TL;DR
Providers of high-risk AI systems keep the technical documentation, quality management documentation, notified body documents and the EU declaration of conformity for ten years from placing on the market or putting into service (Art. 18). Deployers keep the documentation they received for ten years from withdrawal of the system — a different starting point on the same system. Automatically generated logs are kept for a period appropriate to the intended purpose and in any case at least six months (Art. 19 and Art. 26(6)). Serious incidents are reported within fifteen days, ten in the event of death, two for a widespread infringement (Art. 73).
Logging capability is not a retention period
Article 12 requires high-risk systems to technically allow automatic recording of events over the lifetime of the system. It is a design requirement: the capability must exist. How long the records are actually kept is a separate question, answered by Article 19 — a period appropriate to the intended purpose, and not less than six months.
Conflating the two produces the most expensive error available here: keeping every log for the entire life of the system because Article 12 mentions the lifetime. That is disproportionate, it is not required, and on systems that process personal data it is a storage-limitation breach on the largest dataset the organisation holds.
Two clocks on the same system
The provider's ten years run from the moment the system is placed on the market or put into service. The deployer's ten years run from the moment the system is withdrawn. On a system in service for eight years those are two dates almost a decade apart, and an organisation that is both provider and deployer — which is common for internally built systems — runs both.
The provider's obligation is also cumulative rather than rolling: a system updated every quarter for eight years carries its whole documentary history, because the documentation has to show what the system was at each point, not what it is today.
- Logs of a high-risk system almost always contain personal data about the people the system made decisions on. Two retention regimes then apply to the same file — the AI Act's and the GDPR's — and both purposes belong in the record of processing.
- Article 73 sets three reporting deadlines, not one: fifteen days as a rule, ten days where a person has died, and two days for a widespread infringement or a serious incident within the meaning of Article 3(49)(b). The clock starts on becoming aware, not on concluding the internal investigation.
- A model retrained monthly cannot explain a decision taken last year unless the version in use at the time was retained. Keeping the model — or at least its parameters and description — therefore becomes a retention period in its own right, and it is one nobody writes down.
- The documentation is kept at the disposal of national competent authorities. That is availability on request, not archival storage: a backup nobody can read within a reasonable time does not discharge the obligation.
One row for “AI system” is not a record
The technical documentation, the automatically generated logs, the post-market monitoring data and the incident reports have four different purposes, four different periods and, for the logs, two legal regimes at once. A record of processing with a single line for the system describes none of them. The row that most often goes missing is the model version itself, because nobody thinks of a set of weights as a document — until somebody asks why a decision was taken.
The practical test is the same one that works for accounting records: does the retention column hold a number, or does it say which artefact follows which provision? If it holds a number, it is describing a simplification. Here the simplification is newer than the others, which means nobody has yet been caught by it — not that it is safe.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free