Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What AI-governance evidence should you retain, and for how long?
Updated
Regulation (EU) 2024/1689 sets two different retention numbers: Article 18 keeps listed documentation at the disposal of national competent authorities for 10 years, and Article 19 keeps automatically generated logs for at least six months. Not legal advice. Not YOUR retention schedule.
AI evidence retention, last verified 10 September 2026 against Articles 11, 12, 17, 18, 19, 26(6), 47 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product is not a records-retention system of record.
This is Articles 12, 18 and 19, not YOUR retention schedule
Audience: a compliance lead, records manager, CISO, or engineering owner deciding what AI-governance evidence to keep, where, and for how long. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not file with the AI Office and does not keep YOUR statutory records for you.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 12 is a capability requirement — a high-risk system must technically allow automatic recording of events. Article 18 is a documentation-keeping duty measured in years. Article 19 is a log-keeping duty measured in months. Article 26(6) is the deployer's parallel log duty. Those are four different obligations with four different subjects, and only Article 18 carries the ten-year figure. Last verified 10 September 2026. Not legal advice.
- Statute versus standard versus guidance versus product: Articles 11, 12, 17, 18, 19, 26(6), 47 and 113 of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 documented-information practice is a standard, not a legal substitute for the Act. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. The matrix below is a ShipReadyMetrics recommendation. This page labels which kind of text each claim rests on.
- The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the product page for the evidence flow. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
- Retention is not the same question as reporting. Nothing on this page starts an Article 73 or Article 55(1)(c) clock, and keeping a record for the period the Act names does not make an incident reportable or unreportable. Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027; this page does not invent a 2 August 2026 date for Annex I.
What original Articles 12, 18 and 19 actually say
Last verified 10 September 2026 against Articles 12, 18, 19 and 26(6) of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. This page does not apply them to YOU. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 12(1) — the logging capability itself | Authentic Article 12(1): High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. This is a property the system must have, not a period for which anything is stored. | Article 12(1) of 2024/1689. Legal requirement, only if it applies. A capability duty, not a retention duty. This page does not build YOUR logging. | 10 September 2026 |
| Article 12(2) — what the logging must enable | Article 12(2), in substance: to ensure a level of traceability appropriate to the intended purpose, logging capabilities shall enable the recording of events relevant for identifying situations that may result in the system presenting a risk within the meaning of Article 79(1) or in a substantial modification, for facilitating the post-market monitoring referred to in Article 72, and for monitoring the operation of high-risk AI systems referred to in Article 26(5). | Article 12(2) of 2024/1689. Legal requirement, only if it applies. It points at Articles 72 and 79(1), which are separate duties. This page does not run YOUR post-market monitoring. | 10 September 2026 |
| Article 18 — 10 years, and it is documentation, not logs | Authentic Article 18(1), in substance: the provider shall, for a period ending 10 years after the AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a) the technical documentation referred to in Article 11; (b) the documentation concerning the quality management system referred to in Article 17; (c) the documentation concerning any changes approved by notified bodies, where applicable; (d) the decisions and other documents issued by the notified bodies, where applicable; and (e) the EU declaration of conformity referred to in Article 47. Article 18(2) has Member States determine what happens to that documentation if the provider goes bankrupt or ceases activity first. | Article 18 of 2024/1689. Legal requirement, only if it applies. Ten years, running from placing on the market or putting into service — not from creation, and not from the last change. The technical-documentation guide on this site quotes Article 18(1)(a) as well. | 10 September 2026 |
| Article 19 — at least six months, and it is logs, not documentation | Authentic Article 19(1), in substance: providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control; without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular Union law on the protection of personal data. Article 19(2) puts financial institutions' logs inside the documentation kept under Union financial-services law. | Article 19 of 2024/1689. Legal requirement, only if it applies. At least six months is a floor, and 'appropriate to the intended purpose' can be longer. Data-protection law can cut the other way. This page does not set YOUR period. | 10 September 2026 |
| Article 26(6) — the deployer's parallel log duty | Authentic Article 26(6): Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data. | Article 26(6) of 2024/1689. Legal requirement, only if it applies. It is the deployer's duty, distinct from the provider's Article 19 duty. Both are limited to logs under that party's control. | 10 September 2026 |
| Article 11 and Annex IV — what the ten-year documentation is | Article 11 requires the technical documentation of a high-risk AI system to be drawn up before that system is placed on the market or put into service and to be kept up to date, containing at least the elements set out in Annex IV. Article 18(1)(a) is what keeps that file available for ten years. | Articles 11 and 18 of 2024/1689 and Annex IV. Legal requirements, only if they apply. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. | 10 September 2026 |
Retention matrix — record type, period, and who owes it
Each row names a record type, what the cited text says about keeping it, and whose duty it is. Where the Act sets no period, the row says so rather than inventing one. A blank period is an honest answer; a made-up number is not. Last verified 10 September 2026. Not legal advice, and not YOUR retention schedule.
