"Keep the documentation for ten years" is one of those obligations that sounds like it applies to anyone. Filing paperwork is something anyone can do, so when it turns up on a task list, nobody questions it.
Article 18 of Regulation (EU) 2024/1689 doesn't say that, and the reason it doesn't apply to you isn't a matter of hierarchy: it's that you don't have what needs to be kept.
The five documents, and where each one comes from
Paragraph 1 sets out the subject, the time limit and the list: "The provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities:"
- (a) the technical documentation referred to in Article 11;
- (b) the documentation concerning the quality management system referred to in Article 17;
- (c) the documentation covering changes the notified bodies signed off on, where applicable;
- (d) the decisions and other documents issued by the notified bodies, where applicable;
- (e) the EU declaration of conformity referred to in Article 47.
Read it as an inventory, not an obligation. The useful question isn't "can I keep this?" — it's "do I have this?"
The technical documentation under Article 11 is drawn up by whoever builds the system. The documentation under Article 17 is that of the quality management system, which — as we've seen — isn't something the deploying company sets up either. The documents from the notified bodies are issued to the provider as part of the conformity assessment, a procedure a deploying company is never party to. And the EU declaration of conformity is signed by the provider, under its own responsibility.
None of the five exists in the hands of the company that procures the system. It isn't that it can't keep them: it's that it doesn't have them, doesn't receive them, and there's no procedure by which they would ever reach it.
The detail of the time limit, which confirms the same thing
The ten years run "after the high-risk AI system has been placed on the market or put into service."
It's a date from the product's lifecycle, not from your relationship with it. A system can have been on the market for four years by the time you procure it: the Article 18 clock started without you, and it will end six years later regardless of whether you keep using it, replace it, or shut down.
An obligation whose time limit is counted from an event that isn't yours is a clear sign of who it's addressed to.
The article also covers what happens if the provider goes bankrupt or ceases its activity before the time limit ends: each Member State settles it by setting the conditions under which the documentation remains available. The deploying company doesn't appear there either, as some kind of substitute custodian.
What you do keep, and why it gets confused
The deploying company keeps things too, and that's where the confusion comes from: there is a retention duty within the deployer's regime, but its subject matter is different.
What's yours are the records the system itself generates while it's in use — the logs it produces while you operate it — and the trail of your own decisions: which configuration you chose, who provided oversight, when you last reviewed it. It's documentation of use, and you produce it because it comes from what you do.
Article 18's documentation is of product, and it's produced by whoever manufactured it. Two different retention duties, two different subject matters, two different parties. That both get called "keeping documentation" is the only thing they have in common.
What to do about Article 18 if you're a deployer
The same as with Article 17, and for the same reason: ask about it, don't assume it.
A provider of a high-risk system is subject to this duty for ten years. If your system falls under Annex III, knowing that this documentary record exists — and that it will keep existing for as long as you use the system — is information that matters to you, even though keeping it isn't your obligation.
There's one case where it matters more than usual: if the provider disappears. The article leaves that situation to each Member State, but you're the one left running a high-risk system in production with no manufacturer behind it. Asking in advance what happens to the documentation in that scenario is part of what's worth settling before signing, not once it happens.
The shape of the error, once more
Article 17 doesn't apply to you because you don't build. Article 18 doesn't apply to you because you don't have what needs to be kept. Those are two different reasons, and that's the part that matters: "the provider's articles" aren't a block you can dismiss all at once — each one falls away on its own content.
Checking it article by article costs more than dismissing them as a block, and it's the only way to know which ones do apply. Because some do — Article 26 exists, and its duties are perfectly enforceable against the deploying company — they just aren't these ones.
What decides whether a company has this clear isn't having read the Regulation. It's having it written down, system by system: who the provider is, why it is or isn't high-risk, and what falls to each party — with the date that was decided. A document that answers that in two lines is worth more than a folder full of someone else's obligations.
Content in accordance with Article 18 of Regulation (EU) 2024/1689.
This article is for informational purposes only and does not constitute legal advice.