The AI documentation pack: write it now, not under deadline
Most companies owe far less AI paperwork than they fear. The five records worth keeping whatever your risk tier, who asks for each one, and when.
General information, not legal advice. Regulatory duties need your own competent advice.
Less than most people fear. The heavy technical file belongs to providers of high-risk systems, and most business software is not high-risk. What everyone owes is smaller: evidence that staff know what they are doing with AI, plus transparency disclosures once August arrives. Five short records cover that and most of what buyers ask, and they take an afternoon to write.
Which parts land on you depends on two answers worth settling first. Whether you count as a provider or a deployer of each system you run, and whether any of them falls into a high-risk category under Annex III. Most of the small companies we work with end up in the same place, as deployers of systems that are not high-risk. That tier still has paperwork worth writing, just not the paperwork most compliance vendors are selling.
An AI documentation pack is a short set of records that answers five questions: which AI systems you run, what each one is for, where its data comes from, who reviews the output, and what gets logged.
What the Act asks you to keep
Two duties reach every company that uses AI at all, whatever tier it sits in. The first is AI literacy. Article 4 has applied since 2 February 2025 and binds every provider and deployer regardless of risk tier, including a company whose only AI use is staff typing into a general chatbot. Take measures so the people operating AI on your behalf know enough to do it safely. There is no duty to measure anyone's literacy and no required governance structure. No AI officer, no AI board. No fine attaches to Article 4 directly, though Latham & Watkins notes that civil liability has been available since August 2025 where badly briefed staff cause harm. A dated line naming who was told what is the whole evidential answer.
The second is transparency, and it arrives on 2 August 2026. Providers of systems built to interact with people have to make clear that the thing on the other end is software. Providers of generative AI have to mark outputs in a machine-readable way. Deployers have to disclose deepfakes, and AI-written text published to inform the public on matters of public interest unless a person took editorial responsibility for it (a practical guide to Article 50).
The bulky obligations, the technical file and the conformity assessment, sit with providers of high-risk systems, and those deadlines moved. Stand-alone Annex III systems now bite on 2 December 2027 and embedded ones on 2 August 2028 (Gibson Dunn on the Omnibus agreement, May 2026; European Commission timeline). Nothing about transparency moved with them.
The AI system inventory
One row per system. Name, vendor, who owns it internally, what data it sees, whether its output reaches a customer without a person in between.
The value is in how uncomfortable the list gets. Ours ran longer than anyone guessed, because AI arrives through features rather than through procurement. The transcription in the meeting tool counts. The suggested-reply box in the helpdesk counts. So does every coding agent with write access to a repository, which in our case is most of them, since our agents draft specifications, decision records, commit messages and marketing copy as well as code.
The fastest way to build the list is to read a quarter of card statements rather than to ask people what they use. A subscription list does not round down.
Write this one first. Every other record hangs off a row in it, and the rows you forget are the ones that turn up later in somebody's questionnaire.
Purpose statements, one paragraph each
What the system is for, what it must not be used for, and who is affected by its output.
The middle clause carries the weight. "This tool drafts client emails" tells a reviewer nothing. "This tool drafts client emails, is not used to decide anything about a client's account, and every draft is read by the account owner before it goes out" answers the question the reviewer was about to ask next, which saves a round trip that usually costs a week.
Purpose statements do a job internally too. Ours for the writing agent says it drafts and a person signs off before publication, and that is the sentence we point at whenever somebody proposes automating the last step. Written down, a purpose becomes a boundary. Left undocumented, it drifts towards whatever the busiest person needed on a Friday afternoon.
Where the data came from
For each system: what data goes in, whether the vendor trains on it, what is excluded by policy, and where the reference material originated.
Code counts as data here, and this is the part small companies skip. On one platform we built, 58 of its 117 commits carry an AI co-author trailer, and those commits account for roughly two thirds of the changed lines. That is a provenance record rather than a confession, and it exists only because the trailer sat in the commit template from the first week. Investors in technical diligence now ask how much of a codebase was machine-written and what review it went through. Answering with a git query beats answering with a shrug.
Provenance has the shortest shelf life of anything in the pack, because vendors change their training defaults without telling anyone twice. Note the date you checked, not just the answer.
