EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 12Record-keeping

Article 12 requires high-risk AI systems to keep automatically generated logs that trace the system's functioning across its lifecycle — the evidence trail regulators and deployers rely on after something goes wrong.

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • High-risk systems must be technically capable of keeping automatic logs throughout their lifetime.
  • Logs must trace: when the system ran, who was involved in review, the input data, and the output produced.
  • The Act requires logs to be kept for at least 6 months, unless another law sets a longer period.
  • Providers must build the logging capability; deployers are responsible for operating and retaining the logs.
  • Logging supports post-market monitoring (Art. 72) and serious-incident investigations.

Scope

Who this applies to

Providers must design the logging capability in; deployers must actually keep the logs running and retained for the required period.

Obligations

What you must actually do

Design logs in

The system should record meaningful events: usage sessions, human-review actions, input and output data, and confidence or override signals where relevant.

Retain for 6 months minimum

The default retention floor is 6 months; sectoral law (e.g. financial or medical record rules) can require longer. Check your sector's retention obligations.

Protect the logs

Logs must be accurate and tamper-evident in practice — access-controlled, with clear ownership. They are prime evidence in an investigation.

Action plan

Practical first steps

  1. 1

    Specify a logging schema per high-risk system before development: what, when, by whom, with what inputs/outputs.

  2. 2

    Assign a deployer-side log owner and a retention policy that respects both Art. 12 and sectoral rules.

  3. 3

    Test that logs survive an incident — restore from them in a dry run.

  4. 4

    Reconcile logs with the technical documentation's system description.

Penalty exposure

Record-keeping failures sit in the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 12

Who is responsible for keeping the logs — provider or deployer?

Providers must build the logging capability into the system; deployers must operate and retain the logs for the required period and ensure human-review actions are captured.

What if my sector already requires longer retention?

Then the longer sectoral period wins. GDPR, financial services, and healthcare retention rules commonly exceed the 6-month floor — keep the longer of the two.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.