Can be retrofitted
Sections 1, 5, 7, 8, 9
General description, risk management, standards list, Declaration of Conformity, post-market plan - painful to assemble late, but possible from existing records.
EU AI Act Annex IV applies from 2 December 2027 for stand-alone high-risk systems (Digital Omnibus timeline). The 9-section technical-file checklist - and the two sections (data governance, performance metrics) where annotation providers fail audits.

Executive summary
If you supply training data, run an annotation pipeline, or build models for a high-risk AI system going to market in the EU, the EU AI Act Annex IV technical file is the document that decides whether your customer ships on the Act’s timeline or gets pulled from the market. This one is written from the angle that matters most for our work at LabelFort: Section 2 (development process and data governance) and Section 4 (performance metrics) - nearly impossible to reconstruct after the fact.
EU AI Act Article 11 requires every provider of a high-risk AI system to draw up technical documentation before the system is placed on the market and to keep it current throughout the system’s lifecycle. Annex IV is the regulation’s exhaustive specification of what that documentation must contain.
The file is not a marketing artifact. It is the evidentiary backbone of your CE-mark conformity assessment. Get it wrong and the system cannot ship in the EU.
Stand-alone Annex III
2 Dec 2027
Recruitment, credit scoring, education, biometrics, law enforcement, and others.
Annex I embedded
2 Aug 2028
Medical devices, machinery, vehicles - AI built into regulated products.
Penalty: Incomplete Article 11 documentation carries fines of up to €15 million or 3% of global annual turnover, whichever is higher - enforceable at any time, not tied to a single compliance date.
The structure is fixed. Notified Bodies expect to read it in this order, with these names, and find each section either populated or with a defensible reason for its absence.
A plain-language description of the AI system, including: intended purpose, the name and contact of the provider, version, the system’s interactions with hardware or other software, software versions, user interface designs, instructions for use, and a description of the hardware on which the system is intended to run.
This is the section that catches annotation providers out. It must cover methods and techniques, design specifications, system architecture, data requirements (datasheets, provenance, labeling procedures, cleaning methodologies), human oversight measures, validation and testing procedures, and cybersecurity measures.
Detailed information about monitoring, functioning, and control - including capabilities and limitations, degrees of accuracy for specific persons or groups, foreseeable unintended outcomes, and human oversight measures.
A description of the appropriateness of the performance metrics used, plus per-cohort performance metrics - accuracy broken down by every relevant cohort surfaced in Section 3.
Section 5 covers the Article 9 risk management system. Section 6 documents lifecycle changes. Section 7 lists harmonised standards applied. Section 8 is the EU Declaration of Conformity. Section 9 is the post-market monitoring plan under Article 72.
Every Annex IV section needs evidence. Most can be produced retroactively. Section 2 is different.
Can be retrofitted
General description, risk management, standards list, Declaration of Conformity, post-market plan - painful to assemble late, but possible from existing records.
Cannot be backdated
Provenance, labeling procedures, inter-rater reliability, cleaning code, and datasheets decay irrecoverably the moment the annotation tool moves to the next batch.
None of these can be honestly reconstructed two months after the data has been shipped. This is what we mean at LabelFort by evidence-grade annotation: every artifact Annex IV Section 2 will ask for is captured at the time of annotation, versioned, and exportable as a single per-dataset bundle.
In practice, that bundle contains:
Section 4 asks you to justify your performance metrics and present performance broken down by relevant cohort. For a medical-imaging AI screening for diabetic retinopathy, “92% sensitivity” is not Section 4 evidence. The auditable form is sensitivity broken down by age cohort, scanner manufacturer, and demographic sub-groups - flagged where out-of-scope.
