Decommissioning & Retirement

AI Center › Decommissioning & Retirement

Global · The AI Lifecycle — Stage 14 of 14

Decommissioning & Retirement

Stage 14 of 14 in The AI Lifecycle. Decommissioning and retirement is where an AI system is withdrawn, recalled or disposed of, and where the documentation, logs and registration records that outlast it are set out under the EU AI Act, the GDPR and ISO/IEC 5338.

This stage of The AI Lifecycle registers what governs the end of an AI system's life. It draws on Regulation (EU) 2024/1689, the EU AI Act, for the definitions of recall and withdrawal, the ten-year documentation-keeping duty, the log-retention floors, corrective actions and the EU database; on Regulation (EU) 2016/679, the GDPR, for the storage-limitation principle and the right to erasure; on ISO/IEC 5338:2023 for the AI system disposal process; and on NIST AI 100-1 for the deactivation subcategory of its Risk Management Framework. Model deprecation is described as a published provider practice. Each provision is displayed with its named authority, and nothing here is advice.

How does ISO/IEC 5338 frame the retirement of an AI system?

ISO/IEC 5338:2023 places a Disposal process at clause 6.4.17, the last of its technical processes, and it is the process that governs retiring an AI system or one of its elements at the end of its life.

ISO/IEC 5338:2023, Information technology — Artificial intelligence — AI system life cycle processes, sets out life-cycle processes for AI systems that use machine learning and for heuristic AI systems. Its scope records that the document derives from ISO/IEC/IEEE 15288:2023 and ISO/IEC/IEEE 12207:2017, which it adapts and extends with processes specific to AI taken from ISO/IEC 22989 and ISO/IEC 23053. Clause 6 groups processes as agreement processes (6.1), organizational project-enabling processes (6.2), technical management processes (6.3) and technical processes (6.4). The Disposal process appears last among the technical processes, at clause 6.4.17, after the Operation process (6.4.15) and the Maintenance process (6.4.16). Adapted from the disposal process of the referenced system and software life-cycle standards, it is the process that carries an AI system or system element to the close of its life and removes it from operation. Retirement is displayed here as a defined process within the standard, not as a set of steps prescribed to the reader.

Source: ISO/IEC 5338:2023, Information technology — Artificial intelligence — AI system life cycle processes ↗

How long must the provider keep the documentation after a system is placed on the market?

Under EU AI Act Article 18, the provider of a high-risk AI system keeps specified documentation at the disposal of national competent authorities "for a period ending 10 years after the high-risk AI system has been placed on the market or put into service."

Article 18(1) lists what is retained across that period: the technical documentation referred to in Article 11; the documentation concerning the quality management system referred to in Article 17; the documentation on changes approved by notified bodies, where applicable; the decisions and other documents issued by notified bodies, where applicable; and the EU declaration of conformity referred to in Article 47. Article 18(2) requires each Member State to determine the conditions under which that documentation remains at the disposal of the authorities where a provider or its authorised representative goes bankrupt or ceases activity before the ten-year period ends. Article 18(3) provides that providers that are financial institutions maintain the technical documentation as part of the documentation kept under the relevant Union financial-services law. The period runs from the placing on the market or putting into service, not from retirement, so the obligation can extend for years beyond the point at which a system is withdrawn or disposed of.

Source: EU AI Act, Art. 18 — Regulation (EU) 2024/1689 ↗

How long must the logs generated by the system survive?

EU AI Act Article 19 requires the provider to keep the automatically generated logs under its control for a period appropriate to the intended purpose and "of at least six months," unless other Union or national law provides otherwise. Article 26(6) places the same minimum on deployers for logs under their control.

Article 19(1) refers to the logs generated under Article 12(1) and states that the "at least six months" floor applies without prejudice to applicable Union or national law, in particular Union law on the protection of personal data. Article 26(6) mirrors this obligation for deployers, again for a period appropriate to the intended purpose and of at least six months. Providers and deployers that are financial institutions maintain the logs as part of the documentation kept under the relevant Union financial-services law (Articles 19(2) and 26(6)). These retention floors, examined at Stage 11, Monitoring, Logging & Post-Market Surveillance, continue to bind after a system stops operating, so the record survives the running system.

Source: EU AI Act, Art. 19 — Regulation (EU) 2024/1689 ↗

What are the minimum retention periods for records at the end of life?

Four provisions across the EU AI Act and the GDPR set the minimum periods for which end-of-life records must be kept.

Record Governing provision Minimum retention period
Technical documentation, quality-management-system documentation, notified-body decisions and the EU declaration of conformity EU AI Act, Art. 18(1) Ten years after the system is placed on the market or put into service
Provider-controlled automatically generated logs EU AI Act, Art. 19(1) At least six months, appropriate to the intended purpose
Deployer-controlled automatically generated logs EU AI Act, Art. 26(6) At least six months, appropriate to the intended purpose
Personal data (storage limitation) GDPR, Art. 5(1)(e) No longer than is necessary for the purposes of processing

What data-protection duties apply when personal data reaches the end of its life?

Where a retired system's records contain personal data, the GDPR's storage-limitation principle in Article 5(1)(e) and the right to erasure in Article 17 continue to apply. They are displayed here as the governing provisions, not as steps to take.

GDPR Article 5(1)(e) requires personal data to be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed," with a carve-out where data are processed solely for archiving in the public interest, scientific or historical research, or statistical purposes under Article 89(1). Article 17(1) gives the data subject the right to obtain erasure of personal data "without undue delay" where a listed ground applies, including that the data are no longer necessary in relation to the purposes for which they were collected. Article 17(3) sets out exceptions, including where processing is necessary for compliance with a legal obligation to which the controller is subject, or for the establishment, exercise or defence of legal claims. These provisions can coexist with the AI Act's ten-year documentation-keeping duty, which is itself a legal obligation to retain certain records.

Source: GDPR, Art. 5(1)(e) — Regulation (EU) 2016/679 ↗

What do recall and withdrawal of an AI system mean?

The EU AI Act defines them as two distinct end-of-availability measures: recall reaches systems already made available to deployers, while withdrawal stops a system still in the supply chain from being made available on the market.

Article 3(16) provides: "'recall of an AI system' means any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers." Article 3(17) provides: "'withdrawal of an AI system' means any measure aiming to prevent an AI system in the supply chain being made available on the market." Article 20 attaches the provider's duty: a provider that considers a system it has placed on the market not to be in conformity "shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate," and inform distributors, deployers, the authorised representative and importers. Where the system presents a risk within the meaning of Article 79(1), Article 79 lets a market surveillance authority require an operator to bring the system into compliance, withdraw it, or recall it; Article 73 governs the reporting of serious incidents, which triggers investigation and corrective action.

Source: EU AI Act, Art. 3(16)–(17) — Regulation (EU) 2024/1689 ↗

What happens to the EU database registration when a high-risk system is retired?

The registration remains on the EU database the Commission maintains under Article 71; the Article contains no provision removing a system's entry upon retirement.

Article 71(1) has the Commission, in collaboration with the Member States, set up and maintain the EU database for high-risk AI systems referred to in Article 6(2) that are registered under Articles 49 and 60, together with systems not considered high-risk under Article 6(3). Providers or authorised representatives enter the data listed in Sections A and B of Annex VIII (Article 71(2)); deployers that are public authorities enter the Section C data (Article 71(3)). Most information registered under Article 49 is, per Article 71(4), "accessible and publicly available in a user-friendly manner" and machine-readable, apart from the secure non-public section. The Commission is the controller of the database (Article 71(6)), and it holds personal data only in so far as necessary (Article 71(5)). The registration therefore forms part of the record that survives a system after it leaves service.

Source: EU AI Act, Art. 71 — Regulation (EU) 2024/1689 ↗

What does the NIST AI Risk Management Framework say about deactivating or superseding systems?

The framework includes a subcategory addressing end-of-use. MANAGE 2.4 reads: "Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use."

NIST AI 100-1, the Artificial Intelligence Risk Management Framework (AI RMF 1.0), organises outcomes under four functions: GOVERN, MAP, MEASURE and MANAGE. The MANAGE function concerns allocating resources to mapped and measured risks; MANAGE 2 addresses strategies to maximise benefits and minimise negative impacts, and within it MANAGE 2.4 addresses the ability to supersede, disengage or deactivate a system whose performance or outcomes fall outside intended use. The framework is voluntary and describes outcomes rather than prescribing how they are to be achieved. It is a United States authority that runs parallel to, and is not part of, the EU AI Act's binding retirement-related duties, and it is displayed here as one such reference point at end of life.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (January 2023) ↗

What is model deprecation as an industry practice?

Outside the statutory framework, providers of AI models publish deprecation-and-retirement policies describing a model lifecycle. Anthropic's Model deprecations documentation is one published example, setting out defined lifecycle states and a notice arrangement.

That documentation describes a sequence in which a model is active, may become legacy, then deprecated — still functional but no longer recommended, with a named replacement and an assigned retirement date — and finally retired, after which requests to the model fail. The policy states that customers with active deployments receive at least 60 days' notice before retirement for publicly released models, and it records a commitment to long-term preservation of model weights. Described neutrally, model deprecation is the provider-side counterpart of the disposal process in ISO/IEC 5338:2023 and the deactivation subcategory in the NIST framework: a documented, dated removal of a specific model version from availability. The states, dates and terminology differ by provider and are not harmonised by any standard cited here.

