EU AI Act Annex III enforcement: 2 December 2027

Regulator-grade evidence packs
— starting with the EU AI Act.

VERA.AI turns the operational evidence you already produce into a regulator-ready pack — with provenance on every field and a tamper-evident audit trail. We prove it first on the EU AI Act's Annex IV, the mandatory document every high-risk system needs. One engine, already running three frameworks.

Get your free Annex IV readiness report See how it works Try the interactive demo

Built for compliance officers at regulated organisations

Banking Insurance Healthcare Public Sector Legal
The unmet need

Annex IV is the one document every regulator will ask for. None do it with regulator-grade depth, affordably, in Italian.

EU AI Act Article 11 requires Annex IV technical documentation before placing any high-risk AI system on the market. The document has 9 mandatory sections covering data governance, risk management, performance metrics, human oversight, and more. Today, organisations assemble it manually in Word and PowerPoint, pulling from a dozen systems. It takes 6-9 months. We do it in days.

Governance platforms like Credo AI now generate policy-level documentation, and labeling tools produce data. But the deep technical evidence regulators examine first — architecture, traceability, provenance — is the cited gap. VERA.AI goes deepest there, affordably, and Italy-first.

How it works

From your existing process to a regulator-ready pack in days.

01

Connect your sources

Import from Encord, Labelbox, Scale AI for labeling data. Import from Credo AI, OneTrust for governance metadata. Or use our native labeling.

02

Classify the system

Answer 8 structured questions about your AI system. We classify against Annex III and map to the correct Annex IV obligations.

03

Auto-populate the pack

All 9 sections of Annex IV fill from connected sources: purpose, training data, model architecture, performance, monitoring, oversight.

04

Export and refresh

Generate a signed PDF + machine-readable JSON. Refresh annually or on substantial modification. Audit chain proves integrity.

One engine, many regimes

The AI Act was the wedge — not the ceiling.

VERA.AI is a regulatory evidence platform. The same engine — scoring, provenance, tamper-evident audit, multilingual rendering — now powers three frameworks, and adding another is a content-and-rules exercise, not a rebuild.

EU AI Act — Annex IV

Technical documentation for high-risk AI systems. The original framework, in full regulator-grade depth.

NIST AI RMF

AI risk-management evidence for organisations aligning to the US framework alongside the EU.

RIGI — Argentina NEW

Continuing-compliance evidence for large-investment megaprojects (Ley 27.742). A non-AI regime — proof the platform generalises. Bilingual Spanish/English packs.

Pricing

Pay for the artifact, not seats.

You pay a base platform license plus a fee per evidence pack you generate. Annual refresh keeps your packs current as regulations and your AI systems evolve.

Platform license

€15,000/ year

Annual contract per organisation. Includes platform access, support, and Annex IV template engine.

  • Unlimited platform users
  • SOC 2 + GDPR compliance
  • EU data residency enforced
  • Standard support

Evidence pack

€5,000/ pack

One per new high-risk AI system. Then €3,000/year refresh per existing pack.

  • All 9 Annex IV sections
  • Audit chain integrity proof
  • PDF + JSON output
  • Annual refresh included

Multi-framework

€2,500/ system / year

NIST AI RMF and ISO 42001 evidence packs for organisations operating across EU and US.

  • NIST AI RMF mapping
  • ISO 42001 mapping
  • Cross-framework comparison
  • Single source of truth
Why VERA.AI

We're not replacing anyone. We're adding the missing layer.

Need What you use today VERA.AI adds
Data labelingEncord, Labelbox, Scale AIConnector, no replacement
AI governanceCredo AI, Holistic AI, OneTrustConnector, no replacement
Model trainingSageMaker, Vertex AI, Azure MLMetadata import
Annex IV documentationManual Word/PowerPoint, 6-9 monthsAuto-generated in days
Audit chain proofNothing (or claims only)SHA-256 hash chain, verifiable
PII pseudonymisationManual or noneHMAC-SHA256 automatic
Multi-framework (EU + US)Two separate projectsOne platform, both packs
Enforcement timeline

December 2027 is closer than it feels.

Building Annex IV documentation for a complex AI system takes 6-9 months. Starting in 2026 is normal procurement timing for a 2027 deadline.

Aug 2026

GPAI obligations and prohibited practices in force

Article 5 prohibitions and Article 50 transparency obligations remain enforceable from August 2026 regardless of Omnibus.

Dec 2 2027

High-risk Annex III obligations apply

Banking AI, insurance AI, hiring AI, public sector AI all require complete Annex IV documentation. No exceptions.

Aug 2 2028

High-risk Annex I obligations apply

AI in medical devices, automotive safety, industrial machinery, and other regulated products.

See your Annex IV readiness in 30 days.

Free assessment: submit one AI system, we deliver a complete Annex IV readiness report and a sample evidence pack. No commitment.

Request your free assessment