MethodDeclaration maps validation outputs to EU AI Act Article 10 paragraphs 2 to 5 and Article 11, supplying notified-body technical documentation.
ArticleArt. 10(2-5) + Art. 11
Artifact data_governance_declaration.pdf
CheckAcceptance log and manifest
MethodEach delivery ships with an acceptance log and dataset manifest. Provenance, preparation, quality metrics recorded as chain-of-custody evidence.
ArticleArt. 11
Artifact manifest.json + acceptance_log.csv
Why it matters
Validation is a legal checkpoint, not a QA nicety.
EU AI Act Article 10 makes representative, error-free training data a statutory
conformity requirement for high-risk systems. A validation gap is not a model bug, it is
a documented failure a notified body cannot act on.
METHODOLOGY
How we validate, under EU AI Act Article 10
Four methodology stages, each mapped to a specific Article 10 paragraph. Inter-rater agreement is reported as Cohen Kappa with a documented per-task threshold, not as a vague high-quality assertion.
Four stages, four article citations
01
Statistical representativeness checks
Satisfies Article 10(3)
02
Bias detection and mitigation
Satisfies Article 10(2)(f)
03
Inter-rater agreement reporting
Satisfies Article 10(3)
04
Article 10 conformance checkpoint
Satisfies Article 10(2) to 10(5)
Landis & Koch 1977 interpretation scale
YPAI calibrates reliability thresholds per task. The two markers below are the
documented engagement defaults; specific projects can require tighter floors.
Slight
Fair
Moderate
Substantial
Almost perfect
0.000.200.400.600.801.00
κ ≥ 0.70High-subjectivity annotation
κ ≥ 0.85High-risk classification
Regulatory mapping
Every claim, mapped to a named statute
Procurement and legal teams can verify each line against the standard DPA, included with
every data engagement.
EU AI ACTRegulation (EU) 2024/1689Primary anchor
Article 10
ScopeData and data governance
What YPAI ships
Training, validation, and testing datasets are assessed for relevance, representativeness, and documented errors. Bias detection and correction are documented. Human QA follows the agreed acceptance and sampling plan.
EU AI ACTRegulation (EU) 2024/1689
Article 11
ScopeTechnical documentation
What YPAI ships
The Data Governance Declaration details data origin, collection, and preparation. It evidences that Article 10 practices were rigorously applied during development.
GDPRRegulation (EU) 2016/679
Chapter V
ScopeThird-country transfer
What YPAI ships
Norwegian Aksjeselskap. For EEA-pinned engagements, no third-country transfer mechanism is needed in YPAI directly-controlled processing chain; where a transfer is required, SCCs are in place. Sub-processor list and jurisdictions itemised in the DPA.
COMPLETE THE PIPELINE
Validation sits inside a four-service pipeline
Data validation is one component of European regulatory conformity. See how the rest of the EEA data layer composes around it.
How do you document statistical representativeness for Article 10 audits?
A demographic and contextual distribution matrix maps the human QA contributor pool against the high-risk system's intended purpose. The matrix satisfies EU AI Act Article 10(3) with documented sampling methodology.
What mechanisms ensure bias detection without violating GDPR data minimization?
Contributor metadata is used only to measure differential output variance. No extraneous personal data is processed. This aligns Article 10(2)(f) with GDPR Article 5(1)(c).
How is inter-rater agreement calculated and reported?
Multi-annotator overlap can be quantified via Cohen's Kappa for two raters, Fleiss' Kappa for three or more, or another task-appropriate agreement method. The metric, sampling design, threshold, and achieved result are reported against the acceptance plan agreed for the task.
Does your validation process introduce third-country data transfer risks?
YPAI is a Norwegian Aksjeselskap. For EEA-pinned engagements, our directly-controlled processing chain introduces no third-country transfer mechanisms or Transfer Impact Assessment requirements. Sub-processor jurisdictions are itemised in the DPA so your DPO and legal team can verify the full chain of custody.
How does your human QA map to EU AI Act documentation requirements?
Every engagement ships with a Data Governance Declaration detailing origin, collection, and preparation. This is the technical documentation required by EU AI Act Article 11.
Are we required to establish standard contractual clauses (SCCs)?
For EEA-pinned engagements, no SCCs are needed in YPAI directly-controlled processing chain; where a customer-directed transfer requires one, SCCs are in place. Every data engagement includes a GDPR Article 28 aligned DPA, shipped with the statement of work.
Does this validation methodology apply to LLM preference data and RLHF datasets?
Yes. Inter-rater agreement extends to RLHF and LLM evaluation: Cohen's Kappa quantifies agreement on dual-rater preference comparisons (which of two responses is preferred), and Fleiss' Kappa quantifies multi-rater consensus on output quality dimensions such as helpfulness, safety, and factuality. Representativeness checks and bias detection apply identically to preference labels and to traditional classification labels.
VALIDATION PROJECT INTAKE
Scope a validation project.
Bring the model, the operational environment, and the conformance target. We return an indicative scope, timeline, and pricing band within 48 hours, then deliver a Data Governance Declaration mapped to EU AI Act Article 10 paragraphs 2 to 5.
EU AI Act Article 10 conformance, Article 11 documentation
Cohen's and Fleiss' Kappa reporting
Representativeness, bias, error-rate, distribution checks
EEA-resident operations, sub-processor list in DPA
Inquiry Received
Brief received.
We reply within one EU business day with a feasibility read. NDA-first review on request.
Your confirmation email may be delayed. If you do not hear from us within one business
day, write to contact@ypai.ai and
quote the reference above.
EU AI Act Article 10 · Article 11 · GDPR Chapter V
What happens next
From validation brief to a scoped pilot plan
After you submit the validation brief, we scope the metric, sample, operational
environment, acceptance threshold, evidence outputs, timeline, and commercial terms.
Within one business day
Project lead reads your brief
A named EU-resident project lead replies within one business day with feasibility,
scope clarifications, and a first read on the Article 10 risk classification.
During scoping
Indicative scope, timeline, pricing band
Initial scope returned with the task-appropriate agreement method, sampling design,
acceptance threshold, evidence outputs, and delivery plan.
After scoping
Scoped pilot delivered
The pilot uses the actual validation sample, specification, operational environment,
QA method, evidence requirements, and acceptance criteria agreed for the programme.
Scope, timing, and commercial terms are project-specific.
By agreement
Master DPA signed, production scope locked
The DPA, processing locations, sub-processors, delivery plan, and production
acceptance gates are agreed before scale-up.
Norwegian Aksjeselskap. EEA-resident operations. GDPR Article 7 consent on every
contributor. EU AI Act Article 10 evidence pack at delivery.