| Record type | Period the cited text names | Kind of text | Last verified |
|---|---|---|---|
| Article 11 technical documentation (the Annex IV dossier) | Kept at the disposal of national competent authorities for a period ending 10 years after the AI system has been placed on the market or put into service, under Article 18(1)(a). | Article 18(1)(a) of 2024/1689. Legal requirement, only if it applies. A provider duty. This product does not keep YOUR Annex IV file. | 10 September 2026 |
| Article 17 quality-management-system documentation | Same 10-year period under Article 18(1)(b). | Article 18(1)(b) of 2024/1689. Legal requirement, only if it applies. An ISO 42001 certificate does not discharge Article 17. | 10 September 2026 |
| Notified-body approvals, decisions and other documents | Same 10-year period under Article 18(1)(c) and (d), where applicable. | Article 18(1)(c)–(d) of 2024/1689. Legal requirement, only if it applies. This product is not a notified body. | 10 September 2026 |
| EU declaration of conformity under Article 47 | Same 10-year period under Article 18(1)(e). | Article 18(1)(e) of 2024/1689. Legal requirement, only if it applies. Recording that a signed declaration exists is an organisation attestation, never a platform assertion of conformity. | 10 September 2026 |
| Automatically generated logs held by the provider | A period appropriate to the intended purpose, of at least six months, unless Union or national law provides otherwise — in particular data-protection law — under Article 19(1). Only to the extent the logs are under the provider's control. | Article 19(1) of 2024/1689. Legal requirement, only if it applies. Six months is a floor, not a target. | 10 September 2026 |
| Automatically generated logs held by the deployer | The same at-least-six-month formula under Article 26(6), to the extent the logs are under the deployer's control. | Article 26(6) of 2024/1689. Legal requirement, only if it applies. A deployer duty, distinct from Article 19. | 10 September 2026 |
| Risk-management records under Article 9 | Article 9 requires a risk management system established, implemented, documented and maintained as a continuous iterative process throughout the entire lifecycle, requiring regular systematic review and updating. It sets no separate retention figure; where the records form part of the Article 11 documentation they follow Article 18. | Article 9 of 2024/1689. Legal requirement, only if it applies. This page does not invent a retention period the article does not state. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. | 10 September 2026 |
| Serious-incident records and the reports themselves | Articles 73 and 55(1)(c) set reporting duties and, for Article 73, outer caps of 15 days, two days, and 10 days from awareness. They are reporting clocks, not retention periods. The Act does not state a separate retention figure for the incident file. | Articles 55(1)(c) and 73 of 2024/1689. Legal requirements, only if they apply. This page does not start a clock and no product files. The AI-incident-reporting guide on this site is that page. | 10 September 2026 |
| Evaluation and testing results | Article 9(6) and 9(8) speak to testing against preliminarily defined metrics and probabilistic thresholds; Article 15 speaks to accuracy, robustness and cybersecurity. Where those results form part of the Article 11 documentation they follow Article 18. The Act does not set a separate retention figure for them. | Articles 9 and 15 of 2024/1689. Legal requirements, only if they apply. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link. | 10 September 2026 |
| GPAI documentation and the training-content summary | Article 53 duties, including the sufficiently detailed summary about the content used for training under Article 53(1)(d). Chapter V applies from 2 August 2025 under Article 113(b), except Article 101. The Act does not state a general retention figure in Article 53 itself. | Article 53 of 2024/1689. Legal requirement, only if it applies. The training-data-transparency guide on this site is the Article 53(1)(d) page. | 10 September 2026 |
