Logging and record-keeping obligations under Article 12
In short
Logs are the primary evidence used to reconstruct what a high-risk AI system actually did in a specific case, after an incident, a complaint, or a regulator’s inquiry, the log is frequently the only record capable of establishing what happened. Article 12 requires the system to be built to produce them; Article 26(6) requires deployers to keep them.
What Article 12 requires of the system itself
High-risk AI systems must technically enable the automatic recording of events (logs) over the system’s lifetime, at a level of traceability appropriate to the system’s intended purpose. This is a provider-side design obligation, the capability to log has to be built in, not bolted on after deployment.
A stricter standard for biometric identification systems
Article 12(2)(a) sets a more specific logging standard for biometric identification systems: logs must capture the exact period of each use, the reference database checked against, the input data that produced a match, and the identity of the natural person who verified the result. General-purpose logging that omits these specifics does not satisfy the biometric-specific requirement.
The deployer's six-month retention duty
Article 26(6) requires deployers to retain the logs their high-risk system automatically generates for at least six months, unless another applicable law (a sectoral record-keeping rule, for example) requires a longer period. Retention without active use is only half the obligation: Article 26(5) separately expects deployers to actually monitor the system using those logs, not simply archive them.
Logging supports more than one obligation
Logs are not a standalone requirement, they are the evidentiary backbone for post-market monitoring (Article 72), serious incident investigation (Article 73), and a deployer’s monitoring duty (Article 26(5)). A system that logs correctly but whose logs are never reviewed satisfies the letter of Article 12 while missing the practical purpose all of these provisions share.
Providers should document how the logging mechanism works, and where it stores data, within the instructions for use (Article 13(3)(f)) so that deployers actually know how to access and interpret the logs they are required to retain, a common gap is a technically compliant logging system that the deploying organisation never learns how to use.
Frequently asked questions
- How long must high-risk AI system logs be kept?
- Article 26(6) requires deployers to retain the logs their high-risk system automatically generates for at least six months, unless another applicable law (such as a sectoral record-keeping rule) requires a longer period.
- Who is responsible for logging under the EU AI Act?
- It is split. Under Article 12 the provider must build automatic event-logging into the system as a design obligation; under Article 26(6) the deployer must retain the generated logs, and under Article 26(5) actually use them to monitor the system.
- Is there a stricter logging standard for biometric systems?
- Yes. Article 12(2)(a) requires biometric identification systems to log the exact period of each use, the reference database checked against, the input data that produced a match, and the identity of the natural person who verified the result.
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check