Blog

Article 12 EU AI Act: what records need to contain

02/08/2026

Article 12 of the EU AI Act requires high-risk AI systems to automatically record events during operation so that their behaviour remains traceable and verifiable. Technical logs can provide some of this information.

Technical logging is indeed part of the requirement. It just often falls short of what robust governance needs in practice. (Context: a practitioner’s perspective, not legal advice.)

Technical logging answers only part of the question

Classic logging answers the question “What happened technically?”: requests, errors, latencies. Article 12 aims at traceability of relevant events appropriate to the system’s purpose. For internal controls, audits and accountable decisions, an organisation usually needs more context on top: “What did the system know, what was it allowed to do, and why did it decide this way?”

That question can hardly be reconstructed from technical logs after the fact. Which knowledge base applied at the time of the answer? Which rule version was active? Who had which permission? Which exception was approved at that moment? Assembling these facts only when an audit starts creates extra work and may leave gaps.

Build record-keeping into the workflow

For integrated workflows, define which answers, policy checks and actions are recorded. Context includes sources used, applicable policy versions, permission decisions, people and models involved. Signing, export and retention need to be configured and tested for the installation.

Diagram: When only technical logs are captured, additional context must be added later. Recording context during the interaction makes it available for later review.
Simplified example: add context later or record it during the interaction. The information required depends on the specific system.

The difference shows in three places:

  1. Coverage. Check which events are captured and where gaps remain. Include failure cases and access outside the controlled path in this assessment.
  2. Context fidelity. The entry captures what applied at the time, not what applies today. Rule changes do not overwrite history.
  3. Auditability. Signed, exportable evidence bundles make the recorded information available for review.

Agents raise the bar

With AI agents that act instead of merely answering, the question “What did the system answer?” becomes “What did the system do, and who approved it?”. At the latest here you need records per action, including the judgement before execution: allowed, escalated or blocked, and by whom.

NomOS links events recorded on integrated paths with their context. These records can support record-keeping and audit requirements, including, where relevant for the specific high-risk system, the duties under Art. 12; the legal classification remains the task of provider and deployer. The whitepaper explains how NomOS connects these records with sources, policies and decisions.

How the governance principle behind it works is covered concisely in our docs.

Sources