# Technical documentation, model cards and instructions for use

- **Record type**: Control
- **Kind**: Process
- **Owner**: Product or model owner
- **Frequency**: At launch and on material change
- **Duties served**: 13

## What the control achieves

Produces and maintains the documentation that lets a regulator, a customer or a deployer understand what a system is, how it was built and tested, what it is for and how to use it safely.

## How it is typically implemented

A documentation set is started at design time and grows with the system: intended purpose and out-of-scope uses, architecture and dependencies, training and evaluation data, performance results and their limits, known risks and mitigations, oversight measures and the resources needed to operate it. From the same source the team derives a shorter model card or deployer information pack and the instructions for use that ship with each release. Documents live under version control, each release tags the version it was assessed against, and an owner is responsible for updating them whenever the system changes materially.

## Evidence it produces

- Technical documentation file (technical_file): Assembled, versioned documentation of design, data, testing, risks and oversight for one system.
- Model card or deployer information pack (model_documentation)
- Instructions for use (disclosure_notice): User-facing document describing purpose, limits, oversight measures and how to interpret output.

## Legal duties this control serves

- Draw up technical documentation before placing a high-risk system on the market — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation
- Provide deployers with clear instructions for use — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-transparency-to-deployers
- Complete conformity assessment, CE marking and EU database registration — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration
- Meet general-purpose AI model provider obligations — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations
- Providers must keep high-risk AI documentation for ten years — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities
- Providers of GPAI models must maintain technical documentation and inform downstream providers — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-53-gpai-technical-and-downstream-documentation
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-54-gpai-authorised-representative
- Operators of high-impact AI must be able to explain outputs and the main criteria behind them — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (supports): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-explanation-measures
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-user-protection-and-documentation
- Provide appropriate transparency and explainability — UK AI regulation framework, United Kingdom (supports): https://aipolicytracker.org/obligations/uk-principles-transparency-explainability
- Frontier developers must publish a transparency report before deploying a new frontier model — California SB 53, California (United States) (satisfies): https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
- Developers must document high-risk systems and disclose known risks — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-developer-documentation-and-disclosure

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 7.5; Annex A.6.2.3, A.6.2.7, A.8.2
- NIST AI RMF 1.0: GOVERN 1.4; MAP 2.2; MEASURE 2.8

## MIT AI Risk Repository subdomains addressed

7.4, 5.1, 7.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/technical-documentation-and-model-cards
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
