Does EU AI Act require Record-Keeping & Documentation?
European Union • phased enforcement
Yes — 1 provision
Requirements at a glance
This regulation imposes 6 specific requirements for Record-Keeping & Documentation across 1 provision:
- Automatic logging capability — High-risk AI systems must technically allow automatic recording of events over the system's lifetime (Article 12(1))
- Traceability — Logs must enable risk identification and post-market monitoring
- Deployer monitoring — Logs must support operational monitoring by deployers (Article 26(5))
- Log retention — Providers and deployers must keep automatically generated logs under their control for a period appropriate to the system's intended purpose, of at least six months unless applicable Union or national law provides otherwise, particularly data-protection law (Articles 19(1), 26(6)); financial institutions keep logs under the relevant Union financial-services rules (Articles 19(2), 26(6))
- Tamper-evident storage — Editorial best practice, not a statutory requirement. Articles 12, 19 and 26 do not use "immutable" or "tamper-evident", and no specific provision requiring log integrity controls has been identified
- Biometric ID specifics — Remote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data for which the search led to a match, and verifying personnel (Article 12(3))
Record-Keeping & Automatic Logging (Article 12)
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.
Requirements
| Requirement | Details |
|---|---|
| Automatic logging capability | High-risk AI systems must technically allow automatic recording of events over the system's lifetime (Article 12(1)) |
| Traceability | Logs must enable risk identification and post-market monitoring |
| Deployer monitoring | Logs must support operational monitoring by deployers (Article 26(5)) |
| Log retention | Providers and deployers must keep automatically generated logs under their control for a period appropriate to the system's intended purpose, of at least six months unless applicable Union or national law provides otherwise, particularly data-protection law (Articles 19(1), 26(6)); financial institutions keep logs under the relevant Union financial-services rules (Articles 19(2), 26(6)) |
| Tamper-evident storage | Editorial best practice, not a statutory requirement. Articles 12, 19 and 26 do not use "immutable" or "tamper-evident", and no specific provision requiring log integrity controls has been identified |
| Biometric ID specifics | Remote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data for which the search led to a match, and verifying personnel (Article 12(3)) |
Penalties
| Violation | Fine |
|---|---|
| Provider non-compliance through Article 16(a) and 16(e) log keeping, or deployer non-compliance with Article 26(5)-(6) | Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date. |