EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · RECORD KEEPING · ARTICLE 12
STORING LOGS IS NOT THE SAME AS PRESERVING EVIDENCE.
High-risk AI record keeping is useful only when events remain connected to the system, time, context, source and accountable action they represent. TA-14 treats logging as part of a governed evidence chain rather than an archive of unexplained machine events.
Use the current consolidated Regulation as the controlling source. Article 12 addresses high-risk system record-keeping capability, while provider and deployer retention responsibilities are addressed in related provisions including Articles 19 and 26.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
A LOG ENTRY IS NOT SELF-EXPLAINING EVIDENCE
A timestamp and event can be meaningless without system identity, version, context, source and the operational state in which the event occurred. Preserve the relationship between the record and the reality it represents.
02
HIGH-RISK SYSTEMS NEED LOGGING CAPABILITY
Article 12 requires high-risk AI systems to technically allow automatic recording of events over the system lifetime, with logging capabilities appropriate to traceability and risk monitoring under the applicable provisions.
03
PROVIDERS AND DEPLOYERS HOLD DIFFERENT RECORDS
The system may generate logs, while providers and deployers can have distinct retention and access responsibilities. Map the record to the actor who actually controls it rather than assuming one universal owner.
04
RETENTION WITHOUT INTEGRITY IS NOT ENOUGH
Records should preserve chronology, provenance, access, material changes and relevant human interventions so later review can distinguish an authentic historical state from a reconstructed story.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Define what event must be reconstructable
Identify the system, version, use context, risk, decision or incident that the record needs to support before choosing what to log.
02
Preserve source, time and system context
Connect each relevant event to its origin, timestamp, system state, input/output context where appropriate and accountable actors so the record can be interpreted later.
03
Map retention to operator responsibility
Determine which provider or deployer records are under the organization’s control, the applicable retention rule and how integrity and authorized access will be maintained.
04
Connect logs to consequence and revalidation
When records reveal drift, risk, misuse, incident conditions or material change, route the signal to investigation, authority, corrective action and renewed governance rather than leaving it trapped in storage.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
Article 12 requires high-risk AI systems to technically allow automatic recording of events over the system lifetime. The logging capability must support the traceability and monitoring purposes described in the applicable provision.
How long must EU AI Act logs be kept?
Retention depends on the actor and applicable provision. The Regulation contains specific provider and deployer record-retention duties, including deployer retention of automatically generated logs under their control for an appropriate period and at least six months unless other applicable Union or national law provides otherwise. Check the current consolidated text for the exact case.
Are logs the same as technical documentation?
No. Logs are operational records of events. Technical documentation is a broader evidence package describing the system and its compliance-relevant characteristics. They should connect, but one does not replace the other.
Do deployers have to retain high-risk AI logs?
Article 26 contains a deployer duty concerning logs automatically generated by a high-risk AI system to the extent those logs are under the deployer’s control, subject to the applicable retention conditions and other law.
Why does provenance matter for AI logs?
Without provenance, a reviewer may not be able to establish where a record came from, which system version generated it, whether it was altered, or what operational context it represented. Those relationships affect whether the record can support a consequential conclusion.
Can TA-14 serve as our statutory logging system?
TA-14 can structure evidence records, provenance, chronology, accountable action, gaps and revalidation state. Whether a particular implementation satisfies a statutory technical logging or retention requirement depends on the system, actor, applicable provision and technical architecture.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.