Technical documentation, model cards and instructions for use
Produces and maintains the documentation that lets a regulator, a customer or a deployer understand what a system is, how it was built and tested, what it is for and how to use it safely.
- Duties satisfied
- 7
- done properly, does the work
- Duties supported
- 6
- contributes; the duty needs more
- Jurisdictions
- 5
- Evidence items
- 3
How is it implemented?
A documentation set is started at design time and grows with the system: intended purpose and out-of-scope uses, architecture and dependencies, training and evaluation data, performance results and their limits, known risks and mitigations, oversight measures and the resources needed to operate it. From the same source the team derives a shorter model card or deployer information pack and the instructions for use that ship with each release. Documents live under version control, each release tags the version it was assessed against, and an owner is responsible for updating them whenever the system changes materially.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
California (United States) 1 duty
-
satisfies Legal requirement confidence highFrontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53) · applies from 1 Jan 2026
The model card content the report is built from.
Colorado (United States) 1 duty
-
satisfies Legal requirement confidence highDevelopers must document high-risk systems and disclose known risks
Colorado AI Act · C.R.S. 6-1-1702 · applies from 30 Jun 2026
Deployer information pack and public statement derived from the documentation set.
European Union 8 duties
-
satisfies Legal requirement confidence highDraw up technical documentation before placing a high-risk system on the market
EU AI Act · Article 11 and Annex IV · applies from 2 Aug 2026
Versioned technical file structured to the required elements.
-
satisfies Legal requirementProvide deployers with clear instructions for use
EU AI Act · Article 13 · applies from 2 Aug 2026
Instructions for use derived from the technical documentation.
-
satisfies Legal requirementMeet general-purpose AI model provider obligations
EU AI Act · Article 53 and Annexes XI–XII · applies from 2 Aug 2025
Provides the model documentation and the downstream information pack.
-
satisfies Legal requirement confidence highProviders of GPAI models must maintain technical documentation and inform downstream providers
EU AI Act · Article 53(1)(a) and 53(1)(b); Annexes XI and XII · applies from 2 Aug 2025
Model card and technical file structured to Annexes XI and XII.
-
supports Legal requirement confidence highComplete conformity assessment, CE marking and EU database registration
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII · applies from 2 Aug 2026
The technical file is the input to the assessment.
-
supports Legal requirement confidence highProviders must keep high-risk AI documentation for ten years
EU AI Act · Article 18 · applies from 2 Aug 2026
Produces the technical file that must be retained.
-
supports Legal requirement confidence highProviders must supply conformity evidence and log access to authorities on request
EU AI Act · Article 21 · applies from 2 Aug 2026
The documentation set that is handed over.
-
supports Legal requirement confidence highNon-EU providers of GPAI models must appoint an EU authorised representative
EU AI Act · Article 54 · applies from 2 Aug 2025
The documentation the representative holds.
South Korea 2 duties
-
satisfies Legal requirementOperators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1) · applies from 22 Jan 2026
Documentation of safety and reliability measures.
-
supports Legal requirement confidence highOperators of high-impact AI must be able to explain outputs and the main criteria behind them
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1) · applies from 22 Jan 2026
Training-data overview and decision logic documented.
United Kingdom 1 duty
-
supports VoluntaryProvide appropriate transparency and explainability
UK AI regulation framework · Principle 2, Part 3
Explainability documentation.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| Technical documentation file | Technical documentation file | Assembled, versioned documentation of design, data, testing, risks and oversight for one system. |
| Model card or deployer information pack | Model documentation | |
| Instructions for use | Disclosure or notice | User-facing document describing purpose, limits, oversight measures and how to interpret output. |
Owner: Product or model owner. Frequency: at launch and on material change.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 7.4 Lack of transparency or interpretability AI system safety, failures, & limitations5 incidents · 42 risk entries
- 5.1 Overreliance and unsafe use Human-Computer Interaction38 incidents · 60 risk entries
- 7.3 Lack of capability or robustness AI system safety, failures, & limitations305 incidents · 126 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Clause 7.5; Annex A.6.2.3, A.6.2.7, A.8.2 | high | |
| NIST AI RMF | GOVERN 1.4; MAP 2.2; MEASURE 2.8 | medium |
Cite this record
AIPolicyTracker (2026). “Technical documentation, model cards and instructions for use”. https://aipolicytracker.org/controls/technical-documentation-and-model-cards (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Technical documentation, model cards and instructions for use" satisfy?
- It is recorded as satisfying 7 and supporting 6 duties across California (United States), Colorado (United States), European Union, South Korea and United Kingdom. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- Technical documentation file, Model card or deployer information pack and Instructions for use. Owner: Product or model owner. Frequency: at launch and on material change.