What the Article requires
Article 12 requires high-risk AI systems to technically record events relevant to identifying situations where the system could present risks, to facilitating post-market monitoring, and to enabling subsequent monitoring of operation. The logs must be retained appropriately considering intended purpose. For some applications (e.g., biometric identification) specific log content is mandated. The record-keeping must be designed into the system, not bolted on as an afterthought.
In engineering terms
Implies an observability substrate — Langfuse self-hosted or equivalent — that captures every inference, every decision, every escalation. Most customers log enough but few log in a format that survives audit review. The critical engineering controls: content-addressed audit storage (immutable, replayable by hash), structured event schemas (not free-form JSON dumps), and SIEM integration so the audit trail is part of the existing operational fabric.
Compliance checklist
- ✓Auto-generated event logs from the AI system
- ✓Log retention period defined and implemented
- ✓Tamper-evident or content-addressed log storage
- ✓SIEM integration for the operational audit trail
- ✓Replay capability for any historical decision
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 12?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.