alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533
Become a Member
alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533

What AI documentation should you keep?

What AI documentation should you keep?

A good starting point for AI documentation in a small company is a suggested starter set of eight records: the AI inventory, assessments, approval decisions, test results, training records, vendor contracts and documentation, incident reports and a change log. This is not a legal minimum; what the law requires depends on your role and systems, as set out below.

The overall structure also covers the AI use policy, the incident procedure and the access-rights settings. These need not be separate files.

Who maintains each document

Recommendation. Each document needs a named owner and a clear moment when it is updated. Without both, records go out of date within months.

Document Maintained by Updated when
AI inventory Owner of the AI programme A tool is added, changed or retired; reviewed at least twice a year
Assessments: risk assessment, and a data protection impact assessment (DPIA) where required Use-case owner, with the data protection officer (DPO) where personal data is involved Before launch and whenever the use case changes
Approval decisions Person who approved the use case At each approval, condition or rejection
Test results Person who ran the tests Before launch, after a model or data change, and at spot checks
Training records Owner of the AI programme or HR After each session, and when people join or change role
Vendor contracts and documentation Person who manages the vendor At signing and renewal, and when the vendor changes its terms or model
Incident reports, including the personal data breach record where GDPR applies Person handling the incident, reviewed by the programme owner When an incident is reported and when it is closed
Change log Use-case owner Whenever the tool, model, data, purpose or users change
AI use policy and incident procedure Owner of the AI programme At each scheduled review, and after a significant incident
Access-rights settings Owner of the AI programme, with IT When people join, leave or change role

For vendor files, the answers to your questions for an AI vendor are worth keeping alongside the contract.

Keep the records in one place to look, with access control. One place does not mean company-wide access: personal data and incident material should be open only to those who need them. Set a retention and deletion rule, stating how long each type of record is kept, for example after a use case is retired, and who deletes it.

What the law requires for AI documentation

Legal requirement (GDPR, Art. 30). Controllers and processors must already keep records of their processing activities, with a limited exemption for smaller organisations (GDPR, Art. 30). Where these records apply to you, AI tools that process personal data belong in them. Linking each inventory entry to the matching record avoids keeping two versions of the same information.

Legal requirement (GDPR, Art. 33(5)). Where GDPR applies, controllers must already keep a record of every personal data breach, even when notification is not required: what happened, its effects and the remedial action taken, and the reasoning behind notification decisions (GDPR, Art. 33(5); EDPB guide on data breaches). A breach is not only a leak: it can affect the confidentiality, integrity or availability of personal data, for example through alteration or loss.

Legal requirement (EU AI Act, Art. 11, 12 and 26). High-risk AI systems carry separate documentation duties (AI Act). These apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I Section A products; Section B products follow the sector route in Art. 2(2). The full timeline is in what the EU AI Act requires. The duties are:

  • the provider draws up technical documentation before the system is placed on the market or put into service, and keeps it up to date (Art. 11);
  • the provider designs the system so that it automatically records events in logs (Art. 12);
  • the deployer keeps the logs the system automatically generates, to the extent they are under its control, for a period appropriate to the intended purpose, of at least six months, unless other Union or national law, in particular on personal data, provides otherwise (Art. 26(6); AI Act Service Desk, Art. 26).

Following the Digital Omnibus on AI, SMEs, including start-ups, and small mid-caps may provide technical documentation in a simplified form (Art. 11; Regulation (EU) 2026/1744). Which of these duties fall on your company depends on whether you are a provider or a deployer.

The starter set does not by itself meet these obligations or make a company compliant, but it is the base that specific legal requirements build on.

Next step: gather the AI documentation you already have, such as contracts, spreadsheets and emails containing approvals, into one access-controlled folder, name the person who owns it and write down the retention rule.

Sources and further reading

This article is for general information and is not legal advice.

Event

AI Horizon Conference

The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.

November 11, 2026
Lisbon, Portugal
Register Now
AI Horizon
alt alt

Join Us in Shaping the Future of Ethical AI!

Join us as a member and play a vital role in shaping a future where AI is created responsibly, with integrity, transparency, and fairness at its core.

Apply Now