A hospital trust, a bank, and a supervisory authority are all asking for the same evidence - in three different formats.
For AI providers
Build the passport once.
Present it at every border.
A Ripple is the evidence passport your AI system carries: purpose, data categories, legal basis, bias examination, oversight design, accuracy under shift, and diagnostic results. Created once. Reusable across buyers and reviews.
The evidence request is no longer a formality. It is the gate.
Deployers in health, financial services, and minor-facing services now carry personal obligations under the EU AI Act and GDPR that they cannot discharge on your assurance. They need a record they can hold up. A Ripple is that record - and it is yours to issue before they ask.
What the reviewer asks
Eight questions that decide whether your system is cleared.
The DPO asks about basis and special-category data. The CISO asks about tools, credentials, and egress. The procurement lead asks what expires and when. Your passport answers all three from one record - before the review stalls.
Asked at every review
What the passport records
Ten sections. Each tied to the article the reviewer must satisfy.
How it works for providers
Build once. Record the evidence. Present it at every border.
Issue the passport
Complete the Ripple: purpose, data categories, legal basis, oversight design, and the model stack behind the endpoint.
Record the diagnostics
Supply bias examination, accuracy-under-shift, and exposure results as evidence - documents, summaries, results. Each is recorded against the system.
Present it
A Wake carries the recorded evidence to the reviewer - DPO, CISO, procurement, or a competent authority - already assembled.
Carry the credential
"Carries a Ripple" - dated and expiring. A reviewer can view the passport's recorded status at a public link, not a logo.
How the standard travels
The passport is a record the reviewer can view.
The deployer asks
"Send us the Ripple for this system."
The provider issues
One passport. Recorded evidence. Real expiry date.
The system carries it
"Carries a Ripple" - with its status at a public link.
The next reviewer reviews it
The same record, in the same structure, at the next border.
Carries a Ripple - the provider badge
Display it where your buyers look. It links to the passport's recorded status: sections, Evidence Records, expiry date, and the Droplets in force. Viewing it requires no contact with your sales team.
Evidence record. Not certification, conformity assessment, or regulatory approval.
Carries a Ripple
Ripple on record · expires 30 Sep 2026
Addressed
Provider objections - answered.
“We already complete security questionnaires.”
A questionnaire is rebuilt for every reviewer and comparable to nothing. A Ripple is created once and presented in the same structure at each review - to a hospital trust, a bank's third-party risk function, a supervisory authority, a notified body. The evidence is the same; the effort stops recurring.
“Our system is low risk. It does not need a passport.”
Risk is inherited from the deployment, not declared by the provider. The same assistant is low risk in an internal wiki and Annex III high-risk the moment a clinician, a credit officer, or a minor is on the other side of it. A system that carries a Ripple can be cleared for those contexts. One that does not, cannot.
“We will not disclose proprietary model details.”
A passport records what is proven about a system, never how it is built. Raw records, prompts, corpora and model weights are never requested. You supply evidence - documents, summaries, results - and it is recorded against the system.
“We are not in a regulated sector.”
Your deployers are. Health AI carries GDPR Art. 9 and, where it is a device, MDR. Financial AI carries Art. 22 and DORA's third-party requirements. Any system a minor can reach carries GDPR Art. 8 and DSA Art. 28. The obligation arrives with the context your system is sold into.
Step 2 - the passport
Issue the passport your system carries.
Before the next review stalls.
One Ripple answers the health trust, the bank, and the supervisory authority from the same record - with the diagnostic results recorded and the expiry date on its face.
AffectLog provides technical and operational evidence to support AI access decisions. Not legal advice, certification, notified-body conformity assessment, or regulatory approval.