Navigating the Documentation Requirements of the EU AI Act: How ISO/IEC 42001 Can Help Organizations Move Towards Compliance
The EU AI Act promotes the uptake of trustworthy artificial intelligence (AI) and introduces extensive requirements for documenting AI systems and sharing comprehensible information along the AI value chain. In his presentation, Dr. Thomas Zschocke explored these requirements and examined how established standards for information for use, such as IEC/IEEE 82079-1 and ISO/IEC/IEEE 26514, can contribute to meeting them. He also looked at ISO/IEC 42001 as a structured framework for managing and documenting the processes, procedures, and controls needed for trustworthy and responsible AI.
The presentation also highlighted practical approaches to AI documentation, including model cards and data sheets, and discussed the role of technical communicators as AI change agents in helping organizations address regulatory requirements and stakeholder expectations.
The presentation highlighted that AI documentation goes beyond traditional product documentation, encompassing technical, organizational, legal, and user-related information throughout the AI system lifecycle.
The presentation took place on Thursday, May 7, 2026, as part of the International University Network in Technical Communication (IUNTC) program.
Dr. Thomas Zschocke is a research associate at the Center for International Forestry Research and World Agroforestry (CIFOR-ICRAF). He has nearly 25 years of experience in knowledge management, technical communication, research data management, and capacity development, working for the United Nations and other international organizations in Africa, Asia, and Latin America. He holds a doctoral degree in education from the University of Massachusetts Amherst, USA, and a master's degree in Oriental Studies from the University of Cologne, Germany.
Why responsible AI use requires documentation
The use of AI can have significant consequences if systems are not adequately tested, are misunderstood, or are used without clear policies. Well-known examples include fabricated legal references, reports containing non-existent sources, and concerns about the use of copyrighted material for training AI models. Such examples show that AI is not merely a technical issue. It also involves responsibility, liability, copyright, quality assurance, training, and organizational rules.
When organizations place AI systems on the market, make them available, or use them in business, legal, or administrative processes, they need to understand the risks involved. Without appropriate documentation, policies, and training, the use of AI can quickly lead to legal, professional, or reputational problems. Documentation therefore becomes an important safeguard. It helps organizations demonstrate which systems they use, what they are intended for, what their limitations are, and what measures are in place to control them.
AI governance provides an overarching framework for addressing these issues. It brings together policies, responsibilities, risk management, processes, and controls for the responsible development and use of AI. Documentation is an essential part of this framework because it makes decisions, responsibilities, processes, and controls traceable.
The EU AI Act as a risk-based framework
The EU AI Act follows a risk-based approach. Not all AI systems are subject to the same requirements. Particularly extensive requirements apply to high-risk AI systems. For these systems, technical documentation, risk management, transparency obligations, conformity assessment, quality management, and monitoring are key elements.
The AI Act contains a specific article on technical documentation. An annex provides further details on the elements that technical documentation must contain. Other provisions address documentation-related aspects in different contexts, including information for users, transparency obligations, requirements for general-purpose AI models, retention of documentation, conformity assessment, quality management systems, and market monitoring.
An important point is that missing technical documentation can itself become a compliance issue. The AI Act provides for sanctions in cases of non-compliance, and documentation is one of the requirements relevant to demonstrating conformity.
Technical documentation and information for use
The AI Act distinguishes between different types of information relevant to AI systems. Technical documentation primarily serves traceability and conformity assessment. Information for users, including instructions for use, is intended to support transparency during operation.
Instructions for use should enable AI systems to be used transparently. Users need to understand that they are interacting with a system rather than a human. They also need to know how to interpret its outputs, what inputs are required, what limitations apply, and what risks may be associated with the system.
This is particularly important for AI. A system can produce results that appear plausible but are incorrect. It can generate references or content that do not exist, or it can be unsuitable for particular contexts of use. Information for use therefore needs to explain not only how to operate a system but also its limitations, uncertainties, and responsibilities.
Transparency as a documentation task
Transparency obligations are a central element of the AI Act. Documentation serves as a means of providing information about systems and models. These obligations can apply to providers as well as users or operators. General-purpose AI models are also subject to specific information requirements.
Transparency does not simply mean that information exists. Information needs to be prepared in a way that enables relevant target groups to understand and use it. This includes information about purpose, key characteristics, conditions of use, risks, robustness, cybersecurity, inputs, outputs, planned changes, human oversight, and logging.
