AI Security

EU AI Act Technical Documentation Checker

Check technical documentation for a high-risk AI system against the content Annex IV requires, from intended purpose and data provenance through to human oversight and post-market monitoring.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Annex IV is a content list, not a template

The Regulation specifies what the technical documentation must contain rather than how it should be laid out, which means a well-organised document can still be non-compliant by omitting a required element, and a badly organised one can be complete. The sections that go missing are consistently the same: the general logic and design rationale, the trade-offs made against the requirements, and disaggregated accuracy. These are missing because they are the parts that were never written down during development rather than the parts that were written and then lost.

The data section is the hardest to reconstruct

Annex IV asks for the provenance, scope and main characteristics of the training, validation and testing data, how it was obtained and selected, and the labelling procedures. Almost none of this can be reconstructed accurately after the fact: the decisions were made in a notebook by someone who has since moved on, and the dataset has been through several undocumented revisions. Organisations that begin this documentation at the end of development consistently find that the data section is where the work actually is.

Risk management is a process, and the file has to show it running

Article 9 describes a continuous iterative process across the whole lifecycle, so documentation showing a single risk assessment dated once does not evidence compliance with it. What the file needs to show is identification, evaluation, mitigation and re-evaluation happening repeatedly, with the outputs feeding back into design. A risk register with one date on it demonstrates that the process was started, which is a different claim.

Related tools

Frequently Asked Questions

Which Annex IV sections are most often missing?

The general logic and design rationale, the trade-offs made against the requirements, and disaggregated accuracy. They are missing because they were never written during development rather than written and lost.

Does using a foundation model remove the data documentation duty?

No. Annex IV requires the methods and steps performed for development, including any use of pre-trained systems and how they were used, modified and integrated.

Is aggregate accuracy sufficient?

No. Annex IV asks for the level of accuracy for specific persons or groups of persons, so a single overall figure does not satisfy it.

Can risk management be documented once?

No. Article 9 describes a continuous iterative process across the lifecycle. A risk register carrying one date demonstrates the process was started, which is a different claim from compliance.

Does this constitute a conformity assessment?

No. It checks whether the documentation covers the content Annex IV lists. Whether the content is adequate, and whether the system meets Chapter III, are separate questions requiring assessment.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick the sections your documentation contains to score it.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.