RAGBAZ / loom / WeftMark
A dated connection between engineering records and applicable logging, documentation, oversight and lifecycle obligations.
published · Updated 2026-10-05
01 WeftMark
Reviewed 5 October 2026 using the Commission's current overview and AI Act Service Desk text, which identifies the consolidated version as at 27 July 2026. Provider, deployer and general-purpose-model duties differ; intended purpose and the classification rules matter. An engineering ledger does not classify a system or decide whether an exemption applies.
The Commission reports the July 2026 AI Omnibus entering into force on 27 July 2026, with Annex III high-risk requirements applying from 2 December 2027 and the relevant Annex I product pathway from 2 August 2028. Transparency rules and general-purpose-model rules have earlier timelines. Check the current legal text and transitional provisions for the actual system.
02 WeftMark
Articles 11 and 17 concern technical documentation and the provider's quality-management system, with Annex IV describing documentation content. Change Sets can help organise development changes, verification references and decisions, but they do not supply a complete technical file or organisational quality system.
Risk management, data governance, evaluation methods and post-market monitoring have separate obligations under Articles 9, 10 and 72. A traceable fix is useful evidence within those processes; it does not substitute for their system-level content.
03 WeftMark
Article 12 requires relevant high-risk systems to technically allow automatic event recording over their lifetime, supporting traceability, monitoring and identification of risks or substantial modifications. An engineering ledger records the software-workflow story; the deployed AI system still needs instrumentation for its own relevant events.
Articles 19 and 26(6) address provider and deployer retention of automatically generated logs under their control, for an appropriate period of at least six months unless applicable Union or national law provides otherwise, notably data-protection law. This is not a universal requirement to store all prompts or all personal data for six months. Purpose, control and applicable law remain part of the decision.
04 WeftMark
Article 14 concerns high-risk system design for human oversight; Article 26(2) requires deployers to assign it to people with competence, training, authority and support. A review button alone is not meaningful oversight. The person needs understandable evidence, time, an intervention path and authority to refuse or suspend use.
WeftMark can preserve an engineering review and its rationale. Production identity, permission checks and independent review must still be implemented in their own authorities. Article 15's accuracy, robustness and cybersecurity requirements need relevant testing of the AI system, not merely a passing build or valid ledger hash.
05 WeftMark
A procurement or investigation can ask for the revision, evaluation methods, evidence capture interval, operating conditions, review identity and authority, relevant incident history and retention policy. WeftMark, Nostoi and Rebekah can contribute different parts of that technical record.
The applicable conformity-assessment route, declaration, registration duties, fundamental-rights impact assessment where required and any specific sector obligations remain separate questions. WeftMark is a prototype evidence tool, not a notified body, legal adviser or compliance certificate.
A conversation, not a sales funnel
Ask a question, tell us what you need, offer a contribution or simply show your support. RAGBAZ is a software studio working toward kindness, mutual cooperation and the good of all beings.
Prefer email? ragbaz@proton.me