Endpoint
"type": "eu-ai-act-evidence". It takes dateFrom, dateTo and
format as Create Export describes; it
covers the developer’s records, so dataPrincipalId is refused with 400.
The export is stored, read back and expires like any other.
What it is, and is not
The pack draws on Grantex’s records to help evidence obligations under Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744. It is not a conformity assessment, a certification or a statement that a system complies; it supports the operator’s own assessment and covers only what Grantex records. Every export carries this asdata.disclaimer.
Whether an obligation applies depends on the operator’s role (provider or
deployer) and on how its AI system is classified. An authorisation layer is
not itself a high-risk AI system; an agent doing work listed in Annex III may
be. data.applicability gives the dates:
Sections
Each section names its data source (source, or sources) and has a
truncated flag; the export’s top-level truncated is true when any
section left rows out. Periods use dateFrom and dateTo.
art12RecordKeeping
Art. 12 (automatic recording of events) and the log-keeping duties of
Art. 19(1) (providers) and Art. 26(6) (deployers).
art14HumanOversight
Art. 14 (human oversight), and Art. 26 for deployers. sources lists every
table read:
art26Deployer
Art. 26 (obligations of deployers). From grants and agents: for each
agent given grants in the period (up to 500), its name and DID, the grants
issued, active and revoked, and the scopes granted.
art50Transparency
recorded: false. Grantex does not record whether people were told they were
interacting with an AI system (Art. 50(1)), whether generated content was
marked (Art. 50(2)) or other Art. 50 disclosures; that evidence has to come
from the operator’s own systems.
art73Incidents
From the breach register: breaches the
fiduciary became aware of in the period (up to 500). These are personal data
breaches under DPDP Act 2023 s.8(6), not an Art. 73 classification. Whether
any is a serious incident is the operator’s decision; under Art. 73 a serious
incident is reported not later than 15 days after awareness (2 days for a
widespread infringement or one affecting critical infrastructure, 10 days in
the event of a death). Grantex does not classify or report incidents.
Example
eu-ai-act-conformance
The older type is kept for compatibility. It returns the generic keys
(consentRecords, auditLog) as before and, when the export is not
filtered to a data principal, the sections, applicability and disclaimer
above as well. Prefer eu-ai-act-evidence.