By Yuliia Habriiel, Regulatory Lawyer. Last reviewed 12 August 2026, against the AI Act as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI).

EU AI Act compliance requires between six and twenty-five documents, depending on your role and your risk tier. Every organisation using AI needs the same six baseline records: an AI system inventory, a role determination, a risk classification per system, an Article 5 prohibited-practices screen, an AI literacy record, and — the one nobody expects — a written record of the systems you decided were out of scope.

Providers of high-risk systems add roughly nineteen more, headed by Annex IV technical documentation, a quality management system, an EU declaration of conformity and registration in the EU database. Deployers of high-risk systems add eight to ten. Providers of general-purpose AI models have a separate set of four under Article 53.

The Act itself never gives you this list. There is no annex titled “documents you must hold.” The obligations sit scattered across Chapters II, III and V, and you assemble the list yourself by reading your own situation against them. That assembly is the work, and it is where most organisations get it wrong — not by failing to write documents, but by writing the wrong ones for the role they actually occupy.

Start with three questions, and write the answers down

Before you draft anything, answer these. The answers are not preparation for the documentation. They are the first three documents.

What role do you hold for each system? Provider, deployer, importer, distributor, or authorised representative. Article 25 governs this, and it is less stable than people assume. A company that buys a high-risk system, puts its own name on it, and sells it onward is a provider. A company that substantially modifies one, or repurposes it for something the original provider never intended, becomes a provider too. One organisation is routinely three roles across one portfolio.

What is the risk tier of each system? Prohibited under Article 5, high-risk under Article 6 with Annexes I and III, subject to transparency duties under Article 50, or minimal. This determination is made per system, not per company, and it needs to be written and dated.

Do you provide a general-purpose AI model? If so, Chapter V runs in parallel and is indifferent to everything above.

An auditor’s opening request is almost never “show me your risk register.” It is “show me how you decided this system was out of scope.” Which brings us to the document that separates organisations that have done the work from organisations that have bought templates.

EU AI Act document nobody has: the documented negative

Everyone files what they did. Almost nobody files why they concluded a system was outside the regime — that the tool doesn’t meet the Article 3(1) definition, or that it falls outside Annex III, or that it qualifies for the Article 6(3) exemption.

That last one is not optional and not informal. A provider who decides an Annex III system is not high-risk must document that assessment before placing the system on the market, and must register the system in the EU database.

The Digital Omnibus explicitly reinstated the registration limb after it was briefly on the table for removal. It is a filed position, not an internal memo, and it is discoverable.

If you build only one artefact this quarter, build the register of negatives. It is cheap, it is the first thing asked for, and it is the only evidence that your silence about a system was a decision rather than an oversight.

If you are a provider of a high-risk AI system

This is the heavy set, and it does not shrink because the deadline moved. Chapter III, Section 2 sets the substantive requirements; Section 3 turns them into paper.

The master file is the technical documentation under Article 11 and Annex IV — system description, development process, monitoring and control, the risk management system, lifecycle changes, standards applied, the declaration of conformity, and the post-market monitoring plan. Feeding into it, and separately evidenced, are:

  •  Risk management system (Article 9)
  • Data governance and dataset documentation (Article 10)
  • Logging specification (Article 12)
  • Instructions for use (Article 13)
  • Human oversight design record (Article 14)
  • Accuracy, robustness and cybersecurity evidence (Article 15).

Around that sit the organisational and market-facing documents: a quality management system (Article 17), ten-year documentation retention (Article 18), log retention of at least six months (Article 19), corrective action records (Article 20), an authorised representative mandate if you are established outside the Union (Article 22), written agreements with third-party suppliers in your value chain (Article 25), the conformity assessment record (Article 43), the EU declaration of conformity (Article 47 and Annex V, kept ten years), CE marking documentation (Article 48), EU database registration (Article 49 and Annex VIII), a post-market monitoring plan (Article 72), and a serious incident reporting procedure (Article 73) built around its three deadlines: fifteen days as standard, ten where a death is involved, two for widespread infringement or disruption to critical infrastructure.

Twenty-five documents, more or less, and none of them assembles quickly. Conformity assessment and notified body scheduling have long lead times, which is why the working deadline is a great deal earlier than the legal one.

If you are a deployer of a high-risk AI system

Deployers are the population most likely to believe this is somebody else’s problem. It is not, and the deployer set is small enough that there is no excuse for not holding it.