Source: Anthropic, Model deprecations (platform.claude.com) ↗

Does the AI lifecycle loop back to its start?

The records that survive retirement remain available to inform the framing of any successor system. This is stated as a continuity of records under ISO/IEC 5338:2023, which closes the sequence with its Disposal process, not as guidance.

The provider's ten-year documentation-keeping duty (EU AI Act Article 18), the log-retention floors (Articles 19 and 26(6)), the post-market monitoring record built under Article 72, the serious-incident reports under Article 73 and the EU database entry under Article 71 all outlast the operating system. Retirement under the Disposal process at ISO/IEC 5338:2023 clause 6.4.17 closes the fourteen-stage sequence that opens at Stage 1, Problem Framing & Use-Case Definition, where intended purpose and scope are first defined. Where an organisation frames a successor, those surviving records are the material that documents what the retired system was and how it performed. Nothing in the cited authorities requires a successor to be built, and none of this is a recommendation to do so; the loop is displayed as a property of the record, not as advice.

Source: ISO/IEC 5338:2023, Information technology — Artificial intelligence — AI system life cycle processes ↗

When do these retirement-related obligations apply?

Under Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, the registration, post-market monitoring and serious-incident duties at Articles 49, 71, 72 and 73 apply from 2 August 2026, while the documentation-keeping, logging and corrective-action duties at Articles 18, 19, 20 and 26 apply from 2 December 2027 for systems high-risk under Article 6(2) and Annex III and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I. The Article 3 definitions in Chapter I have applied since 2 February 2025.

Article 113 sets general application from 2 August 2026; Chapters I and II have applied since 2 February 2025 and the general-purpose AI provisions of Chapter V since 2 August 2025. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and has been in force since 27 July 2026. It defers Sections 1, 2 and 3 of Chapter III, Articles 6 to 27 — and with them the documentation-keeping, logging and corrective-action duties at Articles 18, 19, 20 and 26 — to 2 December 2027 for systems high-risk under Article 6(2) and Annex III and to 2 August 2028 for systems high-risk under Article 6(1) and Annex I, with Article 6(5) expressly carved out and left at 2 August 2026. Section 5 of Chapter III, Articles 40 to 49 on standards, conformity assessment and registration, is not deferred and applies from 2 August 2026, as do Article 71 and Chapter IX, which carries the post-market monitoring duty at Article 72, the serious-incident reporting duty at Article 73 and the market-surveillance powers at Articles 74 and 79. As of 31 July 2026 no AI Act harmonised standard has been cited in the Official Journal, with EN 18286 the first candidate; CEN and CENELEC approved it in June 2026, but approval is not citation. Dates are displayed as they stand in Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Source: EU AI Act, Art. 113 — Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 ↗

Terms defined at this stage

recall of an AI system
Any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers. The measure reaches systems already in deployers' hands, and is defined at Article 3(16) of the EU AI Act.
withdrawal of an AI system
Any measure aiming to prevent an AI system in the supply chain being made available on the market. Unlike recall, it operates on systems that have not yet reached deployers, and is defined at Article 3(17) of the EU AI Act.
documentation keeping
The Article 18 obligation on the provider of a high-risk AI system to keep the technical documentation, the quality-management-system documentation, notified-body documents and the EU declaration of conformity at the disposal of national competent authorities for a period ending ten years after the system is placed on the market or put into service.
disposal process
In ISO/IEC 5338:2023, the technical process at clause 6.4.17 that governs retiring an AI system or system element and removing it from operation at the end of its life; the standard adapts the disposal process of ISO/IEC/IEEE 15288:2023 and ISO/IEC/IEEE 12207:2017 to the AI system life cycle.
storage limitation
The GDPR principle at Article 5(1)(e) that personal data be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of processing, subject to the Article 89(1) carve-out for archiving in the public interest, scientific or historical research, or statistical purposes.
right to erasure (right to be forgotten)
The GDPR right at Article 17 by which a data subject may obtain from the controller the erasure of personal data without undue delay where a listed ground applies, subject to the exceptions set out in Article 17(3).
EU database for high-risk AI systems
The register the Commission sets up and maintains under Article 71 for high-risk AI systems listed in Annex III and certain systems assessed as not high-risk, into which providers, authorised representatives and public-authority deployers enter the data listed in Annex VIII.

Cite this page

1BusinessWorld AI Center, "Decommissioning & Retirement — The AI Lifecycle." https://1businessworld.com/ai-center/decommissioning-and-retirement/ Version as of July 26, 2026.

The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 26, 2026.