Providers must retain automatically generated logs under their control
Context fileUnder EU AI Act, Article 19
What does it require?
Providers must keep the event logs that a high-risk AI system generates under Article 12, to the extent those logs are within their control, for a period appropriate to the system's intended purpose and in any case for at least six months, unless Union or national law on personal data sets a different period. Financial institutions keep the logs under their sector rules.
Practical action
Configure log retention for hosted or API-served high-risk systems to at least six months with a documented rationale for any longer period.
Who does it apply to?
Providers that host, operate or otherwise hold the logs of a high-risk AI system; deployers have the parallel duty in Article 26(6).
- Actors
- Provider / developer
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesTechnical measureEngineering lead · continuousAutomatic event logging and record retention
Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check
Retention of Article 12 logs for the required period.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Log retention configuration and policy | document | |
| Sample log export demonstrating retention period | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A.6.2.8 | AI system recording of event logs. | high |
| NIST AI RMF 1.0 | MEASURE 2.4, MANAGE 4.1 | Traceability data for monitoring. | medium |
Cite this record
AIPolicyTracker (2026). “Providers must retain automatically generated logs under their control (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-19-provider-log-retention (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Design high-risk systems to log events automatically — EU AI Act, European Union
- Providers must keep high-risk AI documentation for ten years — EU AI Act, European Union
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.