Skip to content
Topic Developing

Documentation Keeping for AI Systems

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requirements around maintaining, organizing, and preserving documentation throughout an AI system's lifecycle, including technical, compliance, and operational documentation.

16 linked items 8 Laws1 Guidance7 Literature

Overview

9 sources · Jul 15, 2026

Legal Framework

Documentation keeping for AI systems is governed primarily by Article 11 and Article 18 of the EU AI Act. Article 11 establishes the obligation for providers of high-risk AI systems to draw up and maintain technical documentation before placing a system on the market or putting it into service. This documentation must demonstrate compliance with the substantive requirements set out in Chapter III of the Act and must be prepared before the system's conformity assessment. The technical documentation must contain, at minimum, a general description of the AI system, its intended purpose, the development process, data training methodologies, and information enabling authorities to assess compliance.

Article 18 specifically addresses documentation keeping as a distinct obligation. It requires providers to maintain the technical documentation and related records for a period of ten years after the AI system has been placed on the market, with the possibility of extension by national authorities. This provision establishes documentation not merely as a one-time compliance exercise but as a continuous lifecycle obligation. The rationale is twofold: enabling post-market surveillance by competent authorities and ensuring traceability throughout the system's operational life. Providers must keep the documentation in a manner that allows authorities to access it upon request, and where the system is modified, updated documentation must reflect the current state of the system.

The interplay between Articles 11 and 18 creates a dual structure: Article 11 governs the content and creation of documentation, while Article 18 governs its preservation, organization, and accessibility over time.

Key Developments

As the AI Act entered into force in August 2024, enforcement has not yet produced a body of case law or DPA decisions specifically interpreting the documentation-keeping obligations. However, the GDPR enforcement landscape provides instructive analogues. In SCHUFA Holding AG v. C-634/21, the CJEU emphasized that automated decision-making processes require demonstrable documentation to enable meaningful judicial review. National DPAs, including the Italian Garante's 2023 restriction on ChatGPT, have consistently demanded that organizations produce evidence of data processing activities — signaling that the absence of documentation will be treated as a standalone compliance failure rather than a procedural gap.

The Dutch DPA's enforcement posture under GDPR Article 30 record-keeping requirements further establishes that authorities expect documentation to be contemporaneous, structured, and retrievable on demand. This precedent will likely transfer to AI Act enforcement, where Article 18's ten-year retention period sets an even higher bar.

Practical Guidance

  • Establish a documentation lifecycle protocol that maps to each phase of AI system development, deployment, and post-market monitoring. Article 11 requires technical documentation to exist before market placement — meaning documentation must be built into the development pipeline, not retrofitted.

  • Implement version control for all technical documentation. Article 18's continuous maintenance obligation means that any modification to the AI system triggers a documentation update. Maintain a change log linking system modifications to corresponding documentation revisions.

  • Designate a documentation owner with defined accountability. The ten-year retention period under Article 18 outlasts typical employee tenure and corporate restructuring. Assign institutional responsibility to a role rather than an individual, with handover protocols embedded in operational procedures.

  • Ensure documentation is audit-ready and structured for authority access. Authorities must be able to assess compliance from the documentation alone. Organize materials so that a competent authority can independently evaluate conformity without requiring supplementary explanations from the provider.

  • Align AI Act documentation with GDPR Article 30 records and DPIAs. Where AI systems process personal data, the technical documentation under Article 11 and the processing records under GDPR should cross-reference each other to avoid duplication and ensure consistency across regulatory regimes.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 8
Art. 3(12) ‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specifie… AI Act Art. 11(1) The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kep… AI Act Art. 11(1)(cont)(1) The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in t… AI Act Art. 11(2) Where a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section A of Annex I is placed on the market… AI Act rec 71 Recital 71 — high-risk AI technical documentation and logs AI Act Jun 2024 art 11 Technical documentation AI Act Jun 2024 art 18 Documentation keeping AI Act Jun 2024 rec 109 Recital 109 — proportionate compliance for general-purpose AI providers AI Act Jun 2024 rec 66 Recital 66 — risk management requirements for high-risk AI AI Act Jun 2024 rec 101 Recital 101 — General-purpose AI model provider transparency obligations AI Act Jun 2024 rec 173 Recital 173 — Commission delegated powers to adapt AI rules AI Act Jun 2024 rec 9 Recital 9 — Harmonised cross-sectoral high-risk AI market rules AI Act Jun 2024
Guidance 1
on stakeholder event on processing of personal data Report on stakeholder event on processing of personal data to target or deliver political advertisements EDPB Mar 2026
Literature 7
Accounting and Auditing From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence Accounting and Auditing Jul 2026 Computer Law Review International Technical Documentation Obligations in Data Protection, Technology, and Cybersecurity Law Computer Law Review International Mar 2026 AFMN Biomedicine REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT AFMN Biomedicine Jul 2026 i-lex Perspectives for Open Source AI i-lex Jul 2026 SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 Journal of European Competition Law & Practice Training national judges for digital competition law: the DMA, private enforcement, and the infrastructure of judicial capacity Journal of European Competition Law & Practice May 2026