Skip to content
Digital Transformation

What AI Documentation the AI Act Requires

The AI Act does not require one document but several, each resting on a different provision and addressed to a different role. An overview of which record rests on what, and who has to keep it.

Emanuel Stadler, MA·22 June 2026·9 min read

This article describes the content of the regulation. It is not legal advice and not an assessment of your specific case, in particular not a statement about which role your company holds.

Ask inside a business what the AI Act requires in terms of documentation and you usually get one of two answers: nothing at all, because we do not build our own AI. Or everything, because lists circulate online that throw every conceivable duty into one pot. Both are misleading.

The regulation in fact requires several distinct records. Each rests on its own provision, and each addresses a particular role. Knowing that mapping quickly shows which part is even in question.

The role decides, not the industry

The AI Act distinguishes providers from deployers. Providers develop a system and place it on the market under their own name. Deployers use a system in the course of their professional activity. Most companies that buy and use AI tools fall into the second group.

That mapping is not static, though. Article 25 describes cases in which a deployer is considered a provider: where they put a system on the market under their own name or trademark, where they make a substantial modification, or where they change the intended purpose such that the system becomes high risk. Anyone passing a purchased tool on to customers under their own name should know this point.

The records and what they rest on

Sorted by what actually occurs in a company that does not build its own AI:

  • Evidence of AI literacy under Article 4. No form prescribed, addressed to providers and deployers.
  • Marking under Article 50 where people interact with an AI system or content has been artificially generated.
  • Classification where a provider concludes that a system from Annex III is not high risk: Article 6(3) and (4), with registration under Article 49(2) and submission to authorities on request.
  • Technical documentation under Article 11 with Annex IV, nine sections, addressed to providers of high risk systems.
  • Automatically generated logs under Article 12, with retention by deployers under Article 26(6).
  • Deployer duties under Article 26: use in accordance with the instructions, appropriate input data, human oversight, reporting channels. Under paragraph 7, informing affected workers before a high risk system is used at the workplace.
  • Independently of all this, under the GDPR: record of processing activities, technical and organisational measures, and where applicable an impact assessment.

The fundamental rights impact assessment does not concern most companies

Article 27 is often sold along with consulting packages. It addresses public bodies and private entities providing public services, plus certain cases from Annex III. A private sector small or medium company usually does not fall under it. Buying a service for it would in most cases be unnecessary.

A pragmatic start

  1. 1.List which AI tools are used in the business and for what.
  2. 2.For each tool, record whether it was purchased, passed on under your own name, or modified.
  3. 3.Record whether personal data goes into it, and attach the data protection part to that.
  4. 4.Prepare the marking where customers talk to a system or receive generated content.
  5. 5.Keep the literacy record, because it applies regardless of risk classification.

These five steps are achievable within a few days and replace no legal assessment. They do create the basis on which such an assessment becomes possible at all, because afterwards what is actually in use is on the table for the first time.


We produce this inventory and the accompanying documentation folder as business consultants. The legal assessment of the individual case belongs with legal counsel, and we say so in advance rather than selling a confirmation we are not permitted to issue.

AI Act
AI Documentation
Annex IV
Logging
SMB Compliance
Business Consulting Vienna
Record Keeping

More Articles

Digital Transformation

AI Literacy Under Article 4: What to Do Now

8 min read
Process Optimization

Documenting Processes Without Overhead

8 min read

Want to implement this in your company?

In a free 30-minute conversation, we'll look at where the biggest levers are in your business.