EU AI Act · Article 9(8) · evidence flow

Article 9(8): how do you show the metrics and thresholds were prior defined?

The Act says what testing must be done against. It does not say how you prove the "prior". This page gives you two ways to make that fact checkable by someone who does not have to trust you: read what your existing test plan already shows, or create a criteria record whose timing a third party can verify.

"Testing shall be carried out against prior defined metrics and probabilistic thresholds that are appropriate to the intended purpose […]"Regulation (EU) 2024/1689, Article 9(8), second sentence (quoted up to the point where the 2024 wording and the consolidated text diverge; verify against EUR-Lex before citing). Annex IV 2(g) asks the technical documentation to describe the validation and testing procedures, the metrics used, the test data, and to include test logs and reports dated and signed by the responsible persons. Neither provision requires a timestamp or a cryptographic record; this page is about evidence, not additional obligations.

This reading works only from the document you provide. It does not determine what happened outside that document, and it does not assess conformity.

or try a sample test plan

We do not retain your document. The text is sent to an AI model provider for analysis. We retain only anonymous usage metadata (document length and the five labels), not the document text. Do not submit confidential or personal information unless you are comfortable with that processing.

Reading against Article 9(8) and Annex IV 2(g)

Quotes are verbatim from your text. Where a check has no supporting text, the tool says so; it does not conclude that the evidence does not exist.

Want the timing itself to be independently checkable next time? Use Door 2 to create the criteria record before the next test campaign, or read what a PRML record is.

Ask a question →

Everything below runs in your browser. Nothing is sent anywhere unless you press "Anchor in the public registry".

One record per metric. For several thresholds, create several records; the digests can be listed together in Annex IV 2(g). The dataset hash should be the SHA-256 of the exact test files; if you do not have it yet, compute it before the test campaign, not after.

Criteria record

Canonical bytes (PRML v0.1)

      
SHA-256 of the canonical bytes

What this record establishes

Criteria object
Digest
Time evidence
None yet. The digest above is computed locally; its time is your clock. Anchor it to obtain an independent time.
Execution ordering
Not established by this record. A record proves that the criteria object existed no later than its anchored time; it does not prove that the test ran after that time. Keep the test run's own dated, signed report (Annex IV 2(g)) next to this record; ordering follows only when the report's date is later and the report names this digest.
Suggested sentence for Annex IV 2(g)

What Article 9(8) asks for, and what this page adds

The obligation is on the provider: testing must be carried out against metrics and thresholds that were defined beforehand and are appropriate to the intended purpose. The technical documentation (Annex IV 2(g)) then has to describe those metrics and the test data and include dated, signed test reports. A notified body, a market surveillance authority or an auditor reading that documentation later has one recurring difficulty: the document says the thresholds were defined first, and the document's own dates are the provider's dates.

This page does not add an obligation. It adds evidence. Door 1 reads your existing text and says, with quotes, what an outside reader can and cannot establish from it. Door 2 turns the criteria into a small canonical record with a digest; anchoring the digest at a public registry gives it an RFC 3161 timestamp from a public time-stamping authority and an entry in a public transparency log, so the time no longer rests on any single party's clock. The record format is PRML, an open specification with a registered media type; the procedure works with any format that produces a reproducible digest.

What the record proves and does not prove

Related: Evidence Check (general documents) · Reproducible is not pre-registered · NIST AI 300-1, field 6.5 · PRML playground.