Governance · Logging · Defence · Health
Auditability & governance
Logging · As of 09/2026

AI governance:traceablefrom day one

We build AI systems so that you can later prove what they did, who approved it and on what basis.

Discuss AI governance
Enquiry
Nikolai Schöbel und Jeremias Burger, Co-Founder Scalableloops

Let's talk about your project.

First we check whether the project fits your business model. Then you get a proposal with phases and effort.

Discuss AI governance or call: +49 151 1576 5566
AI governance

AI governance covers the rules, roles and technical safeguards a company uses to steer how it applies AI, and to prove that it does so responsibly. It includes logs that record what an AI system did, clear approvals by people, and staff with documented AI training. Scalableloops builds this auditability directly into the AI systems we develop instead of bolting it on afterwards. This matters most where traceability is not optional: in defence, healthcare and public administration.

In brief
  • AI governance makes the use of AI in a company visible and provable.
  • Since 2 February 2025, Art. 4 of the EU AI Act requires providers and deployers to take measures on their staff's AI literacy.
  • For high-risk systems, the AI Act requires automatic logs, to be kept for at least six months.
  • We plan logging and human approval into every system from the start.
As of 26 Sep 2026Scalableloops GmbH, Eggenfelden7 min read
Nikolai SchöbelJeremias Burger

Nikolai Schöbel and Jeremias Burger

Co-founders of Scalableloops GmbH. Nikolai Schöbel leads online marketing and AI strategy, Jeremias Burger the AI architecture. Both build AI systems and train teams on them in their own agency work.

On this page
  1. What does AI governance mean for a company?
  2. Which EU AI Act obligations concern logs and evidence?
  3. How do we build auditability into AI systems?
  4. Why is training part of governance?
  5. Frequently asked questions
  6. How we make your AI traceable
  7. Where the information on this page comes from
Definition

What does AI governance mean for a company?

Governance for artificial intelligence connects policies, accountability and processes with technology. It answers three questions: Where do we use AI? Who is responsible for what? And how can we show afterwards what happened? The first two are organisational, the third is technical. It can only be answered if the AI system itself records which inputs it received, which outputs it produced and who approved them.

For us, auditability is therefore not a documentation task at the end of a project but a property of the architecture. A system that does not log cannot be audited later, however well the policy is written. That is why controlling AI belongs in the same architecture as data protection and information security, not in a separate compliance document.

Law

Which EU AI Act obligations concern logs and evidence?

The EU AI Act, Regulation (EU) 2024/1689, applies in stages and sets requirements according to risk. Some obligations apply to every company that uses AI, others only to high-risk systems. The overview lists the provisions that matter most for logging and evidence.

ProvisionContentApplies to
Art. 4 AI literacyproviders and deployers take measures to support their staff's AI literacy, since 2 February 2025 (as amended by the AI Omnibus)everyone using AI
Art. 50 transparencypeople are informed they are interacting with an AI; AI-generated content is markedchatbots, voice agents, generated content
Art. 12 record-keepinghigh-risk systems must technically allow automatic logging of events over their lifetimeproviders of high-risk systems
Art. 19 and Art. 26(6)keep automatically generated logs for at least six months unless other law appliesproviders and deployers of high-risk systems

Whether your system counts as high-risk and from when each obligation applies depends on its intended purpose and is assessed case by case. For the general obligations, see AI literacy under Article 4 and AI disclosure under Article 50.

Implementation

How do we build auditability into AI systems?

Every system we develop records what it processed and what it output, in a form that can be analysed later. Results with external effect only go out after human approval, and the approval itself is part of the log.

At Defence:Connect we deliver AI pipelines for audit, logging and governance requirements, because companies in the defence sector must bring traceability as a precondition. At JourF’x, conversations become audit-proof documentation. And our own AI agent system follows the same principle: it prepares, your team approves.

People

Why is training part of governance?

Rules only work if the people working with AI know them. Art. 4 of the EU AI Act obliges companies to take measures for this. In our AI training for companies, your team learns the AI systems in its own daily work and receives a record for each person.

Frequently asked questions

Frequently asked questions

What is the difference between AI governance and AI compliance?

AI compliance means meeting specific requirements, for example from the EU AI Act and the GDPR. AI governance is the framework around it: roles, rules, approvals and logs with which a company steers and evidences its use of AI.

Does every AI system have to keep logs?

Automatic logging under Art. 12 of the EU AI Act is mandatory for high-risk systems. We recommend it beyond that, because it is the only way to find errors and prove results to customers or auditors.

How long must AI logs be kept?

For high-risk systems, Art. 19 and Art. 26(6) of the EU AI Act require at least six months, unless other law, in particular data protection law, provides otherwise.

Does the AI literacy obligation apply to small companies?

Art. 4 of the EU AI Act addresses providers and deployers of AI systems regardless of size. Which measures fit depends on how your team uses AI.

Can you make existing AI systems auditable afterwards?

Often yes, with limitations. We look at what the system records today and add logs and approvals where technically possible.

Process

How we make your AI traceable

  1. 01

    Inventory

    Which AI systems do you use, for what, and who is responsible?

  2. 02

    Assessment

    Together we check which obligations apply to your use.

  3. 03

    Implementation

    Logs, approvals and labelling are built into the system, not just written on paper.

  4. 04

    Training

    Your team learns the rules in its own daily work and receives a record.

Could you prove today what your AI did last month and who approved it? If not, that is the first step.

or call: +49 151 1576 5566

Sources

Where the information on this page comes from

Projekt-Detail

    Got a project in mind?

    We reply personally. First a use-case check, then an architecture proposal.

    Start your inquiry