Art.12
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 12

Article 12 — Record-Keeping

High-Risk Systems SME Relevant ~2 min read · 436 words

Article 12 requires providers of high-risk AI systems to build in automatic logging capabilities. These logs record what the system does while it operates — creating an audit trail that regulators, deployers, and affected individuals can use to verify compliance and investigate problems.

! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Automatic audit trails for high-risk AI

Article 12 mandates that high-risk AI systems are technically capable of automatically recording events — logs — during their operation. This is not an optional feature. The logging capability must be built into the system by the provider, and the logs must be sufficient to enable post-market monitoring and investigation of incidents.

WHAT IT SAYS

Built-in, automatic, and traceable

  • High-risk AI systems must have the technical capability to automatically generate logs of events throughout their operation
  • Logs must enable the monitoring of operation of the high-risk AI system with respect to the occurrence of situations that may result in the system presenting a risk
  • For AI systems used for real-time biometric identification, logging must include the period of each use, the reference database used, the input data that led to identification, and the identity of the persons who verified the results
  • Logging capabilities must be consistent with generally acknowledged state-of-the-art techniques
  • Deployers retain the logs generated during use — the retention period is at minimum six months unless other EU or national law requires longer retention

WHO IS AFFECTED

Providers must build it in — deployers must keep the records

  • Providers of high-risk AI systems — responsible for ensuring the technical logging capability exists in the system they place on the market
  • Deployers of high-risk AI systems — responsible for storing and retaining the logs generated during their use of the system
  • Market surveillance authorities who may request access to logs during investigations
  • Data protection authorities, given the overlap with GDPR record-keeping obligations

WHAT IT MEANS FOR SMES

Two different obligations depending on your role

  • If you are a provider: logging must be a feature of your system before it goes to market — it cannot be added later as a patch; factor this into your development process from the start
  • If you are a deployer: you are responsible for storing the logs your AI system generates for at least six months — ensure your data infrastructure supports this
  • Logs are your protection as much as a regulatory requirement — if an AI decision is ever challenged, logs are what you use to demonstrate the system operated correctly
  • Check whether your AI vendor’s system already has compliant logging built in before purchasing — this is a legitimate question to ask suppliers
  • The intersection with GDPR is important: logs containing personal data must be handled in compliance with your existing data protection obligations

Related Articles

← Previous Art. 11 — Technical Documentation Next → Art. 13 — Transparency and Provision of Information to Deployers