Blog

The EU's New Documentation Rule for Open Models Just Started. Here Is the Paper Trail an Australian Business Should Keep Anyway

August 2026 · 6 min read · Technical

A stack of dated model records with the top one marked by a terracotta tick, beside a filing cabinet
← Back to all posts

Article 52 of the EU AI Act took effect this month. It requires providers of high-risk AI systems to keep sufficient documentation of training data sources and licensing. On the surface that is a European compliance question, and easy for an Australian business to file under not my problem.

In practice, any Australian business using an open-weight model, selling into the EU, or working with an EU-based client or supplier will feel this indirectly, because the documentation gap Article 52 is closing already exists in most Australian AI deployments.

What model cards actually tell you

Most open-weight model cards give you benchmark scores. Very few tell you, in any detail you could hand to an auditor, exactly what the model was trained on, what licence covers each component, and whether any of that training data carried restrictions that flow through to your usage.

Australian businesses have largely not needed to ask this, because no local regulator requires it yet. That is changing faster than most procurement processes have caught up with, and the awkward part is that the documentation you need is easiest to collect on the day you deploy and nearly impossible to reconstruct two years later.

What to actually keep on file

You do not need to become an EU compliance expert to benefit from this. The practical version is a documentation habit most Australian businesses are missing entirely:

  • The exact model name and version deployed, including the specific checkpoint or release date. Not we use an open-weight model, which is what most registers currently say.

  • The licence text as it existed on the day you deployed, saved as a file rather than a link. Licences change and links break, and the version that governed your deployment is the one that matters.

  • A record of what data, if any, you fine-tuned or retrieval-augmented the model with, and whether any of it included personal information under the Privacy Act.

  • Who approved the deployment and when, which is the single line most likely to be missing and most likely to be asked for.

Two pressures converging on the same answer

  • The EU AI Act sets a documentation bar that flows through global supply chains, reaching businesses that never sell directly into Europe, because their software vendors and platform partners increasingly do and pass the obligation down.

  • APRA has been tightening AI governance expectations in Australian financial services, where we do not actually know what our model was trained on is not an answer that survives an audit.

A third, less discussed pressure: your own customers. Enterprise procurement questionnaires have started asking these questions directly, and a business that can answer them quickly wins deals against one that needs three weeks and a lawyer.

The cost difference is the whole argument

Businesses that keep this paper trail from day one spend a few hours a quarter on it. It is genuinely that small: a folder, a naming convention, and a habit of saving the licence file when a model goes into production.

Businesses that skip it and get asked later typically spend $8,000 to $15,000 in consultant and legal time reconstructing a compliance history after the fact, and frequently cannot fully answer the question anyway because the original model card or licence text has since been updated or removed. Money spent on an incomplete answer is the worst version of this outcome.

What this does not require

Worth being clear about the scope so this does not become a project. You do not need a compliance platform, a governance framework, or a consultant to start. A folder in your existing document store with one subfolder per deployed model covers most of the value, and can be set up in an hour by whoever deployed the model.

You also do not need to do this retrospectively for every experiment your team has ever run. Start with what is actually in production and touching real data. A prototype somebody ran on a laptop in April is not a compliance exposure, and treating it as one is how a sensible habit turns into a stalled initiative nobody maintains.

If you are running any open-weight model in production, start the file today rather than when someone asks for it. The version of this task you do voluntarily is small, and the version you do under a deadline is not.

If you want help setting up an AI documentation register that is proportionate rather than a compliance project in its own right, book a session and we will get the structure right in a single session.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.