Providers must keep high-risk AI documentation for ten years
Context fileUnder EU AI Act, Article 18
What does it require?
For ten years after a high-risk AI system is placed on the market or put into service, the provider must keep at the disposal of national competent authorities the technical documentation, the quality management system documentation, any changes approved by a notified body, the notified body's decisions and other documents, and the EU declaration of conformity. Financial institutions keep these as part of their sector record-keeping.
Practical action
Set a ten-year retention class for the technical file, QMS records and conformity documents of each high-risk system.
Who does it apply to?
Providers of high-risk AI systems; retention runs from the date the system was placed on the market or put into service.
- Actors
- Provider / developer
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesTechnical measureEngineering lead · continuousAutomatic event logging and record retention
Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check
Retention classes and archive controls for the listed documents.
-
supportsProcessProduct or model owner · at launch and on material changeTechnical documentation, model cards and instructions for use
Serves 13 recorded duties · evidence: Technical documentation file, Model card or deployer information pack, Instructions for use
Produces the technical file that must be retained.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Retention schedule for AI conformity records | document | Retention class, storage location and disposal date per document type. |
| Technical file archive index | register |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 7.5.3; Annex A.6.2.7 | Control of documented information and technical documentation. | high |
| NIST AI RMF 1.0 | GOVERN 1.4 | Documentation of governance and risk decisions retained. | medium |
Cite this record
AIPolicyTracker (2026). “Providers must keep high-risk AI documentation for ten years (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Design high-risk systems to log events automatically — EU AI Act, European Union
- Providers must retain automatically generated logs under their control — EU AI Act, European Union
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.