Article 12: Record-Keeping and Automatic Logging
Article 12 requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the system's lifetime, at a level that ensures traceability of the system's functioning appropriate to its intended purpose. This capability must be built into the system design, not bolted on afterward.
- 02 Dec 2027 Applies to Annex III high-risk systems
- 02 Aug 2028 Applies to Annex I embedded high-risk systems
- Design the system so it can automatically record relevant events throughout its operation.
- Ensure log capability supports identification of situations that may result in risk or substantial modification.
- Ensure logs are sufficient to facilitate post-market monitoring and support any biometric-related traceability requirements.
- Coordinate logging design with the log-retention duties placed on deployers under Article 26(6).
- System architecture documentation describing the logging design
Article 12 logging is frequently conflated with GDPR-style access logs for personal data; the AI Act requirement is about system-level event traceability for risk and conformity purposes, not a personal-data audit trail specifically.
What regulators published on Art. 12
- Loading from the public feed…
- Regulation (EU) 2024/1689 on EUR-Lex
- Look for Article 12
- Deadline changes and the acts behind them
Get told when Art. 12 moves.
Deadlines under this regulation have already shifted once in 2026. A signed webhook, a REST API and an MCP server carry the same record this page is built from, so your systems learn about the next change without anyone re-reading the text. Free during the beta.
Get free accessInformational content only. Not legal advice and not a substitute for qualified counsel. Dates reflect Regulation (EU) 2026/1744 as of 04 Aug 2026.