Logging & Monitoring
AI Logging and Traceability
What this control does
Provide and maintain logging capabilities needed for traceability, risk identification, monitoring and investigation.
How to implement
For a high-risk AI provider, define which events the system should record so operation, material changes and investigations can be traced. For a deployer, identify the logs actually under its control. Assign log owners, protect access and integrity, and test that timestamps, system versions and relevant events are retrievable. Apply the retention rule for the specific actor and record; do not use one blanket period for all logs. Where the biometric logging provisions apply, include their specific information requirements. Coordinate logging capability with the separate monitoring, incident and records-retention controls.
Suggested timing and triggers
At design and deployment; continuous logging as applicable; after relevant system changes; periodic retrieval and retention checks.
Evidence examples
Logging specification and enabled configuration Sample event records identifying the system and relevant use Access controls and retrieval test results Actor-specific retention and deletion settings Investigation records demonstrating use of logs
How to check this control
Generate a safe test event or select an existing event and trace it through capture, storage and retrieval. Check the relevant system version, timestamps, permissions and retention settings. Investigate gaps rather than relying on a screenshot showing that logging is enabled.
Related EU AI Act obligations
Article 12
Enable Automatic Event Logging for High-Risk AI Systems
Article 12(1)-(2)
Ensure Logs Support Risk Detection, Post-Market Monitoring and Deployer Monitoring
Sub-obligation of Article 12: Enable Automatic Event Logging for High-Risk AI Systems
Article 12(3)
Provide Required Logging Capabilities for Annex III Remote Biometric Identification
Sub-obligation of Article 12: Enable Automatic Event Logging for High-Risk AI Systems
Article 19
Retain Automatically Generated High-Risk AI Logs
Article 26(6)
Retain High-Risk AI Logs Under the Deployer's Control