# AI Record-Keeping — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/record-keeping-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-specific documentation, logging, and record retention requirements that differ from traditional data protection record-keeping.

## Overview

## Legal Framework

AI record-keeping obligations under the AI Act are anchored primarily in Articles 11 and 12, which impose documentation and logging requirements that are structurally distinct from GDPR Article 30 record-keeping. Article 11 requires providers of high-risk AI systems to draw up and maintain technical documentation demonstrating compliance with the requirements set out in Chapter III of the Act, before the system is placed on the market. The documentation must enable national competent authorities and notified bodies to assess conformity with the Act's requirements. Annex IV prescribes the specific content, covering system architecture, training data descriptions, design specifications, and risk mitigation measures.

Article 12 imposes a separate obligation to ensure that high-risk AI systems are technically capable of automatically recording events (logs) while operating. These logs must enable post-hoc monitoring of the system's functioning relative to the intended purpose and must be retained for a period appropriate to the system's purpose and complexity. This is not a processing-records obligation but a technical capability and retention requirement embedded in the system itself.

Recital 109 introduces a proportionality principle for general-purpose AI model providers, signalling that compliance burdens should scale with provider size and model risk profile. SMEs and start-ups may benefit from simplified compliance pathways, though the substantive obligation to maintain adequate documentation remains.

## Key Developments

No enforcement actions under the AI Act have yet materialised, given the phased application timeline. However, the GDPR enforcement landscape provides instructive parallels. The Dutch Data Protection Authority's approach to documentation deficiencies — particularly its emphasis on demonstrable accountability under Article 5(2) GDPR — signals how supervisory authorities are likely to approach AI Act technical documentation gaps. Regulators have consistently treated incomplete or generic documentation as evidence of non-compliance rather than mere administrative oversight.

The CJEU's jurisprudence on Article 22 GDPR (automated decision-making), including *Schufa Holding v. BF*, establishes that meaningful documentation of automated processing logic is a precondition for lawful deployment. This principle will likely transfer to AI Act enforcement: providers unable to produce coherent technical documentation tracing training data lineage, model behaviour, and risk mitigation will face structural compliance failures rather than marginal ones.

## Practical Guidance

- **Map your role before documenting anything.** Article 11 obligations attach to providers; deployer obligations are narrower under Article 26. Misallocating documentation responsibilities between provider and deployer creates gaps that neither party fills.
- **Build logging capability into the system architecture at design stage.** Article 12 requires automatic event recording as a technical feature, not a manual process. Retrofitting logging capability after deployment will not satisfy the obligation and may itself constitute evidence of non-compliance.
- **Align AI Act documentation with GDPR Article 30 records where overlapping.** Where an AI system processes personal data, the technical documentation under Article 11 and the processing records under Article 30 GDPR should cross-reference each other, but must not be conflated — they serve different supervisory purposes and different authorities.
- **Apply the proportionality principle from Recital 109 to documentation depth.** For SME providers of general-purpose AI models, simplified documentation pathways are available, but the threshold for "simplified" is not defined — maintain substantive coverage of core risk areas even in abbreviated formats.
- **Set retention periods by reference to system risk, not a fixed calendar.** Article 12's "appropriate period" language requires a risk-based determination. High-risk systems used in law enforcement or biometric identification will demand longer retention than low-impact applications.

## Legislation (full text of key provisions)

### Technical documentation

*Source: AI Act, aiact-art-11-en, 2024-06-12 — https://overview.legal/posts/92155*

### Recital 71 — high-risk AI technical documentation and logs

*Source: AI Act, aiact-rec-71-en, 2024-06-12 — https://overview.legal/posts/93824*

Having comprehensible information on how high-risk AI systems have been developed and how they perform throughout their lifetime is essential to enable traceability of those systems, verify compliance with the requirements under this Regulation, as well as monitoring of their operations and post market monitoring. This requires keeping records and the availability of technical documentation, containing information which is necessary to assess the compliance of the AI system with the relevant requirements and facilitate post market monitoring. Such information should include the general characteristics, capabilities and limitations of the system, algorithms, data, training, testing and validation processes used as well as documentation on the relevant risk-management system and drawn in a clear and comprehensive form. The technical documentation should be kept up to date, appropriately throughout the lifetime of the AI system. Furthermore, high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system.

### Recital 109 — proportionate compliance for general-purpose AI providers

*Source: AI Act, aiact-rec-109-en, 2024-06-12 — https://overview.legal/posts/93900*

Compliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

### Recital 66 — risk management requirements for high-risk AI

*Source: AI Act, aiact-rec-66-en, 2024-06-12 — https://overview.legal/posts/93814*

Requirements should apply to high-risk AI systems as regards risk management, the quality and relevance of data sets used, technical documentation and record-keeping, transparency and the provision of information to deployers, human oversight, and robustness, accuracy and cybersecurity. Those requirements are necessary to effectively mitigate the risks for health, safety and fundamental rights. As no other less trade restrictive measures are reasonably available those requirements are not unjustified restrictions to trade.

