What the AI Actlogging requirementsmean for you
The AI Act only mandates automatic logs for high-risk systems, and the start date has moved. Here is who is affected, and why a clean log is useful for almost any business anyway.
Get in touch- What do the AI Act logging requirements ask of you?
- AI Act record-keeping: are you the provider or the deployer?
- High-risk AI obligations: how to tell whether your system is in scope
- When the Digital Omnibus deadlines make logging apply to you
- Log retention period: how long you must keep logs, and how long you may
- GDPR accountability: why logs help even without high-risk AI
- AI system logging: what a useful log should record
- Frequently asked questions
- How to prepare for the AI Act logging requirements
- Where the information on this page comes from

Let's talk about your project.
First we check whether the project fits your business model. Then you get a proposal with phases and effort.
Talk about AI governance or call: +49 151 1576 5566The AI Act logging requirements in Regulation (EU) 2024/1689 apply to high-risk AI systems only. Article 12 requires such systems to be technically capable of recording events automatically over their lifetime, and Articles 19 and 26(6) oblige providers and deployers to keep those logs for at least six months, to the extent the logs are under their control. None of this applies yet: since the Digital Omnibus on AI, Regulation (EU) 2026/1744, the rules take effect on 2 December 2027 for high-risk systems listed in Annex III and on 2 August 2028 for those under Annex I. If you use AI outside the high-risk categories, the AI Act imposes no logging duty on you, but EU data protection law still expects you to be able to demonstrate that you process personal data lawfully.
- Automatic logging is mandatory only for high-risk AI systems, for example tools that screen job applicants or assess the creditworthiness of individuals.
- Logs must be kept for at least six months by the provider and the deployer, each to the extent the logs are under their control.
- Since the Digital Omnibus, the high-risk rules apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems.
- Outside the high-risk categories the AI Act sets no logging duty. Accountability under data protection law still applies, and a short log makes it far easier to meet.
On this page
- What do the AI Act logging requirements ask of you?
- AI Act record-keeping: are you the provider or the deployer?
- High-risk AI obligations: how to tell whether your system is in scope
- When the Digital Omnibus deadlines make logging apply to you
- Log retention period: how long you must keep logs, and how long you may
- GDPR accountability: why logs help even without high-risk AI
- AI system logging: what a useful log should record
- Frequently asked questions
- How to prepare for the AI Act logging requirements
- Where the information on this page comes from
What do the AI Act logging requirements ask of you?
The AI Act logging requirements start with Article 12, which carries the heading “Record-keeping”. Its first paragraph is short: high-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. So the first requirement is a property of the system itself, built in by whoever develops it.
Paragraph 2 explains what the logs are for. They should help identify situations in which the system may present a risk or undergo a substantial modification, they support post-market monitoring under Article 72, and they let the deployer monitor operation as Article 26(5) requires. A fixed minimum list of what a log has to contain exists only for remote biometric identification systems under point 1(a) of Annex III.
Who keeps the logs afterwards is set out in two other articles. The table below shows how the relevant provisions fit together.
| Provision | What it says | Who it applies to |
|---|---|---|
| Art. 12(1) | The system must be able to record events automatically over its lifetime | Provider (when building the system) |
| Art. 13(3)(f) | Instructions for use describe how deployers can collect, store and interpret the logs | Provider |
| Art. 19(1) | Keep automatically generated logs for at least six months, to the extent they are under your control | Provider |
| Art. 26(5) | Monitor operation on the basis of the instructions for use | Deployer |
| Art. 26(6) | Keep automatically generated logs for at least six months, to the extent they are under your control | Deployer |
The minimum period for keeping automatically generated logs, unless other law provides otherwise.
AI Act record-keeping: are you the provider or the deployer?
AI Act record-keeping duties are split between two roles, and most mid-sized businesses are deployers. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses such a system under its own authority in a professional context.
The provider has to make sure the system can log at all and explains in the instructions for use how that works. The deployer uses the system according to those instructions, monitors it and keeps the logs that end up on its side. If the logs sit only with the provider, say because the system runs as a service in the provider's data centre, the wording “to the extent such logs are under their control” comes into play. In practice that means settling in the contract who holds the logs and how you get access to them when you need them.
- 01
Provider
buildsMakes sure the system can log, describes this in the instructions for use and keeps the logs it controls.
- 02
Deployer
usesRuns the system as instructed, monitors it and keeps the logs that sit on its side.
High-risk AI obligations: how to tell whether your system is in scope
The high-risk AI obligations in Chapter III, logging included, only apply to systems the regulation classifies as high-risk. There are two routes into that category. Annex I covers AI used as a safety component of a product that already falls under EU product legislation. Annex III lists areas in which AI helps decide things about people.
