{"slug": "attestly", "title": "Attestly", "summary": "Attestly launched a tool that reads AI agent execution traces from OpenTelemetry, LangSmith, AgentOps, or MCP logs and converts them into EU AI Act Annex IV technical documentation, risk-management summaries, conformity-assessment checklists, and audit-ready evidence trails. The product maps tool calls, model calls, human interventions, and errors to Annex IV requirements, requires a person to review, edit, or reject every generated section before it counts as final, and cryptographically hashes each approval for tamper-evident records. Attestly states it does not provide legal advice or guarantee regulatory compliance, positioning itself as a trace-to-documentation drafting tool rather than a replacement for legal review, a GRC platform, or an AI firewall.", "body_md": "EU AI Act · Technical Documentation\n\nAttestly reads the traces your agents already produce and turns them into EU AI Act technical documentation, risk-management records, and audit-ready evidence — continuously, not as a quarterly scramble.\n\nHow it works\n\nYour agents run\n\nOpenTelemetry, LangSmith, AgentOps, or MCP logs — whatever you already emit.\n\nAttestly structures it\n\nTool calls, model calls, human interventions, and errors, normalized and mapped to Annex IV.\n\nA person signs off\n\nEvery generated section is reviewed, edited, or rejected before it counts as final.\n\nWhat it generates\n\nAnnex IV technical documentation\n\nGeneral description, design specification, and monitoring measures — drafted from what your system actually did.\n\nRisk-management summaries\n\nIdentified risks, mitigations, and residual risk, traced back to the events that surfaced them.\n\nConformity-assessment checklists\n\nA running view of what's covered, what's missing, and what still needs a human decision.\n\nAudit-ready evidence trails\n\nEvery generated sentence links to the specific trace event that justified it, and every approval is cryptographically hashed — tamper-evident, not just asserted.\n\nWho it's for\n\nAI startups\n\nDeploying an autonomous agent to EU customers and need Annex IV documentation before launch, without a dedicated compliance hire.\n\nEnterprise AI teams\n\nRunning internal or customer-facing agents across multiple systems that all need ongoing, not one-time, documentation as behavior changes.\n\nCompliance and risk teams\n\nCurrently reconstructing what an AI system did by hand from logs and interviews, and need a structured, evidence-linked starting point instead.\n\nAI governance consultancies\n\nProducing Annex IV documentation for multiple clients and need a tool that turns each client's traces into a first draft, rather than starting from a blank template every time.\n\nBackground\n\nThe EU AI Act requires providers of high-risk AI systems to maintain technical documentation under Annex IV before the system is placed on the market, and to keep it current as the system changes. Annex IV specifies several required elements: a general description of the system and its intended purpose, details of its design and development process, information on how it's monitored and controlled once deployed, performance and validation metrics, risk-management measures, and a record of significant changes made across the system's lifecycle.\n\nIn practice, most of the underlying evidence for these sections already exists inside the system's own operational traces — which tool calls it made, when a human intervened, what errors occurred, what changed between deployments. Attestly's role is to read that evidence directly from your traces and map it against each Annex IV requirement, rather than have someone manually reconstruct it after the fact from logs, tickets, and memory.\n\nWhy not a generic GRC platform\n\nBroad AI-governance platforms are built around policy management, system inventories, and monitoring dashboards — useful for tracking that an AI system exists and has an owner, but they don't ingest an agent's actual execution traces and turn them into drafted Annex IV documentation with evidence links back to specific events. That gap — live agent behavior into structured, evidence-backed compliance documentation — is the specific problem Attestly is built to solve, not a broader governance dashboard.\n\nAttestly isn't a replacement for legal review, a GRC platform, or an AI firewall. It's the tool that turns operational trace data into a documentation draft a compliance professional can review in minutes instead of building from scratch.\n\nFree tool\n\nNot sure if your AI system is high-risk?\n\nAnswer a few questions and get a directional EU AI Act risk classification.\n\nFrequently asked\n\nDoes Attestly provide legal advice or guarantee compliance?\n\nNo. Attestly does not provide legal advice and does not guarantee regulatory compliance. Every generated section is reviewed, edited, and approved by a human before it counts as final.\n\nWhat trace sources does Attestly support?\n\nAttestly ingests OpenTelemetry traces, LangSmith runs, AgentOps sessions, and generic pre-normalized JSON.\n\nWho is Attestly for?\n\nAI startups shipping agents to EU customers, enterprise AI teams running multiple systems, compliance and risk teams, and AI governance consultancies producing documentation for clients.\n\nHow is Attestly different from a generic AI governance platform?\n\nBroad AI-governance tools focus on policy management, system inventories, and monitoring dashboards. Attestly specifically ingests an agent's operational traces and turns them into drafted Annex IV documentation with evidence links back to the exact events that justify each section — a narrower, deeper problem than a general governance dashboard covers.\n\nIs there a free plan?\n\nYes. The free tier includes one AI system and ten lifetime documentation generations, enough to fully draft one system's Annex IV documentation and see the product work before subscribing.\n\nHow does Attestly know what to write in each documentation section?\n\nEach EU AI Act Annex IV requirement is mapped against the specific trace events (tool calls, model calls, human interventions, errors, system events) relevant to it. Drafting is grounded only in that linked evidence — the system is instructed to flag gaps explicitly rather than invent plausible-sounding text where evidence is missing.\n\nWhat happens to my trace data?\n\nTrace data is stored per-organization with row-level database access controls, so one organization can never see another's data. Only the specific events linked as evidence for a documentation section are sent to the AI model used for drafting that section.\n\nWhat format is the exported documentation in?\n\nAttestly exports a Word (.docx) document containing every requirement, its current review status, whether it's AI-generated or human-edited, and a list of the exact trace events used as supporting evidence.", "url": "https://wpnews.pro/news/attestly", "canonical_source": "https://www.attestly.online/", "published_at": "2026-09-12 07:07:03+00:00", "updated_at": "2026-09-12 07:27:53.755033+00:00", "lang": "en", "topics": ["ai-policy", "ai-agents", "ai-tools", "ai-startups"], "entities": ["Attestly", "EU AI Act", "Annex IV", "OpenTelemetry", "LangSmith", "AgentOps", "MCP"], "alternates": {"html": "https://wpnews.pro/news/attestly", "markdown": "https://wpnews.pro/news/attestly.md", "text": "https://wpnews.pro/news/attestly.txt", "jsonld": "https://wpnews.pro/news/attestly.jsonld"}}