ar.io

EU AI Act

Record-keeping obligations for high-risk AI

The Act requires provable records across the AI lifecycle: technical documentation, automatic event logs, data provenance, and marked AI outputs, retained long enough for authorities to verify them.

Key dates & thresholdsEU AI Act
  • Annex III standalone
    2 Dec 2027
    Deferred from 2 Aug 2026
  • Annex I embedded
    2 Aug 2028
    AI inside regulated products
  • Article 18 retention
    10 years
    From placement on the market
  • Article 19 logs
    6 months
    Minimum retention
  • Article 99 penalty
    €15M / 3%
    Worldwide turnover, whichever higher

Deferrals from the 2026 Digital Omnibus on AI provisional agreement, subject to formal adoption.

01 — At a glance

What the EU AI Act requires, in one block

The EU AI Act requires providers and deployers of high-risk AI systems to keep technical documentation (Article 11 with Annex IV), automatic event logs over the system's lifetime (Article 12), retained logs for at least 6 months (Article 19), and conformity records available to national authorities for 10 years after the system is placed on the market (Article 18). It also requires documented data governance (Article 10) and machine-readable marking of AI-generated content (Article 50). Non-compliance fines reach €15 million or 3% of worldwide annual turnover (Article 99).

02 — What's required

The articles that define the record-keeping problem

Articles 11, 12, 18, and 19 are the core record-keeping obligations on providers and deployers of high-risk AI systems. Article 10 adds data governance, Article 50 adds content transparency, and Articles 26 and 99 cover deployer duties and penalties.

Article11

Technical documentation

Drawn up before the system is placed on the market and kept up to date over its lifetime.

What the evidence looks like

A 9-section Annex IV technical file: system description, development process, monitoring and control, performance metric justification, risk management, lifecycle changes, applied standards, the EU Declaration of Conformity, and the post-market monitoring plan.

Article12

Event logging

High-risk AI systems must technically allow automatic recording of events throughout their lifetime.

What the evidence looks like

Machine-generated logs with sufficient detail to identify risk situations and support post-market monitoring.

Article18

Record retention

Provider must keep technical documentation, QMS records, and the Declaration of Conformity available to national authorities for 10 years.

What the evidence looks like

A 10-year, tamper-evident, regulator-presentable record set.

Article19

Log retention

Provider and deployer must retain automatically generated logs for at least 6 months, unless other Union or national law sets a different period.

What the evidence looks like

A 6-month minimum log archive, typically longer in regulated sectors.

Article10

Data governance

Training, validation, and testing data must meet quality and governance criteria, with documented sources and provenance.

What the evidence looks like

Data-provenance and lineage records proving where datasets came from and that they have not changed since.

Article50

Content transparency

Providers must mark AI-generated or manipulated content (deepfakes, synthetic media) in a machine-readable form.

What the evidence looks like

Machine-readable provenance marking that travels with the content and remains verifiable over time.

Article26

Deployer duties

Deployers must use high-risk systems according to instructions, keep logs under their control, and inform providers of serious incidents.

What the evidence looks like

Logs the deployer can demonstrate are under their effective control.

Article99

Penalties

Up to €35M / 7% worldwide turnover for prohibited practices. €15M / 3% for high-risk non-compliance. €7.5M / 1% for incorrect information to authorities.

What the evidence looks like

This is the downside, not an evidence requirement.

03 — FAQ

Frequently asked questions

01What is the EU AI Act and when does it take effect?
The EU AI Act (Regulation 2024/1689) is the European Union's comprehensive regulation on artificial intelligence, in force since 1 August 2024 with staggered application dates. Prohibited-practice rules applied from 2 February 2025; general-purpose AI obligations from 2 August 2025. High-risk AI obligations under Annex III were originally set to apply from 2 August 2026; under the 2026-05-07 Digital Omnibus on AI provisional agreement, application for new and substantially-modified Annex III standalone systems is deferred to 2 December 2027, and Annex I embedded systems to 2 August 2028. Both are subject to formal adoption.
02What are the requirements for high-risk AI systems under the EU AI Act?
High-risk AI providers must establish a risk-management system (Article 9), apply data-governance practices (Article 10), prepare Annex IV technical documentation (Article 11), build in automatic event logging (Article 12), ensure transparency and human oversight (Articles 13 and 14), meet accuracy, robustness, and cybersecurity thresholds (Article 15), implement a quality management system (Article 17), keep records for 10 years after placement on the market (Article 18), preserve logs for at least 6 months (Article 19), undergo a conformity assessment, affix CE marking, register the system in the EU database, and operate a post-market monitoring system. Deployers have parallel obligations under Article 26.
03What does the EU AI Act require for training data?
Article 10 requires that training, validation, and testing data for high-risk AI meet data-governance and quality criteria, including relevance, representativeness, and examination for bias, with documented data sources. Tamper-evident provenance and lineage records let a provider show which dataset trained a model and that it has not changed since.
04Does the EU AI Act require labeling AI-generated content?
Yes. Article 50 requires providers of AI that generates synthetic audio, image, video, or text to mark outputs as artificially generated or manipulated in a machine-readable format, and deployers of deepfakes to disclose them. The Act does not mandate a specific method.
05Will AI audit trails become a legal requirement?
For high-risk AI systems under the EU AI Act, they already are. Article 12 mandates the technical capability to log automatically; Article 19 mandates retention for at least 6 months. The Act does not prescribe a specific log substrate. The practical choice is between mutable observability logs and tamper-evident records that a regulator can verify independently.
06What penalties apply for non-compliance with the EU AI Act?
Article 99 sets three tiers: up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices under Article 5; up to €15 million or 3% for high-risk non-compliance and failure to meet obligations on conformity assessment, technical documentation, logging, transparency, or registration; up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities. SMEs and start-ups are subject to the same percentage thresholds but pay the lower of the percentage and the absolute amount.
07Does the Digital Omnibus on AI provisional agreement change the substantive obligations?
No. The provisional agreement reached on 7 May 2026 between the Council and the European Parliament defers the application dates and adds targeted simplifications. Annex III standalone high-risk obligations are deferred to 2 December 2027 for new and substantially-modified systems; Annex I embedded obligations to 2 August 2028. None of the substantive requirements on documentation, logging, or retention were watered down. Formal adoption is still pending.