CertifiedData.io
EU AI Act · Article 12

EU AI Act Logging Requirements

Article 12 requires high-risk AI systems to technically allow automatic recording of events over the lifetime of the system so that the system's functioning can be traced at a level appropriate to its intended purpose.

Under Regulation (EU) 2026/1744, Chapter III Sections 1–3 apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Classification and applicability remain system-specific.

What Article 12 actually requires

The core requirement is a technical logging capability. Article 12(2) identifies the purposes the logging capability must support; additional minimum fields apply to specified biometric identification systems under Annex III point 1(a).

Risk situations and substantial modification

Logging capabilities must support identification of events relevant to situations that may present a risk under Article 79(1) or indicate a substantial modification.

Post-market monitoring

Logs must support post-market monitoring under Article 72.

Operational monitoring

Logs must support monitoring of the operation of the high-risk AI systems referenced by Article 26(5).

Keep the evidence layers separate

Runtime event logging

Article 12 concerns the AI system's technical capability to record relevant events automatically. Decision records can help preserve the events, inputs, outputs, policy context, and review facts your implementation actually captures.

Log retention

Article 19 requires providers to keep automatically generated Article 12 logs under their control for an appropriate period of at least six months unless other Union or national law provides otherwise. Article 26 contains a corresponding deployer retention duty for logs under deployer control.

Dataset provenance

Training-data provenance and certification can be relevant to data-governance and technical-documentation evidence elsewhere in the Act. A dataset certificate is not a substitute for Article 12 runtime logging.

Cryptographic integrity

Signed records can make later tampering detectable and improve auditability. The EU AI Act does not turn an Ed25519 signature or a CertifiedData certificate into a legal compliance verdict.

How CertifiedData can support an Article 12 evidence program

Decision Ledger can preserve signed decision evidence for events your system chooses to record, including model and policy context, inputs or references, outputs, human review, and linked artifacts. That can support traceability and later audit of the implementation.

Synthetic-dataset certificates can separately preserve generation provenance and artifact fingerprints for supported CertifiedData-generated datasets. Those records may support the broader technical-documentation or data-governance evidence set, but they do not replace the runtime logging capability required by Article 12.

A valid CertifiedData signature proves integrity and issuer authenticity for the signed payload. Whether an organization complies with Article 12 depends on the applicable system, classification, logging design, retained events, operational controls, and the rest of the regulatory requirements.

Practical implementation questions

  • • Which events are relevant to risk detection, post-market monitoring, and operational monitoring for this system?
  • • Which logs are automatically generated by the high-risk AI system versus created by surrounding application infrastructure?
  • • Who controls each log and therefore carries the applicable retention responsibility?
  • • Can an auditor reconstruct the relevant event history without treating signature validity as a compliance conclusion?
  • • Are retention, access, privacy, incident, and post-market monitoring controls documented separately?
EU AI Act Article 12 · High-risk obligations from Dec 2027

Start logging AI decisions today.

If your AI system makes decisions, you will need an audit log that holds up in front of a regulator. CertifiedData gives you a cryptographically signed, hash-chained record. Free tier includes 1,000 records/month — no credit card.

  1. 1
    Create a free account
    No credit card. Two minutes.
  2. 2
    Get your API key
    One key. Scoped, revocable, rotateable.
  3. 3
    Send your first decision
    One curl. Appears in the public ledger within seconds.
EU AI Act Logging Requirements — Article 12 for High-Risk AI | CertifiedData