Back to Blog

EU AI Act Article 12: What AI Logging Requirements Mean for Audit Firms and Their Clients

EU AI Act Article 12 is already applicable to high-risk AI systems newly placed on the EU market. What it requires, how it overlaps ISO 42001, and what to do now.

Quick Answer

EU AI Act Article 12 is already applicable to high-risk AI systems newly placed on the EU market. What it requires, how it overlaps ISO 42001, and what to do now.

The four-part ISO 42001 series on this blog covered scoping, pricing, evidence sampling, and the 2027-2030 audit market. This standalone post addresses a topic that lives alongside that series and increasingly demands its own treatment: EU AI Act Article 12.

If your audit firm has clients with any EU exposure — sales into the EU, EU-based subsidiaries, EU customers handling EU-resident data, or EU-deployed AI products — Article 12 is now part of your audit scope, whether you have priced for it or not. This post covers what the article actually requires, what the draft technical standards realizing it are likely to demand, where Article 12 overlaps with ISO 42001 (and where it doesn't), and what audit firms should be doing in the next twelve months to be ready.

A note on scope. This is a practitioner's guide, not legal advice. The EU AI Act is a substantial regulation with significant nuance. Where I summarize the regulation, audit firms should confirm against the published regulation text and seek qualified counsel on legal interpretation.

Aug 2026
Article 12 became applicable for high-risk AI systems newly placed on the EU market — the requirement is already active, not future
Aug 2027
the full high-risk regime applies, including to AI systems on the market prior to August 2026 — same window as the first ISO 42001 cert wave
2
draft technical standards (prEN 18229-1 and ISO/IEC DIS 24970) will publish in 2027–2028 and lock the technical norms for Article 12 evidence

What Article 12 actually requires

Article 12 of the EU AI Act, formally titled "Record-keeping," establishes a logging obligation for providers of high-risk AI systems. The text establishes four distinct requirements.

First, automatic event recording. High-risk AI systems must "technically allow for the automatic recording of events ('logs') over their lifetime." This is not a one-time evidence collection. It is a continuous, automatic recording obligation tied to the operating lifetime of the AI system.

Second, traceability of operation. The logging capability must ensure "a level of traceability of the AI system's functioning that is appropriate to the intended purpose." Implementation guidance interprets this to mean traceability of inputs, outputs, and decision points — the operational primitives that determine what the AI system did and why.

Third, identification of risk situations. The logs must enable "the identification of situations that may result in the AI system presenting a risk." This is the surveillance dimension: the logs must support detection of conditions under which the AI is behaving anomalously or in ways that may produce harm.

Fourth, tamper-evidence and independent verifiability. Implementation guidance specifies that the logs must be "tamper-evident, timestamped, and independently verifiable." These are technical properties — not procedural ones — and they demand evidence in a specific shape: signed at write time, immutable after the fact, verifiable without trusting the operator.

What This Means For Most Production Systems

Taken together, these four requirements describe a logging capability substantially more rigorous than the operational logs most production AI systems currently produce. Application logs from a typical LLM-based product satisfy automatic recording but fail on tamper-evidence, fail on verifiability, and frequently fail on traceability of decision points.

Who is subject to Article 12

Article 12 applies to providers of high-risk AI systems. The definition of "high-risk" is set in Article 6 and detailed in Annex III of the regulation. The Annex III categories include:

  • Biometric identification and categorization of natural persons
  • Management and operation of critical infrastructure (water, gas, electricity, digital infrastructure, transport)
  • Education and vocational training (admissions, evaluation, monitoring of test-taking)
  • Employment and worker management (recruitment, screening, evaluation, allocation of work)
  • Access to and enjoyment of essential services (creditworthiness, public benefits, emergency dispatch, life insurance, health insurance)
  • Law enforcement (risk profiling, evidence evaluation, polygraph-equivalent, crime analytics)
  • Migration, asylum, and border control management (risk assessment, document verification, application assessment)
  • Administration of justice and democratic processes (judicial decision support, election influence assessment)

If your client deploys AI into any of these categories — and many B2B SaaS products do, often without recognizing the categorization — they are likely a provider of a high-risk AI system under the EU AI Act, even if the AI is one feature among many.

Deployers Also Have Obligations

Article 26 imposes logging obligations on deployers (the organizations using the AI system, distinct from the providers who built it). Deployers must "keep the logs automatically generated by the high-risk AI system to the extent that such logs are under their control" and retain them for an appropriate period.

This dual-obligation structure matters for audit firms. A SaaS provider that ships an AI-powered hiring tool to a corporate customer is both a provider (subject to Article 12) and may use that tool internally for its own hiring (becoming a deployer subject to Article 26). The audit scope can encompass both sides.

