Blog
Article 12 EU AI Act: what records need to contain
02/08/2026
Article 12 of the EU AI Act requires high-risk AI systems to automatically record events during operation so that their behaviour remains traceable and verifiable. Technical logs can provide some of this information.
Technical logging is indeed part of the requirement. It just often falls short of what robust governance needs in practice. (Context: a practitioner’s perspective, not legal advice.)
Technical logging answers only part of the question
Classic logging answers the question “What happened technically?”: requests, errors, latencies. Article 12 aims at traceability of relevant events appropriate to the system’s purpose. For internal controls, audits and accountable decisions, an organisation usually needs more context on top: “What did the system know, what was it allowed to do, and why did it decide this way?”
That question can hardly be reconstructed from technical logs after the fact. Which knowledge base applied at the time of the answer? Which rule version was active? Who had which permission? Which exception was approved at that moment? Assembling these facts only when an audit starts creates extra work and may leave gaps.
Build record-keeping into the workflow
For integrated workflows, define which answers, policy checks and actions are recorded. Context includes sources used, applicable policy versions, permission decisions, people and models involved. Signing, export and retention need to be configured and tested for the installation.
The difference shows in three places:
- Coverage. Check which events are captured and where gaps remain. Include failure cases and access outside the controlled path in this assessment.
- Context fidelity. The entry captures what applied at the time, not what applies today. Rule changes do not overwrite history.
- Auditability. Signed, exportable evidence bundles make the recorded information available for review.
Agents raise the bar
With AI agents that act instead of merely answering, the question “What did the system answer?” becomes “What did the system do, and who approved it?”. At the latest here you need records per action, including the judgement before execution: allowed, escalated or blocked, and by whom.
NomOS links events recorded on integrated paths with their context. These records can support record-keeping and audit requirements, including, where relevant for the specific high-risk system, the duties under Art. 12; the legal classification remains the task of provider and deployer. The whitepaper explains how NomOS connects these records with sources, policies and decisions.
How the governance principle behind it works is covered concisely in our docs.