Article 12

EU AI Act Article 12 — Record-Keeping and Automatic Logging

Article 12 of Regulation (EU) 2024/1689 requires automatic logging in high-risk AI systems. Logging events, deployer access, retention, and the link to Article 19.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 12 actually requires

Article 12 of Regulation (EU) 2024/1689 obliges providers to design high-risk AI systems with automatic recording of events (logs) over the system's lifetime. The logs must be appropriate to the intended purpose and to the foreseeable risks, and must enable traceability of the system's functioning to a degree appropriate to identifying situations that may result in the system presenting a risk under Article 79(1) or that lead to a substantial modification.

Reg text — Article 12(1): "High-risk AI systems shall technically allow for the automatic recording of events ('logs') over the lifetime of the system."

For Annex III §1 biometric identification systems, Article 12(2) requires logs to record at minimum: (a) the period of each use of the system, (b) the reference database against which input data was checked, (c) the input data for which the search led to a match, and (d) the identification of the natural persons involved in the verification of the results.

Who is covered

Providers design the logging into the system. Deployers receive the logs and must retain them under Article 19 for at least six months unless a different period is required by Union or national law.

What to do

  • Define the loggable event set before the system ships: input fingerprint, model version, output, confidence, deployer-side overseer ID, override decisions, errors, drift alerts.
  • Document log retention in the Annex IV §3 input-data specification and in the Article 13 instructions for use.
  • Confirm the deployer can access the logs without engineering support. Article 26(6) makes deployer log retention an obligation; you cannot oblige a deployer to retain logs they cannot reach.
  • Tie logs to the Article 9 post-market loop and the Article 79 incident-reporting flow. Logs are the evidence regulators ask for first.

Inline crosswalk to ISO 42001 and NIST AI RMF

  • ISO/IEC 42001:2023 Annex A.6.2.7 — System and component logging.
  • NIST AI RMF MEASURE 2.6 — AI system performance or assurance criteria are measured qualitatively or quantitatively.

Common mistakes

  • Logging too little. PII concerns are real but Article 12 is mandatory; pseudonymise rather than skip.
  • Logs deployer cannot reach.
  • No retention SLA documented.

Penalties

Article 99(4) — up to €15 million or 3% of worldwide annual turnover.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 19 · Pro tier · medium

    Retain automatic logs for at least 6 months

    Article 19 requires providers keep logs generated by Article 12 automatic logging for a period appropriate to intended purpose — minimum 6 months.

  • Annex IV · Pro tier · low

    Changelog of every model retrain and architecture change

    Annex IV(2)(f) requires any pre-determined changes to system performance and information about how continuous compliance is ensured.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art19-logs-retentionISO/IEC 42001:2023 Annex A.6.2.7 — System and component loggingArticle 19 minimum-6-month log retention is the logging control in Annex A.6.2.7.
annexiv-changes-logISO/IEC 42001:2023 Clause 8.1 — Operational planning and controlChange-log of retrains and architecture changes is the operational change-control evidence required by Clause 8.1.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art19-logs-retentionNIST AI RMF MEASURE 2.6 — AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstratedAutomatic logs are the quantitative evidence MEASURE 2.6 expects to demonstrate ongoing performance.
annexiv-changes-logNIST AI RMF MANAGE 4.2 — Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested partiesRetrain and architecture changelogs are the measurable continual-improvement activity MANAGE 4.2 expects.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.