How do you document AI use in a way that complies with the AI Act?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

To document AI use in accordance with the AI Act, you must maintain a technical file for each AI system that describes its purpose, risk class, operation, and responsibilities. The level of detail required in this documentation depends on your system’s risk class: high-risk AI requires a complete technical file and registration in an EU database, while AI with limited risk is subject to less stringent transparency requirements. In this article, we answer the most frequently asked questions about AI governance and documentation, so you know exactly what your organization needs to do.

Which AI systems are you required to document under the AI Act?

Under the AI Act, you are required to document your system as soon as you offer or deploy an AI system classified as high-risk, or when you use a system subject to the transparency requirements for limited risk. The majority of current AI applications fall into the minimal-risk or no-risk category and remain unregulated, but you must be able to demonstrate which category your system belongs to.

The law distinguishes between four risk levels. Prohibited AI (unacceptable risk) simply may not be used. High-risk AI requires extensive documentation and a conformity assessment. Low-risk AI is subject to less stringent transparency requirements, such as the obligation to inform users that they are interacting with an AI system. Minimal-risk AI is largely exempt from documentation requirements.

High-risk AI is defined in two categories. First, systems that serve as safety components of products covered by European harmonization legislation and require a third-party conformity assessment. Second, systems that fall under one of the eight domains listed in Annex III:

  • Biometrics
  • Critical Infrastructure
  • Education and Vocational Training
  • Employment and Human Resources Management
  • Access to essential services (such as creditworthiness or emergency calls)
  • Law Enforcement
  • Migration and Border Control
  • The Administration of Justice and Democratic Processes

Important: Systems that perform profiling of natural persons are always high-risk, regardless of the domain. A system that performs only a narrow procedural or preparatory task and does not pose a significant risk to fundamental rights may fall outside the high-risk category, but only if you provide substantiated documentation to support this.

What exactly must be included in AI Act-compliant documentation?

AI Act-compliant documentation for high-risk systems must include, at a minimum, a technical file containing a description of the system and its intended purpose, a risk analysis, information about the training data and the system’s operation, and a description of the human oversight measures. For low-risk systems, a more concise transparency documentation is sufficient.

For high-risk AI, the AI Act requires the following elements to be included in the technical dossier:

  • General description: What does the system do, what is its intended use, and who are the end users?
  • Risk Class Justification: Why does the system fall into the high-risk category—or why doesn’t it?
  • Technical specifications: architecture, algorithms, training data, and performance metrics
  • Risk Management System: What risks have been identified, and what measures have been taken?
  • Human oversight: How and by whom is the system monitored?
  • Declaration of Conformity: a statement that the system meets the requirements
  • Registration: enrollment in the EU database for high-risk systems

Documentation must be retained for ten years after the system is placed on the market or put into service. This also applies to importers, who are required to verify that the conformity assessment has been conducted and that the CE marking is present before introducing a system.

How does documentation differ for AI providers and users?

Providers of AI systems bear the heaviest documentation obligations: they must prepare the complete technical file, conduct the conformity assessment, and register the system. Users (referred to as “deployers” in the AI Act) have a lighter obligation, but are required to use the system in accordance with the provider’s instructions and to report incidents.

In practice, the distinction isn’t always clear-cut. An organization that purchases a standard AI tool from an external vendor is a deployer. But as soon as you customize that tool, put your own name on it, or change its intended purpose in such a way that the system becomes high-risk, you yourself become a provider, with all the associated obligations.

Deployers are subject to the following obligations, among others, when using high-risk AI:

  • Use the system only for its intended purpose as described by the provider
  • Ensure human supervision by qualified staff
  • Report serious incidents to the market surveillance authority
  • Conduct a fundamental rights impact assessment for certain applications
  • Keep logs of usage, to the extent that you have control over it

In addition, providers outside the EU must designate an authorized representative in the EU who will comply with the obligations on their behalf.

How do you set up a practical AI registry for your organization?

To create a practical AI registry, start by taking inventory of all AI systems in your organization, classifying them by risk level, and recording the key details for each system. The registry forms the backbone of your AI governance and makes it possible to quickly demonstrate which systems you use and how you ensure compliance.

