Article 12
EU AI Act Article 12 — Record-Keeping and Automatic Logging
Article 12 of Regulation (EU) 2024/1689 requires automatic logging in high-risk AI systems. Logging events, deployer access, retention, and the link to Article 19.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 12 actually requires
Article 12 of Regulation (EU) 2024/1689 obliges providers to design high-risk AI systems with automatic recording of events (logs) over the system's lifetime. The logs must be appropriate to the intended purpose and to the foreseeable risks, and must enable traceability of the system's functioning to a degree appropriate to identifying situations that may result in the system presenting a risk under Article 79(1) or that lead to a substantial modification.
Reg text — Article 12(1): "High-risk AI systems shall technically allow for the automatic recording of events ('logs') over the lifetime of the system."
For Annex III §1 biometric identification systems, Article 12(2) requires logs to record at minimum: (a) the period of each use of the system, (b) the reference database against which input data was checked, (c) the input data for which the search led to a match, and (d) the identification of the natural persons involved in the verification of the results.
Who is covered
Providers design the logging into the system. Deployers receive the logs and must retain them under Article 19 for at least six months unless a different period is required by Union or national law.
What to do
- Define the loggable event set before the system ships: input fingerprint, model version, output, confidence, deployer-side overseer ID, override decisions, errors, drift alerts.
- Document log retention in the Annex IV §3 input-data specification and in the Article 13 instructions for use.
- Confirm the deployer can access the logs without engineering support. Article 26(6) makes deployer log retention an obligation; you cannot oblige a deployer to retain logs they cannot reach.
- Tie logs to the Article 9 post-market loop and the Article 79 incident-reporting flow. Logs are the evidence regulators ask for first.
Inline crosswalk to ISO 42001 and NIST AI RMF
- ISO/IEC 42001:2023 Annex A.6.2.7 — System and component logging.
- NIST AI RMF MEASURE 2.6 — AI system performance or assurance criteria are measured qualitatively or quantitatively.
Common mistakes
- Logging too little. PII concerns are real but Article 12 is mandatory; pseudonymise rather than skip.
- Logs deployer cannot reach.
- No retention SLA documented.
Penalties
Article 99(4) — up to €15 million or 3% of worldwide annual turnover.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 19 · Pro tier · medium
Retain automatic logs for at least 6 months
Article 19 requires providers keep logs generated by Article 12 automatic logging for a period appropriate to intended purpose — minimum 6 months.
Annex IV · Pro tier · low
Changelog of every model retrain and architecture change
Annex IV(2)(f) requires any pre-determined changes to system performance and information about how continuous compliance is ensured.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art19-logs-retention | ISO/IEC 42001:2023 Annex A.6.2.7 — System and component logging | Article 19 minimum-6-month log retention is the logging control in Annex A.6.2.7. |
annexiv-changes-log | ISO/IEC 42001:2023 Clause 8.1 — Operational planning and control | Change-log of retrains and architecture changes is the operational change-control evidence required by Clause 8.1. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art19-logs-retention | NIST AI RMF MEASURE 2.6 — AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated | Automatic logs are the quantitative evidence MEASURE 2.6 expects to demonstrate ongoing performance. |
annexiv-changes-log | NIST AI RMF MANAGE 4.2 — Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties | Retrain and architecture changelogs are the measurable continual-improvement activity MANAGE 4.2 expects. |
Related
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Article 15
EU AI Act Article 15 — Accuracy, Robustness and Cybersecurity
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Annex IV §1
Annex IV §1 — General Description of the AI System (EU AI Act)
Article 26
EU AI Act Article 26 — Deployer Obligations
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.