Testing plan version 0.1 · amended once
What the provider and the regulator agreed before any run: who is tested, on what data, against which limits, and who may do what.
Participant
Estimate whether a customer is 18 or over at unattended points of sale for age-restricted products, so that the machine either completes or refuses the sale. The harm the plan is written around is a minor being served; accuracy is judged against this purpose and nothing else.
- Provider
- Demo Provider
- System
- Point-of-sale age estimator
- Annex III
- 1(b)
- Classification
- PROVISIONAL, pending legal. Not 1(a): the system establishes no identity and compares against no reference database, it returns an attribute. 1(b) is the nearest fit but is itself doubtful, since 1(b) is limited to sensitive or protected attributes and age is not a GDPR Art. 9 special category; Art. 3 also carves out categorisation ancillary to another commercial service. Recorded as 1(b) so the choice is explicit in every attestation rather than implied.
- Sandbox
- demo-001
- Plan version
- 0.1The plan's own label, amended once since it was first signed. An amendment is a new digest, signed again; the label changes only if the parties change it.
Signatures
What the provider and the regulator agreed before any run (Art. 57(5)). Every field that constrains a run is on this sheet, and the plan digest in every attestation commits to all of it: change a threshold and the digest changes.
- Provider
- Signed
- Regulator
- Signed
- Plan digest
- sha256:d5ac2f71a0b45291e99be29be1d91e451527fa0f67d85e9c702b7ac3105a3f9e
- Signed by
- Provider · the provider's key
Regulator · the regulator's keyKeys the sandbox holds: they show the plan was signed, not which person agreed to it. - Recorded
- ledger seq 26 · 2026-09-28T07:22:49.819Z
- Contents
- This page
- Amendment
- “model_image_digest: the fixed model”The note as recorded, in the parties' words.Put to the gate by the regulator, regulator@authority.example · ledger seq 25
- Changed
- 1 fieldFrom the two signed versions, compared here. The signatures always change and are left out.
- Plan digest
- sha256:553db7105fe427a45926948c8b3289c85875622121f88948e252a6fa6ba9634f
- Signed by
- Provider · the provider's key
Regulator · the regulator's keyKeys the sandbox holds: they show the plan was signed, not which person agreed to it. - Recorded
- ledger seq 1 · 2026-09-28T07:22:34.895Z
- Contents
- Read this version
Timeframe and limits
- Opens
- 2020-01-01T00:00:00Z
- Closes
- 2030-01-01T00:00:00Z
- Max runs
- 10
- Max run duration minutes
- 120
- Max requests per minute
- 600
Pinned artefacts
The gate refuses a run unless each committed digest is the pin.
Datasets
- Role
- independent_heldout
- Held by
- test_lab
- Groups
- skin_tone_band, sex, age_band
- Special category
- Yes · Art. 4 bis
- Commitment
- sha256:5d43d03b9dad51c17c667cbb8cfe371e54f1d398dc2e0d43c786bcf2b3b6733a
- Ledger
- Committedledger seq 10 · 2026-09-28T07:22:34.912Z
Tests
A threshold here is the limit a run is judged against. It cannot be changed after a result is known: that is an amendment, and both parties sign it.
- Type
- accuracy_by_group
- Article
- 15
- Dataset
- lab-heldout-v1
- Metrics
- mae
- Groups
- skin_tone_band, sex, age_band
- Threshold · max_per_group
- 4.0
- Min items per group
- 15
- Confidence level
- 0.95
- Interval method
- bootstrap
- Multiple comparison correction
- bonferroni
- Baseline
- median_age Always predict the dataset median age. A model that does not beat this is not estimating.
- Type
- rate_by_group
- Article
- 10, 15
- Dataset
- lab-heldout-v1
- Metrics
- false_adult_rate
- Groups
- skin_tone_band, sex
- Threshold · max_per_group
- 0.01
- Threshold · max_gap_between_groups
- 0.005
- Min items per group
- 15
- Confidence level
- 0.95
- Interval method
- wilson
- Multiple comparison correction
- bonferroni
- Baseline
- constant_is_adult Wave everyone through. The rate this produces is the floor any system must beat.
- Type
- decision_logging
- Article
- 12, 19
- Threshold · min_log_coverage
- 1.0
- Threshold · max_unmatched_request_ids
- 0
- Required fields
- ts, request_id, output, model_id, model_version, latency_ms
- Retention months
- 6
Roles
Each person signs in with their own organisation's identity provider; the plan decides which role that makes them.
