The AI Act is unusually concrete about paperwork. For each governance artifact, there is an article that names it and a reader who will one day ask for it — a market-surveillance authority, a notified body, or an enterprise customer’s security team. This is the inventory we build from:
Art. 9Risk-management system
A documented, continuously maintained process for identifying, estimating and mitigating the risks your system poses across its lifecycle — including reasonably foreseeable misuse. Not a one-off assessment: the Act requires it to be iterated and updated.
Art. 10Data-governance documentation
For systems trained on data: how training, validation and testing datasets were chosen, their relevance and representativeness, and the measures taken to detect and mitigate bias.
Art. 11 · Annex IVTechnical documentation
The core dossier: system description, intended purpose, architecture, capabilities and limitations, performance metrics, and the records demonstrating conformity — drawn up before market placement and kept current.
Art. 12Logging and record-keeping
Automatic event logging across the system’s lifetime, designed in, so that operation can be reconstructed after the fact.
Art. 13Instructions for use
The transparency package for your deployers: what the system does, what it must not be used for, its accuracy limits and its human-oversight measures — so the people operating it can actually comply.
Art. 14Human-oversight design
Documented measures that let humans understand, monitor, intervene in and override the system — who reviews what, when, and with what authority. Written to the standard high-risk systems require.
Art. 15Accuracy, robustness and cybersecurity
The declared performance levels and the measures maintaining them, including resilience against attempts to manipulate the system.
Art. 17Quality-management system
The umbrella: the documented processes that hold all of the above together, from design controls to post-market monitoring and serious-incident reporting.
LIVE NOWArt. 50Article 50 transparency notices
The user-facing layer that just became mandatory: interaction disclosures (“you are talking to an AI”), machine-readable marking of AI-generated content, deepfake and public-interest-text labels, and the deployer notices for emotion recognition and biometric categorisation. The Commission’s Guidelines on Article 50 and the Code of Practice on Transparency of AI-Generated Content — confirmed adequate by the Commission and the AI Board — define what good looks like; we draft to that standard.
LIVE NOWArt. 53GPAI model documentation
For teams building or fine-tuning models: the model documentation for the AI Office and downstream providers, the copyright policy, and the public training-content summary using the Commission’s template — with the GPAI Code of Practice as the recognised compliance route.
Arts. 26–27Deployer-side governance
If you deploy high-risk AI rather than build it: use per instructions, assigned and trained human oversight, log retention, worker notification — and, for public-sector and certain private deployers, the fundamental-rights impact assessment.
LIVE NOWArt. 4AI-literacy measures
Already in force, and almost universally forgotten: documented measures ensuring your staff have the AI literacy their roles require.
Not every company needs every artifact — the set depends on your role (provider, deployer, GPAI provider, or several at once) and your system’s risk class. The first thing we do is establish which of these documents your product actually owes, and to whom.