Technical documentation
Technical documentation is the record demonstrating a high-risk AI system's compliance, covering the nine points of Annex IV, which must be drawn up before placing on the market, kept up to date, and retained for ten years. It is the record from which a regulator can later reconstruct how the system and its classification decision came about.
The content and timing requirements are set out in Articles 11, 12, 18 and 19, and Article 47(1), with the detailed list in points 1–9 of Annex IV. The documentation must cover, among other things, a general description of the system, the development process, oversight and governance mechanisms, performance metrics, and the risk management system. The ten-year retention period is far longer than the six-month retention duty for logs — reflecting that the documentation does not serve operational incident handling, but long-term, after-the-fact accountability. The documentation cannot simply be produced once: it must be updated in the event of a substantial modification or a material change occurring during the system's lifetime, otherwise a market surveillance authority may deem it outdated and therefore non-compliant.
Documentation must be prepared BEFORE placing on the market, not reconstructed afterwards — in a regulatory review, after-the-fact justifications are, in practice, not accepted.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Risk management systemThe risk management system is a continuous, documented, testing-based process spanning the entire lifecycle of a high-risk AI system, which identifies, evaluates and mitigates the risks the system poses to the health, safety and fundamental rights of third persons. It does not manage organisational risk — it protects a different interest than ISO 31000 or ISO/IEC 42001, and neither creates a presumption of conformity, since neither is a harmonised standard.
- Data governanceData governance covers eight practices applicable to the training, validation and testing data sets of a high-risk AI system, and the substantive standard that data sets be relevant, sufficiently representative, and, to the best extent possible, free of errors and complete. The legislator does not demand flawless data sets, but documented diligence proportionate to the intended purpose.
- LoggingLogging is the automatic recording of events during the operation of a high-risk AI system, enabling traceability and regulatory oversight. Providers must design the system to have logging capabilities, while deployers are subject to a duty to retain the resulting logs for at least six months.
- EU declaration of conformityThe EU declaration of conformity is the provider's written statement that a high-risk AI system meets the applicable requirements of the Regulation. It must be drawn up per system, made available to the market surveillance authority, and kept for at least ten years after the system is withdrawn from the market.
Related questions in the knowledge base (Hungarian)
- Mit kell tartalmaznia a magas kockázatú AI műszaki dokumentációjának és naplózásának?A műszaki dokumentációt a piacra hozatal előtt kell elkészíteni és naprakészen tartani, és a IV. melléklet kilenc pontját kell lefednie. A dokumentációt tíz évig, a szolgáltató kezelésében lévő automatikus naplókat legalább hat hónapig kell megőrizni; az alkalmazói oldalon ugyanez a hat hónap él a 26. cikk (6) alapján.
- Milyen dokumentáció bizonyítja utólag, hogy az AI-rendszerünk nem magas kockázatú?A 6. cikk (4) szerinti, a piacra helyezés előtt keletkezett besorolási értékelés, a 49. cikk (2) szerinti EU-adatbázis-regisztráció, és az ezeket alátámasztó, nyomon követhető bizonyítékok. A kulcs a datáltság és az előzetesség: az utólag gyártott indokolást a hatóság nem fogadja el. Egyetlen aláírt döntés helyett folyamatot kell tudni felmutatni.