Skip to content
Topic Regulator-defined

AI Record-Keeping

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-specific documentation, logging, and record retention requirements that differ from traditional data protection record-keeping.

16 linked items 7 Laws3 Guidance6 Literature

Overview

12 sources · Sep 8, 2026

Legal Framework

AI record-keeping under the AI Act is governed primarily by Article 11, Article 18, and Article 22, which impose documentation, retention, and delegation obligations on providers of high-risk AI systems. These requirements are structurally distinct from GDPR Article 30 record-keeping: they attach to the AI system itself, not to personal data processing operations, and they bind the "provider" as defined in Article 3.

Article 11 requires that technical documentation be prepared before a high-risk AI system is placed on the market or put into service. The documentation must demonstrate compliance with the high-risk AI section and provide authorities with the information needed to assess conformity:

"The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date."
— AI Act Art. 11

Article 18 sets the retention framework. Providers must retain the technical documentation, quality management system documentation, conformity assessment decisions, and the EU declaration of conformity for ten years:

"The provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities:"
— AI Act Art. 18

Article 18(3) provides a specific accommodation for financial institutions, allowing them to maintain technical documentation within their existing Union financial services law documentation frameworks. Article 22 extends record-keeping obligations to authorised representatives of third-country providers, who must verify that documentation has been drawn up and retain copies for the same ten-year period:

"verify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred to in Article 11 have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider;"
— AI Act Art. 22

Key Developments

No enforcement decisions or court rulings have yet interpreted the AI Act's record-keeping provisions. The Act's application dates for high-risk AI systems are phased, meaning the first compliance assessments and potential enforcement actions are still ahead. The EDPB and EDPS have issued joint opinions on simplification proposals affecting record-keeping for SMEs, indicating that regulatory guidance is forming before litigation reaches the courts.

The practical threshold for compliance is therefore set by the statutory text: documentation must be comprehensive enough to allow a competent authority to assess conformity with all requirements in the high-risk AI section. The ten-year retention period operates as a regulatory floor, and the obligation to keep documentation "up-to date" under Article 11(1) imposes a dynamic rather than static duty — documentation must reflect post-deployment modifications.

Status of the Debate

This topic is regulator-defined. The AI Act's record-keeping provisions are newly in force and have not been tested by courts or enforcement bodies. Interpretive questions — what level of detail satisfies the "clear and comprehensive form" standard in Article 11, how the ten-year retention interacts with provider insolvency under Article 18(2), and what constitutes sufficient verification by authorised representatives under Article 22 — remain open. Resolution will likely come through the first market surveillance actions and any delegated acts amending Annex IV to specify documentation contents.

Practical Guidance

  • Prepare technical documentation before deployment: Article 11 requires documentation to be drawn up before the high-risk AI system is placed on the market, and maintained continuously thereafter.
  • Implement a ten-year retention policy: Retain all documentation listed in Article 18(1)(a)–(e) for ten years from the date of placement on the market, with insolvency contingency planning under Article 18(2).
  • Designate an EU authorised representative if established outside the Union: Article 22 requires third-country providers to appoint a representative who must hold copies of the technical documentation and EU declaration of conformity for the same ten-year period.
  • Integrate with existing financial services documentation where applicable: Financial institutions may maintain technical documentation within their existing governance frameworks under Article 18(3).
  • Establish a documentation update process: The Article 11 obligation to keep technical documentation "up-to date" requires a procedure for revising records when the AI system is modified or retrained.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section