Knowledge base / regulation10.com product guide (EU AI Act)
Generate an evidence pack and share it with a notified body
To produce an evidence pack, open the AI system and click Generate evidence pack. The platform assembles the system's completed module runs, technical documentation, and a tamper-evident audit trail into a single export suitable for a conformity assessment. You can then share it with a notified body or a market surveillance authority through a time-limited, access-controlled share link, or download it and send it directly.
The EU AI Act makes this kind of export necessary rather than optional for high-risk systems. Providers of high-risk AI systems must draw up technical documentation (Article 11 and Annex IV), keep records, and be able to demonstrate conformity when a notified body assesses the system or a market surveillance authority asks. The obligation is not just to do the work but to produce it on request in an examinable form. The pack is the platform's answer to that production problem.
What the export contains is the system's actual record: each completed module run with findings and scores, the technical documentation and files you attached, and the audit trail showing who did what and when. Nothing is drafted specially for the reviewer. If your record is incomplete, the pack shows it as incomplete. This is intentional. An assessment body reads many submissions, and a record with honest gaps and visible remediation history is more credible than one that appears finished everywhere the reviewer happens to look.
The audit trail is tamper-evident, so a reviewer can verify that entries were not edited after the fact. For conformity work this converts your history from an assertion into something checkable, which is what the assessment process is for.
Generating a pack discloses nothing by itself. Sharing is a separate step, taken from the evidence page when you decide to disclose. A share link is time-limited, lapsing on the date you set, and access-controlled, so it reaches the intended reviewer rather than anyone who obtains the URL. If the receiving body requires files through its own channel, download the pack and submit it there; the content is identical.
Every generation and every share is written to the audit log. That gives you a precise record of what was disclosed, to whom, and when. If a market surveillance authority later asks what a notified body had before it at a particular date, you can answer from the log rather than from memory.
Packs are point-in-time. An export reflects the record at generation, and work done afterwards does not alter a pack already shared. When the record moves on, generate a new pack.
A working rhythm that suits conformity preparation: complete the module runs the system's classification calls for, generate a pack, review it internally as though you were the notified body, fix what you find, and only then share. Issues found in your own read-through cost you an afternoon. The same issues found during the assessment cost you the assessment timeline.
Ownership of the rhythm matters as much as the mechanics. The compliance lead usually decides when a pack is generated and reviewed, while each system owner supplies whatever the internal read-through shows to be missing. Running that review as one working session, with both people present, closes gaps in hours that an email thread would stretch across weeks.
Steps
- Open the AI system and click Generate evidence pack.
- Let the platform assemble your module runs, technical documentation, and audit trail.
- Create a time-limited, access-controlled share link for a notified body or market surveillance authority.