Different regulations require very different retention windows, and averaging them together is its own compliance failure: a trail kept for six months when a regulation expects years isn't compliant, no matter how good the trail is.
High-risk AI (EU AI Act): the Act's own floor, set in
Articles 19 and 26(6), is at least six months for the automatically generated logs Article 12 requires, for a period appropriate to the system's intended purpose. Six months is a floor, not a target, and where another law requires longer retention for the same record, that longer period governs. This is a much shorter number than the sector-specific figures below, and worth not conflating with them.
Financial services (EU): DORA doesn't set one fixed retention number in the regulation itself;
national competent authorities and supervisory expectations drive it, and in practice organizations generally plan for several years of ICT risk documentation. MiFID II is more explicit: transaction and communications records tied to client orders must be kept for at least five years, extendable to seven at a regulator's request.
Financial services (US): the Bank Secrecy Act requires SAR and CTR records to be retained for five years from the date of filing. OCC/Federal Reserve model risk management guidance (SR 11-7) doesn't specify a minimum retention period explicitly; examination practice has generally treated several years as standard for model validation records, though SR 11-7 was reportedly succeeded by newer guidance (SR 26-2) in April 2026, worth confirming current status before relying on the older figure.
Healthcare (EU): GDPR doesn't specify a retention period; it requires data to be kept only as long as necessary for the specified purpose, which, for an AI system making healthcare decisions, needs to be defined explicitly in the data protection impact assessment.
Healthcare (US): HIPAA's federal floor is six years from creation or last effective date, whichever is later, but that rule applies specifically to HIPAA compliance documentation (policies, risk assessments, training records), not to medical records themselves. Actual clinical or decision records tied to patient care are usually governed by state medical-record retention law, which can run longer, five to twenty-plus years depending on the state. An AI decision record touching PHI may need to satisfy whichever of those is longer, not just the six-year federal floor.
Retention isn't just about duration. Records need to be retrievable, not archived in a format that takes real effort to access. A regulator asking for a specific decision record expects it within examination timelines, which in practice means days, not weeks.