AIPolicyTracker
Legal requirement Record keeping and logging European Union Partially applicable

Providers must keep high-risk AI documentation for ten years

Context fileUnder EU AI Act, Article 18

Source-linked Open official source

What does it require?

For ten years after a high-risk AI system is placed on the market or put into service, the provider must keep at the disposal of national competent authorities the technical documentation, the quality management system documentation, any changes approved by a notified body, the notified body's decisions and other documents, and the EU declaration of conformity. Financial institutions keep these as part of their sector record-keeping.

Practical action

Set a ten-year retention class for the technical file, QMS records and conformity documents of each high-risk system.

Who does it apply to?

Providers of high-risk AI systems; retention runs from the date the system was placed on the market or put into service.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesTechnical measureEngineering lead · continuous
    Automatic event logging and record retention

    Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check

    Retention classes and archive controls for the listed documents.

  • supportsProcessProduct or model owner · at launch and on material change
    Technical documentation, model cards and instructions for use

    Serves 13 recorded duties · evidence: Technical documentation file, Model card or deployer information pack, Instructions for use

    Produces the technical file that must be retained.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Retention schedule for AI conformity recordsdocumentRetention class, storage location and disposal date per document type.
Technical file archive indexregister

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 7.5.3; Annex A.6.2.7Control of documented information and technical documentation.high
NIST AI RMF 1.0GOVERN 1.4Documentation of governance and risk decisions retained.medium

Cite this record

AIPolicyTracker (2026). “Providers must keep high-risk AI documentation for ten years (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.