Documentation Keeping for AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requirements around maintaining, organizing, and preserving documentation throughout an AI system's lifecycle, including technical, compliance, and operational documentation.
Overview
9 sources · Jul 15, 2026Legal Framework
Documentation keeping for AI systems is governed primarily by Article 11 and Article 18 of the EU AI Act. Article 11 establishes the obligation for providers of high-risk AI systems to draw up and maintain technical documentation before placing a system on the market or putting it into service. This documentation must demonstrate compliance with the substantive requirements set out in Chapter III of the Act and must be prepared before the system's conformity assessment. The technical documentation must contain, at minimum, a general description of the AI system, its intended purpose, the development process, data training methodologies, and information enabling authorities to assess compliance.
Article 18 specifically addresses documentation keeping as a distinct obligation. It requires providers to maintain the technical documentation and related records for a period of ten years after the AI system has been placed on the market, with the possibility of extension by national authorities. This provision establishes documentation not merely as a one-time compliance exercise but as a continuous lifecycle obligation. The rationale is twofold: enabling post-market surveillance by competent authorities and ensuring traceability throughout the system's operational life. Providers must keep the documentation in a manner that allows authorities to access it upon request, and where the system is modified, updated documentation must reflect the current state of the system.
The interplay between Articles 11 and 18 creates a dual structure: Article 11 governs the content and creation of documentation, while Article 18 governs its preservation, organization, and accessibility over time.
Key Developments
As the AI Act entered into force in August 2024, enforcement has not yet produced a body of case law or DPA decisions specifically interpreting the documentation-keeping obligations. However, the GDPR enforcement landscape provides instructive analogues. In SCHUFA Holding AG v. C-634/21, the CJEU emphasized that automated decision-making processes require demonstrable documentation to enable meaningful judicial review. National DPAs, including the Italian Garante's 2023 restriction on ChatGPT, have consistently demanded that organizations produce evidence of data processing activities — signaling that the absence of documentation will be treated as a standalone compliance failure rather than a procedural gap.
The Dutch DPA's enforcement posture under GDPR Article 30 record-keeping requirements further establishes that authorities expect documentation to be contemporaneous, structured, and retrievable on demand. This precedent will likely transfer to AI Act enforcement, where Article 18's ten-year retention period sets an even higher bar.
Practical Guidance
Establish a documentation lifecycle protocol that maps to each phase of AI system development, deployment, and post-market monitoring. Article 11 requires technical documentation to exist before market placement — meaning documentation must be built into the development pipeline, not retrofitted.
Implement version control for all technical documentation. Article 18's continuous maintenance obligation means that any modification to the AI system triggers a documentation update. Maintain a change log linking system modifications to corresponding documentation revisions.
Designate a documentation owner with defined accountability. The ten-year retention period under Article 18 outlasts typical employee tenure and corporate restructuring. Assign institutional responsibility to a role rather than an individual, with handover protocols embedded in operational procedures.
Ensure documentation is audit-ready and structured for authority access. Authorities must be able to assess compliance from the documentation alone. Organize materials so that a competent authority can independently evaluate conformity without requiring supplementary explanations from the provider.
Align AI Act documentation with GDPR Article 30 records and DPIAs. Where AI systems process personal data, the technical documentation under Article 11 and the processing records under GDPR should cross-reference each other to avoid duplication and ensure consistency across regulatory regimes.