The classic trap
Annex IV lists 9 mandatory technical documentation blocks for any high-risk AI system. Audit reality: 80% of providers have functional documentation (PRD, product specs) but zero Annex IV-compliant documentation (algorithmic logic, training datasheets, signed test logs, cybersecurity measures). The EU AI Office and national market surveillance authorities can request this documentation at any time, and any gap blocks the conformity assessment procedure. Penalty: up to EUR 15M or 3% of global turnover for provider obligation breaches (Art. 99).
The 9 documentary blocks Annex IV requires
- Block 1: general description (intended purpose, version, hardware/software interactions, forms of placing on market).
- Block 2: detailed development (methods, design specs, architecture, training datasheets, human oversight Art. 14, validation procedures, cybersecurity measures).
- Block 3: monitoring and control (capabilities, limitations, accuracy per group of persons, foreseeable risks).
- Block 4: appropriateness of performance metrics.
- Block 5: risk management system (Art. 9).
- Block 6: significant changes through lifecycle.
- Block 7: list of harmonised standards applied (ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 5338).
- Block 8: EU declaration of conformity.
- Block 9: post-market monitoring system (Art. 72).
The specific trap: living documentation
Annex IV is not a one-shot deliverable. Each model retraining, each feature addition, each dataset update triggers a documentation update obligation. Without an automatic extraction pipeline plugged into your MLOps tools (MLflow, Weights & Biases, Vertex AI, SageMaker), your documentation becomes stale within 3 months and any audit will reveal the gap instantly.
How Luxgap automates this risk
Our Luxgap AI Technical Dossier Forge eliminates documentation drudgery by plugging an AI agent directly into your MLOps pipelines: it extracts, classifies and drafts the 9 Annex IV blocks continuously, at each model commit. You no longer fill an 80-page Word file, you validate documentation already generated from your Git, MLflow, Weights & Biases, Hugging Face Hub, Azure ML, Vertex AI or SageMaker.
- Automatically extracts model version, hyperparameters, architecture and compute resources from your MLflow or W&B runs and feeds Annex IV block 2.
- Generates training datasheets in Google Model Cards and IBM FactSheets format from your dataset metadata (provenance, size, demographic distribution, cleaning procedures).
- Detects significant changes between two model versions (architecture drift, feature additions, retraining) and automatically triggers block 6 update.
- Computes accuracy metrics per demographic group (fairness gap, disparate impact) via Fairlearn or AI Fairness 360 and feeds block 3 on discrimination risks.
- Maps the harmonised standards ISO/IEC 42001, 23894, 5338 and 24029 actually applied in your QMS and generates block 7 with audit evidence.
- Produces a timestamped, cryptographically sealed PDF technical dossier, enforceable before the EU AI Office and the surveillance authority during an audit.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on one of your real models, with a free 48h white audit to measure your gap against the 9 blocks before any engagement.