What goes into EU AI Act technical documentation? The Annex IV checklist
Updated 9 August 2026 for Regulation (EU) 2026/1744.
Under Article 11(1), the technical documentation of a high-risk AI system "shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date". Annex IV sets the minimum content: nine points, from general description to post-market monitoring plan.
Quick answer
- The duty and its timing: the documentation must exist before the system is placed on the market or put into service, and must be kept up to date afterwards (Article 11(1)). The duty applies from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744).
- The test it must pass: demonstrate compliance with the Chapter III, Section 2 requirements and give national competent authorities and notified bodies "the necessary information in a clear and comprehensive form" (Article 11(1)).
- The content: "at a minimum, the elements set out in Annex IV" — nine points covering description, development process, monitoring, metrics, risk management, changes, standards, the declaration of conformity and post-market monitoring.
- SMEs, including start-ups, and SMCs may provide the Annex IV elements "in a simplified manner" using a Commission form — small mid-caps were added in 2026, and the form was still pending at the time of writing (Article 11(1)).
- Retention: ten years after market placement or putting into service (Article 18(1)).
What does Article 11 actually require?
Three things. First, timing: the documentation "shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date" (Article 11(1)). It cannot be assembled retroactively, and a version written once and frozen breaches the second half of the sentence.
Second, a quality standard. The documentation must be drawn up "to demonstrate that the high-risk AI system complies with the requirements set out in this Section" and to give national competent authorities and notified bodies "the necessary information in a clear and comprehensive form to assess the compliance of the AI system" (Article 11(1)). The audience is a regulator reading cold, not your own engineers.
Third, a content floor: "It shall contain, at a minimum, the elements set out in Annex IV" (Article 11(1)).
The duty belongs to the provider: Article 16, point (d) obliges providers to "keep the documentation referred to in Article 18", and Article 18(1), point (a) puts the Article 11 technical documentation first on that list. Technical documentation is one of the requirements that switches on for Annex III systems on 2 December 2027 — the high-risk obligations overview maps the full set.
What are the nine points of Annex IV?
Annex IV requires "at least the following information, as applicable to the relevant AI system". "As applicable" lets you skip elements that genuinely do not apply — not elements you find inconvenient. The nine points:
1. A general description of the AI system. It covers:
- intended purpose, provider name and version "reflecting its relation to previous versions" (point 1(a));
- how the system interacts with external hardware or software, including other AI systems (1(b));
- software and firmware versions and update requirements (1(c));
- every form in which it reaches the market — "software packages embedded into hardware, downloads, or APIs" (1(d));
- the intended hardware (1(e));
- product photographs where it is a product component (1(f));
- the deployer-facing user interface and instructions for use (1(g) and (h)).
2. A detailed description of the elements and the development process. The heaviest point. It covers:
- development methods, including "recourse to pre-trained systems or tools provided by third parties" and how you integrated or modified them (2(a));
- design specifications — the general logic and algorithms, key design choices "including the rationale and assumptions made", what the system is designed to optimise for, and "any possible trade-off" against the Chapter III, Section 2 requirements (2(b));
- system architecture and the computational resources used to develop, train, test and validate it (2(c));
- data requirements — datasheets covering training methodologies, data sets, "their provenance, scope and main characteristics", how data was obtained and selected, labelling and cleaning procedures (2(d)) — the documentation counterpart of the Article 10 data governance requirements;
- the assessment of human oversight measures under Article 14, including technical measures helping deployers interpret outputs under Article 13(3), point (d) (2(e));
- pre-determined changes and how compliance survives them (2(f));
- validation and testing procedures, metrics for "accuracy, robustness ... as well as potentially discriminatory impacts", and "test logs and all test reports dated and signed by the responsible persons" (2(g));
- cybersecurity measures (2(h)).
3. Monitoring, functioning and control. Capabilities and limitations, including "the degrees of accuracy for specific persons or groups of persons" and overall expected accuracy; foreseeable unintended outcomes and sources of risks to health, safety, fundamental rights and discrimination; the human oversight measures; and input data specifications.
4. Performance metrics. "A description of the appropriateness of the performance metrics for the specific AI system" — why your chosen metrics fit, not just their values.
5. The risk management system. A detailed description of the Article 9 system — the documentation surface of the risk management requirement, which has its own lifecycle obligations.
6. Lifecycle changes. Relevant changes made by the provider through the system's lifecycle.
7. Standards. The harmonised standards applied in full or in part, "the references of which have been published in the Official Journal of the European Union"; where none were applied, "a detailed description of the solutions adopted" to meet the Chapter III, Section 2 requirements.
8. The EU declaration of conformity. A copy of the Article 47 declaration.
9. Post-market monitoring. A detailed description of the system for evaluating performance in the post-market phase under Article 72, including the Article 72(3) post-market monitoring plan.
Can SMEs and SMCs use a simplified form?
Yes — in form, not in substance. Regulation (EU) 2026/1744 replaced the second subparagraph of Article 11(1), which now provides that "SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner" and that "the Commission shall establish a simplified technical documentation form targeted at the needs of SMEs, including start-ups, and SMCs". An SME, including a start-up, or an SMC that opts for the simplified route "shall use the form", and "[n]otified bodies shall accept the form for the purposes of the conformity assessment". An SMC is a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099 (Article 3, point (14b)).
Two honest caveats. The simplified manner covers the same Annex IV elements — it lightens presentation, not scope. And at the time of writing, the Commission form was still pending; until it is available, the full Annex IV structure is the only safe course.
How long must you keep it, and what sits beside it?
Ten years. Under Article 18(1), the provider must keep at the disposal of national competent authorities, "for a period ending 10 years after the high-risk AI system has been placed on the market or put into service": the Article 11 technical documentation, the Article 17 quality management system documentation, notified-body change approvals and decisions where applicable, and the EU declaration of conformity.
Each Member State determines how documentation stays available if a provider or its authorised representative established on its territory goes bankrupt or ceases activity before the ten years run out (Article 18(2)). Providers that are financial institutions keep the technical documentation as part of the documentation maintained under Union financial services law (Article 18(3)).
What if your AI system is part of a product regulated under other EU law?
Then you produce one file, not two. Where a high-risk AI system relates to a product covered by the Union harmonisation legislation in Section A of Annex I — medical devices, for instance — "a single set of technical documentation shall be drawn up" containing both the Article 11(1) information and what those acts require (Article 11(2)).
The Commission can also amend Annex IV by delegated act in light of technical progress (Article 11(3)). Today's checklist is not guaranteed to be next year's — another reason the up-to-date duty needs an owner, not a one-off project.
What this means for you
If you're a provider: drawing up and keeping the documentation is your obligation (Article 11(1); Article 16, points (a) and (d)). Work Annex IV in the order an authority would read it: points 1 and 2 demand the most excavation from engineering — design rationale, trade-offs, data provenance, signed test reports — while points 5, 8 and 9 pull in documents your risk management, conformity assessment and post-market monitoring work should already be producing. Complipath's Documentation Workspace gives each system one structure with per-section confirmation and PDF export, so the record grows as the work happens rather than the week before an audit. The documentation workspace asks for point 1 of Annex IV, point 2(d), and the risk management system under Article 9 that point 5 requires. It does not ask for point 3 or point 4, and it covers one lettered item of point 2. Annex IV asks for more than this workspace covers today.
If you're a deployer: you do not draw up Annex IV documentation — the provider does. Your working document is the instructions for use, which point 1(h) of Annex IV folds into the provider's file and which Article 26(1) obliges you to follow. Before deploying, ask the provider for the instructions for use and the Article 13 information — Article 26(9) expects you to use the latter for your GDPR data protection impact assessment. Unsure which role you hold? Start with provider vs deployer.
Which of your systems owe an Annex IV file?
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
When must the technical documentation exist? Before the high-risk AI system is placed on the market or put into service — and it must be kept up to date afterwards (Article 11(1)). The requirement applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744).
Is there a lighter version for startups? Partly. Article 11(1) lets SMEs, including start-ups, and SMCs provide the Annex IV elements "in a simplified manner" using a Commission form, which notified bodies must accept. The form was still pending at the time of writing, and the simplification affects presentation — the Annex IV elements themselves still have to be covered.
How long must technical documentation be kept? Ten years after the system is placed on the market or put into service, at the disposal of national competent authorities (Article 18(1)) — together with the quality management documentation, notified-body decisions where applicable, and the EU declaration of conformity. Financial institutions keep it under their financial services documentation regime (Article 18(3)).
Does Annex IV apply to general-purpose AI models? No. Annex IV is the technical documentation for high-risk AI systems under Article 11(1). GPAI model providers have a separate duty under Article 53(1), point (a) and Annex XI — unless the Article 53(2) free and open-source exemption applies and the model has no systemic risk. A high-risk system built on an exempt model still needs Annex IV.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 11, 16, 18, 26 and 113, and Annexes I and IV, as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced the second subparagraph of Article 11(1), inserted the SMC definition in Article 3, point (14b), replaced Article 113, third paragraph, point (c), and deleted point 1 (the Machinery Directive) from Section A of Annex I, adding the Machinery Regulation (EU) 2023/1230 as point 21 of Section B. Annex IV is unamended. The Commission's simplified technical documentation form under Article 11(1) and the Article 40 harmonised standards were still pending at the time of writing; the documentation duty applies regardless.