Practically, this means existing vendor agreements may need renegotiation, and vendor selection criteria should now include the supplier’s ability to evidence the controls the annex requires. Expect this to be one of the slowest remediation items, because it depends on a third party’s willingness and timeline, not only your own.

4. Cybersecurity as a core GMP requirement

For the first time, cybersecurity is treated as a core GMP requirement rather than an IT concern adjacent to compliance. The draft’s security chapter runs to roughly 20 subsections, covering patch management, penetration testing, firewalls and USB controls, with explicit expectations for regular penetration testing and timely patching.

For most laboratories, the gap here is not the absence of security measures but the absence of evidence — documented, inspectable proof that patching is timely, that penetration testing occurs on a schedule, and that access controls are managed. Reporting on gap assessments consistently finds shortfalls in audit trail review, supplier contracts, access management, and IT security evidence.

5. Alarms, periodic reviews, and electronic signatures

The draft expands or newly addresses system alarms, mandates periodic validation reviews rather than treating validation as a one-time event, tightens electronic signature controls, and integrates the annex with ICH Q10 pharmaceutical quality system expectations. Labs that validated a system once at go-live and have not formally reviewed it since should treat periodic review as a new recurring obligation. See our LIMS validation guide for what that entails.

Annex 22: the AI restriction labs should read carefully

The new Annex 22 is short but consequential, and its central provision is a genuine constraint rather than guidance.

For GMP-critical applications, AI is limited to static, deterministic models. Dynamic models, generative AI, and large language models are excluded from critical use.

Given how aggressively laboratory software vendors now market AI capabilities, this deserves direct attention. A vendor’s AI feature may be genuinely useful for non-critical work — searching notebooks, drafting documentation, summarizing — while being unusable for any function that influences product quality or a release decision. When evaluating platforms, ask specifically which AI features touch GMP-critical paths and how the vendor demonstrates determinism. Our guides to best LIMS for pharmaceutical QC and the wider vendor landscape cover platforms serving regulated environments.

Chapter 4: what now counts as a GMP record

The revised Chapter 4 travels with Annex 11 and matters for labs because it redefines what counts as a GMP record, explicitly including images, video and audio alongside text. All documentation, in whatever form, must remain complete and readable throughout its lifecycle, with risk-management principles integrated into data governance to ensure accuracy, integrity, availability and legibility across paper, digital and hybrid formats.

For laboratories, the practical implication is that instrument screenshots, microscopy images, and recorded observations may fall within formal record-keeping obligations that were previously ambiguous.

What to do now: a practical preparation sequence

The consistent advice across regulatory consultancies is that preparation should begin against the draft rather than waiting for the final text, because the remediation work is substantial and the notice period will be short.

Circulate the draft documents internally to IT, quality, validation and manufacturing leadership. Annex 11 compliance is not a quality-department project; the security and supplier requirements sit squarely with IT and procurement.

Run a coordinated gap analysis across your computerised systems. Start where gaps are most likely: audit trail scope and review practice, supplier contracts, access management, and IT security evidence.

Prioritize by gap size and criticality. Identify which systems and processes carry the largest gaps, and estimate the resources and budget remediation will require. Systems that influence batch release decisions come first.

Engage your vendors early. Ask specifically what their roadmap is for supporting the new requirements — particularly audit trail creation-event capture, and their willingness to accept the contract elements the annex will require. Vendor timelines are outside your control, which is precisely why they should be started first.

Sequence quick wins alongside foundations. Focus on changes implementable quickly while building the foundational elements that more complex changes depend on — a pattern that keeps momentum without stalling on the hardest items.

Update data governance frameworks to address the Chapter 4 requirements on record types and lifecycle legibility.

A note for non-EU labs: the reach extends beyond EU borders through three channels — direct requirements for anyone supplying EU markets, the PIC/S channel as participating authorities progressively adopt parallel text into their own inspection practice, and the supply chain channel, where EU importers and Qualified Persons push new expectations down to suppliers through quality agreements, often before any regulator does.

The honest bottom line

The revised Annex 11 transforms computerised systems from supporting tools into critical GMP-controlled assets, and that reframing is the point. It requires real investment in technology, processes and personnel — and the organizations that begin preparation before the final text lands will align their compliance programs on their own timeline rather than a regulatory one.

For laboratories specifically, the shortest path to readiness runs through four questions. Does your LIMS log data creation, not just modification? Do you review audit trails on a documented, risk-based schedule? Can your cloud vendor evidence the controls the annex will require, and will they contract to them? Can you produce inspectable proof of patching, penetration testing and access management?

Most labs will answer “not yet” to at least two. That is not a crisis — it is a work plan, and the fact that the final text has not yet published means there is still time to work it.

Where to go next

For the regulatory foundations, see our explainers on 21 CFR Part 11, ALCOA+ data integrity, and LIMS validation. Labs selecting or replacing a system in this environment should read our LIMS for pharmaceutical QC guide and our how to choose a LIMS checklist, with the migration guide covering decommissioning obligations.


This guide describes draft regulatory texts published 7 July 2025 and open for consultation until 7 October 2025. Provisions may change before adoption, and the final text had not been published as of early August 2026. Nothing here constitutes regulatory advice; verify all requirements against the final published text and your own regulatory context. LabSoftwareGuide is an independent editorial resource.

Sources

Share the Post:

Related Posts