# Documentation Keeping for AI Systems — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/documentation-keeping-ai
> Sources are cited per item. Verify against the official texts before relying on them.

While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requirements around maintaining, organizing, and preserving documentation throughout an AI system's lifecycle, including technical, compliance, and operational documentation.

## Overview

## Legal Framework

Documentation keeping for AI systems is governed primarily by Article 11 and Article 18 of the EU AI Act. Article 11 establishes the obligation for providers of high-risk AI systems to draw up and maintain technical documentation before placing a system on the market or putting it into service. This documentation must demonstrate compliance with the substantive requirements set out in Chapter III of the Act and must be prepared before the system's conformity assessment. The technical documentation must contain, at minimum, a general description of the AI system, its intended purpose, the development process, data training methodologies, and information enabling authorities to assess compliance.

Article 18 specifically addresses documentation keeping as a distinct obligation. It requires providers to maintain the technical documentation and related records for a period of ten years after the AI system has been placed on the market, with the possibility of extension by national authorities. This provision establishes documentation not merely as a one-time compliance exercise but as a continuous lifecycle obligation. The rationale is twofold: enabling post-market surveillance by competent authorities and ensuring traceability throughout the system's operational life. Providers must keep the documentation in a manner that allows authorities to access it upon request, and where the system is modified, updated documentation must reflect the current state of the system.

The interplay between Articles 11 and 18 creates a dual structure: Article 11 governs the content and creation of documentation, while Article 18 governs its preservation, organization, and accessibility over time.

## Key Developments

As the AI Act entered into force in August 2024, enforcement has not yet produced a body of case law or DPA decisions specifically interpreting the documentation-keeping obligations. However, the GDPR enforcement landscape provides instructive analogues. In *SCHUFA Holding AG v. C-634/21*, the CJEU emphasized that automated decision-making processes require demonstrable documentation to enable meaningful judicial review. National DPAs, including the Italian Garante's 2023 restriction on ChatGPT, have consistently demanded that organizations produce evidence of data processing activities — signaling that the absence of documentation will be treated as a standalone compliance failure rather than a procedural gap.

The Dutch DPA's enforcement posture under GDPR Article 30 record-keeping requirements further establishes that authorities expect documentation to be contemporaneous, structured, and retrievable on demand. This precedent will likely transfer to AI Act enforcement, where Article 18's ten-year retention period sets an even higher bar.

## Practical Guidance

- **Establish a documentation lifecycle protocol** that maps to each phase of AI system development, deployment, and post-market monitoring. Article 11 requires technical documentation to exist before market placement — meaning documentation must be built into the development pipeline, not retrofitted.

- **Implement version control for all technical documentation.** Article 18's continuous maintenance obligation means that any modification to the AI system triggers a documentation update. Maintain a change log linking system modifications to corresponding documentation revisions.

- **Designate a documentation owner with defined accountability.** The ten-year retention period under Article 18 outlasts typical employee tenure and corporate restructuring. Assign institutional responsibility to a role rather than an individual, with handover protocols embedded in operational procedures.

- **Ensure documentation is audit-ready and structured for authority access.** Authorities must be able to assess compliance from the documentation alone. Organize materials so that a competent authority can independently evaluate conformity without requiring supplementary explanations from the provider.

- **Align AI Act documentation with GDPR Article 30 records and DPIAs.** Where AI systems process personal data, the technical documentation under Article 11 and the processing records under GDPR should cross-reference each other to avoid duplication and ensure consistency across regulatory regimes.

## Legislation (full text of key provisions)

### Technical documentation

*Source: AI Act, aiact-art-11-en, 2024-06-12 — https://overview.legal/posts/92155*

### Documentation keeping

*Source: AI Act, aiact-art-18-en, 2024-06-12 — https://overview.legal/posts/92279*

### Recital 71 — high-risk AI technical documentation and logs

*Source: AI Act, aiact-rec-71-en, 2024-06-12 — https://overview.legal/posts/93824*

Having comprehensible information on how high-risk AI systems have been developed and how they perform throughout their lifetime is essential to enable traceability of those systems, verify compliance with the requirements under this Regulation, as well as monitoring of their operations and post market monitoring. This requires keeping records and the availability of technical documentation, containing information which is necessary to assess the compliance of the AI system with the relevant requirements and facilitate post market monitoring. Such information should include the general characteristics, capabilities and limitations of the system, algorithms, data, training, testing and validation processes used as well as documentation on the relevant risk-management system and drawn in a clear and comprehensive form. The technical documentation should be kept up to date, appropriately throughout the lifetime of the AI system. Furthermore, high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system.

