COMPLIPATHDOC complipath.io/annex-iv-technical-documentationRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
By Yobel Tzegai ·Updated 23 August 2026

Annex IV technical documentation: how to draft it and keep it defensible

Annex IV technical documentation is the file every high-risk AI system must have before it is placed on the market or put into service — Article 11(1): "drawn up before that system is placed on the market or put into service", and "kept up-to date" after. It has to contain, at a minimum, the elements of Annex IV's nine points, "as applicable to the relevant AI system", and its job is defined by its reader: to demonstrate compliance with the Chapter III, Section 2 requirements and give authorities and notified bodies what they need to assess it. Drafting it is downstream work — classification decides whether you owe it at all.

Written 12 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, in our pinned source corpus.

What must the documentation demonstrate?

Article 11(1), second subparagraph, as replaced by Regulation (EU) 2026/1744, gives the file a test, not just a table of contents: it must be drawn up "to demonstrate that the high-risk AI system complies with the requirements set out in this Section" and to provide national competent authorities and notified bodies "the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements". A folder of screenshots and design notes can name every Annex IV heading and still fail that test — the document is evidence, and evidence is judged by whether someone else can check it.

The nine points themselves cover description, development process, monitoring, metrics, risk management, changes, standards, the declaration of conformity and post-market monitoring — the point-by-point checklist walks each one, with the "as applicable" qualifier doing real work: Annex IV asks for the elements "as applicable to the relevant AI system", not for every element regardless of relevance.

When must it exist — and for how long?

Three dates bound the duty:

Can SMEs use a simplified form?

Yes — and since 2026 the door is wider. Article 11(1), second subparagraph, as replaced, provides that "SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner"; the Commission "shall establish a simplified technical documentation form" targeted at their needs; an SME or SMC that opts in must use that form; and "Notified bodies shall accept the form for the purposes of the conformity assessment." Small mid-caps — SMCs — were added by the 2026 amendment. The form itself is not in our source corpus as of 12 August 2026 — verify before relying. Until it exists, there is nothing to opt into, and the full Annex IV structure is what a small provider works to.

How does the documentation workspace draft it?

The Complipath documentation workspace holds four sections per system — Overview, Data description, Risks & mitigations, and Human oversight & monitoring. The documentation workspace asks for point 1 of Annex IV, point 2(d), and the risk management system under Article 9 that point 5 requires. It does not ask for point 3 or point 4, and it covers one lettered item of point 2. Annex IV asks for more than this workspace covers today. The base fields are filled from the register: the intended purpose, the classification, the answers and the reasoning behind it, so the documentation and the classification cannot drift apart silently. An AI drafting assistant writes the first draft of each section from that record — from what you already answered, not from a template. It drafts; it does not decide, and it does not confirm: a section stays a draft until a named person on your team confirms it.

Nothing publishes itself: a section stays a draft until a named person on your team confirms it, section by section, because the confirmation is what turns a draft into your evidence. The export is a PDF per system — the file you keep at the disposal of authorities for the ten years Article 18(1) requires — and the whole register travels with you as a CSV, each system with its risk level and citation. What the workspace does not do is decide anything: the four risk outcomes are decided first, and the inventory is where each system's record lives.

Run the classification — real engine output

The block below is not a mock-up. It is rendered from a real run of the Complipath engine, fetched from the live API at every build — the same payload, character for character, that the published example assessment shows in full, with the engine version and the parts the run left undetermined printed rather than trimmed.

Engine output — fetched from the live API at this build, never written by hand
Kestrel Applicant Ranking (test)highengine 2026-08-17.2
point 4(a) of Annex III
What drove it
point 4(a) of Annex III — You answered that the system is used for the recruitment or selection of people — in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.
Article 6(3) — Article 6(3) lets a provider conclude that a system referred to in Annex III is not high-risk. That conclusion is the provider's and is documented against the system — Complipath does not reach it from your answers.
Article 25(1)(b) — Fine-tuning a third-party model can make you a provider under Article 25(1)(b).
What was answered
type: "fine_tuned_third_party" · art5_review: ["none_of_these"] · art50_content: [] · law_functions: [] · art50_exposure: "neither" · emotion_context: null · annex_categories: ["employment"] · automated_action: false · credit_functions: [] · human_can_overrule: false · affects_individuals: true · biometric_functions: [] · sensitive_inference: null · art5_sexual_material: null · employment_functions: ["recruitment_selection"] · scraped_face_database: null · safety_component_endangers: null · criminal_risk_solely_profiling: null · realtime_public_law_enforcement: null
Left undetermined — printed, not trimmed
· Annex I product-legislation routes not assessed in this run
Corpus: Classification derived from Regulation (EU) 2024/1689, Regulation (EU) 2026/1744. Provisions in that corpus that this assessment does not detect: Article 6(1) — Annex I high-risk (applies from 2 August 2028).

The engine is deterministic: fixed rules over your confirmed answers, every verdict traceable to the article it rests on — and where it stops is published, not discovered: what this check can and cannot decide lists both sides, written once by a person, never generated per visitor.

Which of yours need one, and from when?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

What is Annex IV technical documentation? The file Article 11(1) requires for every high-risk AI system: drawn up before the system is placed on the market or put into service, kept up to date, and containing at a minimum the elements of Annex IV's nine points, "as applicable to the relevant AI system". Its purpose is to let authorities and notified bodies assess compliance.

When does the technical documentation duty apply? Article 11 sits in Chapter III, Section 2: it applies from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744). For each system, the file must exist before market placement or putting into service.

Is there a simplified version for small companies? Article 11(1), as replaced in 2026, lets SMEs, start-ups and SMCs provide the Annex IV elements in a simplified manner, on a Commission form that notified bodies must accept. The form is not in our source corpus as of 12 August 2026 — verify before relying; until it exists, the full Annex IV structure is what a small provider works to.

How long must the documentation be kept? Ten years after the high-risk AI system is placed on the market or put into service, at the disposal of national competent authorities (Article 18(1)) — together with the quality-management documentation and the EU declaration of conformity. Keeping it current during the system's life is Article 11(1)'s own "kept up-to date" duty.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 11 and 18, Annex IV, and Article 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — the corpus this page's every quotation is verified against on every build. Product claims are read from the product copy; the engine output on this page is fetched from the live API at build time, its provenance and holds printed by the build, never assumed.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.