EU AI Act

EU AI Act – Annex IV: What belongs in your technical documentation

DEAuf Deutsch lesen →
23. Juni 2026 GARION EU AI Act

Anyone placing an AI system on the EU market under the AI Act will need technical documentation. For high-risk systems, Annex IV defines exactly what that documentation must contain. The good news: at heart, the annex is a structured checklist. The bad news: much of it cannot be produced on demand at the end — it has to be carried along across the whole lifecycle.

What Annex IV requires

Annex IV lists the components of the technical documentation. Simplified, they fall into six blocks:

  • General description of the system: intended purpose, responsible parties, versions, interaction with hardware and software.
  • Detailed technical description: development steps, system architecture, compute resources, data requirements and the design choices made.
  • Data governance: origin, preparation, assumptions and known biases of the training, validation and test data.
  • Monitoring, functioning and control: accuracy, robustness, metrics and the limits of the system.
  • Risk management: the system established under Article 9 and the measures taken.
  • Changes and conformity: lifecycle changes, standards applied and the EU declaration of conformity.

Why readiness starts early

The classic mistake is to treat documentation as a closing act. In practice, data provenance, design rationale or test results can rarely be reconstructed cleanly after the fact. Teams that instead adopt the Annex IV structure early — as their working outline — capture evidence where it is created: inside the development process itself.

In concrete terms, that means a living document rather than a point-in-time report. Every relevant decision — an architecture choice, a rejected dataset, a re-tuned threshold — is recorded together with its rationale. It is exactly this chain of reasoning that later makes a conformity assessment traceable.

A pragmatic sequence

For teams without a dedicated compliance office, a lean order of work tends to hold up:

  • First, pin down the intended purpose precisely — it drives almost everything else.
  • Then document the data basis while the sources are still fresh and at hand.
  • In parallel, set up risk management and let it run alongside development.
  • Only at the end, bring together the cross-cutting artefacts — metrics, declaration of conformity, references to standards.

Where GARION fits in

GARION maps the Annex IV structure as a readiness domain: it walks you through the required blocks, records decisions with their rationale, and shows the working status per section. The output is not a conformity verdict but an ordered, auditable state of preparation — the basis on which professionals carry out the actual assessment.


Note: GARION supports preparation for the EU AI Act and related frameworks. GARION is not a substitute for legal advice, conformity assessment or certification.