Enforcement conversations rarely open with a trick question. They open the same way every time: "Show us your records." A client audit, a tender panel, a regulator's information request — each one is, at heart, a request for paperwork. The EU AI Act is usually described as a risk-regulation law, but on the ground it is a paperwork regulation too. It runs on records: automatic logs, technical documentation, training records, incident reports — evidence an organisation can produce on demand, not a certificate on the wall.

That framing matters for UK and Irish SMEs, because most of the heavy logging duties formally attach to high-risk AI systems — and their compliance dates are still ahead (the timeline is below). But the pressure is not waiting for the dates. Clients, auditors and procurement teams are asking about AI governance now, and "we'll have records by 2027" is not an answer that wins tenders. This page is part of our full guide to the EU AI Act for UK and Irish businesses: which records the Act expects, who each duty binds, and how long each one must be kept. To know which of your tools the high-risk regime will actually catch, start by learning to sort your tools into the Act's risk categories — classification decides which logging duties apply.

The logging rule: Article 12 in plain English

Article 12 is the Act's core logging provision. Stripped of legislative framing, it says three things.

  • Who it binds: providers of high-risk AI systems. If you build an AI system and put it on the EU market, logging is your duty — built into the system, for its whole lifetime.
  • What gets logged: the events that matter. Not everything, but the right things — the events needed to identify risks, monitor how the system performs once it is in the wild (post-market monitoring), and let the businesses using it oversee its operation.
  • Automatic by design. These are system-generated logs, recorded by the system itself. Not a spreadsheet someone remembers to update on Fridays.

So what if you buy rather than build?

Most SMEs are deployers, not providers

You inherit Article 12 rather than build for it. Providers of high-risk systems must hand you instructions for use (Article 13) that explain how to collect and interpret the logs their system generates. Your job as a deployer: keep those logs, and know where they live. If a vendor cannot tell you how logging works, that is a purchasing decision you are about to regret.

How long to keep logs: the six-month floor

Here is the number most people are looking for. If you are a deployer of a high-risk AI system, you must keep the automatically generated logs under your control for a period appropriate to the system's purpose — at least six months (Article 26(6)) — unless GDPR or sector-specific law such as financial services or healthcare rules requires longer. Providers keep the logs under their control for at least six months too (Article 19).

The practical rule: six months is the floor, not the target. Let data-protection law and your sector's retention rules set the ceiling; the AI Act only tells you the minimum below which you may not go. If your data-retention policy already says two years for operational logs, the AI Act does not ask you to cut that back — and month-six deletion is not the compliance move it might look like (see the FAQ).

Documentation beyond logs: the 10-year rule and the rest

Logs are the best-known record, but they sit inside a wider documentation stack. Each entry below follows the same shape: who it binds, what to keep, how long.

Providers · high-risk systems

Technical documentation — 10 years

Providers must draw up technical documentation and keep it for 10 years after the system is placed on the market (Article 18): what the system does, how it was built and tested, the risks assessed and mitigated. If you buy AI tools, this is an argument for vendors who can show their paperwork — you will rarely be able to request it years later.

Providers, fed by deployers

Post-market monitoring (Article 72)

After launch, providers must collect and document performance data — how the system behaves in real use. Deployers feed that loop: the incidents and anomalies you report are the raw material of post-market monitoring. Keep your side of the exchange.

Deployers especially

Serious incident reporting (Article 73)

If a serious incident occurs, deployers must inform the provider — and authorities where relevant. Immediately for breaches of EU fundamental-rights law; otherwise without undue delay and no later than 15 days after becoming aware. The paper trail that protects you is a simple one: who knew, what, when.

Live since 2 February 2025

AI literacy training records (Article 4)

Not logs, but the documentation duty SMEs most often miss: records of who was trained, and when, to what depth, with a refresh cadence. This one has been live since February 2025 — no high-risk classification required.

Live since 2 August 2026

Transparency records (Article 50)

If you run chatbots or publish synthetic content, you owe disclosures and labelling. Keep the evidence of what you disclosed, where — screenshots, configs, disclosure copy. "It was in the footer at the time" needs proof.

Timing: what applies when

The Digital Omnibus reshuffled the calendar, so pin the dates deliberately rather than from memory:

✅ In force since 2 February 2025

AI literacy (Article 4)

Training records duty — already live, regardless of risk class.

✅ In force since 2 August 2026

Transparency (Article 50)

Disclosure and labelling records for chatbots and synthetic content.

2 December 2027

Annex III high-risk regime

Automatic logging (Article 12), deployer retention (Article 26(6)), technical documentation and the rest formally arrive for stand-alone high-risk systems.

2 August 2028

Annex I embedded high-risk

AI embedded in regulated products (machinery, medical devices and similar) follows a year later.

The point of the strip: most logging duties formally arrive with high-risk classification. But classification is a decision you make now — and the evidence habit, plus the client and tender pressure, starts today.

What an SME should actually keep: the practical shelf

You do not need a compliance platform. You need one bookmarkable shelf — six items, most of them an afternoon's work, and each one feeding a duty described above. If you have never built this, expect the first pass to surface shadow AI — tools that never made it into any record. That discovery is the shelf doing its job.

  1. AI inventory. Every AI tool in the business, its owner, its purpose, its risk class. Every AI tool logged in an AI inventory is the register every other record on this shelf refers back to.
  2. Training records. Who was trained, when, to what depth, and when the refresh is due — your Article 4 evidence.
  3. Vendor documentation. The EU Declaration of Conformity, instructions for use, and the Article 13 details of how to access and interpret logs — collected at purchase, because you likely cannot get them later.
  4. Log export and retention config. Where your high-risk tools' logs actually go, and how long they persist. Fix this before 2 December 2027, not after — retro-fitting retention onto logs that were never captured is not a position you want to defend.
  5. Incident log. A simple register of AI incidents and near-misses. It feeds your Article 73 duties and doubles as risk evidence.
  6. Decision trail for AI-assisted decisions. Who oversaw the decision, what the human check was. Protects you under Article 26 and well beyond it.

Six items. The first three can exist as documents this week; the last three are habits with a document at the end. Together they are the difference between producing a shrug and producing a shelf when someone asks to see your records.

The takeaway

The numbers worth remembering: a six-month floor for logs of high-risk systems (deployers and providers alike), 10 years for provider technical documentation — and no minimum at all for the shelf you control today, because inventory, training records and vendor documentation are simply good governance that the Act will eventually formalise. The businesses that will find December 2027 easy are the ones whose records already exist.

Find out where you stand: take the AI Act quiz (two minutes) — it flags which record-keeping duties already apply to a business your size. If you already know you need hands on deck, AI Act Readiness is the human-led route. (Practical guidance throughout — not legal advice.)