AIPolicyTracker
RegisterFree · sent to your work emailEU AI ActISO/IEC 42001

AI Change Log and Substantial Modification Test

Formats: XLSX and DOCX · Version v1 · Built from dataset c6967b988bb5 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Change Log and Substantial Modification Test is a free XLSX and DOCX register for EU AI Act and ISO/IEC 42001. Every release of an AI system after it is in use, with a built-in test that flags a possible substantial modification, the decision and its approver, and the duties a change gate serves.

Format
XLSX and DOCX · Register
Version
v1, built 5 Oct 2026
Duties cited
3 from 1 instruments
Rows from the records
5
Written for
Provider / developer, Deployer / user organisation, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Change log with a formula flag for possible substantial modification
  • Procedure document: what counts as a release, the test, approval
  • Change-related duties sheet

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Change log · 11 columns · blank, 300 rows ready to fill
First rows of the Change log sheet
DateAI systemNew versionWhat changedChanges the intended purpose ▾Affects accuracy, robustness or safety ▾New training data or retraining ▾Foreseen in the original assessment ▾Possible substantial modification ƒDecision and reasoningApproved by
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

Every release of an AI system after it is in use. A change of intended purpose, or an unforeseen change to performance, is flagged for a decision on whether the system needs a new assessment, or whether the organisation has become its provider.

Sheet: Change-related duties · 14 columns · 5 rows from the records
First rows of the Change-related duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Frontier developers must publish a transparency report before deploying a new frontier modelTransparency and disclosureCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websiPublished model transparency report; Redaction justification logAnnex A.8.2, A.8.3GOVERN 4.2, MAP 5.1, MEASURE 2.6Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
Operate a quality management systemQuality management systemEU AI ActEuropean UnionProvider / developerLegal requirementArticle 172027-12-02Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development proceQMS manual and proceduresWhole management system (Clauses 4–10)GOVERN functionSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-quality-management-system
Providers must take corrective action and inform the supply chain about non-conforming high-risk AIIncident reporting and handlingEU AI ActEuropean UnionProvider / developerLegal requirementArticle 202027-12-02A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, withCorrective action and recall procedure for AI systems; Non-conformity investigation recordClause 10.2; Annex A.8.4MANAGE 2.4, MANAGE 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AIGovernance and accountabilityEU AI ActEuropean UnionDeployer / user organisation, Distributor, Importer, Provider / developerLegal requirementArticle 25(1) and 25(2)2027-12-02A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name Change-control reclassification assessment; Cooperation clause with original providerClause 4.1; Annex A.10.2GOVERN 6.1, MAP 1.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider
Providers of GPAI models must maintain technical documentation and inform downstream providersTechnical documentationEU AI ActEuropean UnionGeneral-purpose AI model providerLegal requirementArticle 53(1)(a) and 53(1)(b); Annexes XI and XII2025-08-02Providers of general-purpose AI models must draw up and keep up to date technical documentation covering the training and testing process and evaluation resultsAnnex XI technical documentation; Annex XII downstream integration documentationAnnex A.6.2.7, A.8.2, A.10.4GOVERN 1.4, MAP 2.2, MEASURE 2.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-53-gpai-technical-and-downstream-documentation

The recorded duties served by a release and change-management gate.

Document outline (DOCX)

  1. AI change management and substantial modification procedure
  2. What counts as a release
  3. The test
  4. Approval
  5. Duties on record
  6. Frontier developers must publish a transparency report before deploying a new frontier model
  7. Operate a quality management system
  8. Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
  9. Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
  10. Providers of GPAI models must maintain technical documentation and inform downstream providers

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Change log" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Change-related duties" sheet lists the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (AI change management and substantial modification procedure, Duties on record) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (3)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of AI Change Log and Substantial Modification Test
VersionBuiltDatasetWhat changed
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Change Log and Substantial Modification Test?

Change log with a formula flag for possible substantial modification. Procedure document: what counts as a release, the test, approval. Change-related duties sheet.

Which duties does it cite?

3 recorded duties from EU AI Act, including Articles 43, 47, 48 and 49; Annex VIII, Article 72 and Article 26(5). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.