WHAT FACTS SUPPORT THE CLASSIFICATION?
Preserve the system identity, intended purpose, operator role, applicable risk route, exclusions relied on, versions, dependencies, deployment context and the evidence supporting those facts.
EU AI Act governance becomes real when a business can show the evidence behind its system identity, classification, obligations, controls, changes and continuing reliance. The goal is not a bigger document folder. It is a current, attributable evidence record.
For high-risk AI systems, Article 11 requires technical documentation before market placement or use and requires it to be kept up to date. Article 12 requires automatic logging capability. Article 18 sets a 10-year provider documentation-retention period for specified records, while Article 19 generally requires controlled logs to be kept for at least six months unless other law provides otherwise.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
Preserve the system identity, intended purpose, operator role, applicable risk route, exclusions relied on, versions, dependencies, deployment context and the evidence supporting those facts.
For high-risk systems this can include technical documentation, risk-management records, data-governance evidence, testing, instructions for use, human-oversight measures, accuracy, robustness and cybersecurity evidence.
Logs, monitoring records, incidents, corrective actions, post-market evidence, approved changes, declarations, notices and review history matter because the compliance position must survive beyond a one-time assessment.
Evidence is not durable if old files silently support a new system state. Preserve version changes, model swaps, intended-purpose changes, authority changes, source-state changes and the revalidation decision.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
Start with the claim being supported: system identity, actor role, classification, transparency duty, high-risk requirement, human oversight, or another obligation. A file is only useful if it supports a bounded proposition.
Preserve who produced the evidence, what system/version it concerns, when it was valid, what scope it covers, and which accountable person or authority relies on it.
A governed record should show evidence gaps and stale evidence explicitly instead of allowing an incomplete folder to look complete.
When the system, intended purpose, model, authority, deployment, legal source or control environment changes, question whether the previous evidence can still be relied upon.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
START EVIDENCE PASSPORT →Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.
START COMPLIANCE WORKSPACE →Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.
START GOVERNANCE PRO →Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.
START INSTITUTION →Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
Yes for high-risk AI systems. Article 11 requires technical documentation to be drawn up before the system is placed on the market or put into service, kept up to date, and structured to demonstrate compliance with the high-risk requirements.
Article 11 points to Annex IV. In practice, the documentation covers the system description, development process, monitoring and control, performance, risk-management measures, changes and other information needed to assess conformity.
High-risk AI systems must technically allow automatic logging over their lifetime under Article 12. Providers and deployers must keep logs under their control for an appropriate period, generally at least six months unless other law provides differently.
Article 18 requires providers to keep specified documentation available to competent authorities for 10 years after the high-risk AI system has been placed on the market or put into service.
No. The evidence set depends on the system, operator role, risk classification, intended purpose, sector, customer use, transparency duties and other applicable Union or national law.
No. TA-14 can preserve evidence identity, scope, provenance, gaps, change and revalidation state. The existence of a document—or its presence in a workspace—does not by itself establish legal compliance.
TA-14 Exchange Activity
Live cumulative activity recorded across the public Exchange surface.
···
Visitors
Recorded public visitors
···
Page Views
Recorded Exchange views