EU AI Act
Record-keeping obligations for high-risk AI
The Act requires provable records across the AI lifecycle: technical documentation, automatic event logs, data provenance, and marked AI outputs, retained long enough for authorities to verify them.
- Annex III standalone2 Dec 2027Deferred from 2 Aug 2026
- Annex I embedded2 Aug 2028AI inside regulated products
- Article 18 retention10 yearsFrom placement on the market
- Article 19 logs6 monthsMinimum retention
- Article 99 penalty€15M / 3%Worldwide turnover, whichever higher
Deferrals from the 2026 Digital Omnibus on AI provisional agreement, subject to formal adoption.
What the EU AI Act requires, in one block
The EU AI Act requires providers and deployers of high-risk AI systems to keep technical documentation (Article 11 with Annex IV), automatic event logs over the system's lifetime (Article 12), retained logs for at least 6 months (Article 19), and conformity records available to national authorities for 10 years after the system is placed on the market (Article 18). It also requires documented data governance (Article 10) and machine-readable marking of AI-generated content (Article 50). Non-compliance fines reach €15 million or 3% of worldwide annual turnover (Article 99).
The articles that define the record-keeping problem
Articles 11, 12, 18, and 19 are the core record-keeping obligations on providers and deployers of high-risk AI systems. Article 10 adds data governance, Article 50 adds content transparency, and Articles 26 and 99 cover deployer duties and penalties.
Technical documentation
Drawn up before the system is placed on the market and kept up to date over its lifetime.
A 9-section Annex IV technical file: system description, development process, monitoring and control, performance metric justification, risk management, lifecycle changes, applied standards, the EU Declaration of Conformity, and the post-market monitoring plan.
Event logging
High-risk AI systems must technically allow automatic recording of events throughout their lifetime.
Machine-generated logs with sufficient detail to identify risk situations and support post-market monitoring.
Record retention
Provider must keep technical documentation, QMS records, and the Declaration of Conformity available to national authorities for 10 years.
A 10-year, tamper-evident, regulator-presentable record set.
Log retention
Provider and deployer must retain automatically generated logs for at least 6 months, unless other Union or national law sets a different period.
A 6-month minimum log archive, typically longer in regulated sectors.
Data governance
Training, validation, and testing data must meet quality and governance criteria, with documented sources and provenance.
Data-provenance and lineage records proving where datasets came from and that they have not changed since.
Content transparency
Providers must mark AI-generated or manipulated content (deepfakes, synthetic media) in a machine-readable form.
Machine-readable provenance marking that travels with the content and remains verifiable over time.
Deployer duties
Deployers must use high-risk systems according to instructions, keep logs under their control, and inform providers of serious incidents.
Logs the deployer can demonstrate are under their effective control.
Penalties
Up to €35M / 7% worldwide turnover for prohibited practices. €15M / 3% for high-risk non-compliance. €7.5M / 1% for incorrect information to authorities.
This is the downside, not an evidence requirement.