# Providers must retain automatically generated logs under their control

- **Record type**: Obligation
- **Instrument**: Regulation (EU) 2024/1689 — Artificial Intelligence Act
- **Jurisdiction**: European Union
- **Category**: record_keeping
- **Binding**: Yes
- **Applies from**: 2026-08-02
- **Provision**: Article 19

## What the duty requires

Providers must keep the event logs that a high-risk AI system generates under Article 12, to the extent those logs are within their control, for a period appropriate to the system's intended purpose and in any case for at least six months, unless Union or national law on personal data sets a different period. Financial institutions keep the logs under their sector rules.

## What an organisation does about it

Configure log retention for hosted or API-served high-risk systems to at least six months with a documented rationale for any longer period.

## Controls that meet this duty

- Automatic event logging and record retention (satisfies): https://aipolicytracker.org/controls/record-keeping-and-logging

## Parent instrument

- Regulation (EU) 2024/1689 — Artificial Intelligence Act
  - Record: https://aipolicytracker.org/policies/eu-ai-act
  - Context file: https://aipolicytracker.org/policies/eu-ai-act.md

## Provenance

- **Record page**: https://aipolicytracker.org/obligations/eu-ai-act-art-19-provider-log-retention
- **Official source**: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- **Provision**: Article 19
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
