Annex IV Compliance Evidence System

Other tools log
your agents.
PROVA proves
them compliant.

The only platform that auto-generates regulator-ready Annex IV documentation
  • //EU AI Act · Annex IV Technical Documentation · Auto-generated
  • //Microsoft AGT enforces policy. PROVA proves compliance to regulators.
  • //Annex III high-risk · 02 Dec 2027 (Digital Omnibus, pending adoption) · Fines up to €35M
  • //Deploy in 4 hours. Document auto-generates. Regulator export in one click.
Time
Agent ID
Action
Risk
Status
0 events loggedPROVA LIVE
EU AI Act · Annex III high-risk · Reg. 2024/1689Agreed 2027-12-02 · Digital Omnibus, pending adoption
590Days
·
00Hours
·
00Minutes
·
00Seconds
0
Other agent tools that auto-generate EU AI Act Annex IV documentation
€52K
Annual compliance cost per high-risk AI system without PROVA — manual consultant path
4 hrs
From zero to Annex IV draft no lawyers, no consultants, no months
//Free tool — no signup required

One flow.
Four jurisdictions.

Answer 6 questions. PROVA maps your AI against the EU AI Act plus every active US state law — simultaneously. No lawyers. No consultants. Classification in under 60 seconds.

EU / Global
EU AI Act
Regulation (EU) 2024/1689
High-risk — Dec 2027*

Annex III high-risk + GPAI, Annex IV documentation, Art. 14 human oversight. *Digital Omnibus agreed 7 May 2026 (Annex III 2 Dec 2027, Annex I 2 Aug 2028) — pending formal adoption; obligations unchanged.

Colorado, US
Colorado AI Act
SB 24-205
Stayed — est. Jan 2027

High-risk consequential decisions — employment, credit, healthcare. Developer + deployer obligations. $20K/violation.

Texas, US
Texas TRAIGA
HB 4 / Government AI
In force — Jan 2026

Government AI — law enforcement, justice, critical infrastructure. Behavioral manipulation prohibited outright.

Illinois, US
Illinois HB 3773
Employment AI Act
In force — Jan 2026

Hiring + HR AI — mandatory pre-use notice, opt-out rights, IDOL enforcement. Applies to all Illinois employers.

Get your free classification →No signup  ·  60 seconds  ·  4 jurisdictions
//Regulatory intelligence
Regulatory Radar.
10 jurisdictions. Live.

EU AI Act, Colorado, Texas, Illinois, California AB 2013, New York S 5152, China, Brazil, Canada AIDA, EU AI Liability Directive — tracked in one place. Enforcement dates, recent developments, and PROVA coverage status for every law.

Open Regulatory Radar →
//How it works

Watch PROVA
in 60 seconds.

From the enforcement deadline to the Annex IV export. Six scenes. The full picture — no fluff, no corporate voice-over.

//01 The crisis

Most enterprises are
completely exposed.

The EU AI Act doesn’t govern how you store data — it governs how your AI thinks and acts. For every autonomous agent running in production, you need a full compliance envelope: auditable workflows, human oversight gates, explainable decisions, and complete Annex IV technical documentation.

If you’re running agents in fraud detection, credit decisioning, HR automation, or regulatory reporting — you’re already in scope.

The Digital Omnibus (agreed 7 May 2026) moved the Annex III high-risk date to 2 December 2027, pending formal adoption. The deadline moved. The obligation didn’t. Annex IV documentation, Art. 12 records and Art. 14 oversight are unchanged — and regulators will be less forgiving for having granted the extra runway. A half-built program in late 2027 is a worse position than the same program would have been under the original date.

// EU AI Act Article 99 — Penalties
Prohibited AI practices: up to €35M or 7% global turnover
High-risk violations: up to €15M or 3% global turnover
Misleading information: up to €7.5M or 1.5% global turnover

// Gap 01
50%+ of organizations have no systematic inventory of AI systems in production. You can’t comply with what you can’t find. PROVA Registry solves this on day one.
// Gap 02
Annex IV technical documentation must exist for every high-risk agent. Creating it manually takes months of engineering and legal time. PROVA Docs generates it from your audit trail.
// Gap 03
EU AI Act Article 14 mandates human oversight with clear intervention points. Most agent architectures have none. PROVA Audit adds configurable gates in 4 hours.
// Gap 04
Behavioral drift — when an agent’s actions deviate from its documented baseline — is a direct compliance violation. Static monitoring misses it. PROVA detects it in real time.
//02 The stack

Three layers.
One SDK.
4 hours.

PROVA wraps any AI agent — Claude, GPT, Gemini, open-source — with a complete EU AI Act compliance envelope. Drop in the SDK. No architectural rewrites. No months of consultant time.

01 / PROVA Audit

The compliance SDK

Every agent action intercepted, logged, classified, and signed. The full compliance envelope in two lines of code.

// Risk classification
action.riskHIGH_RISK
action.gateBLOCKED
// Awaiting human oversight
statusESCALATED
  • Immutable audit trail — every action timestamped and signed
  • Human oversight gates — configurable intervention points
  • Annex III risk classification per action, real-time
  • Typed exit states: compliant / flagged / escalated / blocked
  • MCP-native — hooks directly into tool calls
02 / PROVA Docs — The Moat

Annex IV. Auto-generated.

The one thing no other agent tool does. EU AI Act Annex IV technical documentation, generated automatically from your audit trail. What regulators require, what lawyers charge months to produce — PROVA generates in minutes.

// Annex IV status
compliance.scoreA+
annex_iv.statusCOMPLETE
// Microsoft AGT: logs. PROVA: proves.
exportREGULATOR_READY
  • Auto-generated Annex IV technical documentation — from audit trail
  • Per-agent compliance score (A/B/C/F) with gap analysis
  • Article-by-article EU AI Act regulatory mapping
  • One-click regulator export package (PDF + JSON)
  • CE marking readiness report
03 / PROVA Registry

The enterprise command center

Central visibility across every AI system in your organization. The inventory your General Counsel needs before the Annex III high-risk date.

// Registry status
agents.total47
agents.compliant44
agents.at_risk3
deadlineDec 2027
  • Central AI system inventory — solve the 50% blind-spot problem
  • Per-agent compliance status with countdown
  • Article 73 incident tracking and automated reports
  • Role-based access: GC / CTO / Engineering views
  • GRC tool integration API (ServiceNow, Jira)
// Microsoft Agent Governance Toolkit
Proves your agents
are secure.
Policy enforcement · Audit logging · OWASP coverage
Free. MIT. From Microsoft.

But it does not produce what regulators require.
// PROVA — the one thing Microsoft can’t give you
Proves your agents
are compliant.
Annex IV technical documentation · Regulator export
Compliance score per agent · 7-year immutable storage

The package that goes to the EU authority. Not the log.
//04 The moat

Annex IV.
Auto-generated.
Regulator-ready.

EU AI Act Annex IV technical documentation is the most underestimated compliance burden. Regulators can request it at any time. It must cover decision logic, data governance, human oversight architecture, test methodologies, risk assessments, and post-market monitoring.

Most enterprises would need 3–6 months of outside counsel and internal engineering to produce this manually. PROVA generates it automatically from the audit trail it’s already collecting.

Art. 11
Technical documentation
System description, intended purpose, design specifications — auto-generated from your agent config and audit history.
Art. 12
Record keeping
Immutable audit trail with 7-year retention. Cryptographically signed. Stored in append-only cloud — nobody can modify it.
Art. 14
Human oversight
Every configured oversight gate is documented with intervention points, escalation paths, and human decision records.
Art. 15
Accuracy and robustness
Behavioral drift scores, baseline deviation alerts, and performance monitoring — all auto-included in the Annex IV package.
Art. 73
Incident reporting
BLOCKED events auto-filed as incidents. Full incident history included in regulator export package.
// PROVA Docs — Live Preview
Annex IV Technical Documentation
Score: AExport PDF
Section 1 — General Description (Art. 11)
System ID: loan-screener-v2
Purpose: Autonomous agent for credit application assessment and loan eligibility determination
Risk classification: HIGH-RISK — Annex III §5(b): Access to essential services
Deployment context: Financial services · EU data subjects
Section 3 — Audit Record Summary (Art. 12)
2,847
Compliant
143
Flagged
12
Blocked
Section 5 — Human Oversight Architecture (Art. 14)
Oversight gates configured: credit_decision, application_denial, income_verification
Intervention mechanism: Async escalation queue · 5-minute human decision window
Fallback policy: BLOCK (no execution without approval)
Human decisions recorded: 155 escalations · 138 approved · 5 rejected
Section 6 — Behavioral Monitoring (Art. 15)
Drift: 18/100 — Stable
Baseline established over 30-day window. Alert threshold: 15 points. No drift alerts triggered in reporting period.
Export Status
✓ CE Marking Ready✓ Annex IV CompleteCompliance: A
// Generated from 3,002 audit events · 4.2sgetprova.dev
//05 Integration

From install to
regulator-ready.

