EU AI Act record-keeping, in plain words.
Three articles of the EU AI Act concern logs. Here they are without the legal prose, with the dates as they stand, and an honest account of what Sigilbase does and does not do about each.
Checked October 2026. This page describes the rules in plain words and is not legal advice. Dates have moved before and may move again.
Article 12, record-keeping
High-risk AI systems must technically allow events to be recorded automatically over the system's lifetime. The logs are meant to make the system traceable: to identify situations that may present a risk, to support post-market monitoring, and to let deployers monitor operation.
What Sigilbase does: receives the events your system records and keeps them in a form that cannot be altered without detection. What it does not do: decide which events to record. That is a design decision for the provider and the deployer.
Articles 19 and 26, keeping the logs
Providers (Article 19) and deployers (Article 26) must keep the automatically generated logs under their control for a period appropriate to the system's purpose, and for at least six months unless other law says longer. Financial institutions keep them as part of the records required by financial services law.
What Sigilbase does: retains every event forever, on every plan, with no retention setting to get wrong. What it does not do: tell you how long your sector requires.
When
The Digital Omnibus on AI, in force since 27 July 2026, moved the application date for stand-alone high-risk systems listed in Annex III, which include credit scoring, hiring and essential services, to 2 December 2027. Dates have moved once and may move again; check the current position before relying on this page.
What a regulator can check
An evidence bundle exported from Sigilbase carries the events, the signed checkpoints, the public keys and the verifier. A market surveillance authority or notified body can run it on their own machine without an account and without taking our word for anything. That is the difference between a log you keep and a record someone else can test.
What this page does not say
Nothing here means that using Sigilbase makes a system comply with the Act. Compliance depends on what you record, how the system is designed, assessed and monitored, and on obligations this page does not cover. Sigilbase is the evidence layer.
What this proves, and what it does not
Sigilbase proves that a record has not been modified, deleted or reordered since we received it, when we received it, and which identity sent it. Any lawful redaction is declared, never silent.
It does not prove that a model produced the output in the record, or ran at all. It does not prove a decision was accurate, fair or lawful. It does not prove that everything which happened was recorded; coverage is the sender's control. It does not prove the sender's claimed time, only ours. And it says nothing about the period before the sender started.
Sigilbase is the evidence layer. The conclusion belongs to the person examining the evidence.
Questions about the EU AI Act and logs
-
Does the Act require tamper-evident logs?
It requires logs to be kept and does not specify integrity controls. A log that could have been altered has little value when a regulator asks what happened, which is why custody matters even where the text is silent.
-
We use a model vendor's API. Whose logs count?
The deployer must keep the logs under its control. A vendor's dashboard is under the vendor's control.
-
Is Sigilbase in the EU?
Sigilbase Ltd is a UK company. Production runs on OVHcloud in London, with backups in the United Kingdom and France. The security page at sigilbase.io/security/ lists every provider that touches your data and where it runs.
Start recording provable history
Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.
Start free Read the auditor guide
Questions first? Write to hello@sigilbase.io.
More in this section
- AI audit records. Why an AI decision log needs a custodian, and the rules that ask for one.
- AI decision logging. One event per decision, what to put in it, and what it proves.
- Records of what an AI agent did. Agents as actors, tool calls as events, credentials on loan.
- UK automated decisions. The 2025 Act's safeguards, and the record a contested decision needs.
- ISO/IEC 42001 event logs. What control A.6.2.8 asks for and what a certifier samples.
- For AI assurance providers. The verifier, auditor grants and how to request evidence.