Law / European Union

AI Act, Article 21(2) (competent authority access to automatically generated logs)

Regulation (EU) 2024/1689, Article 21(2)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 435 days, effective 2 December 2027.

An AI governance rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • Give a competent authority access to the automatically generated logs of your high-risk AI system, to the extent they are under your control, when it makes a reasoned request, if you are the system's provider.
  • Expect information a competent authority obtains this way to be handled under Article 78's confidentiality rules.

If you get it wrong

Private right of actionNo

What it reaches

How the hook was established

express

What makes it apply

Market targeting, Place of effect

Obligation class

Governance

What it makes you log

Who may demand the log

Regulator

Logging duty

Article 21(2) is the access half of the chain: it names the Article 12(1) logs directly and requires a provider to open them to a competent authority on request. It does not itself create the logging capability, set a retention period, or say what the logs must contain; those are Article 12's and Article 19's.

Kind
Explicit
As of
21 September 2026
Provision
Article 21(2)
Trigger
high_risk_systems

Who checks it

Audit expectation

on_request

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Upon a reasoned request from a competent authority, a provider of a high-risk AI system must give that authority access to the logs automatically generated by the system under Article 12(1), to the extent the logs are under the provider's control. Any information a competent authority obtains under Article 21, including through this access, is subject to the confidentiality obligations of Article 78.

Article 21(2) is the access half of the record-keeping duty: Article 12 requires the logging capability to exist and Article 19 requires a provider to keep the logs, while Article 21(2) is what lets a competent authority reach them.

Article 21 sits in Chapter III, Section 3, so it takes effect on the same schedule as Articles 12, 19 and 26(6): 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

When LexLint raises it

  • high_risk_decisions
  • processes_biometrics

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app