Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Only if you can reconstruct more than the AI’s output. To explain and defend an AI-assisted decision six months later, you need a record of the decision’s purpose and context, the system and relevant information used, its output, how a person reviewed it, why the final action was taken, and what explanation or follow-up the affected person received. A raw log or model-generated explanation alone may not show that the decision was sound.
What makes an AI-assisted decision explainable later?
A useful record lets someone who was not present follow the chain from system use to human action. It should make clear what the AI was asked to do, what its recommendation meant in context, and how a human decision-maker used or rejected it.
This is a governance issue as much as a technical one. NIST’s AI Risk Management Framework treats accountability and transparency as socio-technical characteristics: the system matters, but so do the organization’s processes and human oversight. NIST also says that provenance and attribution can assist transparency and accountability, and that explainable systems can support documentation, audit, and governance. NIST’s trustworthiness characteristics describe that broader context.
Recommended Free Tools
An explanation generated after the fact is not a substitute for contemporaneous evidence. If the organization did not record what information was considered, what the reviewer saw, and why the final decision followed, a later narrative may be incomplete. Documentation should make a decision understandable, not merely replayable.
What to record for a consequential decision
For decisions with meaningful effects on a person or service, create a record that answers these questions. This is a practical governance checklist, not a claim that every field is legally required in every jurisdiction.
- Purpose and scope: What decision was being supported, what was the AI system intended to do, and who was the decision recipient or affected person?
- System context: Which system was used, what role did it play, and what documentation is needed to interpret its output and known limitations? If a vendor supplied the system, obtain the information needed to explain its use.
- Relevant data and provenance: What input or data source shaped the recommendation, and what context is needed to interpret it? Keep only information that is necessary, taking applicable data-protection obligations into account.
- Output and human review: Preserve the output used in the decision. Identify the human reviewer or decision-maker and record whether they accepted, changed, or rejected the recommendation.
- Final rationale: Record the human reasoning, relevant evidence, and policy or criteria applied. Do not treat the system’s score or recommendation as the rationale for the organization’s action.
- Explanation and follow-up: Note what explanation was given, to whom, when, and through which channel. Record relevant corrections, appeals, or subsequent action.
- Ownership, access, and retention: Define who is responsible for the record, who may access it, and how long it will be kept under applicable law and organizational policy.
The UK Information Commissioner’s Office (ICO) recommends documentation that supports an explanation to the decision recipient and an audit trail of who received explanations and how they were provided. Its guidance also recommends documenting the process and choices behind developing, acquiring, and deploying decision-support systems. The ICO’s guidance on explaining AI-assisted decisions is under review following legislative changes, so check it for updates before relying on it.
Rank #2
How detailed should the record be?
Scale documentation to the decision’s risk and impact. The ICO advises a risk-based approach: a consequential recruitment decision warrants more documentation than a low-impact recommendation such as choosing films. A practical record should be detailed enough to show how the system was used, what a human decided, and how the outcome was communicated, without retaining unnecessary personal data.
Technical logs and explanatory records serve related but different purposes. A technical event log can help trace system operation and support monitoring. It may not capture the human reasoning behind the ultimate decision or what the affected person was told. For a defensible account, retain the evidence needed for both traceability and explanation, where appropriate.
Rank #3
Does the law require six months of AI logs?
Not as a universal rule. Under Article 19 of the EU AI Act, providers of high-risk AI systems must retain automatically generated logs under their control for an appropriate period of at least six months, unless applicable EU or national law provides otherwise, particularly data-protection law. The exact duties depend on the Regulation’s scope, the system’s classification, the actor’s role, and whether the logs are under that actor’s control. The consolidated text of Regulation (EU) 2024/1689 should be consulted for the applicable requirements.
Article 12 requires high-risk AI systems to technically support automatic event logging over their lifetime. Those logs are intended to support traceability appropriate to the system’s purpose, including monitoring and identifying situations that may create risk or involve substantial modification. The logging rule does not mean every organization must retain every AI-related record for six months.
Rank #4
Article 18 sets a separate period: providers must keep specified technical documentation available to competent authorities for 10 years. That is not the Article 19 log-retention period, and it should not be used to imply that all logs or decision records must be retained for 10 years.
How NIST and the EU AI Act differ
| Source | What it says | How to apply it |
|---|---|---|
| NIST AI Risk Management Framework | Voluntary framework intended to improve the incorporation of trustworthiness considerations across AI design, development, use, and evaluation. | Use it as governance guidance, not as a law imposing a universal retention period. NIST says AI RMF 1.0 is being updated, so verify the current edition at the time of use. |
| EU AI Act | Binding requirements for covered high-risk systems and relevant actors, including logging and provider retention duties subject to statutory qualifications. | Determine whether the Regulation applies, how the system is classified, and which actor has the specific duty before stating that a requirement applies. |
NIST describes its framework as “intended for voluntary use.” The EU AI Act, by contrast, creates obligations within its defined scope. Neither should be generalized beyond its terms: a voluntary framework is not a legal mandate, and an EU rule for covered high-risk systems is not a global rule for every AI-assisted decision.
Best Value
Use six months as a review test, not a guarantee
Ask whether a colleague could use the record six months later to explain the path from the system’s contribution to the human decision and the communication that followed. If all that remains is a raw output or event log, the record may show what the system did without showing why the organization acted. The answer depends on the decision’s context, the evidence retained, and the applicable legal and organizational requirements.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

