01

The short answer

Documenting an AI system means recording who the provider is, who the deployer is, what data was used for training, validation and testing, and what transparency information was given to the people involved. Regulation (EU) 2024/1689 defines these roles and data categories precisely, and imposes distinct transparency obligations for generated content, deep fakes and biometric categorisation or emotion recognition systems.

02

Who does what: the roles to record

  • The provider develops the AI system or has it developed and places it on the market under its own name or trademark.
  • The deployer uses the AI system under its own authority, except for non-professional personal use.
  • The authorised representative receives a written mandate to carry out obligations on behalf of the provider within the Union.
  • The downstream provider integrates a general-purpose AI model into another system.

03

How to track data and purpose

Steps

  1. Distinguish and separately record training data, validation data and test data used for the system.
  2. Note the input data actually provided to the system or directly acquired by it.
  3. Flag whether the data processed includes special categories of personal data or biometric data.
  4. Prepare the transparency information to be communicated to exposed people no later than the time of first interaction.
  5. Check whether exceptions apply, for example for standard editing activities or authorised criminal investigation purposes.

04

Hypothetical example

A European company offering a customer service chatbot records: its role as provider, the training dataset used for the language model, the test dataset used before release, and the notice shown to users at the first message, as required for artificially generated content. This is a hypothetical example built only from cited elements, not a real case.

05

Controls to check periodically

  • Information provided to exposed people is clear, distinguishable and compliant with accessibility requirements.
  • Artificially generated or manipulated content is marked in a machine-readable format when required.
  • Deep fakes are disclosed to the public, except for exceptions for artistic or satirical works adequately flagged.
  • Staff involved in operating the system receive an adequate level of AI literacy.

06

How to set up documentation with software

A company can ask its software partner to configure separate fields for provider, deployer, training/validation/test datasets and transparency notes, with version traceability and periodic review by a designated person. This is a suggested operational choice, not a guaranteed feature or legal obligation.

07

Minimum checklist for the system file

  • Identity of the provider and, if any, the authorised representative.
  • Identity of the deployer and the declared purpose of use.
  • List of training, validation and test data with their sources.
  • Text of the transparency information given to users, with date of first exposure.
  • Record of exceptions applied, for example for criminal investigation purposes.

08

Next step

Map the roles and data types of your AI system using the definitions in Regulation (EU) 2024/1689, then check with your software partner which traceability fields you can activate to keep the file up to date.

FAQ

Frequently asked questions

What is the difference between a provider and a deployer under the AI Act?

The provider develops or has the system developed and places it on the market under its own name; the deployer uses it under its own authority, except for non-professional personal use.

Which data categories should be distinguished in the documentation?

Training data, validation data, test data and input data should be distinguished, along with flagging any special categories of personal data or biometric data.

When must transparency information be given to the people involved?

Information must be provided clearly and distinguishably no later than the time of first interaction or exposure, in compliance with accessibility requirements.

Sources and verification