The classic trap
Annex VI describes the self-assessment procedure that high-risk AI providers apply without a notified body. The trap: believing that 'internal control' means 'light control'. It is the opposite. The provider alone bears responsibility for compliance with Chapter III Section 2 requirements, and both the EU AI Office and the CNPD (for the personal data aspect) can demand proof afterwards. Technical documentation that diverges from the deployed reality exposes the provider to fines up to 15 million euros or 3% of global turnover.
The 3 mandatory checks under Annex VI
- QMS consistency vs Article 17: the documented quality management system must reflect what actually happens in your MLOps pipelines (versioning, testing, validation, change management).
- Technical documentation consistency vs Chapter III Section 2: risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy robustness cybersecurity (Art. 15).
- Design and development consistency vs post-market monitoring (Art. 72): the monitoring plan must be plugged into operational reality, not a stale Word document.
The consistency test: the key to passing an inspection
Annex VI fully relies on the notion of consistency. An EU AI Office inspection will compare three realities: what your technical documentation says, what your real pipelines do (code, data, deployments), and what your post-market monitoring reports. Any divergence is a non-conformity.
How Luxgap automates this risk
Our Luxgap AI Conformity Mirror turns the Annex VI self-assessment into continuous, court-ready evidence, mirroring in real time your technical documentation against the reality of your AI systems in production. The tool connects to your GitLab/GitHub repositories, your MLflow/Weights and Biases registries, your Azure ML/SageMaker/Vertex AI pipelines and your observability platforms (Datadog, Grafana, Arize) to continuously detect gaps between the declared (Article 11 documentation) and the executed (code, data, served models).
- Scans your code repositories and model registries to automatically rebuild the technical documentation compliant with the 9 sections of Annex IV, without manual entry by data scientists.
- Detects divergences between the declared documentation and the actual production artefacts: served model version, training dataset, hyperparameters, performance metrics, human oversight mechanisms.
- Automatically maps Chapter III Section 2 (Articles 9 to 15) coverage on each AI system and surfaces documentation gaps before any inspection.
- Plugs your Article 72 post-market monitoring plan into your real operational signals (data drift, error rate, user feedback, incidents) and alerts as soon as a metric exits the declared thresholds.
- Verifies the consistency of your Article 17 QMS with your actual processes: risk management policy, test procedures, change management, incident handling, team training.
- Produces an Annex VI conformity file, timestamped and cryptographically signed, enforceable before the EU AI Office and the CNPD on the personal data aspect, regenerated automatically at every production release.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI systems, with a free 48h blank audit to measure the gap between your current documentation and Annex VI requirements before any engagement.