Home · EU AI Act · Articles · Article 12
EU AI Act · Engineering reference

Article 12 — Record-keeping

High-risk AI systems must automatically log events during operation, with log retention sufficient to satisfy traceability requirements.

Audit-survivable
36%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 12 requires high-risk AI systems to technically record events relevant to identifying situations where the system could present risks, to facilitating post-market monitoring, and to enabling subsequent monitoring of operation. The logs must be retained appropriately considering intended purpose. For some applications (e.g., biometric identification) specific log content is mandated. The record-keeping must be designed into the system, not bolted on as an afterthought.

In engineering terms

Implies an observability substrate — Langfuse self-hosted or equivalent — that captures every inference, every decision, every escalation. Most customers log enough but few log in a format that survives audit review. The critical engineering controls: content-addressed audit storage (immutable, replayable by hash), structured event schemas (not free-form JSON dumps), and SIEM integration so the audit trail is part of the existing operational fabric.

Compliance checklist

  • ✓Auto-generated event logs from the AI system
  • ✓Log retention period defined and implemented
  • ✓Tamper-evident or content-addressed log storage
  • ✓SIEM integration for the operational audit trail
  • ✓Replay capability for any historical decision

Terms used here

EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 12?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →