Demo ProviderPoint-of-sale age estimator · Annex III 1(b)
Notified bodyassessor@notified-body.example
Art. 57(5) · what both parties signed

Testing plan version 0.1 · amended once

What the provider and the regulator agreed before any run: who is tested, on what data, against which limits, and who may do what.

Plan digestsha256:d5ac2f71a0b…
Tests3
Opens2020-01-01
Closes2030-01-01
01Declared

Participant

Estimate whether a customer is 18 or over at unattended points of sale for age-restricted products, so that the machine either completes or refuses the sale. The harm the plan is written around is a minor being served; accuracy is judged against this purpose and nothing else.

Provider
Demo Provider
System
Point-of-sale age estimator
Annex III
1(b)
Classification
PROVISIONAL, pending legal. Not 1(a): the system establishes no identity and compares against no reference database, it returns an attribute. 1(b) is the nearest fit but is itself doubtful, since 1(b) is limited to sensitive or protected attributes and age is not a GDPR Art. 9 special category; Art. 3 also carves out categorisation ancillary to another commercial service. Recorded as 1(b) so the choice is explicit in every attestation rather than implied.
Sandbox
demo-001
Plan version
0.1The plan's own label, amended once since it was first signed. An amendment is a new digest, signed again; the label changes only if the parties change it.
02Signed · in force

Signatures

What the provider and the regulator agreed before any run (Art. 57(5)). Every field that constrains a run is on this sheet, and the plan digest in every attestation commits to all of it: change a threshold and the digest changes.

Provider
Signed
Regulator
Signed
Amendment 1In force
Plan digest
sha256:d5ac2f71a0b45291e99be29be1d91e451527fa0f67d85e9c702b7ac3105a3f9e
Signed by
Provider · the provider's key
Regulator · the regulator's keyKeys the sandbox holds: they show the plan was signed, not which person agreed to it.
Recorded
ledger seq 26 · 2026-09-28T07:22:49.819Z
Contents
This page
Amendment
“model_image_digest: the fixed model”The note as recorded, in the parties' words.Put to the gate by the regulator, regulator@authority.example · ledger seq 25
Changed
1 fieldFrom the two signed versions, compared here. The signatures always change and are left out.
FieldWasNow
model_image_digestartifactssha256:49c8d0747ff0bbd3933c9e2cee23ad6af31ba7be2c7b2ba14c8f2fa365c6dcc1sha256:c426b8c53c7b7885e10f5a127e5686544ea2df3a6cd4137d7ccfa612896f3389
As first signedSuperseded · seq 26
Plan digest
sha256:553db7105fe427a45926948c8b3289c85875622121f88948e252a6fa6ba9634f
Signed by
Provider · the provider's key
Regulator · the regulator's keyKeys the sandbox holds: they show the plan was signed, not which person agreed to it.
Recorded
ledger seq 1 · 2026-09-28T07:22:34.895Z
03Open

Timeframe and limits

Opens
2020-01-01T00:00:00Z
Closes
2030-01-01T00:00:00Z
Max runs
10
Max run duration minutes
120
Max requests per minute
600
04Committed · all match

Pinned artefacts

The gate refuses a run unless each committed digest is the pin.

ArtefactPinLedger
model_image_digestsha256:c426b8c53c7b7885e10f5a127e5686544ea2df3a6cd4137d7ccfa612896f3389Committed · matchesledger seq 31 · 2026-09-28T07:22:49.850Z
harness_image_digestsha256:3425bf7337b84446e0ce57ea7a3dc17a2637dd30018a36e5838f3176406f354fCommitted · matchesledger seq 6 · 2026-09-28T07:22:34.904Z
relay_image_digestsha256:ce6d242da5ad427bdf78559a63d327670f34a3ea21973ff28a368d98122fa7d7Committed · matchesledger seq 8 · 2026-09-28T07:22:34.909Z
network_policy_digestsha256:51d4ff55a13081cc3567e69575c20c90d637469b2b127726a3dba734dcd55336Checked in each attestation
prompt_digestsha256:4444444444444444444444444444444444444444444444444444444444444444Checked in each attestation
05Committed

Datasets

lab-heldout-v1
Role
independent_heldout
Held by
test_lab
Groups
skin_tone_band, sex, age_band
Special category
Yes · Art. 4 bis
Commitment
sha256:5d43d03b9dad51c17c667cbb8cfe371e54f1d398dc2e0d43c786bcf2b3b6733a
Ledger
Committedledger seq 10 · 2026-09-28T07:22:34.912Z
06Fixed · 3 before any run

Tests

A threshold here is the limit a run is judged against. It cannot be changed after a result is known: that is an amendment, and both parties sign it.

accuracy_by_group
Type
accuracy_by_group
Article
15
Dataset
lab-heldout-v1
Metrics
mae
Groups
skin_tone_band, sex, age_band
Threshold · max_per_group
4.0
Min items per group
15
Confidence level
0.95
Interval method
bootstrap
Multiple comparison correction
bonferroni
Baseline
median_age Always predict the dataset median age. A model that does not beat this is not estimating.
minors_accepted_by_group
Type
rate_by_group
Article
10, 15
Dataset
lab-heldout-v1
Metrics
false_adult_rate
Groups
skin_tone_band, sex
Threshold · max_per_group
0.01
Threshold · max_gap_between_groups
0.005
Min items per group
15
Confidence level
0.95
Interval method
wilson
Multiple comparison correction
bonferroni
Baseline
constant_is_adult Wave everyone through. The rate this produces is the floor any system must beat.
decision_logging
Type
decision_logging
Article
12, 19
Threshold · min_log_coverage
1.0
Threshold · max_unmatched_request_ids
0
Required fields
ts, request_id, output, model_id, model_version, latency_ms
Retention months
6
07Named · 6

Roles

Each person signs in with their own organisation's identity provider; the plan decides which role that makes them.

