AI Act, Article 19 (automatically generated logs)
Regulation (EU) 2024/1689, Article 19
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 435 days, effective 2 December 2027.
An AI governance rule binding public and private bodies.
As of 20 September 2026.
What it requires
- Keep the logs your high-risk AI system automatically generates under Article 12, to the extent they are under your control, if you are its provider.
- Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it.
- If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require.
If you get it wrong
Private right of actionNo
What it reaches
How the hook was established
express
What makes it apply
Market targeting, Place of effect
Obligation class
Governance, Retention
What it makes you log
Log retention
Six months is a floor, not a fixed term: the article calls for a period appropriate to the system's intended purpose, of at least six months, and that floor yields to a different period set by other Union or national law, in particular data-protection law. A provider that is a financial institution subject to Union financial-services internal-governance rules satisfies this duty by keeping the logs as part of the documentation that law already requires.
- Unit
- Months
- As of
- 21 September 2026
- Basis
- Purpose bound
- Minimum value
- 6
Logging duty
Article 19 is the provider's duty to keep the logs Article 12(1) requires the system to be capable of generating; it does not itself create the logging capability or say what the logs must contain, and it does not say who may see them. Content is Article 12's, and access to a provider's logs is Article 21(2)'s.
- Kind
- Explicit
- As of
- 21 September 2026
- Provision
- Article 19(1)
- Trigger
- high_risk_systems
Who checks it
Audit expectation
none
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Providers of a high-risk AI system must keep the logs the system automatically generates under Article 12(1), to the extent those logs are under the provider's control. The logs must be kept for a period appropriate to the system's intended purpose, at least six months, unless a different period is required under other Union or national law, in particular data-protection law.
A provider that is a financial institution subject to internal-governance requirements under Union financial services law satisfies this duty by keeping the logs as part of the documentation that law already requires it to maintain.
Article 19 sits in Chapter III, Section 3, so like Article 12 it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.
When LexLint raises it
high_risk_decisionsprocesses_biometrics
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.