← Back to Klariq Check my obligations →

What is inside the Klariq sample EU AI Act document pack

Six documents, walked through one by one: what each is for, which article it answers, and which parts you fill in yourself.

The Klariq document pack is a set of six EU AI Act documents for companies that deploy AI or provide limited-risk AI systems, which is where most SMEs using AI land. It is not written for providers of high-risk systems. You answer a three-minute classification questionnaire, and the pack is built from those answers for a one-time EUR 249. The classification and the legal text are produced deterministically from templates keyed to the Regulation, so no large language model writes the legal output. This page walks through the sample so you can read the whole thing before deciding.

Read the full sample pack (PDF, 13 pages)

The paid pack is delivered in the same four languages. Each sample is a complete pack for the fictional company described further down, with every page stamped SAMPLE.

The six documents at a glance

The pack's contents page splits it into duties that are already binding and the material that supports them: three documents marked ACT NOW, three marked REFERENCE.

#DocumentCoversStatus in the sample
1Classification memoYour risk tier and every duty that appliesACT NOW
2AI literacy policyArticle 4, applies since 2 February 2025ACT NOW
3Transparency & content-marking procedureArticle 50, applies 2 August 2026ACT NOW
4AI governance & acceptable-use policyInternal control baselineREFERENCE
5AI system registerInventory of your AI systemsREFERENCE
6AI literacy training moduleStaff training and completion recordREFERENCE

Document 1: AI Act classification memo

Serves: the whole pack · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

The memo states your role, your risk tier and the list of duties that follow, with the reasoning recorded. It is the document to hand an enterprise customer's procurement team or a market-surveillance authority, because it shows a documented classification rather than an assertion.

In the sample it opens with a one-line result, then three exhibits. Exhibit 1, Duties that apply to you, tables four obligations: Art. 4 AI literacy, Art. 50(1) chatbot disclosure, Art. 50(2) marking of AI-generated content, and the Art. 5 ban on generating non-consensual intimate imagery and CSAM, each with its date and a required action. Exhibit 2, a horizon matrix, sorts them into already binding, within 90 days, later this year and beyond 12 months. Exhibit 3, What to do first, and by when, turns each duty into a first action with an owner column.

You fill in: the owner column in Exhibit 3. The rest of the document is generated end to end from the questionnaire.

Document 2: AI literacy policy

Serves: Article 4, in force since 2 February 2025

Article 4 binds every provider and deployer of any AI system, at every risk level, and it has been in force the longest of the duties in this pack. A written policy plus training records is the usual evidence that measures were taken.

The sample policy runs to five numbered sections: Purpose, Scope, Training requirements, Records and Review. The purpose section states the duty as amended, that the obligation is to support the development of AI literacy, not to ensure a particular level for any individual. Section 3 is a table matching three audiences to a minimum training and a frequency: all staff using AI tools, staff publishing AI output or supervising AI assistants, and product and engineering staff. Section 4 sets a five-year retention period for the training register and names it as the primary evidence during market-surveillance inquiries.

You fill in: the effective date and the policy owner, both left blank on the page. The audience table is worth editing to match your actual roles.

Document 3: AI transparency notice and content-marking procedure

Serves: Article 50, applies 2 August 2026; marking of pre-existing systems by 2 December 2026

This is the operational half of Article 50: the words your chatbot shows, and the technique that marks your generated content as machine-readable. It answers the two questions a customer or an authority asks about a limited-risk system.

Section 1 gives a ready disclosure line for conversational channels, "You are chatting with an AI assistant. You can ask for a human at any time.", followed by an implementation checklist: notice visible without scrolling, present in every language the assistant supports, human hand-off path tested, screenshot evidence stored with date. Section 2 ranks three accepted marking techniques in order of preference, C2PA content credentials, provider-native watermarking, and IPTC DigitalSourceType metadata as a fallback, and requires the technique chosen per output channel to be recorded in the register with the date it was enabled. A closing section covers the Art. 5 prohibition on generating NCII and CSAM, from 2 December 2026.

You fill in: the disclosure wording if your brand voice differs, and the per-channel technique choice that then feeds Document 5.

Document 4: AI governance and acceptable-use policy

Serves: internal control baseline, referenced by the other five documents

The internal rulebook that makes the rest enforceable. Buyers usually need it when an enterprise customer sends a vendor questionnaire, or when an insurer or investor asks who owns AI risk.

Five sections: Roles, Acceptable use rules, Procurement screening, Incident handling and Regulatory watch. It names an AI Owner accountable for the policy, the register and regulatory tracking, plus a system owner per register entry. The acceptable-use rules restrict business use to systems listed in the register, bar unapproved data classes from AI tools, and require a qualified human review before AI output is published, sent to customers or used in decisions affecting people. Procurement screening records vendor, purpose, data classes, whether the use could fall under Annex III or Art. 50, and the legal basis for any personal-data processing.

