Sigilbase

EU AI Act record-keeping, in plain words.

Three articles of the EU AI Act concern logs. Here they are without the legal prose, with the dates as they stand, and an honest account of what Sigilbase does and does not do about each.

Checked October 2026. This page describes the rules in plain words and is not legal advice. Dates have moved before and may move again.

Article 12, record-keeping

High-risk AI systems must technically allow events to be recorded automatically over the system's lifetime. The logs are meant to make the system traceable: to identify situations that may present a risk, to support post-market monitoring, and to let deployers monitor operation.

What Sigilbase does: receives the events your system records and keeps them in a form that cannot be altered without detection. What it does not do: decide which events to record. That is a design decision for the provider and the deployer.

Articles 19 and 26, keeping the logs

Providers (Article 19) and deployers (Article 26) must keep the automatically generated logs under their control for a period appropriate to the system's purpose, and for at least six months unless other law says longer. Financial institutions keep them as part of the records required by financial services law.

What Sigilbase does: retains every event forever, on every plan, with no retention setting to get wrong. What it does not do: tell you how long your sector requires.

When

The Digital Omnibus on AI, in force since 27 July 2026, moved the application date for stand-alone high-risk systems listed in Annex III, which include credit scoring, hiring and essential services, to 2 December 2027. Dates have moved once and may move again; check the current position before relying on this page.

What a regulator can check

An evidence bundle exported from Sigilbase carries the events, the signed checkpoints, the public keys and the verifier. A market surveillance authority or notified body can run it on their own machine without an account and without taking our word for anything. That is the difference between a log you keep and a record someone else can test.

What this page does not say

Nothing here means that using Sigilbase makes a system comply with the Act. Compliance depends on what you record, how the system is designed, assessed and monitored, and on obligations this page does not cover. Sigilbase is the evidence layer.

What this proves, and what it does not

Sigilbase proves that a record has not been modified, deleted or reordered since we received it, when we received it, and which identity sent it. Any lawful redaction is declared, never silent.

It does not prove that a model produced the output in the record, or ran at all. It does not prove a decision was accurate, fair or lawful. It does not prove that everything which happened was recorded; coverage is the sender's control. It does not prove the sender's claimed time, only ours. And it says nothing about the period before the sender started.

Sigilbase is the evidence layer. The conclusion belongs to the person examining the evidence.

Questions about the EU AI Act and logs

  • Does the Act require tamper-evident logs?

    It requires logs to be kept and does not specify integrity controls. A log that could have been altered has little value when a regulator asks what happened, which is why custody matters even where the text is silent.

  • We use a model vendor's API. Whose logs count?

    The deployer must keep the logs under its control. A vendor's dashboard is under the vendor's control.

  • Is Sigilbase in the EU?

    Sigilbase Ltd is a UK company. Production runs on OVHcloud in London, with backups in the United Kingdom and France. The security page at sigilbase.io/security/ lists every provider that touches your data and where it runs.

Start recording provable history

Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.

Start free Read the auditor guide

Questions first? Write to hello@sigilbase.io.

More in this section

Privacy

This site runs no analytics and no trackers.

The site itself collects nothing. If you create a Sigilbase account, the data that involves is described in the privacy policy.

To have your email removed, contact hello@sigilbase.io.

Read the full privacy policy.

Last updated July 2026.