Design high-risk systems to log events automatically
Under EU AI Act, Article 12; Article 26(6) for deployers
What does it require?
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Practical action
Define the log schema, retention and access controls, and confirm deployer retention meets the minimum.
Who does it apply to?
Providers (design) and deployers (retention) of high-risk AI systems.
- Sectors
- Cross-sector / all sectors
Applies from:
Evidence examples
- Logging specification and retention policy (document)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A control on event logging | Original editorial mapping. | medium |
| NIST AI RMF 1.0 | MEASURE 2.x, MANAGE 4.1 | Monitoring and traceability. | medium |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.