Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Talk to sales
Log in Talk to sales
← Docs
← All documentation

EU AI Act Regulator Documents

Backsplice assembles three things a regulator may ask about from the records you already keep: the market dates and EU database registration of an AI system, a technical documentation pack that follows Annex IV of the EU AI Act, and a draft serious-incident report under Article 73. Each is prepared from your records. None is a conformity assessment, a submission to an authority, or legal advice, and whether a provision applies to a system is for your organization to determine, with counsel where needed.

Market dates and EU database registration

On an AI system's page, the registry entry has a Market dates and EU database registration group. Record, as your organization knows them:

  • Placed on the market on: Article 3(9) defines placing on the market as "the first making available of an AI system or a general-purpose AI model on the Union market".
  • Put into service on: Article 3(11) defines putting into service as "the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose".
  • EU database registration reference and Registered in the EU database on: the reference of the registration in the EU database (Articles 49 and 71), exactly as it appears there. No format is assumed. A registration date needs its reference.

A date cannot be in the future, judged in your organization's time zone. Leave a field blank when it does not apply or is not known; blank always reads as "not recorded", never as a date.

The registration note

The system's EU AI Act registration and documentation panel shows the reference when one is recorded. When none is, and the system is recorded as high-risk under Annex III, with a link to the EU, and not rejected or retired, the panel states that no EU database registration is recorded, with the provision that names who registers:

  • for a provider or its authorized representative, Article 49(1): before such a system is placed on the market or put into service, the provider (or, where applicable, its authorized representative) registers itself and the system in the EU database referred to in Article 71. Systems in point 2 of Annex III are registered at national level (Article 49(5)), and Backsplice does not record which point of Annex III a system falls under;
  • for a deployer, Article 49(3) names "deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf". Backsplice does not record whether your organization is one of them;
  • with no role recorded, it says the role decides it;
  • for an importer or distributor role only, or "none", it shows no registration note.

It is a statement about your records, not a finding that the system must be registered.

The Article 73 clock

The serious-incident clock reads the two dates for its Article 111(2) note. Under Article 111(2), as amended by Regulation (EU) 2026/1744, the Regulation reaches a high-risk system placed on the market or put into service before the date its class's high-risk rules apply only if its design changes significantly on or after that date, and one intended for use by public authorities must comply by 2 August 2030 in any case. With a date recorded before that date, the incident page says the system is recorded as placed on the market or put into service before it; with both recorded on or after it, that the rule for earlier systems does not reach it on the dates recorded; with only one recorded on or after it, which date is missing. It never judges whether a design change was significant. See AI Incidents.

The technical documentation pack (Annex IV)

Technical documentation pack on the system's page downloads a PDF, Markdown or JSON file listing every point of Annex IV, in its order: the general description (points 1(a) to 1(h)), the detailed description of the system and its development (2(a) to 2(h)), monitoring, functioning and control (3), the performance metrics (4), the risk management system (5), changes through the lifecycle (6), the standards applied (7), the EU declaration of conformity (8) and the post-market monitoring system and plan (9). Each point quotes the Annex and shows what your records hold for it: the registry entry, the models and their versions, providers, evaluations and model cards, the datasets and their lineage, the human-oversight roster, bias audits, monitoring metrics, the risk register, impact assessments and assessments, the change log and lifecycle history, and the published monitoring plan.

A point your records do not hold says Not recorded in Backsplice; none is left out. Backsplice never holds an EU declaration of conformity, so point 8 always says so. Point 7 lists the frameworks and question sets the system was assessed against, by name, and says that no harmonised standard is recorded as applied: being assessed against a voluntary framework is not applying a standard.

Article 11(1), as amended by Regulation (EU) 2026/1744, provides that "SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner", on a form the Commission establishes. The pack follows the points of Annex IV and is not that form.

An organization administrator or an auditor whose access includes AI systems can download it. The download comes with a plan; it is not in the demo. The risk register and change log sections follow their own registers' access: a section you cannot open there says it is withheld, and why. Each download is recorded in the audit log.

The Article 73 report draft

On an incident with an EU AI Act reporting deadline, Draft the Article 73 report downloads a draft (PDF or Markdown) with:

  • the AI system: its name, your recorded EU roles and classification, how it reaches the EU, its EU database registration and market dates, its purpose and the models it uses with their providers;
  • the incident: its description, dates, when your organization became aware, and the serious-incident category in the Regulation's words;
  • the reporting deadline exactly as the incident page states it (never recalculated), with the readiness or Article 111(2) note;
  • the people affected and whether personal data was involved;
  • the investigator and the investigation notes;
  • corrective actions: the remediation tasks recorded against the AI system (a task is not linked to an incident, and the draft says so) and any response playbook run on the incident;
  • the human-oversight roster and the published monitoring plan;
  • when the provider was informed, when the initial report was sent, and when the authority was notified, with your note of which authority and its reference.

The draft follows no official form. Article 73(7) provides that "The Commission shall develop dedicated guidance to facilitate compliance with the obligations set out in paragraph 1 of this Article." Check that guidance, and what the market surveillance authority asks for, before you submit a report. Only an organization administrator can download the draft, as only they can open the incident. The download comes with a plan; it is not in the demo.

This is not legal advice.

Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile) NIST Cyber AI Profile (IR 8596 initial preliminary draft) UK AI Cyber Security Code of Practice (2025) OWASP Top 10 for LLM Applications 2026 MITRE ATLAS 2026.09

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.