### Recital 9 — Harmonised cross-sectoral high-risk AI market rules

*Source: AI Act, aiact-rec-9-en, 2024-06-12 — https://overview.legal/posts/93700*

Harmonised rules applicable to the placing on the market, the putting into service and the use of high-risk AI systems should be laid down consistently with Regulation (EC) No 765/2008 of the European Parliament and of the Council (7), Decision No 768/2008/EC of the European Parliament and of the Council (8) and Regulation (EU) 2019/1020 of the European Parliament and of the Council (9) (New Legislative Framework). The harmonised rules laid down in this Regulation should apply across sectors and, in line with the New Legislative Framework, should be without prejudice to existing Union law, in particular on data protection, consumer protection, fundamental rights, employment, and protection of workers, and product safety, to which this Regulation is complementary. As a consequence, all rights and remedies provided for by such Union law to consumers, and other persons on whom AI systems may have a negative impact, including as regards the compensation of possible damages pursuant to Council Directive 85/374/EEC (10) remain unaffected and fully applicable. Furthermore, in the context of employment and protection of workers, this Regulation should therefore not affect Union law on social policy and national labour law, in compliance with Union law, concerning employment and working conditions, including health and safety at work and the relationship between employers and workers. This Regulation should also not affect the exercise of fundamental rights as recognised in the Member States and at Union level, including the right or freedom to strike or to take other action covered by the specific industrial relations systems in Member States as well as the right to negotiate, to conclude and enforce collective agreements or to take collective action in accordance with national law. This Regulation should not affect the provisions aiming to improve working conditions in platform work laid down in a Directive of the European Parliament and of the Council on improving working conditions in platform work. Moreover, this Regulation aims to strengthen the effectiveness of such existing rights and remedies by establishing specific requirements and obligations, including in respect of the transparency, technical documentation and record-keeping of AI systems. Furthermore, the obligations placed on various operators involved in the AI value chain under this Regulation should apply without prejudice to national law, in compliance with Union law, having the effect of limiting the use of certain AI systems where such law falls outside the scope of this Regulation or pursues legitimate public interest objectives other than those pursued by this Regulation. For example, national labour law and law on the protection of minors, namely persons below the age of 18, taking into account the UNCRC General Comment No 25 (2021) on children’s rights in relation to the digital environment, insofar as they are not specific to AI systems and pursue other legitimate public interest objectives, should not be affected by this Regulation.

## Guidance

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

## Recent developments

### De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming).

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/51791*

De GDPR-risicoanalyse is bedoeld om controllers en verwerkers te helpen bij het identificeren van de risicofactoren voor de rechten en vrijheden van de betrokkenen, wiens gegevens worden verwerkt. Het doel is om een eerste inschatting te maken van het inherente risico, inclusief de noodzaak om een Privacy Impact Assessment (DIA) uit te voeren, en om het resterende risico te schatten als maatregelen en beveiligingsmechanismen worden gebruikt om specifieke risicofactoren te verminderen.

### CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/6291 — original: https://www.huntonprivacyblog.com/2022/08/17/cnil-proposes-60-million-euros-fine-against-french-adtech-company-for-non-compliance-with-gdpr/#entry-12*

> The proposed fine follows complaints filed by privacy NGO ‘Privacy International’ against Criteo. […]
Under the CNIL’s sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

### Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations

*Source: Hunton Andrews Kurth, 2022-09-07 — https://overview.legal/posts/6284 — original: https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/#entry-216*

> The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, children’s phone numbers and email addresses were publicly accessible.

## Literature

### Technical Documentation Obligations in Data Protection, Technology, and Cybersecurity Law

*Source: Computer Law Review International, 2026-03-01 — https://overview.legal/posts/132593 — original: https://doi.org/10.9785/cri-2026-270104*

Abstract The article examines the obligation to prepare technical documentation under the GDPR, the CRA, and the AI Act, conducts a comparative analysis to explore synergies, overlaps, and divergences between the technical documentation obligations under the three frameworks, and assesses the feasibility of developing joint technical documentation.

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Related topics

- **Technical Documentation for AI Systems** — https://overview.legal/topics/technical-documentation-ai
  The AI Act imposes specific technical documentation requirements for AI systems, particularly high-risk AI systems. This dedicated topic would cover the mandato
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Documentation Keeping for AI Systems** — https://overview.legal/topics/documentation-keeping-ai
  While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requir
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **AI Act Requirements** — https://overview.legal/topics/ai-act-requirements
  The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that go
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection

---
Generated by overview.legal · https://overview.legal/topics/record-keeping-ai · 2026-08-22
