The four documents missing from almost every Article 10 file
Article 10 of the EU AI Act produces four documents somebody outside your company will read: data provenance, a bias examination, a mitigation record and a written gap analysis. Most providers have none of the four, and the Digital Omnibus did not remove the duty behind them.

A customer's procurement team asks for your data governance documentation. You send the model card, a fairness metric on gender and the slide that lists your data sources. They write back asking for the rest, and nobody in the building agrees on what the rest is.
Article 10 of the EU AI Act sets out eight data governance practices for training, validation and testing sets. Four of them have to end up as a document somebody outside your company reads: a reviewer at a notified body, a market surveillance authority, or the procurement team that started this. Most providers we meet have none of the four.
Data provenance, Article 10(2)(b)
The sub-point covers data collection processes and the origin of the data. Where personal data sits in the set, it also covers the original purpose of that collection.
The second half is the one that catches people. CVs a client gathered to fill its own vacancies in 2019 have a provenance answer. A scraped corpus whose licence terms nobody kept has no answer, and no way to build one after training.
Per source, the file needs the origin, the acquisition route, the licence or lawful basis, the collection date range, and for personal data what it was first collected to do.
Bias examination, Article 10(2)(f)
The text asks for examination of possible biases likely to affect health and safety or to lead to discrimination prohibited under Union law.
A demographic parity figure measures one attribute on one cut of the data. The examination this sub-point asks for is the reasoning around it: which attributes you considered, which you ruled out and on what grounds, how your training distribution compares with the population the system will be used on, and where you looked and found nothing. Reviewers treat the places you looked and found nothing as the strongest evidence in the file, because nobody invents those.
The mitigation record, Article 10(2)(g)
Measures to detect, prevent and mitigate the biases found under (f). This is a separate limb and it fails on its own. A reviewer fails you here for findings you never treated, and again for treatment you never wrote down.
For each bias you identified: the measure, the date, the re-test result, the residual risk you accepted, and who accepted it.
The gap analysis, Article 10(2)(h)
Identification of relevant data gaps or shortcomings that prevent compliance. The Regulation asks you to write down where your data falls short.
Clients fight this one hardest, because it reads like handing a regulator a signed confession. Read it next to Annex IV point 7.2 and it does the opposite job. It gives you somewhere to say: we could not obtain representative data for this subgroup, so we narrowed the intended purpose and said so in the instructions for use. Write the gap down and design the intended purpose around it, and you have answered (h). Leave it out, and the first person to find it is a reviewer.
The Omnibus did not remove the bias duty
Regulation (EU) 2026/1744 deleted Article 10(5) and inserted a new Article 4a. Commentary published since has read that deletion as the end of bias testing.
It is a misreading. Article 4a(1) lets providers process special categories of personal data where that is strictly necessary for bias detection and correction under Article 10(2), points (f) and (g). Article 4a(2) closes by saying it creates no obligation to conduct such detection and correction. The permission moved and widened. The duty stayed in 10(2)(f) and (g), which the Omnibus did not touch.
There is no standard to stand behind yet
CEN-CENELEC published EN 18286:2026, the quality management standard supporting Article 17, in July 2026. It is the first European standard finished for AI Act purposes, and the Commission has not cited it in the Official Journal. Until that citation, no presumption of conformity is available to anyone, for any requirement. No published European standard covers Article 10 data governance at all.
So every provider builds an Article 10 file under Annex IV point 7.2: describe the solutions adopted. You choose the method, you write it down, and you defend it to a reviewer who has no checklist to measure it against either. Keep the law and the good practice apart while you do it. Points (b), (f), (g) and (h) are law. The shape of the register you keep them in is a house style, ours or somebody else's.
What we built
We kept assembling the same four artefacts by hand on every engagement, and the hours cost clients more than the findings were worth. So we built the tooling.
AIAuditSense reads product URLs, repositories and documentation, classifies the system against the EU AI Act, the NIST AI RMF and India's DPDP Act, and returns a graded scorecard with penalty exposure and a remediation roadmap. For Article 10 the output arrives shaped like the file itself: a provenance register, an examination log, a mitigation record and a gap statement, each row tied to the sub-point it answers. Somebody reviews every report before it reaches a client.
Around it sit the sector questionnaires and evidence requests we use across the Annex III areas, and an Annex IV checklist that tracks what is drafted, what is stubbed and what is missing.
Why this matters before December 2027
The Omnibus moved stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Anyone still quoting 2 August 2026 is reading superseded text. Article 18 then holds the technical documentation for ten years after the system goes on the market.
Provenance you can reconstruct is provenance you captured while collecting. A team training a model this quarter is writing the Article 10 file it hands over in 2028.
If you already keep a source register with licences and collection dates, and you can show the bias work you did alongside the bias work you decided against, you may not need us for this. Send the file to somebody who will be rude about it. If nobody can find the file, start there.
This article is general information, not legal advice. Classification and obligations depend on facts specific to your organisation. Take advice before acting on anything here.
Questions this raises
Did the Digital Omnibus remove the bias-testing requirement from the AI Act?
No. Regulation (EU) 2026/1744 deleted Article 10(5) and inserted a new Article 4a, which permits providers to process special categories of personal data where that is strictly necessary for bias detection and correction. Article 4a(2) says in terms that it creates no obligation to carry out that detection and correction. The obligation itself sits in Article 10(2), points (f) and (g), and the Omnibus did not amend either.
Is there a harmonised standard covering Article 10 yet?
No. CEN-CENELEC published EN 18286:2026 in July 2026 for the quality management system under Article 17, and the Commission has not cited it in the Official Journal. Without that citation there is no presumption of conformity for any requirement, and no published European standard covers Article 10 data governance. Providers document their method under Annex IV point 7.2 and defend it.
When do these obligations start to apply?
The Digital Omnibus moved stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk systems to 2 August 2028. Article 18 then requires the provider to keep the technical documentation for ten years after the system is placed on the market or put into service, so data decisions taken now are documented for a long time afterwards.