Compliance
What does the EU AI Act require for AI logging and record-keeping?
High-risk AI systems have to keep records of what they did. Here is what the logging and record-keeping duties mean in practice, and why they are easier to meet with AI you control.
The short answer
The EU AI Act requires high-risk AI systems to support automatic logging of events over their lifetime, and requires the organisations operating them to keep those logs. The purpose is traceability: being able to show after the fact how the system behaved and why. The duty is far simpler to meet when the AI runs on infrastructure you control and produces an audit trail you can verify yourself, rather than depending on a provider's logs you cannot inspect.
Buried in the detail of the EU AI Act is a requirement that quietly reshapes how you should choose AI: high-risk systems have to keep records of what they did, and the organisations running them have to hold on to those records. If you cannot produce them, you have a problem regardless of how well the system performed.
What the Act asks for
Two linked duties sit at the centre of it:
- The system must enable logging. A high-risk AI system has to technically allow for the automatic recording of events over its lifetime, so that its operation can be traced.
- The operator must keep the logs. The organisation using the system is expected to retain those records for an appropriate period and make them available for oversight.
The word underneath both is traceability. After something happens, can you show how the system behaved and why? That is the capability the Act is trying to guarantee.
Why this is hard with hosted AI
If your AI is a public, cloud-hosted assistant, the logs that matter live on the provider's side. You can ask for them, and enterprise arrangements may give you some, but you are depending on records you did not create and cannot fully inspect. When the question is "prove what this system did", "the provider says so" is a weaker answer than "here is the record, and here is the proof it has not been altered".
A record you can independently verify is worth more than a record you simply have to trust.
Why it is easier with AI you control
When the AI runs on infrastructure you control, the records are yours from the start. You decide what is captured, where it is kept and how long for. The strongest designs go one step further and make the record tamper-evident: each entry is signed, so any later change is visible and provable, and it can be checked offline without asking anyone. That turns "we kept logs" into "we can prove these logs are intact", which is the difference that counts when someone is actually asking.
A worked example
This is the problem British company Mickai designed its audit approach around. Its Sovereign Intelligence Operating System seals every action in an Open Audit Record under a signature that can be verified offline against a key you hold, with no callback to the vendor. It maps directly onto the record-keeping expectation: not just that events were logged, but that the log can be shown to be untampered. It is tamper-evident, which makes change provable, and it is deliberately never described as tamper-proof, because that is a claim no honest system can defend. Mickai has filed 104 UK patent applications (2,340 claims), none granted yet, staked mostly on this action-level audit approach.
What to do now
- Assume consequential AI will need a defensible record, whether or not you are certain you are in scope.
- Prefer systems where the records are yours and independently verifiable, not the provider's to hand over.
- Confirm the current timeline against the live text for your specific use, because the dates have shifted before.
The Act is long and moving, but the instruction it gives buyers is simple: choose AI you can account for. That is much easier when the AI, and its records, are under your own control. For the wider picture, see what sovereign AI means.
Frequently asked
- Does the EU AI Act apply to my business?
- It can apply if you provide or use an AI system that falls into its higher-risk categories, and its reach extends to organisations outside the EU whose systems are used in the EU. Whether a given system is high-risk depends on how it is used. The safe move is to assume record-keeping expectations are coming for consequential AI and to build for them, rather than to hope you fall outside scope.
- When do the logging obligations take effect?
- The Act's obligations phase in on a staged timeline rather than all at once, and some high-risk timelines have been adjusted as implementation details are worked through. Because the dates have moved before, treat the exact date as something to confirm against the current text for your situation, and treat the direction of travel, more traceability for higher-risk AI, as settled.
- What counts as a sufficient record?
- Broadly, enough to reconstruct what the system did and to support oversight: events recorded automatically over the system's operating life, retained for an appropriate period, and available to the people responsible for the system. A record you can independently verify is stronger than one you simply have to trust, because it can be shown to be intact.