This is particularly relevant to technical communication. Technical communicators have methods for making information understandable, usable, and appropriate for different target groups. In the context of AI systems, these skills need to be applied to new types of information, including data resources, model behavior, interpretability, risks, human oversight, and organizational requirements for use.
AI literacy as an organizational requirement
Another important aspect is AI literacy. Organizations need to ensure that people who use or operate AI systems have sufficient knowledge and awareness. Providing a system is not enough. Users need to understand what they are doing, what risks exist, and which rules apply.
AI literacy includes training, awareness, policies, and communication. Organizations need clear guidelines on how AI may be used, in which contexts particular caution is required, and how outputs need to be checked. This applies not only to technical departments but also to areas such as legal affairs, administration, research, manufacturing, accounting, and other business processes in which AI is used.
This also makes internal documentation important. Policies, training materials, process descriptions, and instructions for use are part of a comprehensive documentation system. Technical communication can play an important role here, as it not only creates information but also structures it and prepares it for different target groups.
ISO/IEC 42001 as an AI management system
One way of addressing these extensive requirements systematically is ISO/IEC 42001. The standard specifies an AI management system and can help organizations structure policies, responsibilities, risks, resources, competencies, communication, and documented information.
An AI management system does not consider AI merely as a technical solution. It also addresses the organizational context: Why does an organization use AI? Which internal or external stakeholders are involved? Which policies are in place? Which risks need to be addressed? What resources are required? Which competencies are needed? Which information needs to be documented?
The structure of such a management system can be connected with the requirements of the AI Act. This is particularly evident in risk management. The AI Act follows a risk-based approach, while ISO/IEC 42001 includes elements relating to planning, risk treatment, controls, operation, evaluation, and improvement. The standard can therefore help organizations embed AI Act documentation requirements into their organizational processes.
Documented information as a key element
Documented information plays a central role in an AI management system. Organizations need to determine which information is required, how it is created, how it is maintained, and how it remains available. This includes information about resources, data, tools, systems, computing resources, personnel, and competencies.
Data resources are particularly important for AI systems. Training data, input data, and other data sources need to be documented in a traceable way. Tooling resources, system resources, computing resources, and the competencies required to operate and monitor an AI system are equally relevant.
The results and changes associated with a system also need to be documented. When a system learns, is updated, or is used in a new context, new monitoring and documentation requirements may arise. Documentation therefore needs not only to describe the initial state but also to accompany the operation and further development of the system.
The AI system lifecycle
AI documentation should be considered throughout the entire lifecycle of a system. At the beginning are policies, purpose, context, and risk treatment. During development, documentation covers system specifications, data descriptions, model information, and verification and validation processes. When the system is deployed, information for users, instructions for use, and organizational requirements become necessary.
After deployment, the system needs to be monitored. Operation, changes, results, risks, continuous learning, incidents, and further development need to be documented. Decommissioning or disposal of a system or model is also part of its lifecycle and should be documented.
This lifecycle perspective shows that AI documentation is not a one-time package. It is an ongoing process. Documentation needs to remain up to date because AI systems, their use, and their associated risks can change over time.
Connecting AI requirements with technical communication standards
For technical communicators, standards for information for use are already familiar. Such standards can also be useful in the context of the AI Act. Information for use contributes to conformity by explaining how a product or system can be used safely and as intended.
However, there is not yet a simple, direct equivalent for AI in established documentation standards covering software or system lifecycles. There are standards for software and system processes as well as standards for information for use. For AI systems, these approaches need to be brought together and applied to new types of content.
Existing standards therefore remain relevant, but they need to be considered within a broader framework. Information for use, technical documentation, risk management, quality management, and AI management systems need to be viewed together.
The draft European standard FprEN 18286, “Artificial intelligence - Quality management system for EU AI Act regulatory purposes”, provides an important development in this context. ISO/IEC 42001 is not itself a harmonized European standard. However, ISO/IEC 42001 is referenced in informative Annex D of FprEN 18286, including a correspondence mapping. Organizations that have already implemented ISO/IEC 42001 should be able to use this mapping to support the demonstration of compliance with relevant EU AI Act requirements.
This also highlights the potential for integrating AI management with other established management systems, such as quality management, risk management, and information security. Rather than creating separate structures, organizations can build on existing processes and documented information.
Mapping the AI Act, ISO/IEC 42001, and technical communication
A key approach is to map the requirements of the AI Act against the structures of ISO/IEC 42001 and standards for technical communication. There is no simple one-to-one correspondence, but mapping can help clarify responsibilities, document types, and processes.