### Recital 109 — proportionate compliance for general-purpose AI providers

*Source: AI Act, aiact-rec-109-en, 2024-06-12 — https://overview.legal/posts/93900*

Compliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.

### Recital 66 — risk management requirements for high-risk AI

*Source: AI Act, aiact-rec-66-en, 2024-06-12 — https://overview.legal/posts/93814*

Requirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of information to deployers, human oversight, and robustness, accuracy and cybersecurity. Those requirements are necessary to effectively mitigate the risks for health, safety and fundamental rights. As no other less trade restrictive measures are reasonably available those requirements are not unjustified restrictions to trade.

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

### Recital 9 — Harmonised cross-sectoral high-risk AI market rules

*Source: AI Act, aiact-rec-9-en, 2024-06-12 — https://overview.legal/posts/93700*

Harmonised rules applicable to the placing on the market, the putting into service and the use of high-risk AI systems should be laid down consistently with Regulation (EC) No 765/2008 of the European Parliament and of the Council (7), Decision No 768/2008/EC of the European Parliament and of the Council (8) and Regulation (EU) 2019/1020 of the European Parliament and of the Council (9) (New Legislative Framework). The harmonised rules laid down in this Regulation should apply across sectors and, in line with the New Legislative Framework, should be without prejudice to existing Union law, in particular on data protection, consumer protection, fundamental rights, employment, and protection of workers, and product safety, to which this Regulation is complementary. As a consequence, all rights and remedies provided for by such Union law to consumers, and other persons on whom AI systems may have a negative impact, including as regards the compensation of possible damages pursuant to Council Directive 85/374/EEC (10) remain unaffected and fully applicable. Furthermore, in the context of employment and protection of workers, this Regulation should therefore not affect Union law on social policy and national labour law, in compliance with Union law, concerning employment and working conditions, including health and safety at work and the relationship between employers and workers. This Regulation should also not affect the exercise of fundamental rights as recognised in the Member States and at Union level, including the right or freedom to strike or to take other action covered by the specific industrial relations systems in Member States as well as the right to negotiate, to conclude and enforce collective agreements or to take collective action in accordance with national law. This Regulation should not affect the provisions aiming to improve working conditions in platform work laid down in a Directive of the European Parliament and of the Council on improving working conditions in platform work. Moreover, this Regulation aims to strengthen the effectiveness of such existing rights and remedies by establishing specific requirements and obligations, including in respect of the transparency, technical documentation and record-keeping of AI systems. Furthermore, the obligations placed on various operators involved in the AI value chain under this Regulation should apply without prejudice to national law, in compliance with Union law, having the effect of limiting the use of certain AI systems where such law falls outside the scope of this Regulation or pursues legitimate public interest objectives other than those pursued by this Regulation. For example, national labour law and law on the protection of minors, namely persons below the age of 18, taking into account the UNCRC General Comment No 25 (2021) on children’s rights in relation to the digital environment, insofar as they are not specific to AI systems and pursue other legitimate public interest objectives, should not be affected by this Regulation.

## Guidance

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

## Literature

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### Technical Documentation Obligations in Data Protection, Technology, and Cybersecurity Law

*Source: Computer Law Review International, 2026-03-01 — https://overview.legal/posts/132593 — original: https://doi.org/10.9785/cri-2026-270104*

Abstract The article examines the obligation to prepare technical documentation under the GDPR, the CRA, and the AI Act, conducts a comparative analysis to explore synergies, overlaps, and divergences between the technical documentation obligations under the three frameworks, and assesses the feasibility of developing joint technical documentation.

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### Perspectives for Open Source AI

*Source: i-lex, 2026-07-07 — https://overview.legal/posts/83512 — original: https://doi.org/10.60923/issn.1825-1927/23382*

The world’s first most comprehensive law regulating artificial intelligence, the EU Artificial Intelligence Act, has been enacted in June 2024 and entered into force in August 2024. The AI Act aims to provide transparency and ensure safe use of AI systems by introducing obligations and requirements for developers and deployers based on the risk posed by AI systems. Despite the long legislation process that launched in 2020 and multiple negotiations, the final version of the Act includes a number

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

## Related topics

- **Technical Documentation for AI Systems** — https://overview.legal/topics/technical-documentation-ai
  The AI Act imposes specific technical documentation requirements for AI systems, particularly high-risk AI systems. This dedicated topic would cover the mandato
- **AI Record-Keeping** — https://overview.legal/topics/record-keeping-ai
  The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-spe
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **AI Act Requirements** — https://overview.legal/topics/ai-act-requirements
  The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that go
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection

---
Generated by overview.legal · https://overview.legal/topics/documentation-keeping-ai · 2026-08-22
