! High compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
Automatic audit trails for high-risk AI
Article 12 mandates that high-risk AI systems are technically capable of automatically recording events — logs — during their operation. This is not an optional feature. The logging capability must be built into the system by the provider, and the logs must be sufficient to enable post-market monitoring and investigation of incidents.
WHAT IT SAYS
Built-in, automatic, and traceable
- High-risk AI systems must have the technical capability to automatically generate logs of events throughout their operation
- Logs must enable the monitoring of operation of the high-risk AI system with respect to the occurrence of situations that may result in the system presenting a risk
- For AI systems used for real-time biometric identification, logging must include the period of each use, the reference database used, the input data that led to identification, and the identity of the persons who verified the results
- Logging capabilities must be consistent with generally acknowledged state-of-the-art techniques
- Deployers retain the logs generated during use — the retention period is at minimum six months unless other EU or national law requires longer retention
WHO IS AFFECTED
Providers must build it in — deployers must keep the records
- Providers of high-risk AI systems — responsible for ensuring the technical logging capability exists in the system they place on the market
- Deployers of high-risk AI systems — responsible for storing and retaining the logs generated during their use of the system
- Market surveillance authorities who may request access to logs during investigations
- Data protection authorities, given the overlap with GDPR record-keeping obligations
WHAT IT MEANS FOR SMES
Two different obligations depending on your role
- If you are a provider: logging must be a feature of your system before it goes to market — it cannot be added later as a patch; factor this into your development process from the start
- If you are a deployer: you are responsible for storing the logs your AI system generates for at least six months — ensure your data infrastructure supports this
- Logs are your protection as much as a regulatory requirement — if an AI decision is ever challenged, logs are what you use to demonstrate the system operated correctly
- Check whether your AI vendor’s system already has compliant logging built in before purchasing — this is a legitimate question to ask suppliers
- The intersection with GDPR is important: logs containing personal data must be handled in compliance with your existing data protection obligations
Related Articles
- Article 11 — Technical documentation (logging specifications should be documented)
- Article 18 — Documentation keeping (retention obligations for providers)
- Article 19 — Automatically generated logs (the deployer-side retention obligation)
- Article 72 — Post-market monitoring (logs feed directly into this process)
