Source: OJ L, 2024/1689, 12.7.2024

Current language: FR

Article 19 Journaux générés automatiquement


Summary What does Article 19 of the AI act regulation say?

This article establishes the log retention obligations for providers of high-risk AI systems, building directly on Article 12, which requires those systems to be capable of automatically generating logs in the first place.

Here, the focus shifts to how long those logs must be kept.

The retention obligation only applies to logs that are actually under the provider's control, and a minimum retention period of six months is set, subject to any overriding Union or national law, including data protection rules.

A carve-out is also provided for providers that are financial institutions, who may fold their log retention into their existing documentation obligations under Union financial services law.

Important points:

  • Retain the automatically generated logs of your high-risk AI systems for a minimum of six months, to the extent those logs are under your control.
  • The six-month minimum can be overridden by applicable Union or national law, including Union data protection law.
  • Providers that are financial institutions subject to Union financial services law can satisfy this obligation by maintaining the logs as part of their documentation under that law.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Les fournisseurs de systèmes d’IA à haut risque assurent la tenue des journaux générés automatiquement par leurs systèmes d’IA à haut risque, visés à l’article 12, paragraphe 1, dans la mesure où ces journaux se trouvent sous leur contrôle. Sans préjudice du droit de l’Union ou du droit national applicable, les journaux sont conservés pendant une période adaptée à la destination du système d’IA à haut risque, d’au moins six mois, sauf disposition contraire dans le droit de l’Union ou le droit national applicable, en particulier dans le droit de l’Union sur la protection des données à caractère personnel.

    1. Si les fournisseurs sont des établissements financiers soumis à des exigences relatives à leur gouvernance, à leurs dispositifs ou à leurs processus internes prévues par la législation de l’Union sur les services financiers, ils tiennent à jour les journaux générés automatiquement par leurs systèmes d’IA à haut risque dans le cadre de la documentation conservée en vertu de la législation pertinente sur les services financiers.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod