AI Change Log and Substantial Modification Test
In brief
The AI Change Log and Substantial Modification Test is a free XLSX and DOCX register for EU AI Act and ISO/IEC 42001. Every release of an AI system after it is in use, with a built-in test that flags a possible substantial modification, the decision and its approver, and the duties a change gate serves.
- Format
- XLSX and DOCX · Register
- Version
- v1, built 5 Oct 2026
- Duties cited
- 3 from 1 instruments
- Rows from the records
- 5
- Frameworks
- EU AI Act, ISO/IEC 42001
- Written for
- Provider / developer, Deployer / user organisation, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Change log with a formula flag for possible substantial modification
- Procedure document: what counts as a release, the test, approval
- Change-related duties sheet
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Change log
| Date | AI system | New version | What changed | Changes the intended purpose ▾ | Affects accuracy, robustness or safety ▾ | New training data or retraining ▾ | Foreseen in the original assessment ▾ | Possible substantial modification ƒ | Decision and reasoning | Approved by |
|---|---|---|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | ||||||||||
Every release of an AI system after it is in use. A change of intended purpose, or an unforeseen change to performance, is flagged for a decision on whether the system needs a new assessment, or whether the organisation has become its provider.
Sheet: Change-related duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Frontier developers must publish a transparency report before deploying a new frontier model | Transparency and disclosure | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websi | Published model transparency report; Redaction justification log | Annex A.8.2, A.8.3 | GOVERN 4.2, MAP 5.1, MEASURE 2.6 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report |
| Operate a quality management system | Quality management system | EU AI Act | European Union | Provider / developer | Legal requirement | Article 17 | 2027-12-02 | Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development proce | QMS manual and procedures | Whole management system (Clauses 4–10) | GOVERN function | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system |
| Providers must take corrective action and inform the supply chain about non-conforming high-risk AI | Incident reporting and handling | EU AI Act | European Union | Provider / developer | Legal requirement | Article 20 | 2027-12-02 | A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, with | Corrective action and recall procedure for AI systems; Non-conformity investigation record | Clause 10.2; Annex A.8.4 | MANAGE 2.4, MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information |
| Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI | Governance and accountability | EU AI Act | European Union | Deployer / user organisation, Distributor, Importer, Provider / developer | Legal requirement | Article 25(1) and 25(2) | 2027-12-02 | A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name | Change-control reclassification assessment; Cooperation clause with original provider | Clause 4.1; Annex A.10.2 | GOVERN 6.1, MAP 1.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider |
| Providers of GPAI models must maintain technical documentation and inform downstream providers | Technical documentation | EU AI Act | European Union | General-purpose AI model provider | Legal requirement | Article 53(1)(a) and 53(1)(b); Annexes XI and XII | 2025-08-02 | Providers of general-purpose AI models must draw up and keep up to date technical documentation covering the training and testing process and evaluation results | Annex XI technical documentation; Annex XII downstream integration documentation | Annex A.6.2.7, A.8.2, A.10.4 | GOVERN 1.4, MAP 2.2, MEASURE 2.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-53-gpai-technical-and-downstream-documentation |
The recorded duties served by a release and change-management gate.
Document outline (DOCX)
- AI change management and substantial modification procedure
- What counts as a release
- The test
- Approval
- Duties on record
- Frontier developers must publish a transparency report before deploying a new frontier model
- Operate a quality management system
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Providers of GPAI models must maintain technical documentation and inform downstream providers
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Change log" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Change-related duties" sheet lists the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (AI change management and substantial modification procedure, Duties on record) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (3)
Each is cited in the file with its source reference and a link back to the record.
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Change Log and Substantial Modification Test?
Change log with a formula flag for possible substantial modification. Procedure document: what counts as a release, the test, approval. Change-related duties sheet.
Which duties does it cite?
3 recorded duties from EU AI Act, including Articles 43, 47, 48 and 49; Annex VIII, Article 72 and Article 26(5). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.