The enforcement timeline

The EU AI Act entered into force in August 2024. The provisions apply on a staggered timeline:

  • February 2025: Prohibited AI practices took effect.
  • August 2025: General-purpose AI model rules began applying.
  • August 2026: The majority of the high-risk system requirements — including Article 12 — became applicable for AI systems newly placed on the market.
  • August 2027: The full high-risk system regime applies, including to AI systems that were on the market prior to August 2026 but fall within high-risk categories established by Annex III.

For most audit firms reading this in 2026, the relevant fact is: Article 12 is already applicable to high-risk AI systems newly placed on the EU market. Clients deploying high-risk AI in the EU in 2026 should already have logging capabilities that satisfy the article. Many do not.

The draft technical standards

Article 12 establishes what is required. The technical standards that will specify how it is to be satisfied are presently in draft.

prEN 18229-1: AI logging and human oversight. Developed by CEN-CENELEC JTC 21 under EU standardization request M/593. This is the European harmonized standard that will give providers a presumption of conformity with Article 12 (and Article 14, on human oversight). Publication is expected in 2027 or 2028.

ISO/IEC DIS 24970: AI system logging. Developed by ISO/IEC JTC 1/SC 42, the international AI standardization committee. International scope; expected to converge substantially with the European standard but with broader applicability.

Both standards are presently underspecified. Their detailed technical content is being developed. Standards-track work proposing candidate technical realizations is in scope for the drafting bodies' consideration.

The Window That's Open Right Now

For audit firms, the practical implication: the audit norms for Article 12 evidence are being established now. Firms that develop substantive points of view on what good Article 12 evidence looks like will be better positioned to defend their audit findings in 2027–2028 than firms waiting for the standards to land.

Article 12 vs. ISO 42001: overlap and divergence

Many audit firms reading this will already have ISO 42001 in their practice plans. Article 12 is not a substitute for 42001, nor is 42001 a substitute for Article 12. The two requirements overlap in significant ways but have meaningful differences.

Where they overlap:

  • Both require records of AI system operation
  • Both demand integrity of those records
  • Both apply to high-risk or impact-bearing AI systems
  • Both anticipate that records will support post-hoc analysis (audits, incidents, affected-party requests)
  • Both create demand for evidence at finer granularity than traditional GRC tooling produces

Where they differ:

Dimension
ISO/IEC 42001
EU AI Act Article 12
Legal nature
Voluntary international standard with certification process
Binding regulation in EU jurisdictions
Scope
Organization's full AI Management System
Specific to high-risk AI systems as defined by Annex III
Mechanism
Management system audit, certification by accredited body
Regulatory enforcement by national supervisory authorities; CE marking
Technical specificity
Annex A controls catalogue; technical detail deferred to other frameworks
Article 12 is technical (tamper-evident, timestamped, verifiable)
Retention
Per organizational record retention policy (typically 3 years)
"Appropriate to the intended purpose" — interpreted as lifetime of the AI system for many high-risk categories
Geographic applicability
Worldwide adoption
EU and EU-exposed deployments

The practical scoping implication: a client subject to both ISO 42001 and Article 12 will need an audit program that satisfies both, not one or the other. The Article 12 logging capability can support ISO 42001's documented information requirements, but the converse is not always true: an ISO 42001 audit program that relies on point-in-time evidence collection will not satisfy Article 12's continuous logging mandate.

What audit firms should be doing now

Audit firms with EU-exposed clients should be doing four things in the next twelve months.

Add Article 12 scoping questions to engagement intake

The scoping post in the four-part series listed five questions for ISO 42001 complexity. For EU-exposed clients, three additional questions should be added: (1) Does the client place any AI system on the EU market, or have any deployment that reaches EU users? (2) Do any of the client's AI use cases fall within Annex III of the EU AI Act? (3) What logging capability does the client currently maintain — specifically: are logs tamper-evident, independently verifiable, and retained at lifetime-of-system durations? A client that answers "no logging beyond application logs" to the third question — which is the majority of mid-market AI deployers in 2026 — has a remediation gap that the audit firm should surface during the engagement, not discover at the certification stage.

Develop Article 12-specific evidence procedures

Beyond the ISO 42001 sampling patterns, Article 12 demands procedures for tamper-evidence testing (verifying logs cannot be modified after creation — cryptographic signatures, transparency log inclusion proofs, or equivalent integrity mechanisms), independent verifiability testing (a third party can verify logs without relying on the client's own systems), lifetime retention verification (logs retained for the lifetime of the AI system, not a fixed period), and coverage verification (sampling actual decisions and confirming that logs cover inputs, outputs, and decision points). These procedures will set the evidentiary norms that the draft technical standards eventually formalize.

