Art.19
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 19

Article 19 — Automatically Generated Logs

High-Risk Systems SME Relevant ~2 min read · 474 words

Article 19 is the provider-side companion to Article 12. Where Article 12 required logging capabilities to be built into the system, Article 19 deals with what happens to those logs once they exist — specifically, how long providers must retain them and under what conditions.

⚠ Medium compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Provider retention of the logs their systems generate

Article 19 establishes the log retention obligation for providers of high-risk AI systems. It is closely linked to Article 12 — which required systems to have automatic logging capabilities built in — and to Article 18, which deals with broader documentation retention. Together, these three articles create the full paper trail that enables post-market monitoring and incident investigation.

WHAT IT SAYS

Six months minimum — longer where law requires

  • Providers of high-risk AI systems must retain the automatically generated logs referred to in Article 12, to the extent those logs are under their control
  • Logs must be kept for a minimum of six months, unless applicable EU or national law — particularly data protection law — requires a different period
  • Financial institutions must keep logs as part of their internal governance documentation under EU financial services law
  • The retention obligation applies only to logs that are under the provider’s control — where logs are retained solely by the deployer, the provider’s obligation does not apply to those specific logs
  • The six-month minimum is a floor, not a ceiling — providers may retain logs longer if operationally appropriate, subject to data protection obligations

WHO IS AFFECTED

Providers who retain control of log data

  • Providers of high-risk AI systems who have access to or control over the logs generated during use
  • SaaS and cloud-based AI providers who process data on behalf of deployers — they typically control log data and are therefore subject to this article
  • On-premise AI system providers whose systems are deployed entirely within the deployer’s infrastructure — their control over logs is limited and the obligation falls primarily on the deployer
  • Financial institutions subject to specific sectoral governance requirements around log retention

WHAT IT MEANS FOR SMES

Understand who controls the logs in your specific deployment model

  • The key question is control — if your AI system sends logs back to your servers or cloud infrastructure, you are retaining logs and this article applies to you
  • If you offer an on-premise deployment where all data stays with the deployer, your log retention obligations under this article are minimal — but the deployer’s obligations under Article 12 become more significant
  • Six months is a short period — build your log retention infrastructure to handle at least this period from day one; extending later is easier than reconstructing past logs
  • Logs frequently contain personal data — your log retention policy must be consistent with your GDPR obligations, including data minimisation and storage limitation principles
  • When contracting with deployers, clearly specify who retains which logs and for how long — this avoids compliance gaps and disputes later

Related Articles

← Previous Art. 18 — Documentation Keeping Next → Art. 20 — Corrective Actions and Duty of Information