Obligation guide

What are AI Record-Keeping Requirements?

Required by 38 regulations across 11 jurisdictions in the XIRA catalog (state, federal, and local codes).

Definition

Record-keeping obligations require you to retain evidence that you complied with AI rules: assessments, notices, audit outputs, and change logs. Regulators assume that if it is not documented, it did not happen.

See also our AI compliance glossary for short definitions of common terms.

Related glossary entries

Which regulations require this

Which states reference this obligation

CACOCTFEDERALILMDMTNYTNTXWA

What you should do next

  • Define retention periods per jurisdiction and system class.
  • Store documents in a system with access controls and immutable timestamps where possible.
  • Label records so counsel can assemble a packet quickly during an inquiry.
  • Delete only when both engineering and legal agree the retention window ended.
  • Monitor vendor subprocessors who may hold copies on your behalf.

Check if this applies to your company

The free scan maps obligations to your states, tools, and role.

Start your free scan