Build your registry in three steps:

  1. Take stock: Identify all AI applications, including purchased tools, features embedded in software, and internally developed systems. Don’t forget AI features in existing software, such as automatic email sorting or predictive text.
  2. Classify: Determine the risk class for each system based on the AI Act criteria. Document your reasoning so that, in the event of an audit, you can demonstrate why you classified a system as low-risk.
  3. Document: For each system, record who the provider is, what the intended use is, who is responsible within your organization, what data the system uses, and what measures are in place for human oversight.

Keep the registry up to date by linking it to your procurement process: every new AI system you purchase or implement is immediately recorded and classified. Assign an owner for each system so that responsibilities are clear. The AI Act also requires organizations to ensure AI literacy (Article 4, effective as of February 2, 2025), which means that employees who work with AI systems must have sufficient knowledge of how they operate and the risks they pose.

What tools and templates can help with AI Act documentation?

For AI Act documentation, you can use risk assessment templates from national regulators, open standards such as model cards and data sheets for datasets, and specialized compliance software solutions. The European Commission and the AI Office also publish guidelines and standard forms that serve as a starting point.

Practical tools you can use:

  • Risk Assessment Templates: The AI Office and national authorities provide templates for classifying AI systems and justifying your choice of risk class
  • Model cards: standardized documents that describe the operation, limitations, and intended uses of an AI model, originally developed by the research community
  • Data Impact Assessments: Templates for Assessing the Risks of Training Data, Including Bias and Privacy Considerations
  • Fundamental Rights Impact Assessment: This is mandatory for certain high-risk applications; the Commission is working on a standardized format
  • Compliance software: specialized platforms help you maintain your AI registry, schedule audits, and manage documentation across multiple systems

Where possible, align your AI documentation with existing information security and privacy management processes. If your organization already uses an Information Security Management System (ISMS) based on ISO 27001, you can logically integrate AI-related risks and documentation into it.

What are the consequences if your AI documentation isn’t in order?

If your AI documentation does not comply with the AI Act, you risk fines of up to 15 million euros or 3% of your global annual revenue for non-compliance with the requirements. For violations of prohibited practices, the fine can reach up to 35 million euros or 7% of annual revenue. In addition to financial penalties, you also risk reputational damage and operational shutdowns.

The penalty structure has three levels:

  • Prohibited Practices (Article 5): up to 35 million euros or 7% of global annual revenue
  • Non-compliance with other obligations: up to 15 million euros or 3% of annual revenue
  • Inaccurate or misleading information provided to authorities: up to 7.5 million euros or 1% of annual revenue

For SMEs and startups, the lower of the percentage or the fixed amount applies in each case, which offers some protection. Most of the requirements for high-risk Annex III systems take effect on August 2, 2026, so organizations still have time to get their documentation in order. Oversight of high-risk AI rests with national market surveillance authorities, which may lead to differences in priorities among Member States. In January 2026, Finland became the first Member State to grant enforcement powers to its authority.

In addition to fines, there are also indirect consequences: without demonstrable AI governance, you lose the trust of customers and partners, you can no longer legally deploy high-risk systems, and you run the risk of liability if an AI system causes harm without you being able to demonstrate that you had taken the appropriate measures.

How Pegamento Helps with AI Governance and Documentation

Setting up effective AI governance requires more than just a spreadsheet listing systems. It requires a structured approach that aligns with your existing security, quality, and compliance processes. We help organizations establish a practical AI governance structure, from assessment to documentation and monitoring.

What specifically we can do for you:

  • Identify which AI systems your organization uses, including features embedded in existing software
  • Classifying systems based on the AI Act risk criteria, with supporting documentation
  • Setting up an AI registry that aligns with your existing ISMS and ISO 27001 processes
  • Implementation of Agentic AI assistants that comply with transparency and documentation requirements, including the necessary technical documentation
  • Training employees in AI literacy in accordance with Article 4 of the AI Act

Our approach combines proven standard building blocks into a customized solution for your organization, without the need for costly custom development. Everything under one roof: from consulting and implementation to management and support. Want to know where you stand with your AI documentation and what you still need to do to meet the 2026 deadlines? Get in touch, and we’ll work together to find the best approach for your situation.

Frequently Asked Questions

Moet ik als kleine organisatie of kmo ook voldoen aan de AI Act-documentatieverplichtingen?