Regulator
regulator@authority.example
Dpa
dpa@dpa.example
Test lab
lab@testlab.example
Provider
dev@provider.example
Data processor
annotation@labservices.example via test-lab-sso
Notified body
assessor@notifiedbody.example
08Declared

Objectives

activities:
- testing
sectors:
- 'Retail: unattended sale of age-restricted products'
goals:
- id: minors_not_served
  description: Show that the system refuses minors at a rate the authority accepts,
    in every skin-tone band and sex, on data the provider has never seen.
  evidenced_by:
  - minors_accepted_by_group
  - accuracy_by_group
- id: decisions_are_logged
  description: Show that every decision is logged with the fields Art. 12 needs.
  evidenced_by:
  - decision_logging
- id: human_oversight_design
  description: Discuss with the authority how staff override a refusal at the point
    of sale. Assessed by the authority; no automated test measures it.
cooperation:
- with: the data protection authority
  kind: authority
  purpose: Joins the review of the held-out set's legal basis before the first run.
- with: Independent test lab
  kind: expert
  purpose: Curates and commits the held-out set; never sees model outputs.
- with: Retail trade association
  kind: ecosystem
  purpose: Comments on how an override at the till would work in practice.
09Declared

Development constraints

- activity: testing
  constraint: The provider never sees the held-out items or their labels, so it cannot
    tune on them; a failure is reported by group and metric only.
- activity: training
  constraint: No training happens in the sandbox; the model arrives trained.
10Declared

Methodology

regulatory_flexibilities:
- reference: AI Act Art. 14
  description: The authority gives guidance on the override design instead of a finding;
    the goal human_oversight_design is not scored.
information_exchange: A fortnightly call between the provider and the regulator; everything
  else through the console, whose actions are all in the ledger.
11Declared

Process indicators

- id: signature_turnaround
  description: Working days from a plan amendment being proposed to both signatures.
  target: 10 working days or fewer
- id: exit_report_turnaround
  description: Days from exit to the exit report reaching the provider.
  target: Within the two months of draft implementing act Art. 6(4)
12Declared

Requirements in scope

- reference: AI Act Art. 10
  note: Data governance for the held-out and stress sets
- reference: AI Act Art. 12
  note: Automatic logging of decisions
- reference: AI Act Art. 14
  note: Human oversight at the point of sale; guidance only
- reference: AI Act Art. 15
  note: Accuracy and robustness
- reference: AI Act Art. 4 bis
  note: Special-category data for bias detection
- reference: GDPR Art. 9
  note: Face images and group labels
13Declared

Regulatory challenges

- reference: AI Act Art. 4 bis
  challenge: Whether bias detection justifies processing skin-tone labels when synthetic
    faces cannot show the disparity.
- reference: AI Act Art. 14
  challenge: What human oversight means at an unattended point of sale.
14Declared

Personal data

processed: true
dpa_involvement: required
categories:
- face images (biometric data, GDPR Art. 9)
- skin-tone band (racial or ethnic origin, GDPR Art. 9)
- sex
- true age
legal_basis: AI Act Art. 4 bis(1) for the special-category group labels used to detect
  bias; PENDING LEGAL for the rest of the processing. Placeholder, like the thresholds.
note: The held-out set holds real face images labelled with skin-tone band and sex.
  The DPA named under roles is associated with the sandbox (AI Act Art. 57(10)).
15Declared

Risk management

safeguards:
- The model runs with no route to the data, the network or persistent storage.
- Labels and groups never leave segment A; only metrics and hashes leave.
- The regulator or the DPA can halt a run or suspend the participation at any time.
- Data keys are destroyed at exit.
serious_incident_procedure: Either party that suspects a serious incident (AI Act
  Art. 3(49)) tells the regulator the same day. The regulator suspends the participation
  from the console, which records the reason in the ledger, and informs the DPA when
  personal data is involved.
16Declared

Complaints procedure

A customer refused at a demo point of sale can complain to the provider's published address; the provider forwards each complaint to the regulator within five working days and the regulator records it against the participation.
17Declared

Confidentiality

confidential:
- /participant/provider
- /datasets/0/processors
note: The provider's name until market launch; the test lab's subcontractor.
18Declared

Agreements

- id: demo-centre-undertaking
  kind: centre_undertaking
  centre: simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only
    netns)
  document_sha256: sha256:4f1e63cc76d2563609b8e56ba3bbc130489f7bd10b89ed7d31c01a90186b90f0
  valid_from: '2020-01-01T00:00:00Z'
  valid_until: '2030-01-01T00:00:00Z'
  clauses:
  - root_memory
  - crash_dumps
  - core_files
  - monitoring
  - hardware_service
  note: The template in docs/templates/, standing in for a signed undertaking of a
    simulated centre.
19Declared

Standards

- id: prEN 18229-2
  title: 'AI Trustworthiness Framework — Part 2: Accuracy and Robustness'
  status: draft
  alignment: tracked
20Declared

Execution

centre:
  name: simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only
    netns)
  partition: sandbox
  cpu_arch: x86_64
  runtime: apptainer
  personal_data_accepted: special_category