Have the Article 12 conversation with current clients

For audit firms with existing client relationships in EU-exposed industries — financial services, healthcare, HR/employment, education, B2B SaaS with EU customers — Article 12 is a conversation that should happen in 2026, not 2027. Three parts: "Do you understand the scope of Article 12 as it applies to your AI products?" / "What logging capability do you currently maintain, and what is the gap to what Article 12 requires?" / "What is your remediation plan, and what is the audit posture you want when enforcement matures?" Clients who hear these questions in 2026 are more likely to remediate ahead of 2027 enforcement maturation.

Track the draft standards

Both prEN 18229-1 and ISO/IEC DIS 24970 are open standards processes. National mirror committees (NIST, ANSI, BSI, AFNOR, DIN, JISC depending on jurisdiction) accept comments. Identify the national mirror committee for your firm's primary jurisdiction; review the working drafts as they progress; submit at least one substantive comment cycle's worth of feedback. This is a low-cost positioning move with disproportionate long-term return.

The convergence question

A natural question for audit firms thinking strategically: will Article 12 and ISO 42001 converge, or will they remain separate requirements?

The most likely outcome is partial convergence. The technical mechanism that satisfies Article 12 — tamper-evident, timestamped, independently verifiable logging — also satisfies a substantial portion of ISO 42001's documented information requirements (clauses 7.5, 8, 9, 10). A client building Article 12-compliant logging is well on the way to ISO 42001's evidence requirements as a byproduct.

But the management system layer above Article 12's logging is distinct. ISO 42001 requires policy, organizational accountability, risk assessment, impact assessment, lifecycle management — not just logging. Article 12 does not require any of those things on its own.

The Likely Convergence Pattern

Article 12 establishes the evidence substrate — what records must exist, how they must be produced, what integrity they must have. ISO 42001 establishes the management system overlay — what the organization must do with those records, how it must govern AI more broadly.

Audit firms positioning for this convergence should build practice capability in both. Firms that build only one will be exposed to clients who need both.

Conclusion

EU AI Act Article 12 is a binding logging obligation for providers of high-risk AI systems. It is already applicable for AI systems newly placed on the market and will be applicable to legacy systems by August 2027. The technical standards that will specify the article's detailed requirements are in draft now and will publish in the same window as the first ISO 42001 certification audits.

For audit firms with EU-exposed clients, Article 12 is not a future concern. It is a current scoping dimension. Firms that add Article 12 to their engagement intake, develop substantive evidence procedures for tamper-evidence and verifiability, have the conversation with current clients, and track the draft standards are positioning themselves for the 2027-2028 enforcement maturation. Firms that wait for the standards to land will be behind.

The four-part ISO 42001 series covered the broader AI assurance practice landscape — from the mid-market demand picture through scoping and pricing, evidence sampling, and the 2027–2030 market trajectory. Article 12 is the regulatory anchor that makes that practice more than a voluntary standard — it makes it a compliance obligation with specific technical requirements. The audit firms that recognize both threads, and the convergence pattern that links them, will be the ones that win the 2027-2030 AI audit market.

Build the evidence substrate Article 12 demands

The technical mechanism that satisfies Article 12 — tamper-evident, timestamped, independently verifiable logs — is the same substrate that makes ISO 42001 audits go cleanly. vCISO Lite is the integrated platform that sits between your clients' AI infrastructure and your audit findings, turning signed logs into a controls-linked evidence layer that satisfies both regimes from a single capture pipeline.

If you're advising EU-exposed clients on Article 12 readiness, or building the audit practice that will absorb the 2027-2028 enforcement wave, visit vcisolite.com to learn more and get started.

Where this matters next

Platform: APRI (AI-Powered Risk Intelligence)the MCP surface exposing verify-* provenance + freshness envelopes — the Article-12-shaped logging capability.

APRI: AI-Powered Risk Intelligencethe compliance-AI surface built to the standards Article 12 wants: measured, cited, audited.

Where this matters next

The First AI Audits Hit in 2027. Most Mid-Market Companies Will Fail Them. — In 18 months, a new generation of audit opinions will start landing in mid-market boardrooms

The 2027-2030 AI Audit Market: How Assurance Firms Will Differentiate — By 2030, the firms that started early will have shaped how AI assurance is delivered

What to Sample in an ISO 42001 Audit: An Evidence Field Guide — ISO 42001 requires \

How often is your compliance AI actually right? — Every vendor pitching an 'AI compliance agent' makes the same promise — set it loose on your controls and it will attest while…

Share this article:

Ready to build your security program?

See how easy it can be.