EU AI Act guide · updated 2 August 2026

Annex IV technical documentation: what it is and what goes in it

Annex IV is the EU AI Act’s core paperwork obligation for high-risk providers: the technical documentation that must exist before a high-risk AI system is placed on the EU market (Article 11) and stay current for ten years after. It is the document a market-surveillance authority asks for first, the backbone of the conformity assessment, and — since 2 August 2026 — an enforceable requirement backed by the €15M / 3% penalty tier.

Think of Annex IV as the system’s defence file: if a regulator, customer or court asks “show me this system is what you say it is,” Annex IV is the answer. If it doesn’t exist, no amount of good engineering substitutes for it.

What Annex IV must contain

1 · General description

Intended purpose, provider, version and how the system interacts with hardware or other software; forms of market placement; hardware requirements; user interface and instructions for the deployer.

2 · Detailed technical description

Development process and methods; design specifications, architecture and algorithmic logic; data requirements — training, validation and test datasets, their provenance and preparation (datasheets); human-oversight measures per Article 14; pre-determined changes; validation and testing procedures with metrics; cybersecurity measures.

3 · Monitoring, functioning and control

The system's capabilities and limitations, expected accuracy levels, foreseeable unintended outcomes and risk sources, and the input-data specifications deployers must respect.

4 · Performance metrics

The appropriateness of the chosen metrics, explained.

5 · Risk-management summary

The Article 9 risk-management system, documented.

6 · Lifecycle changes

Relevant changes made through the system's lifecycle.

7 · Standards applied

Harmonised standards applied in full or in part; where none, the solutions used to meet the requirements instead.

8 · EU declaration of conformity

A copy of the Article 47 declaration.

9 · Post-market monitoring plan

The Article 72 plan for evaluating performance after deployment.

Where drafts actually fail

  • Data provenance (§2)— teams can describe the model but not the training data’s origin, licensing and preparation. Start collecting this now; it is the slowest section to reconstruct.
  • Human oversight (§2)— a sentence saying “a human reviews outputs” is not an Article 14 design. Name the oversight measures, the interface affordances, the training the overseer gets.
  • Known limitations (§3) — omitting foreseeable misuse and failure modes reads as either negligence or concealment. Documented limitations are a defence, not an admission.
  • Version drift — documentation frozen at v1 while the system ships weekly. Annex IV must track material changes; tie it to your release process.

Generate a pre-filled Annex IV skeleton from a 10-minute assessment

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

The fast path

The efficient sequence: confirm the system is actually high-risk (many aren’t, and the Article 6(3) analysis is cheaper than the documentation), generate a structured skeleton pre-filled from a classification assessment, have engineering fill the factual sections, and spend counsel budget on review rather than drafting. Hours of structured work, not the blank-page months a consultancy quotes.

Frequently asked questions

When must Annex IV documentation exist?

Before the high-risk system is placed on the EU market or put into service, and it must be kept up to date afterwards (Article 11). It is not a post-hoc audit artifact — a provider selling today should hold it today, and authorities can demand it at any time.

Is there an official Annex IV template?

The Act specifies the required content, not a form. Annex IV lists the sections every technical documentation must contain; how you present them is up to you. SMEs and startups may provide the elements in a simplified form the Commission publishes, but the substance is the same.

Who writes it — engineering or legal?

Both, unavoidably: most of Annex IV is engineering fact (architecture, data, testing, oversight design) that lawyers can't invent, structured for a legal audience. The efficient split is engineering-sourced content in a pre-structured skeleton, then counsel review — not counsel drafting from a blank page at outside rates.

What's the penalty for not having it?

Missing or deficient technical documentation is a breach of a provider obligation — the €15M / 3% tier. It is also the fastest way to fail the conformity assessment that gates market access in the first place.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.