Human oversight points that are real
For each system, where a person sits in the loop and what they can do about it. "Reviewed by a human" is not an oversight point unless someone is rostered, has the time, and has authority to overrule the output.
There is a UK reason to be precise here beyond the AI Act. The Data (Use and Access) Act 2025 reforms came into force on 5 February 2026 and replaced UK GDPR Article 22 with new Articles 22A to 22D. Explicit consent is no longer needed for significant automated decisions that do not involve special category data, but the safeguards stayed: notice that the decision was automated, a right to contest it, and human review on request (ICO guidance on the DUAA).
Human review on request is an operational promise. If your policy offers it and nobody owns the rota, you have documented a liability.
What you log, and for how long
Four decisions, written down: what each system records, how long you keep it, who can read it, and what never enters the store.
Most teams drift into one of two accidental defaults. Either nothing is kept, so any review after an incident is guesswork, or everything is kept indefinitely, including prompt text with client details in it, which quietly converts a retention question into a data protection one. Neither is a decision. Both pass for one in a questionnaire, until somebody asks for the retention period and the call goes quiet.
A workable version is unimpressive on the page: a retention window in days, a rule about what never appears in a stored prompt, and the names of the people who can read it. Nobody praises that paragraph. It ends the question.
Who asks for each record, and when
| Record | Who asks for it | When they ask |
|---|---|---|
| AI system inventory | Enterprise procurement and security reviewers | Vendor onboarding, before a contract is signed |
| Purpose statements | The same reviewers, and anyone checking your Article 50 disclosures | Contract stage, and from 2 August 2026 for disclosure duties |
| Data provenance notes | Investors in technical diligence, your data protection lead | Funding rounds, and any data protection impact assessment |
| Human oversight points | Customers whose own users can contest a decision | Contract negotiation, and the first time an output is challenged |
| Logging decisions | Whoever runs your incident response, and your insurer | After something goes wrong, a poor time to start deciding |
| Record of AI briefing given to staff | Buyers, and anyone testing your Article 4 measures | Ongoing since 2 February 2025 |
The overlap is the reason to write it once and properly. An enterprise security questionnaire and an investor's diligence list ask the same things in different words, and the Article 50 duty sits inside the answers to both.
Writing the pack without ceremony
The format that has survived for us is a decision record per choice that mattered, each one carrying a status line, a date, and an authorship line saying which decisions the human made and which parts the agent drafted. On one platform there are eleven of them. One was superseded the day after it was accepted, and we left it in the repository with its banner and its original comparison table intact.
That last bit is the part worth stealing. A diligence reader is not impressed by documents that were always right. A pack with one reversal in it reads as true. A pack with none reads as written last Tuesday, because it usually was. We keep this for every platform we build, and it has yet to take more than an afternoon per system.
Six to ten pages covers a company running five or six systems. An unread pack decays into fiction within two quarters, so dates and named owners matter more than length.
If you want a second opinion on scope before starting, the Commission's AI Act Service Desk has run an interactive Compliance Checker since October 2025. The Omnibus package also promises simplified guidance and standardised documentation templates for smaller companies, which beats buying a compliance suite written for a machinery manufacturer.
Questions we get asked
Do we need documentation if our only AI use is a chatbot subscription?
Yes, though very little of it. Article 4 literacy applies to deployers regardless of risk tier, so you want an inventory row, a purpose statement and a dated note of what staff were told. Twenty minutes of work, and it is the same page an enterprise buyer will ask for.
Does the delay to high-risk rules mean we can leave this until 2027?
No. The Digital Omnibus moved high-risk deadlines to December 2027 and August 2028, but Article 50 transparency still applies from 2 August 2026 and Article 4 has been in force since February 2025. The delayed part is the part most small companies were never in.
What is the penalty if we get it wrong?
Fines under Article 99 run to 15 million euro or 3% of worldwide annual turnover for most operator duties. For SMEs and start-ups each cap applies at whichever of the fixed sum or the percentage is lower, the reverse of the general rule (Article 99).
Ready to build the thing?
Book a free 30-minute call. We'll dig into your idea, your stack and your timeline, and give you an honest read on what it will take to build and launch. You'll leave with a clearer plan whether or not you hire us.