For businesses outside the public sector and the justice system, two areas of Annex III matter most. Employment and workers management covers systems that place targeted job ads, analyse and filter applications, evaluate candidates, or monitor and evaluate the performance and behaviour of staff. Access to essential services covers, among other things, creditworthiness assessments of natural persons and risk assessment and pricing for life and health insurance.
And even there an exception applies. Under Article 6(3), a system listed in Annex III is not considered high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, for instance because it does not materially influence the outcome of a decision. A chatbot that answers product questions appears in none of these lists; it is, however, covered by the disclosure duty in Article 50, which has applied since 2 August 2026 and which we explain in our post on AI chatbot disclosure under Article 50.
When the Digital Omnibus deadlines make logging apply to you
The Digital Omnibus deadlines are the reason the logging duty does not bite anyone directly today. Originally, the high-risk rules for Annex III systems were due to apply from 2 August 2026. Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026, entered into force on 27 July 2026 and amended Article 113. Among its reasons it cites the late availability of standards and guidance and national authorities that had not yet been set up.
Since then, Sections 1 to 3 of Chapter III, and with them Articles 12, 19 and 26, apply from 2 December 2027 to high-risk systems under Annex III and from 2 August 2028 to systems under Annex I. Germany's Federal Network Agency (Bundesnetzagentur) lists the same dates in its AI Act timeline.
The rewritten Article 111(2) matters for systems you already use. High-risk systems placed on the market or put into service before those dates are only caught if their design is significantly changed afterwards; for systems intended for use by public authorities, the deadline is 2 August 2030. How “significant” will be read in practice is honestly not clear yet, as guidance is still pending. If you plan to replace HR or credit scoring software anyway, it makes sense to ask about logging as part of the purchase.
From this date logging and log retention apply to high-risk systems under Annex III.
Log retention period: how long you must keep logs, and how long you may
The log retention period under Article 19(1) and Article 26(6) is at least six months, and more precisely “a period appropriate to the intended purpose of the high-risk AI system”. Six months is the floor, not automatically the right answer.
Both articles add a proviso: the period applies unless otherwise provided in Union law, in particular data protection law, or in national law. That is more than a formality, because the logs of a recruiting tool will almost always contain personal data. Those data fall under the storage limitation principle in Article 5(1)(e) of the General Data Protection Regulation, which allows identifiable data to be kept no longer than necessary for the purpose. A sensible approach is a written, reasoned deletion period per system that does not go below six months and does not run far beyond it without a reason.
Financial institutions have their own rule: where EU financial services law sets requirements for their internal governance, they keep the logs as part of the documentation required there. Do not confuse the logs with the provider's technical documentation, which Article 18 requires to be kept available for ten years after the system is placed on the market.
GDPR accountability: why logs help even without high-risk AI
GDPR accountability under Article 5(2) applies whether or not your AI system is high-risk. The controller has to be able to demonstrate compliance with the principles in paragraph 1, such as lawfulness, purpose limitation and data minimisation.
That provision does not create an explicit duty to log AI outputs. But when a customer asks why an assistant gave a particular answer, or an error turns up internally, a short log is often the only way to reconstruct what happened. In our experience (we build AI systems for our own agency work and for clients) it is a lot easier to plan this traceability in from the start than to retrofit it later. How we approach that in projects is described on our page on AI governance.
One more piece belongs here: anyone using AI has to support the AI literacy of their staff under Article 4 of the AI Act. What that means in practice is covered in our post on the AI literacy obligation under Article 4.
AI system logging: what a useful log should record
For AI system logging outside the high-risk category there is no statutory list of fields. Article 12(3) still offers a good reference point, because for remote biometric identification it requires at least four items: the start and end of each use, the reference database, the input data that led to a match, and the people who verified the results.
Translated to an ordinary business, that gives a rule of thumb which is not a legal requirement but works well: record when the system ran, with which version and settings, what went in, what came out and who approved or rejected the result. For AI agents that take actions on their own, add which tools they called; there is more on that in our post on agentic AI.
Keep personal content in the log as lean as you can. Often a reference to the case is enough instead of the full text, and that makes deletion at the end of the retention period much simpler.
| Item in the log | What it is for |
|---|---|
| Time and duration of use | Placing events in time |
| Model, version and settings | Explaining changed behaviour after an update |
| Input, or a reference to it | Seeing what an output was based on |
| Output and actions triggered | Evidencing the result and its consequences |
| Human approval | Showing who made the decision |
Frequently asked questions
Do the AI Act logging requirements already apply?
No. Articles 12, 19 and 26 sit in Chapter III and, after the Digital Omnibus amendment, apply from 2 December 2027 to high-risk systems under Annex III and from 2 August 2028 to those under Annex I.
Do I have to keep the logs of my website chatbot?
Not under the AI Act, as long as the chatbot is not a high-risk system. The disclosure duty in Article 50 does apply to it. If the chatbot stores personal data, EU data protection law applies to those data, including storage limitation and accountability.
Who keeps automatically generated logs, the provider or the deployer?
Both, each to the extent the logs are under their control. The provider is bound by Article 19, the deployer by Article 26(6). If the system runs on the provider's side, agree in the contract how you get access to the logs.
What do deployer obligations under Article 26 involve?
Among other things: using the system in line with the instructions for use, assigning human oversight to competent people, monitoring operation and keeping automatically generated logs for at least six months. Employers must also inform workers' representatives and affected staff before putting such a system into use at the workplace.
Does Article 12 AI Act prescribe specific log fields?
Only for remote biometric identification systems under point 1(a) of Annex III. For every other high-risk system, Article 12(2) defines the purposes the logs must serve, not a field list.
What are the fines for breaching deployer obligations?
Article 99(4) provides for fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher, for breaches of the deployer obligations in Article 26. Under Article 99(6), SMEs face the lower of the two amounts.
How to prepare for the AI Act logging requirements
- 01
List your AI use
Note where AI runs in your business and flag everything related to applications, performance reviews, creditworthiness or insurance pricing.
- 02
Clarify role and log location
Record for each system whether you are provider or deployer and where the logs are actually stored. Ask your vendor for the relevant section of the instructions for use.
- 03
Justify a deletion period
Set a retention period for each system that reflects its purpose and data protection law, and write down why.
- 04
Make approvals visible
Make sure the log shows who approved an AI result. If you are unsure how your system is classified, get legal advice.
A log nobody reads protects very little. If you want to know whether one of your systems might fall under Annex III and where its logs end up today, we are happy to look at it with you; the legal classification of an individual case remains a matter for your legal adviser.
AI agentsAgentic AI Explained: What It Means for Your Business
Google indexingRequest Indexing on Google: What the Button Really Does
SEO visibility indexSEO Visibility Index: What It Measures and What It Misses
RAGWhat Is RAG in AI? Retrieval Augmented Generation Explained
Gemini 4 ArgonGemini 4 Argon: What the Model Is Actually Built For
Computer useComputer Use Agent: What It Operates and What It May Do
AI voice agentAI Voice Agent Pricing: Cost per Call and Disclosure
Google spam updateGoogle Spam Update: What Can Your Numbers Really Tell You?
LLM costsLLM Cost Optimization: When a Model Switch Pays Off
Detect AI-written textDetect AI-written text: what AI detectors get wrong
Google AI ModeGoogle AI Mode: What It Means for Your Website
AI agentsWhat Is an AI Agent, and How Is It Different From a Chatbot?
Structured DataStructured Data: What It Really Does for AI Search
AI AssistantAI Assistant for Business: Types, Uses and Data Protection
GEOE-E-A-T: Trust Signals for Google and AI Search
Local AILocal AI for Business: What “Local” Really Means
GEOAI Crawlers in robots.txt: Managing GPTBot and Co.
AI for SMEsAI for SMEs: How to Introduce AI Step by Step
Perplexity SEOPerplexity SEO: How to Get Your Site Cited as a Source
ChatGPT SEOChatGPT SEO: How to Get Your Business Found in ChatGPT
llms.txtllms.txt: What the File Does and When It Pays Off
AI SEOAI SEO: What Changes Compared to Traditional SEO
AI OverviewsGoogle AI Overviews: How Google Picks Its Sources
GEO vs AEO vs LLMOGEO vs AEO vs LLMO: The AI Search Terms Explained
Measure AI VisibilityMeasure AI Visibility: Method, Metrics and Limits
ChatGPT AdsChatGPT Ads: How to Advertise on ChatGPT in Germany
AI Literacy ObligationAI Literacy Obligation: What Article 4 Requires Since 2026
AI DisclosureAI Chatbot Disclosure: Article 50 in Practice
AI Text WatermarkAI Text Watermark: What Claude Marks and What It Doesn't
Where the information on this page comes from
- Regulation (EU) 2024/1689 (AI Act), Art. 6, 12, 13, 18, 19, 26, 99, Annex IIIretrieved 9 Oct 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)retrieved 9 Oct 2026
- Bundesnetzagentur: AI Act objectives, target groups and timeline (German)retrieved 9 Oct 2026
- ai-act-law.eu: Art. 12 AI Act, Record-keepingretrieved 9 Oct 2026
- ai-act-law.eu: Art. 19 AI Act, Automatically generated logsretrieved 9 Oct 2026
- ai-act-law.eu: Art. 26 AI Act, Obligations of deployersretrieved 9 Oct 2026
- Regulation (EU) 2016/679 (GDPR), Art. 5retrieved 9 Oct 2026
- gdpr-info.eu: Art. 5 GDPRretrieved 9 Oct 2026