You cannot generate that table at audit time. You can only generate it if your training annotation captured the cohort tags. Sections 2 and 4 are an evidence pair.
| Section | Evidence the file contains (illustrative) |
|---|---|
| 1. General description | Diabetic retinopathy triage AI; v3.2.1; deployed on hospital PACS; HL7 FHIR integration. |
| 2. Development & data governance | Dataset card v3 covering 47,000 retinal scans; provenance log; annotator guideline v1.4; per-cohort IRR (κ = 0.86 adult, 0.79 geriatric); cleaning code at commit a4b2f9c. |
| 3. Monitoring & control | Capability statement; per-cohort accuracy table; foreseeable misuse register; Article 14 human oversight design. |
| 4. Performance metrics | Sensitivity 91.2%, specificity 94.6%, AUROC 0.96; cohort breakdown; metric justification. |
| 5–9 | Risk register, lifecycle changes, harmonised standards, Declaration of Conformity, post-market monitoring plan. |
On 19 November 2025 the Commission proposed pushing Annex III obligations to December 2027. Parliament adopted the text on 16 June 2026 and the Council gave final approval on 29 June 2026: stand-alone high-risk obligations now apply from 2 December 2027, Annex I embedded systems from 2 August 2028. See our Article 12 logging guide for the full Digital Omnibus timeline.
| Section | Produced? | Versioned? | Survives Notified Body spot-check? |
|---|---|---|---|
| 1. General description | ☐ | ☐ | ☐ |
| 2. Development & data governance | ☐ | ☐ | ☐ |
| Datasheet (Gebru-pattern) | ☐ | ☐ | ☐ |
| Annotator guideline (versioned) | ☐ | ☐ | ☐ |
| Inter-rater reliability per cohort | ☐ | ☐ | ☐ |
| Data cleaning code + commit hash | ☐ | ☐ | ☐ |
| Provenance log incl. cross-border | ☐ | ☐ | ☐ |
| 3. Monitoring & control | ☐ | ☐ | ☐ |
| 4. Performance metrics (cohort breakdown) | ☐ | ☐ | ☐ |
| 5. Risk management (Article 9) | ☐ | ☐ | ☐ |
| 6. Lifecycle changes log | ☐ | ☐ | ☐ |
| 7. Harmonised standards applied | ☐ | ☐ | ☐ |
| 8. Declaration of Conformity (Article 47) | ☐ | ☐ | ☐ |
| 9. Post-market monitoring plan (Article 72) | ☐ | ☐ | ☐ |
If your system is classified as high-risk under Annex III. It must be produced before placing the system on the EU market and kept current for the life of the system. Stand-alone Annex III obligations apply from 2 December 2027; Annex I embedded from 2 August 2028.
Up to €15 million or 3% of total worldwide annual turnover, whichever is higher, for non-compliance with Article 11.
Yes. Article 11(1) permits SMEs to supply elements in a simplified manner - but as of Q2 2026 that simplified form has not yet been published, so SMEs should produce the full Annex IV structure.
Yes. The regulation is agnostic on in-house vs outsourced. What it requires is the evidence - provenance, procedure, inter-rater reliability, cleaning, and datasheet.
ISO/IEC 42001 is the international management-system standard for AI. It is complementary: 42001 evidences the management system; Annex IV evidences the technical file for a specific system.
Every batch ships with a versioned annotator guideline, per-record annotator and adjudicator identity, cohort-level inter-rater reliability, cleaning code with commit hash, and a Gebru-pattern datasheet - exportable as a single per-dataset bundle.
Separate. GPAI providers have obligations under Articles 53–55. Annex IV is the high-risk-system technical file; GPAI obligations are foundation-model-provider obligations.
No - Annex IV is the high-risk technical-file standard. Limited-risk systems have transparency obligations under Article 50 but no Annex IV file.
Continuously. Article 11 requires the technical documentation to be kept up to date. Material changes reopen the relevant sections - most often Sections 2, 4, 6, and 9.
EU AI Act
Audit
AnnotationIAA scored per cohort, audit trails on every action, evidence exports mapped to EU AI Act Articles 10 & 12.