You need a record showing you use the system in accordance with the provider’s instructions (Article 26(1)); a human oversight assignment naming individuals with the competence, the training and the actual authority to stop the system (Article 26(2)); an input data record where you control the input data (Article 26(4)); a monitoring and suspension record, including notifications to the provider and the authority (Article 26(5)); log retention of at least six months (Article 26(6)); a worker information notice issued before the system goes live in the workplace (Article 26(7)); and a procedure for the Article 86 right to an explanation of individual decisions.

Public authorities acting as deployers also register in the EU database under Article 49(3).

Then there is the fundamental rights impact assessment. Article 27 binds bodies governed by public law, private entities providing public services, and deployers using high-risk systems for creditworthiness evaluation or credit scoring, and for risk assessment and pricing in life and health insurance.

If you are a private deployer outside those categories, the FRIA is good practice rather than obligation. It does not replace a GDPR data protection impact assessment; where both apply, they run together.

If you provide a general-purpose AI model

Four documents, under Article 53, and they have been in force since 2 August 2025: technical documentation meeting Annex XI, an information package for downstream providers meeting Annex XII, a copyright policy, and a public summary of training content published on your website using the Commission’s mandatory template. Non-EU providers add an authorised representative mandate under Article 54.

Models placed on the market before 2 August 2025 have until 2 August 2027 to publish the training-content summary. Models with systemic risk add four more under Article 55: evaluation and adversarial testing records, a systemic risk assessment and mitigation record, incident reporting to the AI Office, and cybersecurity documentation.

The relevant change this year is not to the obligations but to their enforcement. The AI Office gained its enforcement powers on 2 August 2026. The duty was always live; the consequences were not.

The layer everyone underestimates: Article 50

Here is the part that catches ordinary software companies with no high-risk exposure whatsoever. Article 50 transparency applied from 2 August 2026 and was not deferred by the Digital Omnibus.

If your system interacts with people, Article 50(1) requires that they are told they are dealing with an AI, and your evidence is a disclosure record: the wording, where it appears, when it went in, what accessibility standard it meets.

If your system generates synthetic audio, image, video or text, Article 50(2) requires machine-readable marking — and a claim that your outputs are marked is not evidence. A repeatable test protocol that survives a screenshot-and-re-encode cycle is.

Deployers of emotion recognition or biometric categorisation systems owe notices under Article 50(3), and deployers publishing deepfakes or generated text on matters of public interest owe disclosure under Article 50(4).

One wrinkle worth knowing: for systems already on the market on 2 August 2026, the Article 50(2) marking obligation does not bite until 2 December 2026. New systems have been in scope since August.

What the Digital Omnibus actually changed

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July. The headline is that high-risk deadlines moved. The detail that matters more is that not a single documentation obligation was deleted.

DateWhat applies
2 February 2025Article 5 prohibitions; Article 4 AI literacy
2 August 2025Chapter V general-purpose AI obligations; governance; penalties
27 July 2026Regulation (EU) 2026/1744 in force; softened Article 4
2 August 2026Article 50 transparency; AI Office enforcement over GPAI; simplified quality management for SMEs
2 December 2026Article 50(2) for systems already on the market; new prohibited practices
2 August 2027Legacy GPAI models; national regulatory sandboxes
2 December 2027High-risk obligations, Annex III stand-alone systems
2 August 2028High-risk obligations, Annex I embedded systems

Three amendments change how you draft rather than what you draft. Article 11(1) now allows technical documentation in simplified form, with a Commission template that notified bodies are required to accept. The simplified quality management route widened from micro-enterprises to SMEs generally. And Article 4 was softened from guaranteeing a level of AI literacy to supporting its development — a lower bar, with no small-business exemption, and still a documented duty.

Set against that, new Articles 75a to 75d give the AI Office investigative powers including on-site inspections. Which reframes the whole exercise: a document you cannot produce inside the window of a regulator’s request is, for enforcement purposes, a document you do not have. Retrievability is now part of the obligation.

The deferral bought sixteen months. It did not buy a smaller pile.

Frequently asked questions

What documents are required under the EU AI Act? Six baseline records apply to everyone: an AI system inventory, role determination, risk classification, an Article 5 prohibited-practices screen, an Article 4 AI literacy record, and documented negatives. Providers of high-risk systems add around nineteen more under Articles 9 to 22, 43, 47 to 49 and 72 to 73. Deployers of high-risk systems add eight to ten under Articles 26, 27, 49 and 86. Providers of general-purpose AI models have a separate four-document set under Article 53.