| Policies, AI literacy records, and ownership records | No period stated in the Act. ISO/IEC 42001:2023 asks for documented information to be controlled, available and suitable — as management-system practice, not a statutory period. | ISO/IEC 42001:2023 practice plus ShipReadyMetrics recommendation. Not a legal retention duty. Keeping them longer than any statutory floor is a business decision. | 10 September 2026 |
Legal requirement versus guidance versus ShipReady recommendation
The table below labels each text. Do not treat the ten-year figure as covering logs, do not treat the six-month figure as covering documentation, and do not treat a product surface as a determination. Last verified 10 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Article 18 | Legal requirement — 10 years, from placing on the market or putting into service, for the Article 11 documentation, the Article 17 quality-management-system documentation, notified-body documents, and the Article 47 EU declaration of conformity, only if it applies. | Does not apply the ten-year period to logs, and does not determine that YOU are a provider of a high-risk AI system. |
| Regulation (EU) 2024/1689 Articles 12, 19 and 26(6) | Legal requirements — an automatic event-recording capability over the lifetime of the system, and log keeping for a period appropriate to the intended purpose of at least six months, only if they apply. | Does not apply the six-month floor to the Article 11 documentation, and does not set YOUR period. Union or national law, in particular data-protection law, can provide otherwise. |
| Regulation (EU) 2024/1689 Article 113 | Legal requirement of the application dates. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; residual 2 August 2026; Article 113(c) Article 6(1) and corresponding obligations 2 August 2027. | Does not invent a 2 August 2026 date for Annex I product-embedded high-risk. Does not start a clock. |
| ISO/IEC 42001:2023 | Best practice / standard. Documented information controlled, available and suitable for use. Not a legal substitute for the Act. | Does not treat an ISO 42001 records procedure as discharging Article 18 or Article 19. |
| NIST AI RMF 1.0 (NIST AI 100-1, January 2023) | Guidance, not law. Voluntary US agency framework. | Does not treat a Manage-function activity as an AI Act retention duty. |
| European Commission AI Act pages and AI Office materials | Commission materials. Guidance, not the regulation. | Does not treat a Commission page as rewriting Article 18 or Article 19. |
| This product's evidence collection and evidence review | ShipReady recommendation: collected artefacts and a human review overlay over the organisation's own records. Not a records-retention system of record and not forensic chain of custody. | Does not keep YOUR statutory records, does not guarantee a retention period, and does not determine that a period has been met. A named human still owns the assessment. |
What to do now
As of last verification on 10 September 2026, Article 12, Article 18, Article 19 and Article 26(6) sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation. It is not a determination that any of those duties binds YOU. Walk it with counsel.
- Write the two numbers down separately and never in the same sentence as each other: 10 years for the Article 18 documentation list, at least six months for the Article 19 and Article 26(6) logs. Conflating them is the most common error on this topic.
- For each system, ask who controls the logs. Article 19 and Article 26(6) both say 'to the extent such logs are under their control', which means a deployed third-party system may leave neither party holding everything.
- Check whether data-protection law shortens what the Act would otherwise keep. Both log articles defer to Union or national law, in particular Union law on the protection of personal data.
- Do not invent a retention figure for records the Act does not date — risk-management records, evaluation results, incident files, policies. Say why you chose the period you chose, and record that reasoning with the records.
- The AI-audit-evidence guide on this site is the evidence-request-by-role page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the product page for the evidence flow. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a determination that any retention duty binds YOU, and not a filing. Walk it with counsel. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- For each system, are YOU the provider, the deployer, or neither? Article 19 is a provider duty and Article 26(6) is a deployer duty.
- Is the ten-year period in Article 18 about logs? No. It is about the Article 11 technical documentation, the Article 17 quality-management-system documentation, notified-body documents, and the Article 47 EU declaration of conformity.
- Is the six-month period in Article 19 a maximum? No. It is a floor, inside a period appropriate to the intended purpose, and Union or national law can provide otherwise.
- When does the ten-year clock start? Article 18 measures from the AI system being placed on the market or put into service, not from when a document was written.
- Do you actually hold the logs, or does a provider? Both log articles are limited to logs under that party's control.
- Does this product keep your statutory records for you? No. It collects and reviews evidence the organisation supplied; it is not a records-retention system of record and not forensic chain of custody.
- Document the assessment, including a no-retention-duty decision and the reasoning behind any period you set yourself. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance records, per registered system, whether a record-keeping artefact under Article 12 and a technical-documentation artefact under Article 11 exist. Those are facts the organisation entered about itself. Recording them is not retention, is not a finding that a period has been met, and is not a determination that YOUR system is high-risk. Marking in-scope is not applicability. A named human still owns the assessment.
Evidence collection stores artefacts the organisation supplied, and a human evidence review can accept a manually supplied row as meeting a control. That overlay is a reviewed human judgement, not a machine verdict and not a legal conclusion. This product is not a records-retention system of record, is not forensic chain of custody, is not a regulator filing pack, does not file with the AI Office, does not register in the EU database, does not issue certifications, and does not affix CE marks. The cyber risk register lives under Security and is a different register.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 10 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 9, 11, 12, 15, 17, 18, 19, 26, 47, 53, 73 and 113 and Annex IV, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The training-data-transparency guide on this site is the Article 53(1)(d) page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated map of AI-governance retention distilled from Regulation (EU) 2024/1689 Articles 12, 18, 19 and 26(6), with ISO/IEC 42001:2023 labelled as a standard and NIST AI RMF labelled as guidance, not the regulation. Whether those articles apply to YOU, and what your retention schedule should say, are legal questions for counsel on your facts. This page does not start a clock.
Does the ten-year period apply to our logs?
No. Article 18 of Regulation (EU) 2024/1689 keeps the Article 11 technical documentation, the Article 17 quality-management-system documentation, notified-body documents, and the Article 47 EU declaration of conformity at the disposal of national competent authorities for a period ending 10 years after the AI system has been placed on the market or put into service. Automatically generated logs are Article 19 and Article 26(6): a period appropriate to the intended purpose, of at least six months. Two duties, two numbers.
Is six months the maximum we need to keep AI logs?
No. Article 19(1) of Regulation (EU) 2024/1689 sets a period appropriate to the intended purpose of the high-risk AI system, of at least six months. Six months is a floor inside that formula, not a ceiling and not a default. Applicable Union or national law can provide otherwise, in particular Union law on the protection of personal data, which may require a shorter period. Counsel resolves that on your facts. Last verified 10 September 2026.
Does ShipReady keep our statutory AI records for us?
No. Signed-in app → Compliance → AI governance records whether artefacts exist, and evidence collection stores what the organisation supplied with a human review overlay on top. That is not a records-retention system of record, not forensic chain of custody, and not a regulator filing pack. This product does not keep the Article 11 file, does not keep Article 19 or Article 26(6) logs, does not file with the AI Office, and does not register in the EU database.
Does ISO 42001 documented-information practice discharge Article 18?
No. ISO/IEC 42001:2023 is a voluntary management-system standard that asks for documented information to be controlled, available and suitable for use. The AI Act is Regulation (EU) 2024/1689. An ISO 42001 records procedure, or a certificate, is not a determination that the Article 18 ten-year duty or the Article 19 log duty has been met. Last verified 10 September 2026.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.