Transparency and instructions for use
Article 13 requires that high-risk AI systems are designed and developed to be sufficiently transparent so that deployers can use them properly. This is primarily achieved by providing clear, concise, and complete instructions for use that explain the system's capabilities, limitations, and oversight requirements.
What it means
The intent of this requirement is to eliminate "black box" deployments where the user does not understand why a system produces a certain output or how to intervene when it fails. Transparency ensures that the person deploying the AI can make informed decisions about its application and can effectively implement human oversight as required by other parts of the Act.
In practice, this applies specifically to providers of high-risk AI systems. The scope extends beyond a simple user manual; it requires a comprehensive disclosure of the system's operational boundaries. If a deployer cannot reasonably predict when the system might err or how to mitigate those errors based on the provided documentation, the transparency requirement is not met.
How to meet it
- Develop a formal "Instructions for Use" document that clearly defines the AI system's intended purpose and its specific capabilities.
- Document known limitations of the system, including scenarios where accuracy may drop or where the system should not be relied upon.
- Provide clear specifications on the input data required for the system to function as intended and any constraints on that data.
- Detail the human oversight measures necessary to mitigate risks, explaining exactly how a human operator can monitor the system and override its outputs.
- Specify the expected level of performance (e.g., accuracy or precision metrics) under normal operating conditions.
- Ensure all documentation is written in a language easily understood by the target deployer and provided in a format that is accessible during operation.
Evidence an auditor asks for
- The final version of the Instructions for Use manual delivered to the customer/deployer.
- A traceability matrix linking identified risks (from the risk management system) to specific warnings or instructions in the user manual.
- Records of version control showing how instructions are updated when the AI model is retrained or modified.
- Evidence that the deployer has received and had access to these instructions prior to putting the system into service.
Common pitfalls
- Using generic, boilerplate templates that do not address the specific technical risks and limitations of the actual model being deployed.
- Writing documentation for a technical audience (engineers) rather than the operational audience (deployers/end-users) who will actually be overseeing the AI.
- Treating transparency as a one-time "launch" task instead of an ongoing process that updates as the system's performance drifts or evolves over time.