Article 26(6)
UpcomingConditional timingRetain High-Risk AI Logs Under the Deployer's Control
Applies to Deployer; High-Risk AI.
- Actors
- Deployer
- AI class
- High-Risk AI
- Themes
- Data, Privacy & InformationGovernance & Accountability
Tracker Guidance
Keep automatically generated high-risk AI logs that are under the deployer's control for a period appropriate to the intended purpose and at least six months, unless another period is provided by applicable Union or national law, including personal-data protection law.
Official text
6. Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data. Deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law.
Timing depends on the system
- 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
- 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
- 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
- 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
- 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities