Source: OJ L, 2024/1689, 12.7.2024

Current language: EN

Article 12 Record-keeping


Summary What does Article 12 of the AI act regulation say?

This article sets out the logging and automatic event-recording requirements for high-risk AI systems.

The core obligation is that such systems must be technically capable of automatically recording events throughout their lifetime, with those logs serving the purposes of traceability, post-market monitoring, and operational oversight.

The article connects directly to several other provisions in the regulation, notably Article 72 on post-market monitoring, Article 79 on risk identification, and Article 26(5) on deployer monitoring obligations.

A more specific set of minimum logging requirements is imposed on a particular subset of high-risk AI systems — those falling under point 1(a) of Annex III, which relates to biometric identification systems — requiring granular records such as session times, reference databases used, matched input data, and the identity of persons involved in verifying results.

Important points:

  • Ensure high-risk AI systems are technically built to automatically record events across their entire lifetime.
  • Logging capabilities must cover three purposes: identifying potential risks or substantial modifications, supporting post-market monitoring, and enabling operational oversight by deployers.
  • For high-risk AI systems used for biometric identification (Annex III, point 1(a)), a specific minimum set of log data is required, including session timestamps, reference databases, matched inputs, and the identities of result-verifying personnel.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.

    1. In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for:

      1. identifying situations that may result in the high-risk AI system presenting a risk within the meaning of Article 79(1) or in a substantial modification;

      2. facilitating the post-market monitoring referred to in Article 72; and

      3. monitoring the operation of high-risk AI systems referred to in Article 26(5).

    1. For high-risk AI systems referred to in point 1 (a), of Annex III, the logging capabilities shall provide, at a minimum:

      1. recording of the period of each use of the system (start date and time and end date and time of each use);

      2. the reference database against which input data has been checked by the system;

      3. the input data for which the search has led to a match;

      4. the identification of the natural persons involved in the verification of the results, as referred to in Article 14(5).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod