ART-12 READINESS CHECK

Does your LLM stack produce Art-12-grade records?

Ten questions map what your current logging can actually prove to the engineering substrate under EU AI Act Article 12 (record-keeping) and Article 26 (deployer duties). Scoped to gateway-routed traffic.

Not legal advice. It does not determine whether you are compliant; that is your counsel’s call and depends on how your system is classified. It scores your stack against the requirement.

0 / 10 ANSWERED
  1. 01
    Tamper-evidence

    Can you prove a given log entry has not been altered since it was written?

  2. 02
    Completeness evidence

    Would a silently deleted record leave a visible, provable gap?

  3. 03
    Independent verifiability

    Can a third party check your records’ integrity without trusting your team or your vendor?

  4. 04
    Automatic in-path capture

    Is every model request recorded automatically in the request path — not opt-in per app or SDK?

  5. 05
    Per-decision enforcement evidence

    For any single request, can you show which policies and guardrails were actually applied — not just documented?

  6. 06
    Attribution

    Can you attribute each request to a use case, team, or key — and to what it cost?

  7. 07
    Time & order integrity

    Can you establish the order and time of events in a way that survives a skeptical review?

  8. 08
    Immutability by cryptography

    Is your record store append-only by cryptography — not just by an IAM policy an admin can change?

  9. 09
    Multi-year retention

    Are these records retained for the multi-year horizon high-risk systems require?

  10. 10
    Auditor-ready export

    Can you hand an auditor a self-contained bundle they can verify independently?