EU AI Act templates, without the e-mail form
7 of the documents the Regulation asks for — the Annex IV technical file, an AI system inventory built on the Annex VIII fields, the Article 27 FRIA, the declaration of conformity, an Article 50 disclosure register, the Article 73 incident report and the post-market monitoring plan.
Every template on this page is readable in full right here, copyable as Markdown, and downloadable as a PDF. No sign-up, no e-mail address, no click-to-reveal.
Why a library like this exists at all
The Regulation instructs the Commission and the AI Office to prepare several model forms — among them the Article 27(5) FRIA questionnaire and the simplified technical-documentation form for small and microenterprises foreseen in Article 11(1). At the time of writing those have not been issued, so every provider and deployer is drafting from the bare text of the Act. These are our drafts of that text: complete, free, and downloadable without handing over an address.
Not an official document. This is a working draft built from the text of Regulation (EU) 2024/1689 — it is not issued or endorsed by the European Commission, any national authority or any notified body, and it is not legal advice. Fill it in with your own facts and have it reviewed by counsel before you rely on it.
Which of these is yours
The Act attaches documents to roles, and one company usually holds several. Pick the description that matches what you do with a given system — not what your company does in general.
You build the AI system and put your name on it
You are the provider. The technical file, the declaration and the monitoring plan are yours, and so is the incident report if something goes wrong.
You use an AI system somebody else built
You are the deployer, with independent duties. Start with the inventory; if you are a public body, provide a public service, or score creditworthiness or life and health insurance risk, the FRIA is mandatory before first use.
Your product talks to people or generates content
Transparency duties under Article 50 have applied since 2 August 2026. The hard part is not writing the notice — it is proving which notice was live, where, and from when.
The library
Annex IV technical documentation
The nine-section technical file a provider of a high-risk AI system has to draw up before the system goes on the market.
AI system inventory and register
One row per AI system, with the columns the EU database will ask for — so the register you keep internally is the register you can file from.
Fundamental Rights Impact Assessment (FRIA)
The six-element assessment certain deployers of high-risk AI must complete before the first use of the system.
EU Declaration of Conformity
The provider's signed statement that a high-risk AI system conforms — one page, kept for ten years, produced on request.
Article 50 AI disclosure register
One row per surface: the notice text you actually shipped, where it appears, when it went live, and who owns it.
Serious incident report (Article 73)
The dossier you send to the market-surveillance authority, and the clock that starts the moment you become aware.
Post-market monitoring plan
How you will know the system is still behaving after launch — sources, thresholds, owners, and the route to an incident report.
What a template does not do
It does not classify your system, and every document here is downstream of that one decision — a technical file for a system that turns out not to be high-risk is wasted work, and no file at all for one that is, is the expensive mistake. Run the free risk checker first, or read the Article 6 classification rules.
It also does not fill itself in. Every section below carries a note on what an assessor looks for, because the difference between a file that survives scrutiny and one that does not is almost never the headings — it is whether the answers are specific, dated and owned by a named person.