You fill in: the AI Owner's name, the effective date, and any house rules your sector adds.

Document 5: AI system register

Serves: the evidence backbone the other documents point to

One row per AI system you use or are developing. When an authority or a customer asks what AI you run and under what controls, this is the artefact that answers in one page rather than in an email thread.

The sample ships the register as an empty table with eight columns: system or tool, vendor, purpose, system owner, risk tier, Art. 50 duty and technique, data classes, and approved on. Underneath sits pre-fill guidance naming the permitted values, tier as prohibited, high-risk, limited (Art. 50) or minimal per the classification memo, and technique as C2PA, watermark, metadata, visible label or disclosure notice. It is blank by design: an inventory of a stranger's systems would be worth nothing to you.

You fill in: every row. This is the document that takes the most work on your side, and the one that keeps the other five current.

Document 6: AI literacy training module and completion record

Serves: the training and evidence Article 4 and Document 2 require

The training itself, plus the paperwork that proves it happened. Article 4 asks for measures and records, and this document delivers both.

Eight slides split into three modules: a core module for all staff using AI tools, a transparency module for staff publishing AI output or supervising assistants, and a provider module for product and engineering staff. Slide topics run from What AI tools do well, and where they fail through What must never go into an AI tool, Human in the loop, Red lines, practices banned by Art. 5, and Approved tools and incident reporting. A ten-question multiple-choice quiz follows, with a trainer answer key and an 80 percent pass mark, then a completion record sheet with columns for name, role, modules, quiz score, date and signature. Delivery runs two ways: online, where each person clicks through the slides, takes the quiz in 15 to 20 minutes and downloads a personal completion certificate with a verification code, for a team of up to 20, or on paper from the same slides. Records are kept at least five years.

You fill in: the completion record, one row per participant, or let the online route collect the certificates for you. The training link arrives with your purchase.

How the sample was generated

The sample is the output of the same engine that builds the paid pack, run against one fixed fictional profile: Vzor s.r.o., a small company in Czechia that is both a provider and a deployer, using a customer-facing chatbot, content generation and internal AI tools. That profile is deliberately mid-range: it produces several Art. 50 duties plus Art. 4 and the Art. 5 omnibus prohibition, so the exhibits, the horizon matrix and the 90-day plan all carry real content.

Every page of the sample carries a SAMPLE watermark marking it a preview rather than a licensed document, and the first page carries a SAMPLE banner. Like a purchased pack, it ends with a generation-evidence block recording the timestamp, the timeline basis and a SHA-256 hash of the document set, so you can show later which version of the law your documents were built against. In a purchased pack that hash is computed over your own answers. Both are dated against the post-omnibus timeline: Regulation (EU) 2026/1744, in force 27 July 2026.

Check which documents you need →

The classification questionnaire is free and takes about three minutes. The pack is a one-time EUR 249.

Automated compliance documents, not legal advice.

Common questions

How many documents are in the Klariq pack?

Six: an AI Act classification memo, an AI literacy policy for Article 4, an AI transparency notice and content-marking procedure for Article 50, an AI governance and acceptable-use policy, an AI system register, and an AI literacy training module with a ten-question quiz and a completion record.

Is the sample the same as the paid pack?

It is the same structure produced by the same generator, run against a fictional company called Vzor s.r.o. Every page is watermarked SAMPLE. It carries the same generation-evidence block and SHA-256 hash as a purchased pack; a purchased pack is generated from your own questionnaire answers and the hash is computed over them.

What does the document pack cost?

A one-time EUR 249, with no subscription. The Article 4 staff training for a team of up to 20 can be bought on its own for EUR 49, credited in full against the EUR 249 pack. After purchase you can add Monitoring for EUR 79 per year, which emails you the regenerated pack when the obligation dates change.

Which company does the sample describe?

A fictional small Czech company, Vzor s.r.o., that is both a provider and a deployer, runs a customer-facing chatbot, generates content with AI and uses internal AI tools. That profile lands in the limited-risk tier and triggers Article 4 plus the Article 50 duties and the Article 5 omnibus prohibition, so the exhibits and the action plan have real content to show.

Does the pack cover high-risk AI systems?

No. It is written for deployers and limited-risk providers, which is where most SMEs using AI land. Providers of Annex III or Annex I high-risk systems need the Chapter III regime, including Annex IV technical documentation and conformity assessment, which this pack does not produce. Those duties apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I.

Can I edit the documents after I receive them?

Yes. The policies, the register and the training module are yours to adapt, and several fields are deliberately left blank for you to complete: the effective date, the policy owner, the AI Owner, and every row of the AI system register.

This page describes a document pack generated automatically against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It is general information, not legal advice, and it does not replace a case-by-case legal assessment. Have a qualified adviser review the pack before relying on it. Last verified: 1 September 2026.