Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Reference · European Union

EU AI Act Article 12: Automatic Logging for High-Risk AI After the Digital Omnibus

Record-keeping under Articles 12, 19 and 26(6) of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Last reviewed October 11, 2026

At a glance

Requirement
High-risk AI systems technically allow the automatic recording of events (logs) over their lifetime (Article 12)
Who keeps logs
Providers (Article 19) and deployers (Article 26(6)), each for the logs under its control
Retention
At least six months, unless other Union or national law provides otherwise
Banks, insurers
Financial institutions under Union financial services law keep the logs within the documentation that law requires
Applies from
2 December 2027 for Annex III systems, credit scoring and life and health insurance pricing among them; 2 August 2028 for Annex I systems

Article 12 of the EU AI Act is a design requirement. A high-risk AI system must technically allow the automatic recording of events, its logs, over the lifetime of the system.AI Act · Art. 12(1) Two retention duties sit on top of it. The provider and the deployer each keep the logs under their own control, for at least six months.AI Act · Art. 19(1), 26(6)

The Digital Omnibus on AI, Regulation (EU) 2026/1744, left those articles as they were and moved the date they apply. For the Annex III systems, which include credit scoring and pricing in life and health insurance, the logging duties apply from 2 December 2027. For AI built into products covered by Annex I, they apply from 2 August 2028.Digital Omnibus · Art. 1(40)

Logs must make the system traceable for three purposes

Article 12 sets the standard as traceability appropriate to the system's intended purpose. The logging capabilities must record the events relevant to three things:AI Act · Art. 12(2)

  • Identifying situations that may lead the system to present a risk to health, safety or fundamental rights, or that may amount to a substantial modification of the system.AI Act · Art. 12(2)(a), 79(1)
  • Post-market monitoring, the provider's system for collecting and analysing data on the system's performance throughout its lifetime.AI Act · Art. 12(2)(b), 72
  • The deployer's monitoring of the system's operation, on the basis of the instructions for use.AI Act · Art. 12(2)(c), 26(5)

Only remote biometric identification has a set field list

Article 12 lists minimum contents for one use alone: the remote biometric identification systems in Annex III point 1(a). Their logs record at least the period of each use, with start and end date and time; the reference database the input data was checked against; the input data that led to a match; and the people involved in verifying the results.AI Act · Art. 12(3) Point 1(a) excludes biometric verification whose sole purpose is to confirm that a person is who they claim to be.AI Act · Annex III, 1(a)

For credit scoring and insurance pricing, Article 12 names no fields. The content of the log follows from the three purposes above and from the provider's instructions for use, which describe, where relevant, the mechanisms that let deployers collect, store and interpret the logs.AI Act · Art. 13(3)(f)

Providers build the logging; both parties keep the logs they hold

The provider builds the logging into the system and keeps the logs under its control for a period appropriate to the system's intended purpose, of at least six months.AI Act · Art. 16(a), (e), 19(1) On a reasoned request from a competent authority, it gives that authority access to them.AI Act · Art. 21(2)

The deployer keeps the logs the system generates, to the extent they are under its control, for the same minimum.AI Act · Art. 26(6) It also monitors the system's operation on the basis of the instructions for use. Where it has reason to consider that such use may result in a risk, it informs the provider or distributor and the market surveillance authority without undue delay, and suspends use.AI Act · Art. 26(5)

Both minimums yield to other Union or national law, and the Act names data protection law in particular.AI Act · Art. 19(1), 26(6) Both duties also reach only the logs under that party's control, so where the logs are held decides who keeps them. When the provider hosts the system, the contract should say which logs each party holds.

Flow

Who records, keeps and hands over the logs of a high-risk AI system

  1. Art. 12(1)The system records eventsAutomatic logging over the lifetime of the system
  2. Art. 13(3)(f)The provider describes the logsHow deployers collect, store and interpret them
  3. Art. 26(5)The deployer monitors operationOn the basis of the instructions for use
  4. Art. 19, 26(6)Each party keeps its logsAt least six months, for the logs under its control
  5. Art. 21(2), 26(12)Authorities get accessProviders on reasoned request; deployers cooperate
Each step is from Regulation (EU) 2024/1689 at the article shown. The Act does not set the steps in a sequence; the order is ours.