01

Install the SDK

One npm or pip install. The PROVA Audit core is open-source — inspect every line before you deploy.

02

Wrap your agent

Two lines of code. PROVA intercepts the async generator loop and wraps every tool call with audit and risk classification. No architectural rewrites required.

03

Configure oversight gates

Define which decisions require human intervention before execution. This is EU AI Act Article 14 — PROVA makes it configurable, not hard-coded.

04

Generate your documentation

PROVA Docs auto-generates Annex IV technical documentation from the audit trail it’s already collecting. What takes lawyers months, PROVA does in minutes.

# Install
npm install @prova-ai/audit
 
# Wrap your agent
import { ProvaAudit } from '@prova-ai/audit';
 
const agent = new ProvaAudit({
agentId: 'loan-screener-v2',
apiKey: process.env.PROVA_KEY,
riskProfile: 'high-risk',
oversightGates: [
'credit_decision',
'application_denial' 
]
});
 
# Typed exit states
const result = await agent.run(message);
# compliant | flagged | escalated | blocked
getprova.dev/docs
//06 Pricing

Start free.
Scale when you need to.

No platform fees. Usage-based beyond free tier. Cancel anytime. Enterprise pricing per agent, not per seat. The free tier gives you everything you need to validate PROVA against your stack.

// Starter
$0
1 agent · 10K events/mo
  • PROVA Audit SDK (open-source)
  • Basic audit trail
  • Compliance score
  • Community support
  • Human oversight gates
  • PROVA Docs
  • PROVA Registry
Start free
Popular
// Growth
$999/mo
10 agents · 1M events/mo
  • Everything in Starter
  • Human oversight gates
  • Full PROVA Docs suite
  • PROVA Registry dashboard
  • Annex IV documentation
  • Email support
  • Custom GRC integrations
Start Growth trial
// Scale
$4,999/mo
50 agents · 10M events/mo
  • Everything in Growth
  • Multi-region audit storage
  • Team role-based access
  • Article 73 auto-reporting
  • CE marking readiness
  • Priority support
  • Dedicated CSM
Start Scale trial
// Enterprise
Custom
Unlimited agents + events
  • Everything in Scale
  • Custom GRC integrations
  • Compliance cert support
  • Dedicated CSM
  • 99.99% SLA + BAA
  • On-premises deployment
  • White-glove onboarding
Talk to sales
//07 Proof

Early teams
shipping compliant.

We had 12 agents in production with zero documentation. Our GC gave us 6 weeks to fix it or shut them down. PROVA had us audit-ready in a weekend. The Annex IV doc generator alone is worth the price of the enterprise plan.

MR
M. Richter
// Head of AI Infrastructure, FinTech · Frankfurt

I evaluated three compliance vendors. Two required a 3-month implementation. PROVA's SDK wrapped our entire MCP server in 90 minutes. The Registry dashboard is what sold our CISO — full inventory, live compliance scores, one screen.

SL
S. Laurent
// CTO, Enterprise SaaS · Paris

We build AI agents for our enterprise clients. PROVA is now baked into our deployment pipeline. Every client we ship gets a compliance score on day one. It's become a sales differentiator — 'PROVA-certified' closes deals.

AK
A. Kowalski
// Founder, AI Agency · Warsaw
//08 Deploy

Every day without
Annex IV is a liability.
PROVA takes 4 hours.

// The only platform that auto-generates what regulators actually require.

Free tier. Open SDK. No card.

1 agent, 10K events/month — wired to a real Annex IV draft in the dashboard. The fastest path to seeing what your regulator envelope actually looks like.

Deploy PROVA free — start in 4 hours →

// No credit card. Free tier includes 1 agent + 10K events/month.

Free toolClassify your AI in 60 seconds — EU AI Act + Colorado + Texas + Illinois.No signup · No card
Get free classification →