Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 12 — Record-keeping

Article 12 requires a high-risk system to technically allow automatic logging of events across its lifetime, at a level of traceability appropriate to its purpose. It is a capability requirement on the provider. The six-month retention figure people associate with it is in two other articles entirely.

§ 1 — In practice

Logging capability over the lifetime — not a retention rule

The verb is the whole provision: a high-risk system "shall technically allow for" automatic recording. Article 12 obliges the provider to build logging capability, and says nothing about keeping anything. The retention duty appears twice elsewhere — on the provider, and on the deployer through Article 26 — and both are qualified by whether the logs are under that party’s control, with a six-month floor. A provider that ships adequate capability and retains nothing has satisfied Article 12 and breached its retention duty; these are different findings against different provisions.

There is no log schema for most systems, and looking for one is why implementations go wrong in both directions. The four-item minimum — use timestamps, reference database, matching input, the identity of the verifying persons — applies to remote biometric identification and to nothing else. Applying it to a credit model produces a log design nobody needed. Its fourth item exists solely so the two-person verification rule elsewhere in the Regulation can be audited: the log field and the oversight requirement are one control, and neither works alone.

For everything else, sufficiency is defined by reference to what the logs must enable: detecting situations that may present a risk or a substantial modification, feeding post-market monitoring, and supporting the deployer’s monitoring duty. That makes Article 12 the only requirement in its section whose adequacy is judged by three other articles. It also gives the assessment its question. Not "what do you log" — the answer is always "a great deal" — but show me a monitoring finding, or a suspension decision, that was reached *from* the logs. Where nothing downstream has ever been produced from them, the traceability the Act asks for has not been demonstrated.

§ 2 — What discharges it

What an assessor asks of your AI audit trail

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    A logging specification traced to the three downstream uses

    Each recorded event class should map to what it exists to enable: risk identification, post-market monitoring, or deployer monitoring. Events that map to none of the three are operational telemetry, which is fine but is not what this provision is asking for.

  2. 02

    Something downstream that came out of the logs

    A monitoring finding, a substantial-modification determination, a suspension decision. This is the only evidence that distinguishes capability from volume, and its absence over a long operating period is itself the finding.

  3. 03

    The retention position, and who holds it

    Which logs sit under the provider’s control and which under the deployer’s, with the six-month floor applied to each, and the data-protection constraint that the Act expressly preserves where logs contain personal data.

  4. 04

    For biometric identification, the four minimum fields

    Start and end of each use, the reference database checked against, the input data that produced a match, and the identity of the people who verified the result. The last of these makes the two-person verification rule auditable.

§ 3 — Who it binds

Who must build the logging, and who must keep it

Provider

Every high-risk AI system under either Article 6 gateway, unconditionally — unlike the data-governance requirement, there is no carve-out for systems that do not train a model. The four-item minimum content list triggers only for remote biometric identification under Annex III point 1(a), which excludes one-to-one verification.

§ 4 — Worked example

Worked example — comprehensive logs, unmet requirement

A software provider ships a high-risk workforce-management system with comprehensive application logging: every request, every model call, every configuration change, retained twenty-four months in the customer’s own tenancy. The provider holds no logs itself, on the basis that the customer controls the environment and holds the data.

Where does this leave the provider?

Better placed on retention than on Article 12, which is the reverse of what the provider assumes. The retention position is defensible: the duty is qualified by control, and logs sitting in the customer’s tenancy are arguably not under the provider’s. Article 12 is the harder question, because comprehensive is not the same as sufficient. The provision asks whether the logs enable identification of situations that may present a risk to health, safety or fundamental rights, whether they feed post-market monitoring, and whether they support the deployer’s monitoring duty. Request-level application logs answer none of those without a layer that relates events to outcomes for affected people. The provider should be able to show a post-market monitoring finding derived from these logs; if none exists after two years of operation, the capability requirement is unmet however much data is being written.

§ 5 — What a weak answer looks like

Application logs offered as AI logs

Volume offered as traceability. The provider produces retention periods, storage figures and a list of every event class emitted, and cannot point to a single occasion on which any of it was used to establish anything. Article 12 is not satisfied by writing data; it is satisfied by a system whose records make the three named downstream activities possible. An assessor with limited time will skip the schema and ask what the logs have ever shown.

§ 6 — When it applies

When the logging duty applies

  1. 2 December 2027

    Annex III standalone high-risk systems. Moved from 2 August 2026 by the Digital Omnibus — a sixteen-month extension driven by undesignated national authorities and the absence of harmonised standards, not by any relaxation of the Section 2 requirements themselves.

  2. 2 August 2028

    Annex I embedded high-risk systems — medical devices, machinery, vehicles — where AI Act requirements fold into the existing sectoral conformity assessment. Moved from 2 August 2027.

§ 7 — Exposure

Exposure — three parties, three provisions, one ceiling

€15 million or 3% of worldwide annual turnover, whichever is higher

Article 99(4)(a), reached through Article 16(a) — Article 12 sits in Chapter III Section 2 and is not itself enumerated in Article 99(4). The provider’s separate retention duty has a shorter route, being named inside Article 16 directly; the deployer’s equivalent is reached through Article 99(4)(e). Three parties, three provisions, one ceiling. Articles 99(6) and 99(6a) give SMEs and small mid-caps the lower figure.

§ 8 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • ISO/IEC 42001

    ISO/IEC 42001 Annex A carries a control for AI system event logging, which addresses the same capability from the management-system side. Cited by number and title so the reference remains checkable against the standard itself.

  • GDPR and data-protection law

    Storage limitation and the six-month retention floor pull in opposite directions where logs contain personal data. The Act concedes the tension expressly, subordinating its floor to Union data-protection law.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 9 — provenance

Certification

Assessed on the same standard of evidence

Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.