AI Act, Article 12 (record-keeping)
Regulation (EU) 2024/1689, Article 12
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 438 days, effective 2 December 2027.
An AI governance rule binding public and private bodies.
As of 20 September 2026.
What it requires
- Build automatic event logging into a high-risk AI system so it can record events over the system's lifetime, if you are its provider.
- Design the logging capability to support identifying an emerging risk or a substantial modification, post-market monitoring, and a deployer's monitoring of the system's operation.
- For a remote biometric identification system, log the start and end date and time of each use, the reference database checked, the input data that produced a match, and the identity of the person who verified the result.
If you get it wrong
Private right of actionNo
What it reaches
Obligation class
Governance
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
High-risk AI systems must be technically capable of automatically recording events, in logs, over the system's lifetime. The logging capability must enable recording of events relevant to identifying a risk under Article 79(1) or a substantial modification, to supporting the post-market monitoring required by Article 72, and to the deployer monitoring required by Article 26(5).
For a remote biometric identification system, one of the Annex III use cases classified as high-risk under Article 6(2), the logs must at minimum record the start and end date and time of each use, the reference database checked against the input data, the input data for which a search produced a match, and the identity of the natural persons who verified the results under Article 14(5); this minimum contents list does not extend to high-risk systems generally.
Article 12 does not itself set how long a log must be kept or who may demand access to one: retention is Article 19's duty for a provider and Article 26(6)'s for a deployer, and access is Article 21(2)'s. Article 12 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.
When LexLint raises it
high_risk_decisionsprocesses_biometrics
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.