What is EU AI Act Annex IV technical documentation?
Annex IV of the EU AI Act (Regulation (EU) 2024/1689) sets out the technical documentation a provider of a high-risk AI system must draw up and keep current before that system is placed on the EU market, and for as long as it remains in use.
What it has to contain
Annex IV requires several categories of information: a general description of the system and its intended purpose; details of the design and development process, including the system architecture and key design choices; information on how the system is monitored, functions, and is controlled once deployed; performance metrics and validation results; risk-management measures and their outcomes; and a log of significant changes made across the system's lifecycle.
Who needs it
Providers of high-risk AI systems — those falling under Annex III's eight domains (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice/democratic processes) or embedded as a safety component in an already-regulated product. Annex IV documentation is required regardless of which conformity assessment route applies (internal control or notified-body assessment) — it's the same underlying documentation either way.
Why it's usually built manually today
Most of the underlying evidence for Annex IV already exists inside a system's own operational traces and logs — but assembling it into the structured format Annex IV requires is typically a manual, one-off project done ahead of an audit, rather than something that stays current as the system changes. That gap is what Attestly's trace-to-documentation pipeline is built to close.