EU AI Act: verification gates for automated decisions
Article 12 is a design obligation, not a post-incident paperwork exercise. High-risk systems must log automatically with tamper-evident integrity. Proof-not-log audit fits that bar.
EU AI Act Article 12 logging requires providers of high-risk AI systems to record events automatically throughout the system lifetime with enough detail for post-market monitoring and integrity protection against tampering. AffixIO implements proof-not-log audit at the decision boundary.
EU AI Act Article 12 requires automatic tamper-evident logging for high-risk AI by December 2027. AffixIO appends signed allow or deny digests to a Merkle tree auditors verify without admin access.
Deadlines procurement teams track
- 2 December 2027: Annex III stand-alone high-risk AI systems must support Article 12 logging.
- 2 August 2028: embedded high-risk systems in regulated products.
- Deployer duty: retain logs at least six months and monitor operation.
See the full regulatory deadlines calendar.
Why application logs alone fail Article 12
Database administrators can edit rows. Clock skew breaks sequencing. Retention policies vary by team. Merkle audit over signed decision digests gives regulators something they can replay independently. Compare proof-not-log vs SIEM.
Agent gates and general-purpose AI
Chatbots classified as high-risk under Annex III need logging at the action boundary, not only at training time. Pair Article 12 architecture with agent authorisation gates for tool calls and exports. Guide: shadow AI agents.
Readiness workflow
- Run the Article 12 readiness checker.
- Read the buyer guide.
- Reproduce verify flows and Merkle export in the sandbox.
Whitepaper: EU AI Act and NIS2 compliance.