Banks and insurers keep the logs with their existing documentation

A deployer that is a financial institution subject to internal governance requirements under Union financial services law maintains the logs as part of the documentation it keeps under that law.AI Act · Art. 26(6) A provider that is a financial institution does the same with the logs and with the system's technical documentation.AI Act · Art. 18(3), 19(2)

The deployer's monitoring duty is deemed fulfilled by complying with the internal governance rules of the relevant financial services law.AI Act · Art. 26(5) A financial institution that places a credit-scoring or insurance-pricing system on the market, or puts one into service, may integrate the post-market monitoring elements into the monitoring systems and plans it already has, provided the level of protection is equivalent.AI Act · Art. 72(4)

Supervision follows the same line. For high-risk systems placed on the market, put into service or used by financial institutions in direct connection with financial services, the market surveillance authority is the national authority responsible for their financial supervision, unless the Member State identifies another authority.AI Act · Art. 74(6), (7) By default, the authority that asks a lender or an insurer for its logs is its financial supervisor.

Annex III logging applies from 2 December 2027

As adopted in 2024, the Act applied the high-risk regime from 2 August 2026, except the Article 6(1) obligations, which waited until 2 August 2027.AI Act · Art. 113 Article 12 sits in Section 2 of Chapter III, and Articles 19 and 26 in Section 3, so the logging duties for Annex III systems were due on 2 August 2026.

The Omnibus was adopted on 8 July 2026, published in the Official Journal on 24 July and has been in force since 27 July 2026. It replaced that schedule: Sections 1, 2 and 3 of Chapter III now apply from 2 December 2027 to systems that are high-risk under Annex III, and from 2 August 2028 to those under Annex I.Digital Omnibus · Art. 1(40), Art. 4 The recitals give the reason: standards, common specifications and guidance arrived late, and so did the national competent authorities.Digital Omnibus · Recital 40 The Commission lists "logging of activity to ensure traceability of results" among the obligations that start on 2 December 2027.European Commission

Guidance written against the original text gives 2 August 2026 for the high-risk duties, because that was the date the Act set. The date has not gone away: it remains the Act's general application date, and the Article 50 transparency rules took effect on it.European Commission

Systems already in use are treated separately. A high-risk system placed on the market or put into service before its Chapter III date comes under the Act only if its design changes significantly from that date.Digital Omnibus · Art. 1(39) The recitals apply this by type and model: later units of an unchanged design share the grace period of the first unit lawfully placed on the market, and a significant design change triggers full compliance.Digital Omnibus · Recital 39

CEN and CENELEC are still drafting the logging standards

The Commission has asked CEN and CENELEC for harmonised standards in ten areas, record keeping through the logging capabilities of AI systems among them.Commission FAQ Their joint technical committee, JTC 21, is developing the standards, and lists logging among the more specific standards that will supplement the core set.Commission, standardisationCEN-CENELEC

A system that conforms to a harmonised standard referenced in the Official Journal is presumed to meet the Section 2 requirements the standard covers, Article 12 among them.AI Act · Art. 40(1) The Commission's questions and answers, last updated in March 2026, expect the first harmonised standards from CEN and CENELEC in 2026, followed by a Commission review before any reference in the Official Journal.Commission FAQ Its standardisation page, last updated on 3 August 2026, records that the first draft to enter public enquiry, on 30 October 2025, covers quality management.Commission, standardisation

The 2 December 2027 date is fixed in the Act and does not wait for a logging standard.Digital Omnibus · Art. 1(40) Until one is referenced, a provider's quality management system records the technical specifications it applied and the means it uses to meet the requirement.AI Act · Art. 17(1)(e)

Two further points are open in the text itself. Article 26(6) does not name the financial services acts whose documentation the logs join, or say how their retention periods combine with the six-month minimum. Commission guidance on the post-market monitoring plan, which the logs feed, is due by 2 September 2027 with a template; the Omnibus put it in place of the implementing act the Act originally required.Digital Omnibus · Art. 1(30)

What answers a supervisor's request for logs

Deployers of credit-scoring and life and health insurance pricing systems carry the Article 26 duties and, before first use, a fundamental rights impact assessment.AI Act · Annex III, 5(b), 5(c); Art. 27(1) When the financial supervisor, acting as market surveillance authority, asks how those systems are logged, the answer is a set of records:

  • The inventory entry for each system: its Annex III point, whether the institution is its provider or its deployer, and the date of that determination.
  • The provider's instructions for use, with the description of how the logs are collected, stored and interpreted.
  • A retention rule for each system: the period, why it suits the intended purpose, and the financial services documentation the logs are kept under.
  • The logs themselves, retrievable by system, time window and case, reaching back at least six months.
  • Monitoring records that show the logs in use: the reviews run under the institution's internal governance rules, and any risk or incident notices sent to the provider.
  • Access controls and change history for the log store, showing who can read, alter or delete a log.
  • For each system in use before 2 December 2027, the assessment of whether a later change to its design is significant.

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Logging capability (Art. 12)Record events over the system's lifetime that serve risk identification, post-market monitoring and operational monitoringThe instructions for use describing the logging, and a sample log mapped to the three purposes
Provider retention (Art. 19)Keep the logs under the provider's control for a period suited to the intended purpose, at least six monthsRetention configuration, and the contract terms on which logs the provider holds
Deployer retention (Art. 26(6))Keep the logs under the deployer's control for a period suited to the intended purpose, at least six monthsA retention rule per system with its rationale, and the retained logs
Financial institutions (Art. 19(2), 26(6))Maintain the logs as part of the documentation kept under Union financial services lawThe documentation policy that names the logs, and their place in the records inventory
Monitoring (Art. 26(5))Monitor operation on the basis of the instructions for use, through internal governance rules for financial institutionsMonitoring records that cite the logs reviewed, and notices sent to the provider
Authority access (Art. 21(2), 26(12))Give competent authorities access to the logs and cooperate with their actionsA tested retrieval procedure and a named owner for authority requests

Key dates

Timeline, drawn to scale

When the Article 12 logging duties apply

In effect as of October 11, 2026UpcomingLogging duties apply
20252026202720281 AUG 2024AI Act in force27 JUL 2026Omnibus in force2 AUG 2026General application2 SEP 2027Monitoring guidance due2 DEC 2027Annex III logging applies2 AUG 2028Annex I logging applies
Dates from Article 113 of Regulation (EU) 2024/1689 and Article 1(30), (40) and Article 4 of Regulation (EU) 2026/1744. Status as of October 11, 2026.
  • 1 August 2024Regulation (EU) 2024/1689 enters into force.
  • 19 November 2025The Commission proposes the Digital Omnibus on AI.
  • 7 May 2026Political agreement on the Digital Omnibus.
  • 24 July 2026Regulation (EU) 2026/1744 published in the Official Journal.
  • 27 July 2026The Digital Omnibus enters into force.
  • 2 August 2026General application date. Under the Act as adopted, the Annex III high-risk duties, Article 12 logging included, applied from this date.
  • 2 September 2027Commission guidance on the post-market monitoring plan, including a template, due under Article 72(3) as amended.
  • 2 December 2027Articles 12, 19 and 26 apply to Annex III high-risk systems, credit scoring and life and health insurance pricing among them.
  • 2 August 2028Articles 12, 19 and 26 apply to Annex I high-risk systems.

Sources cited

Common gaps

Where lenders and insurers most often fall short on Article 12.

  • Retention left at the tool's default. A log store that expires records on its own schedule can drop them before six months, or hold personal data longer than the purpose supports. Article 26(6) sets the minimum and yields to other law, so the period is a decision to record for each system.AI Act · Art. 26(6)
  • No agreement on who holds which logs. Articles 19 and 26(6) each reach only the logs under that party's control. A contract that leaves this open lets each side assume the other keeps them.
  • Logs that cannot be tied to a case. A credit decision or a premium is reviewed one case at a time. Logs that cannot be retrieved by applicant, policy or time window do not support the monitoring Article 26(5) calls for.
  • Treating legacy systems as permanently out of scope. The grace period in Article 111(2) ends when a system's design changes significantly. A rebuilt scoring model or a new data source needs an assessment against that test, kept on file.
  • Waiting for the standard. Article 12 applies on 2 December 2027 whether or not a logging standard has been referenced by then. A provider without one documents the specifications it applied instead.AI Act · Art. 17(1)(e)

Last reviewed October 11, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.