COMPLIPATHDOC complipath.io/guides/ai-act-technical-documentationRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Requirements ·By Yobel Tzegai ·Updated 22 August 2026

What goes into EU AI Act technical documentation? The Annex IV checklist

Updated 9 August 2026 for Regulation (EU) 2026/1744.

Under Article 11(1), the technical documentation of a high-risk AI system "shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date". Annex IV sets the minimum content: nine points, from general description to post-market monitoring plan.

Quick answer

What does Article 11 actually require?

Three things. First, timing: the documentation "shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date" (Article 11(1)). It cannot be assembled retroactively, and a version written once and frozen breaches the second half of the sentence.

Second, a quality standard. The documentation must be drawn up "to demonstrate that the high-risk AI system complies with the requirements set out in this Section" and to give national competent authorities and notified bodies "the necessary information in a clear and comprehensive form to assess the compliance of the AI system" (Article 11(1)). The audience is a regulator reading cold, not your own engineers.

Third, a content floor: "It shall contain, at a minimum, the elements set out in Annex IV" (Article 11(1)).

The duty belongs to the provider: Article 16, point (d) obliges providers to "keep the documentation referred to in Article 18", and Article 18(1), point (a) puts the Article 11 technical documentation first on that list. Technical documentation is one of the requirements that switches on for Annex III systems on 2 December 2027 — the high-risk obligations overview maps the full set.

What are the nine points of Annex IV?

Annex IV requires "at least the following information, as applicable to the relevant AI system". "As applicable" lets you skip elements that genuinely do not apply — not elements you find inconvenient. The nine points:

1. A general description of the AI system. It covers:

2. A detailed description of the elements and the development process. The heaviest point. It covers:

3. Monitoring, functioning and control. Capabilities and limitations, including "the degrees of accuracy for specific persons or groups of persons" and overall expected accuracy; foreseeable unintended outcomes and sources of risks to health, safety, fundamental rights and discrimination; the human oversight measures; and input data specifications.

4. Performance metrics. "A description of the appropriateness of the performance metrics for the specific AI system" — why your chosen metrics fit, not just their values.

5. The risk management system. A detailed description of the Article 9 system — the documentation surface of the risk management requirement, which has its own lifecycle obligations.

6. Lifecycle changes. Relevant changes made by the provider through the system's lifecycle.

7. Standards. The harmonised standards applied in full or in part, "the references of which have been published in the Official Journal of the European Union"; where none were applied, "a detailed description of the solutions adopted" to meet the Chapter III, Section 2 requirements.

8. The EU declaration of conformity. A copy of the Article 47 declaration.

9. Post-market monitoring. A detailed description of the system for evaluating performance in the post-market phase under Article 72, including the Article 72(3) post-market monitoring plan.

Can SMEs and SMCs use a simplified form?

Yes — in form, not in substance. Regulation (EU) 2026/1744 replaced the second subparagraph of Article 11(1), which now provides that "SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner" and that "the Commission shall establish a simplified technical documentation form targeted at the needs of SMEs, including start-ups, and SMCs". An SME, including a start-up, or an SMC that opts for the simplified route "shall use the form", and "[n]otified bodies shall accept the form for the purposes of the conformity assessment". An SMC is a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099 (Article 3, point (14b)).

Two honest caveats. The simplified manner covers the same Annex IV elements — it lightens presentation, not scope. And at the time of writing, the Commission form was still pending; until it is available, the full Annex IV structure is the only safe course.

How long must you keep it, and what sits beside it?

Ten years. Under Article 18(1), the provider must keep at the disposal of national competent authorities, "for a period ending 10 years after the high-risk AI system has been placed on the market or put into service": the Article 11 technical documentation, the Article 17 quality management system documentation, notified-body change approvals and decisions where applicable, and the EU declaration of conformity.

Each Member State determines how documentation stays available if a provider or its authorised representative established on its territory goes bankrupt or ceases activity before the ten years run out (Article 18(2)). Providers that are financial institutions keep the technical documentation as part of the documentation maintained under Union financial services law (Article 18(3)).

What if your AI system is part of a product regulated under other EU law?

Then you produce one file, not two. Where a high-risk AI system relates to a product covered by the Union harmonisation legislation in Section A of Annex I — medical devices, for instance — "a single set of technical documentation shall be drawn up" containing both the Article 11(1) information and what those acts require (Article 11(2)).

The Commission can also amend Annex IV by delegated act in light of technical progress (Article 11(3)). Today's checklist is not guaranteed to be next year's — another reason the up-to-date duty needs an owner, not a one-off project.

What this means for you

If you're a provider: drawing up and keeping the documentation is your obligation (Article 11(1); Article 16, points (a) and (d)). Work Annex IV in the order an authority would read it: points 1 and 2 demand the most excavation from engineering — design rationale, trade-offs, data provenance, signed test reports — while points 5, 8 and 9 pull in documents your risk management, conformity assessment and post-market monitoring work should already be producing. Complipath's Documentation Workspace gives each system one structure with per-section confirmation and PDF export, so the record grows as the work happens rather than the week before an audit. The documentation workspace asks for point 1 of Annex IV, point 2(d), and the risk management system under Article 9 that point 5 requires. It does not ask for point 3 or point 4, and it covers one lettered item of point 2. Annex IV asks for more than this workspace covers today.

If you're a deployer: you do not draw up Annex IV documentation — the provider does. Your working document is the instructions for use, which point 1(h) of Annex IV folds into the provider's file and which Article 26(1) obliges you to follow. Before deploying, ask the provider for the instructions for use and the Article 13 information — Article 26(9) expects you to use the latter for your GDPR data protection impact assessment. Unsure which role you hold? Start with provider vs deployer.

Which of your systems owe an Annex IV file?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

When must the technical documentation exist? Before the high-risk AI system is placed on the market or put into service — and it must be kept up to date afterwards (Article 11(1)). The requirement applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744).

Is there a lighter version for startups? Partly. Article 11(1) lets SMEs, including start-ups, and SMCs provide the Annex IV elements "in a simplified manner" using a Commission form, which notified bodies must accept. The form was still pending at the time of writing, and the simplification affects presentation — the Annex IV elements themselves still have to be covered.

How long must technical documentation be kept? Ten years after the system is placed on the market or put into service, at the disposal of national competent authorities (Article 18(1)) — together with the quality management documentation, notified-body decisions where applicable, and the EU declaration of conformity. Financial institutions keep it under their financial services documentation regime (Article 18(3)).

Does Annex IV apply to general-purpose AI models? No. Annex IV is the technical documentation for high-risk AI systems under Article 11(1). GPAI model providers have a separate duty under Article 53(1), point (a) and Annex XI — unless the Article 53(2) free and open-source exemption applies and the model has no systemic risk. A high-risk system built on an exempt model still needs Annex IV.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 11, 16, 18, 26 and 113, and Annexes I and IV, as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced the second subparagraph of Article 11(1), inserted the SMC definition in Article 3, point (14b), replaced Article 113, third paragraph, point (c), and deleted point 1 (the Machinery Directive) from Section A of Annex I, adding the Machinery Regulation (EU) 2023/1230 as point 21 of Section B. Annex IV is unamended. The Commission's simplified technical documentation form under Article 11(1) and the Article 40 harmonised standards were still pending at the time of writing; the documentation duty applies regardless.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.