⚠ Medium compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
Provider retention of the logs their systems generate
Article 19 establishes the log retention obligation for providers of high-risk AI systems. It is closely linked to Article 12 — which required systems to have automatic logging capabilities built in — and to Article 18, which deals with broader documentation retention. Together, these three articles create the full paper trail that enables post-market monitoring and incident investigation.
WHAT IT SAYS
Six months minimum — longer where law requires
- Providers of high-risk AI systems must retain the automatically generated logs referred to in Article 12, to the extent those logs are under their control
- Logs must be kept for a minimum of six months, unless applicable EU or national law — particularly data protection law — requires a different period
- Financial institutions must keep logs as part of their internal governance documentation under EU financial services law
- The retention obligation applies only to logs that are under the provider’s control — where logs are retained solely by the deployer, the provider’s obligation does not apply to those specific logs
- The six-month minimum is a floor, not a ceiling — providers may retain logs longer if operationally appropriate, subject to data protection obligations
WHO IS AFFECTED
Providers who retain control of log data
- Providers of high-risk AI systems who have access to or control over the logs generated during use
- SaaS and cloud-based AI providers who process data on behalf of deployers — they typically control log data and are therefore subject to this article
- On-premise AI system providers whose systems are deployed entirely within the deployer’s infrastructure — their control over logs is limited and the obligation falls primarily on the deployer
- Financial institutions subject to specific sectoral governance requirements around log retention
WHAT IT MEANS FOR SMES
Understand who controls the logs in your specific deployment model
- The key question is control — if your AI system sends logs back to your servers or cloud infrastructure, you are retaining logs and this article applies to you
- If you offer an on-premise deployment where all data stays with the deployer, your log retention obligations under this article are minimal — but the deployer’s obligations under Article 12 become more significant
- Six months is a short period — build your log retention infrastructure to handle at least this period from day one; extending later is easier than reconstructing past logs
- Logs frequently contain personal data — your log retention policy must be consistent with your GDPR obligations, including data minimisation and storage limitation principles
- When contracting with deployers, clearly specify who retains which logs and for how long — this avoids compliance gaps and disputes later
Related Articles
- Article 12 — Record-keeping (establishes the logging requirement that this article builds on)
- Article 18 — Documentation keeping (the broader ten-year retention obligation for providers)
- Article 72 — Post-market monitoring (logs are central to this process)
- Article 73 — Reporting of serious incidents (logs are the evidence base for incident reports)
