Skip to main content

Endpoint

with "type": "eu-ai-act-evidence". It takes dateFrom, dateTo and format as Create Export describes; it covers the developer’s records, so dataPrincipalId is refused with 400. The export is stored, read back and expires like any other.

What it is, and is not

The pack draws on Grantex’s records to help evidence obligations under Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744. It is not a conformity assessment, a certification or a statement that a system complies; it supports the operator’s own assessment and covers only what Grantex records. Every export carries this as data.disclaimer. Whether an obligation applies depends on the operator’s role (provider or deployer) and on how its AI system is classified. An authorisation layer is not itself a high-risk AI system; an agent doing work listed in Annex III may be. data.applicability gives the dates:

Sections

Each section names its data source (source, or sources) and has a truncated flag; the export’s top-level truncated is true when any section left rows out. Periods use dateFrom and dateTo.

art12RecordKeeping

Art. 12 (automatic recording of events) and the log-keeping duties of Art. 19(1) (providers) and Art. 26(6) (deployers).

art14HumanOversight

Art. 14 (human oversight), and Art. 26 for deployers. sources lists every table read:

art26Deployer

Art. 26 (obligations of deployers). From grants and agents: for each agent given grants in the period (up to 500), its name and DID, the grants issued, active and revoked, and the scopes granted.

art50Transparency

recorded: false. Grantex does not record whether people were told they were interacting with an AI system (Art. 50(1)), whether generated content was marked (Art. 50(2)) or other Art. 50 disclosures; that evidence has to come from the operator’s own systems.

art73Incidents

From the breach register: breaches the fiduciary became aware of in the period (up to 500). These are personal data breaches under DPDP Act 2023 s.8(6), not an Art. 73 classification. Whether any is a serious incident is the operator’s decision; under Art. 73 a serious incident is reported not later than 15 days after awareness (2 days for a widespread infringement or one affecting critical infrastructure, 10 days in the event of a death). Grantex does not classify or report incidents.

Example

eu-ai-act-conformance

The older type is kept for compatibility. It returns the generic keys (consentRecords, auditLog) as before and, when the export is not filtered to a data principal, the sections, applicability and disclaimer above as well. Prefer eu-ai-act-evidence.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 30, 2026