Law / European Union

AI Act, Article 12 (record-keeping)

Regulation (EU) 2024/1689, Article 12

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 438 days, effective 2 December 2027.

An AI governance rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • Build automatic event logging into a high-risk AI system so it can record events over the system's lifetime, if you are its provider.
  • Design the logging capability to support identifying an emerging risk or a substantial modification, post-market monitoring, and a deployer's monitoring of the system's operation.
  • For a remote biometric identification system, log the start and end date and time of each use, the reference database checked, the input data that produced a match, and the identity of the person who verified the result.

If you get it wrong

Private right of actionNo

What it reaches

Obligation class

Governance

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

High-risk AI systems must be technically capable of automatically recording events, in logs, over the system's lifetime. The logging capability must enable recording of events relevant to identifying a risk under Article 79(1) or a substantial modification, to supporting the post-market monitoring required by Article 72, and to the deployer monitoring required by Article 26(5).

For a remote biometric identification system, one of the Annex III use cases classified as high-risk under Article 6(2), the logs must at minimum record the start and end date and time of each use, the reference database checked against the input data, the input data for which a search produced a match, and the identity of the natural persons who verified the results under Article 14(5); this minimum contents list does not extend to high-risk systems generally.

Article 12 does not itself set how long a log must be kept or who may demand access to one: retention is Article 19's duty for a provider and Article 26(6)'s for a deployer, and access is Article 21(2)'s. Article 12 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

When LexLint raises it

  • high_risk_decisions
  • processes_biometrics

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app