Ja, de AI Act geldt in principe voor alle organisaties die AI-systemen aanbieden of inzetten binnen de EU, ongeacht hun omvang. Kmo’s en start-ups krijgen wel enige bescherming via de boetestructuur (het laagste van het vaste bedrag of het percentage van de omzet geldt), en het AI Office biedt vereenvoudigde richtsnoeren specifiek voor kleinere organisaties. Toch is het verstandig om ook als kmo nu al te starten met een basisinventarisatie van je AI-systemen, zodat je niet voor verrassingen staat wanneer de deadlines van 2026 naderen.

Hoe weet ik of een AI-tool die ik inkoop bij een externe leverancier hoog-risico is?

Vraag bij de leverancier actief naar de risicoklassificatie van het systeem en of er een technisch dossier en conformiteitsverklaring beschikbaar zijn. Hoog-risico systemen moeten door de aanbieder zijn geregistreerd in de EU-databank en voorzien zijn van een CE-markering. Als deployer ben je verplicht te verifiëren dat de aanbieder zijn verplichtingen heeft nageleefd voordat je het systeem in gebruik neemt — ontbreekt deze documentatie, dan loop je zelf risico bij een controle.

Wat is het verschil tussen een AI-register en een technisch dossier, en heb ik beide nodig?

Een AI-register is een intern overzichtsdocument van alle AI-systemen die je organisatie gebruikt, inclusief hun risicoklasse, eigenaar en gebruiksdoel — het is jouw beheertool voor AI governance. Een technisch dossier is een gedetailleerd, wettelijk verplicht document per hoog-risico systeem dat de technische werking, risicoanalyse en conformiteitsverklaring bevat. Je hebt beide nodig: het register als fundament voor je governance-structuur, en het technisch dossier als bewijs van compliance voor hoog-risico toepassingen.

Wat moet ik doen als een AI-systeem dat ik gebruik van risicoklasse verandert, bijvoorbeeld door een update van de leverancier?

Zodra een leverancier een significante update doorvoert die het beoogde gebruik of de werking van het systeem wezenlijk wijzigt, kan de risicoklassificatie inderdaad veranderen — en daarmee ook jouw verplichtingen als deployer. Houd contractueel vast dat leveranciers je informeren bij wijzigingen die de risicoklasse kunnen beïnvloeden, en herzie de classificatie in je AI-register bij elke materiële update. Koppel dit aan je inkoopproces zodat je niet achteraf voor verrassingen staat.

Hoe ga ik om met AI-functies die al ingebouwd zitten in bestaande software, zoals CRM- of HR-systemen?

Ingebedde AI-functies in standaardsoftware worden vaak over het hoofd gezien, maar vallen wel degelijk onder de AI Act als ze beslissingen ondersteunen in hoog-risico domeinen zoals personeelsbeheer of kredietverlening. Inventariseer actief welke AI-functionaliteiten aanwezig zijn in je bestaande softwarepaketten — vraag dit na bij leveranciers als het niet duidelijk is — en neem ze op in je AI-register. Als de leverancier de aanbieder is, controleer dan of zij hun documentatieverplichtingen hebben nageleefd.

Hoe zorg ik ervoor dat mijn AI-documentatie up-to-date blijft naarmate de regelgeving evolueert?

Wijs een verantwoordelijke aan — bijvoorbeeld een AI-coördinator of een bestaande compliance-functionaris — die de ontwikkelingen rondom de AI Act actief volgt, waaronder richtsnoeren van het AI Office en updates van nationale toezichthouders. Koppel je AI-register aan een vaste reviewcyclus, minimaal jaarlijks of bij elke significante wijziging in een systeem of de regelgeving. Abonneer je op updates van het Europees AI Office en relevante nationale autoriteiten om tijdig te reageren op nieuwe verplichtingen of gewijzigde interpretaties.

Kunnen medewerkers persoonlijk aansprakelijk worden gesteld als AI-documentatie niet op orde is?

De AI Act richt zich primair op organisaties als juridische entiteiten, niet op individuele medewerkers. Toch kan binnen een organisatie interne aansprakelijkheid ontstaan als een medewerker aantoonbaar nalatig is geweest in het naleven van vastgelegde procedures. Zorg daarom voor heldere taakverdeling in je AI governance — leg vast wie verantwoordelijk is voor documentatie, classificatie en toezicht — en zorg dat medewerkers voldoende zijn getraind op hun verplichtingen conform Artikel 4 van de AI Act.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.