cd /news/ai-policy/attestly · home topics ai-policy article
[ARTICLE · art-127502] src=attestly.online ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Attestly

Attestly launched a tool that reads AI agent execution traces from OpenTelemetry, LangSmith, AgentOps, or MCP logs and converts them into EU AI Act Annex IV technical documentation, risk-management summaries, conformity-assessment checklists, and audit-ready evidence trails. The product maps tool calls, model calls, human interventions, and errors to Annex IV requirements, requires a person to review, edit, or reject every generated section before it counts as final, and cryptographically hashes each approval for tamper-evident records. Attestly states it does not provide legal advice or guarantee regulatory compliance, positioning itself as a trace-to-documentation drafting tool rather than a replacement for legal review, a GRC platform, or an AI firewall.

read4 min views3 publishedSep 12, 2026
Attestly
Image: source

EU AI Act · Technical Documentation

Attestly reads the traces your agents already produce and turns them into EU AI Act technical documentation, risk-management records, and audit-ready evidence — continuously, not as a quarterly scramble.

How it works

Your agents run

OpenTelemetry, LangSmith, AgentOps, or MCP logs — whatever you already emit.

Attestly structures it

Tool calls, model calls, human interventions, and errors, normalized and mapped to Annex IV.

A person signs off

Every generated section is reviewed, edited, or rejected before it counts as final.

What it generates

Annex IV technical documentation

General description, design specification, and monitoring measures — drafted from what your system actually did.

Risk-management summaries

Identified risks, mitigations, and residual risk, traced back to the events that surfaced them.

Conformity-assessment checklists

A running view of what's covered, what's missing, and what still needs a human decision.

Audit-ready evidence trails

Every generated sentence links to the specific trace event that justified it, and every approval is cryptographically hashed — tamper-evident, not just asserted.

Who it's for

AI startups

Deploying an autonomous agent to EU customers and need Annex IV documentation before launch, without a dedicated compliance hire.

Enterprise AI teams

Running internal or customer-facing agents across multiple systems that all need ongoing, not one-time, documentation as behavior changes.

Compliance and risk teams

Currently reconstructing what an AI system did by hand from logs and interviews, and need a structured, evidence-linked starting point instead.

AI governance consultancies

Producing Annex IV documentation for multiple clients and need a tool that turns each client's traces into a first draft, rather than starting from a blank template every time.

Background

The EU AI Act requires providers of high-risk AI systems to maintain technical documentation under Annex IV before the system is placed on the market, and to keep it current as the system changes. Annex IV specifies several required elements: a general description of the system and its intended purpose, details of its design and development process, information on how it's monitored and controlled once deployed, performance and validation metrics, risk-management measures, and a record of significant changes made across the system's lifecycle.

In practice, most of the underlying evidence for these sections already exists inside the system's own operational traces — which tool calls it made, when a human intervened, what errors occurred, what changed between deployments. Attestly's role is to read that evidence directly from your traces and map it against each Annex IV requirement, rather than have someone manually reconstruct it after the fact from logs, tickets, and memory.

Why not a generic GRC platform

Broad AI-governance platforms are built around policy management, system inventories, and monitoring dashboards — useful for tracking that an AI system exists and has an owner, but they don't ingest an agent's actual execution traces and turn them into drafted Annex IV documentation with evidence links back to specific events. That gap — live agent behavior into structured, evidence-backed compliance documentation — is the specific problem Attestly is built to solve, not a broader governance dashboard.

Attestly isn't a replacement for legal review, a GRC platform, or an AI firewall. It's the tool that turns operational trace data into a documentation draft a compliance professional can review in minutes instead of building from scratch.

Free tool

Not sure if your AI system is high-risk?

Answer a few questions and get a directional EU AI Act risk classification.

Frequently asked

Does Attestly provide legal advice or guarantee compliance?

No. Attestly does not provide legal advice and does not guarantee regulatory compliance. Every generated section is reviewed, edited, and approved by a human before it counts as final.

What trace sources does Attestly support?

Attestly ingests OpenTelemetry traces, LangSmith runs, AgentOps sessions, and generic pre-normalized JSON.

Who is Attestly for?

AI startups shipping agents to EU customers, enterprise AI teams running multiple systems, compliance and risk teams, and AI governance consultancies producing documentation for clients.

How is Attestly different from a generic AI governance platform?

Broad AI-governance tools focus on policy management, system inventories, and monitoring dashboards. Attestly specifically ingests an agent's operational traces and turns them into drafted Annex IV documentation with evidence links back to the exact events that justify each section — a narrower, deeper problem than a general governance dashboard covers.

Is there a free plan?

Yes. The free tier includes one AI system and ten lifetime documentation generations, enough to fully draft one system's Annex IV documentation and see the product work before subscribing.

How does Attestly know what to write in each documentation section?

Each EU AI Act Annex IV requirement is mapped against the specific trace events (tool calls, model calls, human interventions, errors, system events) relevant to it. Drafting is grounded only in that linked evidence — the system is instructed to flag gaps explicitly rather than invent plausible-sounding text where evidence is missing.

What happens to my trace data?

Trace data is stored per-organization with row-level database access controls, so one organization can never see another's data. Only the specific events linked as evidence for a documentation section are sent to the AI model used for drafting that section.

What format is the exported documentation in?

Attestly exports a Word (.docx) document containing every requirement, its current review status, whether it's AI-generated or human-edited, and a list of the exact trace events used as supporting evidence.

── more in #ai-policy 4 stories · sorted by recency
── more on @attestly 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/attestly] indexed:0 read:4min 2026-09-12 ·