Do I need documentation if my AI system is not high-risk? Yes. The classification record, the prohibited-practices screen and the AI literacy record apply regardless of tier, and if your system interacts with people or generates synthetic content, Article 50 transparency documentation has applied since 2 August 2026. The only way to prove you sit outside the high-risk tier is a written classification assessment.

What is Annex IV technical documentation? Annex IV sets out the content of the technical documentation required by Article 11 for high-risk AI systems: a general description of the system, its elements and development process, monitoring and control information, the risk management system, lifecycle changes, standards applied, the EU declaration of conformity and the post-market monitoring plan. Since the Digital Omnibus, SMEs and small mid-caps may present it in simplified form using a Commission template that notified bodies must accept.

What documents does a deployer of a high-risk AI system need? An instructions-for-use conformance record, a human oversight assignment naming competent individuals, an input data record where the deployer controls the data, a monitoring and suspension record, log retention of at least six months, a worker information notice, an Article 86 explanation procedure, and — for public bodies, private providers of public services, credit scoring and life and health insurance — an Article 27 fundamental rights impact assessment.

Is a fundamental rights impact assessment mandatory? Only for the categories in Article 27: bodies governed by public law, private entities providing public services, and deployers of high-risk systems used for creditworthiness evaluation or credit scoring and for risk assessment and pricing in life and health insurance. Other deployers may complete one voluntarily. A FRIA does not replace a GDPR data protection impact assessment.

What documentation do general-purpose AI model providers need? Four documents under Article 53: technical documentation meeting Annex XI, an information package for downstream providers meeting Annex XII, a copyright policy, and a public summary of training content published using the Commission’s mandatory template. Non-EU providers add an authorised representative mandate under Article 54. Systemic-risk models add evaluation records, risk mitigation documentation, incident reporting to the AI Office and cybersecurity documentation under Article 55.

How long must EU AI Act documentation be retained? Ten years for technical documentation, quality management records and the EU declaration of conformity, running from the date the system is placed on the market or put into service. At least six months for automatically generated logs, for providers and deployers alike, unless sectoral law requires longer.

Did the Digital Omnibus remove any documentation requirements? No. Regulation (EU) 2026/1744 deferred high-risk deadlines to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, simplified the format of technical documentation and quality management for smaller firms, and softened the Article 4 AI literacy duty. Every document category in the original Act survives, and Article 50 transparency was not deferred at all.

Do SMEs get simplified EU AI Act documentation? In form, not in substance. The Digital Omnibus added SME and small mid-cap definitions to Article 3 and widened the simplified quality management route from micro-enterprises to SMEs generally, and Article 11(1) provides for a simplified technical documentation form. The Annex IV content still has to be there.

Can I reuse my GDPR or ISO/IEC 42001 documentation? Partially. A record of processing and a DPIA cover overlapping ground on data governance and impact assessment, and ISO/IEC 42001 maps well onto the Article 17 quality management system. Neither satisfies Article 11 technical documentation, Article 43 conformity assessment, the Article 47 declaration of conformity or Article 49 registration. Treat what you have as source material, not substitution.

What are the penalties for missing EU AI Act documentation? Up to €35 million or 7% of worldwide annual turnover for breaching the Article 5 prohibitions; up to €15 million or 3% for provider, deployer and transparency obligations, including documentation duties under Articles 16, 26 and 50; and up to €7.5 million or 1% for supplying incorrect or misleading information to notified bodies or authorities. For SMEs, the lower of the two figures applies.

Do I need documentation for an AI chatbot? Yes. Article 50(1) requires people to be told they are interacting with an AI system unless it is obvious to a reasonably well-informed person, and the evidence is a disclosure record: the wording used, where it appears, when it was implemented, and the accessibility requirements it meets. If the chatbot generates synthetic content, Article 50(2) machine-readable marking applies as well.


Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act); Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ 24 July 2026; European Commission, Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models, 24 July 2025; European Commission guidelines on the scope of obligations for providers of general-purpose AI models, 18 July 2025.

Yuliia Habriiel is a regulatory lawyer and the author of the EU AI Act Field Manual: Provable Compliance, Audit-Ready Evidence, and the Post-Omnibus Rules of the Game. She is the founder of European Compliance Suite and of GRECTA.

The checklist in this article is available as an editable workbook, together with an AI system inventory, a documented-negative record, a post-Omnibus compliance calendar and an Article 5 prohibition screen: download the EU AI Act Compliance Pack.

General information on EU law, not legal advice on any specific system or organisation. Classification, role determination and conformity routes are fact-specific.