Logging
Logging is the automatic recording of events during the operation of a high-risk AI system, enabling traceability and regulatory oversight. Providers must design the system to have logging capabilities, while deployers are subject to a duty to retain the resulting logs for at least six months.
The provider's design obligation is set out in Article 12, and the deployer's retention obligation in Article 26(6) — on both sides, the minimum retention period is at least six months, unless sectoral law provides otherwise. Logging serves a dual purpose: it ensures that the system's operation can be reconstructed after the fact when investigating an incident or complaint, and it provides the basis for exercising human oversight, since the person performing oversight can only meaningfully override the system if they have visibility into its past operation. Unlike technical documentation — which must be retained for ten years — the retention period for logs is shorter, but this six-month window is often exactly the timeframe in which an employee or customer complaint arises, so failing to meet even this shorter deadline carries real risk.
A deploying SME has a concrete, checkable task: logs must be kept for at least six months — this is often missing from a purchased AI tool's default settings, and needs to be verified.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Technical documentationTechnical documentation is the record demonstrating a high-risk AI system's compliance, covering the nine points of Annex IV, which must be drawn up before placing on the market, kept up to date, and retained for ten years. It is the record from which a regulator can later reconstruct how the system and its classification decision came about.
- Human oversightUnder Article 14, human oversight does not require a human to be in the loop, but requires that a high-risk AI system be designed to enable genuine oversight. The person exercising oversight must understand the system's limitations, be aware of automation bias, and have a real right to override, disregard the output of, or halt the system.
- DeployerA deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
Related questions in the knowledge base (Hungarian)
- Mit kell tartalmaznia a magas kockázatú AI műszaki dokumentációjának és naplózásának?A műszaki dokumentációt a piacra hozatal előtt kell elkészíteni és naprakészen tartani, és a IV. melléklet kilenc pontját kell lefednie. A dokumentációt tíz évig, a szolgáltató kezelésében lévő automatikus naplókat legalább hat hónapig kell megőrizni; az alkalmazói oldalon ugyanez a hat hónap él a 26. cikk (6) alapján.
- Milyen kötelezettségei vannak az alkalmazónak magas kockázatú AI-rendszernél?A 26. cikk tizenkét bekezdést tartalmaz, de nem mind kötelezettség és nem mind mindenkire szól. Egy vásárló magáncégre a mag: a használati útmutató szerinti használat, kompetens emberi felügyelet, a bemeneti adatok relevanciája, a működés monitorozása, a naplók legalább hat hónapos megőrzése, és a hatósággal való együttműködés.