AI Act, Article 26(6) (deployer log-keeping)
Regulation (EU) 2024/1689, Article 26(6)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 435 days, effective 2 December 2027.
An AI governance rule binding public and private bodies.
As of 20 September 2026.
What it requires
- Keep the logs your high-risk AI system automatically generates, to the extent they are under your control, if you are its deployer.
- Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it.
- If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require.
If you get it wrong
Private right of actionNo
What it reaches
How the hook was established
express
What makes it apply
Operator establishment, Place of effect
Obligation class
Governance, Retention
What it makes you log
Log retention
The same floor as Article 19, in nearly identical wording: a period appropriate to the system's intended purpose, of at least six months, yielding to a different period under other Union or national law, in particular data-protection law. A deployer that is a financial institution subject to Union financial-services internal-governance rules satisfies this duty through the documentation that law already requires.
- Unit
- Months
- As of
- 21 September 2026
- Basis
- Purpose bound
- Minimum value
- 6
Logging duty
Article 26(6) is the deployer's counterpart to Article 19: it names the logs the system automatically generates and requires the deployer to keep them, on the same six-month floor. It does not create the logging capability or say what the logs must contain; both are Article 12's. Unlike a provider's logs, which Article 21(2) makes accessible to a competent authority on request, no provision of Article 26 or Article 21 gives a competent authority the same named route into a deployer's copy of the logs. Article 74(1) applies Regulation (EU) 2019/1020 to AI systems and treats a reference to an economic operator under that Regulation as including every operator named in Article 2(1), deployers included, which gives a market surveillance authority a general document and information production power reaching a deployer's records. That is a real route, but it is 2019/1020's own general power over any operator's documentation, not an AI Act clause naming access to "the logs" for a deployer the way Article 21(2) names it for a provider, so no named accessor is recorded here rather than importing a background power that would apply identically to every instrument in this file.
- Kind
- Explicit
- As of
- 21 September 2026
- Provision
- Article 26(6)
- Trigger
- high_risk_systems
Who checks it
Audit expectation
none
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A deployer of a high-risk AI system must keep the logs the system automatically generates, to the extent the logs are under the deployer's control, for a period appropriate to the system's intended purpose, at least six months, unless a different period is required under other Union or national law, in particular data-protection law.
A deployer that is a financial institution subject to internal-governance requirements under Union financial services law satisfies this duty by maintaining the logs as part of the documentation that law already requires it to keep. Article 26(6) is the deployer-side counterpart of Article 19: the two provisions state the same retention period, of a deployer and a provider respectively, in nearly identical wording.
Article 26 sits in Chapter III, Section 3, so like Articles 12, 19 and 21 it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.
When LexLint raises it
high_risk_decisionsprocesses_biometrics
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.