← Glossary

What is EU AI Act Annex IV technical documentation?

Annex IV of the EU AI Act (Regulation (EU) 2024/1689) sets out the technical documentation a provider of a high-risk AI system must draw up and keep current before that system is placed on the EU market, and for as long as it remains in use.

What it has to contain

Annex IV requires several categories of information: a general description of the system and its intended purpose; details of the design and development process, including the system architecture and key design choices; information on how the system is monitored, functions, and is controlled once deployed; performance metrics and validation results; risk-management measures and their outcomes; and a log of significant changes made across the system's lifecycle.

Who needs it

Providers of high-risk AI systems — those falling under Annex III's eight domains (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice/democratic processes) or embedded as a safety component in an already-regulated product. Annex IV documentation is required regardless of which conformity assessment route applies (internal control or notified-body assessment) — it's the same underlying documentation either way.

Why it's usually built manually today

Most of the underlying evidence for Annex IV already exists inside a system's own operational traces and logs — but assembling it into the structured format Annex IV requires is typically a manual, one-off project done ahead of an audit, rather than something that stays current as the system changes. That gap is what Attestly's trace-to-documentation pipeline is built to close.

This is general educational information, not legal advice. Regulatory timelines and interpretations have changed multiple times in 2026 — verify current status before making compliance decisions.
Check your system's risk tier →See Attestly's pricing →