There's a comfortable way to feel in order with the AI Act: run through a checklist, tick every box, and consider the job done. It's fast, it's cheap, and it produces a pleasant sense of control. It's also, at the worst possible moment, insufficient. Because the day an authority, an auditing client, or an insurer renewing your policy asks how you govern your AI, they won't want to see ticked boxes. They'll want to see evidence. And those two things aren't the same.
What a checklist proves (and what it doesn't)
A checklist answers one question: did you do this? And its answer is a yes or a no. "Do you have an AI use policy? Yes." "Have you trained the team? Yes." "Did you classify your systems? Yes."
The problem is that a yes in a box proves nothing on its own. It doesn't say what policy you have, or whether it fits your systems. It doesn't say who was trained, on what, or when. It doesn't say how you classified each system or by what criteria. The box records a claim; it doesn't support it.
When a serious review arrives, the question changes shape. It's no longer "did you do it?" but "prove it." And there, the box goes silent.
What auditable evidence is
Evidence is what supports the claim. For everything you say you've done, evidence answers a set of uncomfortable questions:
- What exactly was done (the specific policy, the specific assessment — not its generic existence).
- Who did it and who signed off on it.
- When it was done and when it was last reviewed.
- How that decision was reached (the classification criterion, the legal basis chosen, the reasoning).
- What changed since then, with its trail.
Auditable evidence is traceable: it can be followed back to the origin of every decision. It's what lets you argue, with substance, that you acted with due diligence. It doesn't prove you have a stamp; it proves you thought, decided, and documented.
The difference, in one example
Take the classification of a candidate-scoring system.
Checklist approach: box ticked — "systems classified: yes." End of story.
Evidence approach: a record stating that this specific system was classified as high-risk because of its purpose — pre-selecting candidates — under Annex III; that the decision was made by a named person on a given date; that it relied on a stated criterion; that it carries an associated DPIA for the data processing involved, with its legal basis; that it will be reviewed when the system's use changes; and that the last review took place on a given date.
The first approach leaves you defenceless against the question "why did you classify this system that way?" The second answers it on its own.
Why this matters especially now
With the high-risk deadline pushed back to late 2027, it's tempting to ease off and settle for "having the boxes ready just in case." That's a sequencing mistake. The room the Omnibus gives you isn't for doing less; it's for doing it properly. Building a traceable body of evidence takes time — you have to generate the record as decisions are made, not reconstruct it at the last minute. The company that uses these months to accumulate real evidence reaches any review without surprises. The one that only ticks boxes finds out, too late, that it can't prove anything.
There's also a deeper reason. AI governance isn't done to pass a one-off exam; it's done so you can account, at any moment, for how you use a technology that makes decisions about people. A checklist is a snapshot. Evidence is a living record. Only the second one holds up as time passes and systems change.
What to look for in a governance tool
If you're evaluating a solution to govern your AI, the question that separates the serious from the cosmetic is simple: does this generate auditable evidence, or does it just let me tick boxes? Specifically, it's worth checking whether it:
- Records the why behind each classification, not just the result.
- Keeps the history: who, when, what changed.
- Produces exportable documentation you can put in front of a third party.
- Maintains a living record that updates as your systems change, rather than a frozen snapshot.
A tool that only helps you say "yes" on a list gives you cheap peace of mind. One that helps you build evidence gives you something more useful: the ability to demonstrate diligence the day it's called for. The difference looks subtle on paper. It stops being subtle the moment someone asks you to prove it.
This article is for informational purposes only and does not constitute legal advice.