The AI governance industry has produced an enormous volume of documentation. Risk frameworks, model cards, impact assessments, ethical AI policies, bias evaluation templates, human oversight protocols. There are consultancies dedicated to producing this documentation, software platforms for managing it, and auditors for reviewing it. Documentation has become the primary currency of AI compliance.
The problem is that documentation is not evidence. And regulators — especially regulators investigating specific adverse AI outcomes — do not want documentation. They want evidence.
The Distinction That Matters
Documentation describes what an AI system is designed to do, what governance controls are in place, what risks have been identified, and what mitigations have been implemented. Documentation is prospective: it captures intention and design. A model card tells you the training data distribution and intended use cases. A risk assessment tells you what harms the organisation anticipated and how they planned to prevent them. Technical documentation tells you what the architecture looks like. All of this is valuable — but none of it tells you what happened when the system was deployed and operating in the real world.
Evidence shows what the AI system actually did. It is retrospective: it captures behaviour and outcome. Decision logs showing what inputs the system processed and what outputs it produced. Performance monitoring records showing how accuracy and fairness metrics evolved over time. Incident records showing when the system behaved unexpectedly and how that was addressed. Override logs showing when human reviewers disagreed with AI recommendations. Evidence is the record of reality, not the record of intention.
Why Regulators Are Shifting to Evidence
The EU AI Act's Article 12 requirement for automatic logging is, at its core, an evidence requirement. It requires that high-risk AI systems generate records of what they actually do — not just documentation of what they are designed to do. The requirement for post-hoc monitoring capability is a requirement for evidence: the ability to reconstruct, after the fact, exactly what the system did in any given case.
This shift reflects a maturing regulatory approach to AI. First-generation AI governance guidance focused on documentation because it was what was immediately achievable: produce an impact assessment, write a risk framework, appoint a responsible AI officer. Second-generation AI regulation — embodied in the EU AI Act — focuses on evidence because documentation has proven insufficient to demonstrate actual accountability. You can write an excellent bias mitigation policy and still operate a biased AI system. The policy does not prevent the bias. Evidence of ongoing monitoring and remediation does.
Building an Evidence-Based AI Compliance Programme
The shift from documentation-centric to evidence-centric AI compliance requires two things: the infrastructure to generate evidence, and the organisational discipline to treat evidence as a compliance deliverable rather than an engineering artefact.
Infrastructure means implementing AI decision logging that is automatic, decision-level, tamper-evident, and retained for the periods required. It means building monitoring systems that generate evidence of ongoing oversight — not just dashboards for internal consumption, but records that demonstrate to external scrutiny that monitoring actually occurred and that issues were identified and addressed. And it means maintaining chain-of-custody documentation that links the evidence to the AI system that generated it — so that a record produced in discovery three years hence can be traced to the specific model version, running in the specific environment, that was active at the time of the decision.
Organisational discipline means treating the evidence archive as a compliance asset, not an engineering output. It means funding, maintaining, and governing the evidence infrastructure with the same rigour applied to financial records. And it means building the institutional capacity to retrieve, interpret, and present AI evidence to regulators, auditors, and courts — because the ability to generate evidence is only valuable if you can also use it.
Documentation tells the story of your intentions. Evidence tells the story of your actions. Both matter. But when regulators come looking, they will want the evidence first.