EU AI Act guide · updated 2 August 2026
Annex IV technical documentation: what it is and what goes in it
Annex IV is the EU AI Act’s core paperwork obligation for high-risk providers: the technical documentation that must exist before a high-risk AI system is placed on the EU market (Article 11) and stay current for ten years after. It is the document a market-surveillance authority asks for first, the backbone of the conformity assessment, and — since 2 August 2026 — an enforceable requirement backed by the €15M / 3% penalty tier.
What Annex IV must contain
1 · General description
Intended purpose, provider, version and how the system interacts with hardware or other software; forms of market placement; hardware requirements; user interface and instructions for the deployer.
2 · Detailed technical description
Development process and methods; design specifications, architecture and algorithmic logic; data requirements — training, validation and test datasets, their provenance and preparation (datasheets); human-oversight measures per Article 14; pre-determined changes; validation and testing procedures with metrics; cybersecurity measures.
3 · Monitoring, functioning and control
The system's capabilities and limitations, expected accuracy levels, foreseeable unintended outcomes and risk sources, and the input-data specifications deployers must respect.
4 · Performance metrics
The appropriateness of the chosen metrics, explained.
5 · Risk-management summary
The Article 9 risk-management system, documented.
6 · Lifecycle changes
Relevant changes made through the system's lifecycle.
7 · Standards applied
Harmonised standards applied in full or in part; where none, the solutions used to meet the requirements instead.
8 · EU declaration of conformity
A copy of the Article 47 declaration.
9 · Post-market monitoring plan
The Article 72 plan for evaluating performance after deployment.
Where drafts actually fail
- Data provenance (§2)— teams can describe the model but not the training data’s origin, licensing and preparation. Start collecting this now; it is the slowest section to reconstruct.
- Human oversight (§2)— a sentence saying “a human reviews outputs” is not an Article 14 design. Name the oversight measures, the interface affordances, the training the overseer gets.
- Known limitations (§3) — omitting foreseeable misuse and failure modes reads as either negligence or concealment. Documented limitations are a defence, not an admission.
- Version drift — documentation frozen at v1 while the system ships weekly. Annex IV must track material changes; tie it to your release process.
Generate a pre-filled Annex IV skeleton from a 10-minute assessment
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →The fast path
The efficient sequence: confirm the system is actually high-risk (many aren’t, and the Article 6(3) analysis is cheaper than the documentation), generate a structured skeleton pre-filled from a classification assessment, have engineering fill the factual sections, and spend counsel budget on review rather than drafting. Hours of structured work, not the blank-page months a consultancy quotes.
Frequently asked questions
→When must Annex IV documentation exist?
Before the high-risk system is placed on the EU market or put into service, and it must be kept up to date afterwards (Article 11). It is not a post-hoc audit artifact — a provider selling today should hold it today, and authorities can demand it at any time.
→Is there an official Annex IV template?
The Act specifies the required content, not a form. Annex IV lists the sections every technical documentation must contain; how you present them is up to you. SMEs and startups may provide the elements in a simplified form the Commission publishes, but the substance is the same.
→Who writes it — engineering or legal?
Both, unavoidably: most of Annex IV is engineering fact (architecture, data, testing, oversight design) that lawyers can't invent, structured for a legal audience. The efficient split is engineering-sourced content in a pre-structured skeleton, then counsel review — not counsel drafting from a blank page at outside rates.
→What's the penalty for not having it?
Missing or deficient technical documentation is a breach of a provider obligation — the €15M / 3% tier. It is also the fastest way to fail the conformity assessment that gates market access in the first place.
Where does your AI system actually stand?
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →Keep reading
AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.