- Regulator
- regulator@authority.example
- Dpa
- dpa@dpa.example
- Test lab
- lab@testlab.example
- Provider
- dev@provider.example
- Data processor
- annotation@labservices.example via test-lab-sso
- Notified body
- assessor@notifiedbody.example
Objectives
activities:
- testing
sectors:
- 'Retail: unattended sale of age-restricted products'
goals:
- id: minors_not_served
description: Show that the system refuses minors at a rate the authority accepts,
in every skin-tone band and sex, on data the provider has never seen.
evidenced_by:
- minors_accepted_by_group
- accuracy_by_group
- id: decisions_are_logged
description: Show that every decision is logged with the fields Art. 12 needs.
evidenced_by:
- decision_logging
- id: human_oversight_design
description: Discuss with the authority how staff override a refusal at the point
of sale. Assessed by the authority; no automated test measures it.
cooperation:
- with: the data protection authority
kind: authority
purpose: Joins the review of the held-out set's legal basis before the first run.
- with: Independent test lab
kind: expert
purpose: Curates and commits the held-out set; never sees model outputs.
- with: Retail trade association
kind: ecosystem
purpose: Comments on how an override at the till would work in practice.
Development constraints
- activity: testing
constraint: The provider never sees the held-out items or their labels, so it cannot
tune on them; a failure is reported by group and metric only.
- activity: training
constraint: No training happens in the sandbox; the model arrives trained.
Methodology
regulatory_flexibilities:
- reference: AI Act Art. 14
description: The authority gives guidance on the override design instead of a finding;
the goal human_oversight_design is not scored.
information_exchange: A fortnightly call between the provider and the regulator; everything
else through the console, whose actions are all in the ledger.
Process indicators
- id: signature_turnaround description: Working days from a plan amendment being proposed to both signatures. target: 10 working days or fewer - id: exit_report_turnaround description: Days from exit to the exit report reaching the provider. target: Within the two months of draft implementing act Art. 6(4)
Requirements in scope
- reference: AI Act Art. 10 note: Data governance for the held-out and stress sets - reference: AI Act Art. 12 note: Automatic logging of decisions - reference: AI Act Art. 14 note: Human oversight at the point of sale; guidance only - reference: AI Act Art. 15 note: Accuracy and robustness - reference: AI Act Art. 4 bis note: Special-category data for bias detection - reference: GDPR Art. 9 note: Face images and group labels
Regulatory challenges
- reference: AI Act Art. 4 bis
challenge: Whether bias detection justifies processing skin-tone labels when synthetic
faces cannot show the disparity.
- reference: AI Act Art. 14
challenge: What human oversight means at an unattended point of sale.
Personal data
processed: true dpa_involvement: required categories: - face images (biometric data, GDPR Art. 9) - skin-tone band (racial or ethnic origin, GDPR Art. 9) - sex - true age legal_basis: AI Act Art. 4 bis(1) for the special-category group labels used to detect bias; PENDING LEGAL for the rest of the processing. Placeholder, like the thresholds. note: The held-out set holds real face images labelled with skin-tone band and sex. The DPA named under roles is associated with the sandbox (AI Act Art. 57(10)).
Risk management
safeguards: - The model runs with no route to the data, the network or persistent storage. - Labels and groups never leave segment A; only metrics and hashes leave. - The regulator or the DPA can halt a run or suspend the participation at any time. - Data keys are destroyed at exit. serious_incident_procedure: Either party that suspects a serious incident (AI Act Art. 3(49)) tells the regulator the same day. The regulator suspends the participation from the console, which records the reason in the ledger, and informs the DPA when personal data is involved.
Complaints procedure
Confidentiality
confidential: - /participant/provider - /datasets/0/processors note: The provider's name until market launch; the test lab's subcontractor.
Agreements
- id: demo-centre-undertaking
kind: centre_undertaking
centre: simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only
netns)
document_sha256: sha256:4f1e63cc76d2563609b8e56ba3bbc130489f7bd10b89ed7d31c01a90186b90f0
valid_from: '2020-01-01T00:00:00Z'
valid_until: '2030-01-01T00:00:00Z'
clauses:
- root_memory
- crash_dumps
- core_files
- monitoring
- hardware_service
note: The template in docs/templates/, standing in for a signed undertaking of a
simulated centre.
Standards
- id: prEN 18229-2 title: 'AI Trustworthiness Framework — Part 2: Accuracy and Robustness' status: draft alignment: tracked
Execution
centre:
name: simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only
netns)
partition: sandbox
cpu_arch: x86_64
runtime: apptainer
personal_data_accepted: special_category