Source: OJ L, 2024/1689, 12.7.2024

Current language: FR

Article 18 Conservation des documents


Summary What does Article 18 of the AI act regulation say?

This article sets out the record-keeping obligations for providers of high-risk AI systems, requiring them to retain a defined set of compliance documentation and make it available to national competent authorities for a period of 10 years following the system being placed on the market or put into service.

It connects directly to several other articles in the regulation, as the documents to be retained are those produced under the technical documentation, quality management system, and EU declaration of conformity requirements established elsewhere.

The article also addresses two specific edge cases: what happens to documentation availability if a provider ceases to exist before the retention period ends, and how financial institutions that are providers can integrate their record-keeping obligations into existing requirements under Union financial services law.

Important points:

  • Retain all key compliance documentation, including technical documentation, quality management system records, notified body decisions, and the EU declaration of conformity, for 10 years after the high-risk AI system is placed on the market or put into service.
  • Member States are required to determine the conditions under which documentation remains accessible to national competent authorities if a provider or its authorised representative goes bankrupt or ceases activity before the 10-year period ends.
  • Providers that are financial institutions subject to Union financial services law may maintain the required technical documentation as part of their existing record-keeping obligations under that law.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Pendant une période prenant fin 10 ans après la mise sur le marché ou la mise en service du système d’IA à haut risque, le fournisseur tient à la disposition des autorités nationales compétentes:

      1. la documentation technique visée à l’article 11;

      2. la documentation concernant le système de gestion de la qualité visé à l’article 17;

      3. la documentation concernant les modifications approuvées par les organismes notifiés, le cas échéant;

      4. les décisions et autres documents émis par les organismes notifiés, le cas échéant;

      5. la déclaration UE de conformité visée à l’article 47.

    1. Chaque État membre détermine les conditions dans lesquelles la documentation visée au paragraphe 1 reste à la disposition des autorités nationales compétentes pendant la période indiquée audit paragraphe dans le cas où un fournisseur ou son mandataire établi sur son territoire fait faillite ou met un terme à ses activités avant la fin de cette période.

    1. Si les fournisseurs sont des établissements financiers soumis à des exigences relatives à leur gouvernance, à leurs dispositifs ou à leurs processus internes prévues par la législation de l’Union sur les services financiers, ils tiennent à jour la documentation technique dans le cadre de la documentation conservée en vertu de la législation pertinente de l’Union sur les services financiers.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod