Model Cards and Datasheets: Technical Documentation Required under the AI Act

The European Union’s Artificial Intelligence Act (AI Act) introduces new requirements not only for how AI systems are developed and used, but also for how these processes are documented.

In the cases specified by the Regulation, it is not enough for a provider simply to make claims about a system’s accuracy or safety. The provider must also have technical documentation that makes it possible to understand how the AI system works, what data it was trained and tested on, what limitations it has, and how the associated risks are managed.

Even before the AI Act was adopted, Model Cards and Datasheets for Datasets were widely used to organise this type of information. These tools provide a structured way to describe a model, its intended purpose and limitations, as well as the provenance, characteristics, and relevant features of the data used.

With the introduction of the AI Act, however, the technical documentation of AI systems has moved firmly into the regulatory sphere. The Regulation lays down technical documentation requirements for specific categories of AI systems and models, specifying what information providers must document and keep up to date and, in certain circumstances, make available to competent authorities.

Importantly, the AI Act does not impose a single set of technical documentation requirements on all AI systems and models. The scope of the documentation and the information it must contain depend on the type of system or model concerned. In particular, the Regulation establishes distinct requirements for high-risk AI systems and general-purpose AI models.

Technical Documentation for High-Risk AI Systems

For high-risk AI systems, the key requirement is set out in Article 11 of the AI Act. Providers must draw up technical documentation before the system is placed on the market or put into service and keep it up to date thereafter. The purpose of this documentation goes well beyond a conventional technical description of a product. It must be prepared in a way that demonstrates the system’s compliance with the requirements of the AI Act and provides national competent authorities and conformity assessment bodies with the information necessary to assess that compliance in a clear and comprehensive form.

The minimum information to be included in the technical documentation is set out in Annex IV to the AI Act. In essence, it requires the documentation to cover the AI system throughout its lifecycle: from its intended purpose and development process to testing, risk management, and post-market monitoring.

Content of the Technical Documentation

First, the documentation must provide a general description of the AI system, including its intended purpose, the name of the provider, the current version of the system and its relationship to previous versions. It must also describe how the AI system interacts, or can be used to interact, with hardware or software outside the system itself, including other AI systems where applicable. The documentation must specify the forms in which the system is placed on the market or put into service, such as software packages embedded into hardware, downloads, or APIs, as well as the hardware on which the system is intended to run. It must also include a basic description of the user interface provided to the deployer and instructions for use.

Beyond this general description, the documentation must provide a detailed description of the elements of the AI system and the process for its development.

This includes the methods and steps performed in developing the system and its design specifications, including the general logic of the AI system and its algorithms, key design choices and the rationale and assumptions underlying them. The documentation must also describe the system architecture, explaining how its software components build on or feed into each other and integrate into the overall processing, as well as the computational resources used to develop, train, test, and validate the system. Where relevant, if pre-trained systems or tools provided by third parties were used during development, the documentation must explain how they were used, integrated, or modified by the provider.

Data, Testing and Evaluation of the System

Annex IV places particular emphasis on data. Where relevant, the technical documentation must include datasheets describing the training methodologies and techniques and the training data sets used. These must include a general description of the data sets, information about their provenance, scope and main characteristics, how the data was obtained and selected, the labelling procedures applied, and data cleaning methodologies, including outliers detection.

The documentation must also describe the validation and testing procedures used, including the validation and testing data and their main characteristics, the metrics used to measure accuracy and robustness, and any potentially discriminatory impacts. It must also include test logs and test reports. In addition, the documentation must set out the system’s capabilities and limitations in performance, its overall expected level of accuracy, foreseeable unintended outcomes, and sources of risks to health and safety, fundamental rights and discrimination.

The performance metrics used to evaluate the system must be appropriate for the specific AI system.

Human Oversight, Cybersecurity and Risk Management

The documentation must also cover the human oversight measures needed, and the technical measures put in place to facilitate the interpretation of the AI system’s outputs by deployers, as well as the cybersecurity measures implemented.

Another mandatory element is a detailed description of the risk management system in accordance with Article 9 of the AI Act. This includes identifying and evaluating known and reasonably foreseeable risks, taking measures to eliminate or reduce those risks, and regularly reviewing and updating the risk management process.

From System Changes to Post-Market Monitoring

The documentation must also reflect relevant changes made to the system throughout its lifecycle, include a list of the harmonised standards applied or a description of other solutions adopted to meet the requirements of the AI Act, and contain a copy of the EU declaration of conformity.

Documentation does not end once the system is placed on the market. The technical documentation must also include a description of the system in place to evaluate the AI system’s performance in the post-market phase, including the post-market monitoring plan.

What About Retention Periods?

The retention period is equally important. Under Article 18 of the AI Act, providers must, for a period ending ten years after a high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities the technical documentation referred to in Article 11 and the documentation concerning the quality management system referred to in Article 17. Where applicable, providers must also retain documentation concerning changes approved by notified bodies, as well as decisions and other documents issued by those bodies. The EU declaration of conformity referred to in Article 47 must be retained for the same period.

Technical Documentation for General-Purpose AI Models

The AI Act lays down separate technical documentation requirements for general-purpose AI models. Under Article 53 of the AI Act, providers of such models must draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation. This documentation must contain, at a minimum, the information set out in Annex XI and must be provided, upon request, to the AI Office and the national competent authorities.

Do the Documentation and Retention Requirements Apply to Everyone?

This documentation requirement does not, however, apply to providers of AI models released under a free and open-source licence that allows for the access, usage, modification and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception does not apply to general-purpose AI models with systemic risks.

Unlike for high-risk AI systems, the AI Act does not establish a single retention period for the technical documentation of general-purpose AI models.

A separate rule applies, however, to providers established in third countries: their authorised representative in the Union must keep a copy of the technical documentation for a period of ten years after the model has been placed on the market.

What Is the Minimum Information Required in the Technical Documentation for a General-Purpose AI Model?

The minimum content of the technical documentation is set out in Annex XI, with the information to be provided as appropriate to the size and risk profile of the particular model.

First, the documentation must provide a general description of the model. This includes the tasks that the model is intended to perform, the type and nature of AI systems into which it can be integrated, the applicable acceptable use policies, the date of release and methods of distribution. The documentation must also specify the model architecture and number of parameters, the modality and format of inputs and outputs, and the licence for the model.

In addition, the documentation must describe the training methodologies and techniques, as well as the key design choices, including their rationale and assumptions, the optimisation objective and the relevance of the different parameters. It must also specify the technical means required for the model to be integrated into AI systems, the computational resources used for training, the training time, and the model’s known or estimated energy consumption.

For general-purpose AI models, a significant part of the documentation requirements also concerns the data used. For data used for training, testing and validation, the documentation must include information on the type and provenance of the data, its scope and main characteristics, how the data was obtained and selected, and the curation methodologies applied, including cleaning and filtering. Where applicable, it must also describe measures to detect unsuitable data sources and methods to detect identifiable biases.

Systemic Risk: What Does It Change?

For general-purpose AI models with systemic risk, Annex XI sets out additional documentation requirements. Providers must provide a detailed description of the model evaluation strategies and evaluation results, including the criteria and metrics used and the methodology applied to identify model limitations. Where applicable, the documentation must also provide a detailed description of the measures put in place for internal and/or external adversarial testing, including red teaming, as well as model adaptations, including alignment and fine-tuning. In addition, where applicable, it must provide a detailed description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing.

Model Cards and Datasheets for Datasets: How Do They Fit into the AI Act Requirements?

It is important to emphasise that the AI Act does not require technical documentation to take the specific form of Model Cards or Datasheets for Datasets. However, their content overlaps considerably with the information required under the Regulation. Model Cards can help structure information about a model’s intended purpose, capabilities and limitations, as well as its testing and evaluation. Datasheets for Datasets, in turn, can help organise information about the provenance and characteristics of data and how it was obtained, selected and prepared.

These documents can therefore serve as practical tools for organising some of the information needed to meet the AI Act requirements. Model Cards and Datasheets for Datasets alone, however, are not sufficient to satisfy all of the Regulation’s requirements. The technical documentation required under the AI Act covers a much broader range of information about AI systems and models and the processes involved in their development, evaluation and use.

Tags
  • AI Act
  • Data Sheets
  • Model Cards
Do you have any questions for the lawyers?
up to 500 characters
An error occurred
The request has been sent Thank you for your message! We will process it as soon as possible.

Articles on the topic

Go to the blog