your organization is compliant with this requirement.
“High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.”
“Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data.”
“In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for … identifying situations that may result in the high-risk AI system presenting a risk …”
In plain terms: The framework (Art. 12 / 26(6)) calls for automatic event logging, ≥6-mo retention.
Merkle+TSA signed audit + configurable retention; agent identity gives traceability.
Enforcement primitive: Record — Signed, tamper-evident audit entry — the evidence chain.