your organization is fully covered on this requirement.
“High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.”
“Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data.”
“In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for … identifying situations that may result in the high-risk AI system presenting a risk …”
In plain terms: The framework (Art. 12 / 26(6)) calls for automatic event logging + retention.
Merkle+TSA signed audit; the signed receipts sit outside the plan retention window while the queryable log follows it: 30 days on the default tier, 365 on Team, custom on Enterprise.
Enforcement primitive: Record – Signed, tamper-evident audit entry, the evidence chain.