Skip to main content
Praxikon
All obligations
Upcomingv1.0.0

Article 18: documentation keeping

The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.

Paragraph 1 provides that the provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a) the technical documentation referred to in Article 11; (b) the documentation concerning the quality management system referred to in Article 17; (c) the documentation concerning the changes approved by notified bodies, where applicable; (d) the decisions and other documents issued by the notified bodies, where applicable; (e) the EU declaration of conformity referred to in Article 47.

Praxikon tracks Article 18: documentation keeping under the EU AI Act, checked against the official source on 14 August 2026, citing the source for every statement.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
14 August 2026

Review status: placed against the official source (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Upcoming · 2 December 2027

For whom

  • Authorised representative
  • Deployer
  • Provider of an AI system

What you do

Set up the ten year retention of the system documentation

What you record

Retention file per high-risk system

Official source

Article 18(1)-(3)

Who this is relevant to

When this applies

  • Authorised representative

    The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service.
  2. 2Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e).

What the official source establishes

The amended application dates for Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), are 2 December 2027 for the standalone Annex III route and 2 August 2028 for high-risk AI in products covered by the Annex I harmonisation legislation.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

Four things here are our reading and not the text. First the application date: Regulation (EU) 2026/1744 does not name Article 18 separately, so the fact that this duty moves with 2 December 2027 and 2 August 2028 follows from its placement in Chapter III, Section 3, and not from an explicit provision. Second the starting moment. Paragraph 1 names the placing on the market and the putting into service side by side without choosing, and for a system where both moments occur that is years of difference at the end of the period. Counting from the later moment is the only count that falls short under neither reading, and that is what we would advise a provider. The other reading is defensible: in Union product law the placing on the market is usually the moment that counts, and then the period ends earlier. Third a substantially modified version: the text is silent, and it is equally defensible that every version gets its own period as that the original one continues. Fourth the reach of paragraph 3: it names only the technical documentation, so we keep points (b) to (e) under the general regime until the contrary is settled. Paragraph 2, finally, is addressed to the Member State and not to you. The Netherlands has not yet determined those conditions, so what happens to your file on insolvency or cessation of activity currently follows from contract and not from law.

Watch the boundaries of this duty, because they get crossed in both directions. The automatically generated logs are not among the five components: they fall under Article 19, with its own and much shorter period of at least six months, appropriate to the intended purpose, and with a clause for financial institutions that parallels paragraph 3. So do not stretch the ten years to your logs, and conversely do not settle for six months for your documentation. For a provider established in a third country the actual availability moreover sits with two parties at once: Article 22(3)(b) requires the authorised representative to keep, for ten years, the contact details of the provider, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body at the disposal of the competent authorities and of the bodies referred to in Article 74(10). Two files that drift apart are worse than one. Point (e) overlaps with Article 47(1), which gives the declaration of conformity its own ten year period, and under Article 23(5) the importer carries ten years again for the certificate, the instructions for use and the declaration of conformity. That overlap is no reason to drop one of the periods: they are independent duties of different parties. It is a reason to choose a place of retention where they coincide. On the GDPR, finally: a retention duty under Union law is itself a ground under Article 6(1)(c) GDPR, and the storage limitation of Article 5(1)(e) permits retention that the law requires. The question is therefore not whether it is allowed but how far it reaches. Ten years applies to what Article 18(1) names, and not to everything created along the way: separate test sets, log samples and raw data dumps from the documentation you must be able to produce.

This is the duty that asks nothing at the moment you take it on and everything at the moment you have forgotten it. Ten years is longer than the average life of a supplier contract, a document management system and a product team. In the organisations where we encounter this, the five components rarely sit in one archive: the quality system sits with compliance, the notified body decisions with certification, the declaration of conformity with legal. That is not law, but it is common enough that it is worth checking before you assume your situation is different. Whoever first assembles the documents when an authority asks discovers that retention in fact depended on a person and not on a process. Note also the side that is not about you: paragraph 2 concerns the situation where the provider or its representative goes bankrupt, and that is exactly the risk you run as a customer of a small supplier. It is a contracting question before it becomes a compliance question.

What you can do now

Designate per high-risk system one place of retention where the five components of paragraph 1 come together. Record side by side when the system was placed on the market and when it was put into service, and calculate the end date from the later of those two moments, so that you do not fall short under either reading. Set that end date as a commitment in a system that survives a change of staff, and keep the Article 19 logs separately with their own period. If you work with an authorised representative, record who holds which copy, because Article 22(3)(b) places the same availability on them as well. When procuring a high-risk system, put in the contract what happens to the documentation if the supplier stops or goes bankrupt, because paragraph 2 leaves that arrangement to national law that does not yet exist in the Netherlands.

  1. 01

    Set up the ten year retention of the system documentation

    Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.

What to retain

Retention file per high-risk system

Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.

Control and reassessment

  • Periodic check on completeness and retrievability of the retention file

    The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.

Public tools

Conditions and exceptions

No separate exception is recorded in this first public version.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 18(1)-(3)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113 application dates

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 18: documentation keeping",
praxikon:eu:ai-act:obligation:article-18-document-retention@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z,
sha256 0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb,
https://www.praxikon.com/en/verplichtingen/article-18-document-retention
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-18-document-retention&effective_at=2026-07-27&known_at=2026-08-14&lang=en, accessed 2026-09-15)

Short form

praxikon:eu:ai-act:obligation:article-18-document-retention@1.0.0 (sha256 0971f35c)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-18-document-retention-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 18: documentation keeping},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-18-document-retention},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb},
  url          = {https://www.praxikon.com/en/verplichtingen/article-18-document-retention},
  urldate      = {2026-09-15},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-18-document-retention@1.0.0",
    "type": "dataset",
    "title": "Article 18: documentation keeping",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-18-document-retention",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-18-document-retention",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          14
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          15
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-18-document-retention&effective_at=2026-07-27&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    27 July 2026

    Article 18: documentation keeping

    The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist

Help with implementation

Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.

View AI governance at Embed AI

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.