A hospital trust, a bank, and a supervisory authority are all asking for the same evidence - in three different formats.

For AI providers

Build the passport once.
Present it at every border.

A Ripple is the evidence passport your AI system carries: purpose, data categories, legal basis, bias examination, oversight design, accuracy under shift, and diagnostic results. Created once. Reusable across buyers and reviews.

Created once, reusable across reviewsStatus viewable at a public linkEvidence record. Not certification.

The evidence request is no longer a formality. It is the gate.

Deployers in health, financial services, and minor-facing services now carry personal obligations under the EU AI Act and GDPR that they cannot discharge on your assurance. They need a record they can hold up. A Ripple is that record - and it is yours to issue before they ask.

What the reviewer asks

Eight questions that decide whether your system is cleared.

The DPO asks about basis and special-category data. The CISO asks about tools, credentials, and egress. The procurement lead asks what expires and when. Your passport answers all three from one record - before the review stalls.

Asked at every review

Which special-category data does the system process - GDPR Art. 9?
Is our data used to train or fine-tune your model?
Where does inference run, and on what transfer basis does data leave?
How was bias examined - AI Act Art. 10? Show the result, not the policy.
How is human oversight designed - AI Act Art. 14? Who can override, and on what basis?
Has accuracy held since validation - Art. 15 - or has the population shifted?
Are the system's events automatically logged - Art. 12?
If you swap the model behind the endpoint, how would we know?

What the passport records

Ten sections. Each tied to the article the reviewer must satisfy.

Identity, provider, and intended purpose
Data categories - Art. 9, Art. 8, financial profiling
Model and provider stack, with changes recorded
Legal basis - GDPR Art. 6, 9, 22 · DPIA under Art. 35
Data governance and bias examination - AI Act Art. 10
Human oversight design - AI Act Art. 14
Accuracy and robustness under shift - AI Act Art. 15
Event logging and traceability - AI Act Art. 12
Subprocessors, hosting region, transfer basis
Evidence Records, expiry, and visas in force

How it works for providers

Build once. Record the evidence. Present it at every border.

01

Issue the passport

Complete the Ripple: purpose, data categories, legal basis, oversight design, and the model stack behind the endpoint.

02

Record the diagnostics

Supply bias examination, accuracy-under-shift, and exposure results as evidence - documents, summaries, results. Each is recorded against the system.

03

Present it

A Wake carries the recorded evidence to the reviewer - DPO, CISO, procurement, or a competent authority - already assembled.

04

Carry the credential

"Carries a Ripple" - dated and expiring. A reviewer can view the passport's recorded status at a public link, not a logo.

How the standard travels

The passport is a record the reviewer can view.

The deployer asks

"Send us the Ripple for this system."

The provider issues

One passport. Recorded evidence. Real expiry date.

The system carries it

"Carries a Ripple" - with its status at a public link.

The next reviewer reviews it

The same record, in the same structure, at the next border.

Carries a Ripple - the provider badge

Display it where your buyers look. It links to the passport's recorded status: sections, Evidence Records, expiry date, and the Droplets in force. Viewing it requires no contact with your sales team.

Evidence record. Not certification, conformity assessment, or regulatory approval.

Carries a Ripple

Ripple on record · expires 30 Sep 2026

Addressed

Provider objections - answered.

“We already complete security questionnaires.”

A questionnaire is rebuilt for every reviewer and comparable to nothing. A Ripple is created once and presented in the same structure at each review - to a hospital trust, a bank's third-party risk function, a supervisory authority, a notified body. The evidence is the same; the effort stops recurring.

“Our system is low risk. It does not need a passport.”

Risk is inherited from the deployment, not declared by the provider. The same assistant is low risk in an internal wiki and Annex III high-risk the moment a clinician, a credit officer, or a minor is on the other side of it. A system that carries a Ripple can be cleared for those contexts. One that does not, cannot.

“We will not disclose proprietary model details.”

A passport records what is proven about a system, never how it is built. Raw records, prompts, corpora and model weights are never requested. You supply evidence - documents, summaries, results - and it is recorded against the system.

“We are not in a regulated sector.”

Your deployers are. Health AI carries GDPR Art. 9 and, where it is a device, MDR. Financial AI carries Art. 22 and DORA's third-party requirements. Any system a minor can reach carries GDPR Art. 8 and DSA Art. 28. The obligation arrives with the context your system is sold into.

Step 2 - the passport

Issue the passport your system carries.
Before the next review stalls.

One Ripple answers the health trust, the bank, and the supervisory authority from the same record - with the diagnostic results recorded and the expiry date on its face.

AffectLog provides technical and operational evidence to support AI access decisions. Not legal advice, certification, notified-body conformity assessment, or regulatory approval.