⚖️ EVIDE & AI Act
Evidence for Regulatory Requirements and Disputes
When the functioning of an AI system needs to be examined, it helps to be able to reconstruct the operational context, the available artefacts, the documented human oversight and the sequence of events. EVIDE contributes to preserving and making verifiable the material received, within a declared perimeter.
Section 1
1. Explore the detailed framework in your language
This page is EVIDE's English-language regulatory reference. The detailed evidentiary-defensibility framework it draws on is also available in four other languages, on EVIDE's AI Governance Dispute Defense Layer page.
Section 2
2. Regulatory requirements and evidentiary questions
Regulatory obligations under the AI Act fall on specific addressees - mainly providers (who develop or have developed the AI system) and deployers (who use it under their own authority). The table below keeps that distinction explicit, and separates what the regulation requires from how EVIDE can help document it.
| Regulatory area | Evidence question | How EVIDE can help |
|---|---|---|
| Event logging & log preservation Art. 12 (provider) · Art. 26(6) (deployer) |
Providers must design high-risk systems to enable automatic event logging. Deployers must then keep those logs, to the extent under their control, for at least six months. Can the retained logs later be related to an independently anchored reference? | EVIDE can receive and retain a submitted log file directly, computing its own hash and keeping it available for retrieval - or, for a log held externally, anchor the sender's declared reference and hash without itself verifying that the external file exists or matches it. |
| Human oversight documentation Art. 14 (provider) · Art. 26(2) (deployer) |
Providers must design for effective human oversight; deployers must assign it to competent, trained individuals with the necessary authority. Can a specific instance of human review or intervention be shown, rather than only asserted? | EVIDE can preserve a declared record of an oversight event - what was reviewed, by whom it was declared to be reviewed, what action followed - as submitted, within the agreed scope. |
| Risk management & technical documentation Art. 9 · Art. 11 (provider) |
Providers must maintain a risk management system and technical documentation covering the system's design, risks and mitigations. Can the state of that documentation at a given point in time be fixed and later verified? | EVIDE can receive and retain submitted documentation directly, computing its own hash - or, for documentation held externally, anchor the sender's declared reference and hash without itself verifying the external material's existence or content. |
| Incident monitoring & reconstruction Art. 72 (provider) · Art. 26(5) (deployer) |
Providers must monitor system performance after deployment; deployers must monitor operation and inform the provider or market surveillance authority of emerging risks. After an incident, can the sequence of declared events be reconstructed from material preserved independently of the system itself? | EVIDE can preserve, as submitted within scope, the declared sequence of inputs, classifications, actions and human interventions associated with an event, so later reconstruction does not depend solely on the system's own account. |
| External review & disputes General - applies across providers and deployers |
When a decision or outcome is challenged, can material be presented that was preserved before the dispute began, by a party independent of the one being examined? | EVIDE's role is to preserve declared material independently and make its anchoring verifiable. What weight that material carries in a given review or dispute is for the examining authority, not EVIDE, to determine. |
Section 3
3. Italian national legislation — D.Lgs. 160/2026
The obligations above come from Regulation (EU) 2024/1689 (the AI Act), which applies across the Union. Separately, Italy has adopted national legislation that is relevant to the same questions but operates under its own rules.
Legislative Decree 9 September 2026, no. 160 (in force from 30 September 2026) introduces, among other things, Article 437-bis of the Italian Criminal Code and Articles 17 to 19 on civil proceedings. These are Italian national provisions. Whether and how they apply to a given system, organisation or dispute must be assessed case by case, with qualified legal advice.
Art. 437-bis of the Criminal Code: criminalises the omission of required technical security measures or human-oversight measures, and the alteration of a high-risk AI system, when concrete danger to life, to public or individual safety, or to State security results. Grave negligence and intentional omission by a professional user are separately addressed.
Articles 17-19 of the decree (civil proceedings): Article 17 lets a court order disclosure of material relevant to how an AI system functioned; Article 18 provides a rebuttable presumption of causal link where damage results from a breach of AI Act obligations; Article 19 states that certified conformity with the AI Act does not by itself exclude liability.
Note: "Article 17" here refers to Article 17 of this Italian decree (access to evidence). It is a different provision from Article 17 of the EU AI Act itself, which concerns providers' quality management systems. The two should not be confused.
Section 4
4. What EVIDE does not do
- EVIDE supports reconstruction within the boundary of the material actually preserved.
- EVIDE does not replace security measures, human oversight or risk management.
- EVIDE does not automatically certify compliance with the AI Act.
- EVIDE does not determine lawfulness, fault or responsibility.
- EVIDE does not guarantee the admissibility or sufficiency of its records as evidence.
- Anchoring alone does not automatically establish the truth of the original content.
References
- Regulation (EU) 2024/1689 (AI Act), official text: eur-lex.europa.eu
- D.Lgs. 9 September 2026, n. 160 (Italy), official text: normattiva.it
- EVIDE for Legal & Evidentiary Use: app.certifywebcontent.com/legal-evidentiary-use
- EVIDE ANCHOR (declared operational perimeter): app.certifywebcontent.com/docs/evide-anchor/
- EVIDE External Artifacts: app.certifywebcontent.com/docs/evide-artifacts/
- EVIDE for Healthcare and Diagnostic AI: app.certifywebcontent.com/docs/evide-healthcare-diagnostic-ai/
- EVIDE for Home Robotics: app.certifywebcontent.com/docs/evide-home-robotics/
- AI Governance Dispute Defense Layer (5 languages): certifywebcontent.com
- EVIDE Governance Lab: lab.certifywebcontent.com
- Contact: info@certifywebcontent.com