Compliance / EU AI Act
Compliance frameworkEU AI Act Record-Keeping & Logging
The AI Act is the first regime to treat an AI system's own logs as regulated records. If your people are using assistants for business work, the question is no longer whether those interactions are records — it is who holds them, and for how long.
Applies to: Providers and deployers of high-risk AI systems placed on the market or used in the EU, including organisations established outside the EU whose systems are used there. Obligations for high-risk systems apply from 2 August 2026.
At a glance
| Regulation | EU AI Act (EU 2024/1689) |
|---|---|
| Applies to | Providers & deployers of high-risk AI systems |
| High-risk duties from | 2 August 2026 |
| Log retention | At least 6 months (Arts. 19, 26(6)) |
What EU AI Act requires
Automatic logging over the system lifetime
Article 12 requires high-risk AI systems to technically allow the automatic recording of events over the lifetime of the system. Automatic is the operative word: manual documentation does not satisfy it.
Logs that serve three purposes
Article 12(2) frames the logging around identifying situations where the system may present a risk or undergo substantial modification, supporting post-market monitoring, and supporting deployers' monitoring of operation.
A six-month retention floor — set elsewhere
Article 12 itself sets no retention period. The floor of at least six months sits in Article 19 for providers and Article 26(6) for deployers, each to the extent the logs are under their control. Sectoral rules can require far longer, and regulated financial institutions generally follow their financial-services retention period instead.
Traceability to a person
For certain systems the logging must identify the natural persons involved in verifying results, which means the record has to carry identity, not just content.
How Grotabyte helps with EU AI Act
Frequently asked questions
Are AI assistant conversations business records?
Where the work is business work, yes — and regulators have not carved out an exception for conversations that happen to be with a model. A request for all communications concerning a matter does not stop at the boundary of your email system.
How long do AI logs have to be kept?
At least six months under Articles 19 and 26(6), to the extent the logs are under your control. That is a floor rather than a target: data-protection and sectoral rules can require longer, and a regulated financial institution generally applies its own recordkeeping period instead.
Which AI sources does Grotabyte archive today?
Claude Enterprise, through Anthropic's Compliance API. That is the shipped AI source, and the site does not claim others — ChatGPT, Copilot and Gemini capture have been researched and modelled but are not shipped, and Gemini's feed carries no message bodies.
Does the AI Act replace our existing recordkeeping obligations?
No, it adds to them. A firm subject to MiFID II or FINRA still holds its communications for the period those rules set; the AI Act adds obligations about the AI system's own logs. Holding both in one archive is what stops the two schedules drifting apart.
Meet EU AI Act with confidence
See how Grotabyte captures, preserves, and produces your records to satisfy EU AI Act and the other regulations that govern your organization.