The rules
Only the mandatory rules decide a pack's finding. A recommended rule that fails is reported and does not, on its own, make a record non-compliant. Each rule's words below are the pack's own.
eu-ai-act-record-keeping mandatory
The record belongs to a lineage of records that is kept, ordered and traced to its origin. Checks: the lineage is at least one record long; the training input is committed by a Merkle root, and a record that declares its training input not held or not disclosed fails; a record with predecessors names the one before it by hash; training does not end before it starts or after the record was issued, and the collection period does not end before it starts; and the lineage was verified back to the initial record, so a successor evaluated without its predecessors is indeterminate. Does not check: the events of the system in operation. Art. 12 asks for the automatic recording of events over the system's lifetime; reading a lineage of records, which notes each change to the model (12(2)(a): substantial modifications), as part of that record-keeping is this pack's reading, and it is narrower than the logs Art. 12 requires.
Regulation (EU) 2024/1689 (AI Act) Art. 12(1) and 12(2)(a)
eu-ai-act-accuracy-robustness mandatory
What was learned is pinned, so the system deployed can be shown to be the system whose accuracy and robustness were assessed. Checks: the learned state and each of its components carry a parseable hash and a positive size; and a deployment or policy-change record keeps the model of its verified immediate predecessor, the same model_hash, so one evaluated without that predecessor is indeterminate. Does not check: accuracy or robustness themselves, which Art. 15(1) requires at an appropriate level. The rule identifies the system; it does not measure it.
Regulation (EU) 2024/1689 (AI Act) Art. 15(1)
eu-ai-act-technical-documentation mandatory
The development environment is identified in the technical documentation. Checks: the training software and the software hash of the environment the learning ran in are declared and not empty, and the software hash parses as a hash; an empty value, which is how a record says there is none, fails. Does not check: that the hash is the hash of the software actually used, or the rest of what Annex IV point 1(c) asks for. Annex IV point 1(c) asks for the versions of relevant software; pinning the software stack by hash as well is this pack's reading.
Regulation (EU) 2024/1689 (AI Act) Art. 11(1) and Annex IV(1)(c)
eu-ai-act-cybersecurity-attestation recommended
The issuer attests at software level or stronger, so the record resists alteration by a party that is not the provider. Art. 15(5) requires resilience against unauthorised third parties who try to alter a system's use, outputs or performance; choosing attestation as the means is this pack's reading, which is why the rule is recommended rather than mandatory. Checks: the record declares an attestation_level of software or stronger. Does not check: the resilience Art. 15(5) asks for, or the technical solutions it asks to be built in. The level is the issuer's own claim about itself, and what the trust store grants the signing key is the verifier's trust.attestation check, before any pack is evaluated.
Regulation (EU) 2024/1689 (AI Act) Art. 15(5)
eu-ai-act-data-governance recommended
The record pins, by SHA-256, the document its issuer names as its data governance documentation. Checks: the record carries data_governance, and its documentation_hash is a hash; a record without the member declares that it pins no such document, and fails. Does not check: that the document exists, can be obtained or says anything, or that the data governance and management practices of Art. 10(2), or the qualities Art. 10(3) and 10(4) ask of the data sets, are in place or adequate. A pinned document shows which document the issuer relied on, not that it complies. Annex IV(2)(d) puts datasheets of the training data into the technical documentation; reading the pinned document as that part of it is this pack's reading, which is why the rule is recommended rather than mandatory.
Regulation (EU) 2024/1689 (AI Act) Art. 10(2) and Annex IV(2)(d)
eu-ai-act-human-oversight recommended
The record pins, by SHA-256, the document its issuer names as its human oversight documentation. Checks: the record carries human_oversight, and its documentation_hash is a hash; a record without the member declares that it pins no such document, and fails. Does not check: that the document exists, can be obtained or says anything, that the oversight measures of Art. 14(3) are built in or identified, or that natural persons can oversee the system as Art. 14(4) requires. A pinned document shows which document the issuer relied on, not that it complies. Annex IV(2)(e) puts the assessment of those measures into the technical documentation; reading the pinned document as that assessment is this pack's reading, which is why the rule is recommended rather than mandatory.
Regulation (EU) 2024/1689 (AI Act) Art. 14(3) and Annex IV(2)(e)