EU AI Act Art. 12 — Record-keeping
Article 12 requires high-risk AI systems to keep automatically generated logs that trace the system's functioning across its lifecycle — the evidence trail regulators and deployers rely on after something goes wrong.
At a glance
What this article requires
- High-risk systems must be technically capable of keeping automatic logs throughout their lifetime.
- Logs must trace: when the system ran, who was involved in review, the input data, and the output produced.
- The Act requires logs to be kept for at least 6 months, unless another law sets a longer period.
- Providers must build the logging capability; deployers are responsible for operating and retaining the logs.
- Logging supports post-market monitoring (Art. 72) and serious-incident investigations.
Scope
Who this applies to
Providers must design the logging capability in; deployers must actually keep the logs running and retained for the required period.
Obligations
What you must actually do
Design logs in
The system should record meaningful events: usage sessions, human-review actions, input and output data, and confidence or override signals where relevant.
Retain for 6 months minimum
The default retention floor is 6 months; sectoral law (e.g. financial or medical record rules) can require longer. Check your sector's retention obligations.
Protect the logs
Logs must be accurate and tamper-evident in practice — access-controlled, with clear ownership. They are prime evidence in an investigation.
Action plan
Practical first steps
- 1
Specify a logging schema per high-risk system before development: what, when, by whom, with what inputs/outputs.
- 2
Assign a deployer-side log owner and a retention policy that respects both Art. 12 and sectoral rules.
- 3
Test that logs survive an incident — restore from them in a dry run.
- 4
Reconcile logs with the technical documentation's system description.
Penalty exposure
Record-keeping failures sit in the general tier: up to €15 million or 3% of global annual turnover.
FAQ
Questions about Art. 12
Who is responsible for keeping the logs — provider or deployer?
Providers must build the logging capability into the system; deployers must operate and retain the logs for the required period and ensure human-review actions are captured.
What if my sector already requires longer retention?
Then the longer sectoral period wins. GDPR, financial services, and healthcare retention rules commonly exceed the 6-month floor — keep the longer of the two.
Sources
Citations & further reading
Related
More article explainers
Wondering which articles apply to your AI?
Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.
Check my use casePreliminary EU AI Act clarity summary. Not legal advice.