Chapter III · Section 3 · Obligations of providers and deployers of high-risk AI systems and other parties
Article 18 — Documentation keeping
▼ Primary text, verbatim. Our annotations appear below, visibly separated.
1. The provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities:
(a) the technical documentation referred to in Article 11;
(b) the documentation concerning the quality management system referred to in Article 17;
(c) the documentation concerning the changes approved by notified bodies, where applicable;
(d) the decisions and other documents issued by the notified bodies, where applicable;
(e) the EU declaration of conformity referred to in Article 47.
2. Each Member State shall determine conditions under which the documentation referred to in paragraph 1 remains at the disposal of the national competent authorities for the period indicated in that paragraph for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period.
3. Providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.
What this means for you
In your terms · Keeping the documentation for ten years
The technical file you generate today must still be producible a decade from now.
In your terms · Keeping the documentation for ten years
Durable, restorable storage for the archive is an operations problem: test the restore, not just the backup.
- Archive restore test on a schedule
In your terms · Keeping the documentation for ten years
Ten years outlives your stack, your vendors and probably your storage format. Custody needs a named owner and a migration plan.
- Ten-year documentation archive with named custodian
Failure smells likeA request arrives for the file of a system retired four years ago, and the repository it lived in was archived with the team that owned it.
Obligations derived from this article
If you would rather not read the law
The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.