Chapter III · Section 3 · Obligations of providers and deployers of high-risk AI systems and other parties
Article 19 — Automatically generated logs
▼ Primary text, verbatim. Our annotations appear below, visibly separated.
1. Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data.
2. Providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs automatically generated by their high-risk AI systems as part of the documentation kept under the relevant financial services law.
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.
What this means for you
In your terms · Keeping the automatically generated logs
Log formats you change casually today are formats someone must still parse months from now.
In your terms · Keeping the automatically generated logs
Most platforms run days of retention and sampled events; this wants months, complete, and recoverable on request.
You already haveRetention exists, typically at days or weeks and sampled. The floor here is months, complete.
- Retention policy meeting the six-month floor
- Restore test on aged logs
Failure smells likeThe logs covering the period under question were rotated out, on a retention default nobody set with this obligation in mind.
In your terms · Keeping the automatically generated logs
Retention at decision fidelity is a storage budget and a privacy trade-off to settle with your DPO, not a default.
- Retention budget and DPO sign-off
Obligations derived from this article
Commonly misquoted
What gets said
Logs have to be kept for seven years.
What the provision says
Article 19(1) sets a floor, not a fixed term: the provider keeps the logs its systems generate automatically, to the extent they are under its control, for a period appropriate to the intended purpose and of at least six months, unless other Union or national law says otherwise. Article 26(6) says the same to the deployer for the logs under its control. The long clock people are remembering is Article 18, which keeps technical documentation at the disposal of national competent authorities for ten years, and that is documentation rather than logs.
If you would rather not read the law
The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.