Legal requirement Record keeping and logging European Union Partially applicable

Design high-risk systems to log events automatically

Under EU AI Act, Article 12; Article 26(6) for deployers

Source-linked Open official source

What does it require?

High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.

Practical action

Define the log schema, retention and access controls, and confirm deployer retention meets the minimum.

Who does it apply to?

Providers (design) and deployers (retention) of high-risk AI systems.

Applies from:

Evidence examples

  • Logging specification and retention policy (document)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A control on event loggingOriginal editorial mapping.medium
NIST AI RMF 1.0MEASURE 2.x, MANAGE 4.1Monitoring and traceability.medium

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.