The AI Act specifies requirements such as technical documentation, transparency, risk management, conformity assessment, quality management, and market monitoring. ISO/IEC 42001 provides structures for context, leadership, planning, support, operation, performance evaluation, and improvement. Standards for information for use support the creation of understandable, accurate, and target group-oriented information.
Taken together, these approaches can help organizations meet documentation requirements more effectively. The aim is not to create even more isolated documents but to establish a coherent system of documented information.
Technical communication as an overview function
Technical communicators will not create all the information required for AI compliance themselves. Nor will they be solely responsible for risk management, data management, model validation, data protection, or quality management. Nevertheless, they can play an important role.
Technical communication is often the function with the clearest understanding of what information is needed, how it needs to be structured, and how it can be made usable for different target groups. Technical communicators can help organizations maintain an overview of the required documentation. They can connect specifications, instructions for use, policies, risk information, user information, and organizational requirements.
Because AI documentation is broader than traditional product documentation, it requires a coordinating information perspective. Technical communication can contribute this perspective.
Quality management, conformity assessment, and market monitoring
Technical documentation is also closely connected with quality management and conformity assessment. As part of a conformity assessment, organizations may need to demonstrate that an AI system meets the applicable requirements. Technical documentation provides an important basis for this. It needs to show how the system was developed, how risks were addressed, which data were used, which tests were carried out, and which information was provided to users.
Market monitoring and post-market monitoring also involve documentation. Systems need to be monitored after they have been placed on the market. Results, changes, risks, and incidents need to be documented so that organizations can demonstrate that they are fulfilling their responsibilities.
Documentation therefore becomes a permanent part of compliance. It does not end when a system is approved but accompanies the system throughout its operation.
Harmonized standards and European developments
At the European level, work is underway to further develop standards and guidance. ISO/IEC 42001 is a published international standard, but it is not automatically a harmonized European standard under European legislation. At the same time, European work is progressing on an AI quality management system intended to support organizations in meeting the requirements of the AI Act.
These developments are particularly relevant for organizations that already work with management systems. Many companies have established quality management, risk management, data protection, information security, or IT governance structures. AI governance and AI management can be integrated into these existing structures.
This creates the possibility of an integrated management system. Existing processes and documentation do not necessarily need to be replaced. Instead, they can be extended to address AI-specific requirements.
Simplification and practical tools
The AI Act is widely perceived as extensive and complex. This has led to efforts at the EU level to simplify its implementation. In May 2026, an agreement was reached in the trilogue negotiations on the Digital Omnibus on AI, subject to the subsequent approval and formal adoption procedures. Simplification measures are intended, among other things, to reduce the burden on small and medium-sized enterprises. Simplified approaches may also be relevant for smaller systems and certain general-purpose AI models.
At the same time, organizations can use various tools to assess their current situation. These include online tools for assessing readiness for ISO/IEC 42001, conformity assessment tools for AI models or systems, and national tools for checking requirements related to the AI Act. From a technical communication perspective, transparency requirements are particularly relevant, because documentation is an integral part of them.
There is still a need for more practical guidance on implementing and documenting AI, including guidance on applying ISO/IEC 42001 in practice. ISO is currently developing a new guidance document, ISO/IEC AWI 42003, to support the implementation of ISO/IEC 42001.
Open questions around assessment and implementation
One of the practical challenges is determining exactly how compliance with documentation requirements will be assessed. Depending on the system, context of use, and type of conformity assessment, national authorities or external bodies may be responsible. Organizations can use standards to demonstrate that they meet certain requirements. Nevertheless, it remains unclear in many cases how detailed and comprehensive the documentation needs to be.
AI systems that are regularly updated or continue to learn raise additional questions about how documentation needs to be maintained. Which changes are significant? Which information needs to be reviewed? How much detail is required when describing changes to models, data, or contexts of use? Further guidance and practical experience are needed to answer these questions.
Conclusion: AI documentation as a new area of responsibility for technical communication
AI is fundamentally changing the requirements for documentation. The focus is no longer only on specifications and end-user information but on a comprehensive system of documented information that connects technical, organizational, legal, and user-related aspects.
The EU AI Act makes clear that documentation is part of compliance. ISO/IEC 42001 can help structure the organizational side, while standards for information for use can support the creation of understandable and target group-oriented information. Technical communication can help connect these different levels.
This creates an important role for technical communicators. They do not need to develop, assess, or regulate AI systems themselves. However, they can help ensure that the necessary information is available, structured, understandable, up to date, and traceable. As AI systems become increasingly embedded in professional processes, this information expertise will become an essential part of technical communication.