Ten questions map what your current logging can actually prove to the engineering substrate under EU AI Act Article 12 (record-keeping) and Article 26 (deployer duties). Scoped to gateway-routed traffic.
Not legal advice. It does not determine whether you are compliant; that is your counsel’s call and depends on how your system is classified. It scores your stack against the requirement.
Can you prove a given log entry has not been altered since it was written?
Would a silently deleted record leave a visible, provable gap?
Can a third party check your records’ integrity without trusting your team or your vendor?
Is every model request recorded automatically in the request path — not opt-in per app or SDK?
For any single request, can you show which policies and guardrails were actually applied — not just documented?
Can you attribute each request to a use case, team, or key — and to what it cost?
Can you establish the order and time of events in a way that survives a skeptical review?
Is your record store append-only by cryptography — not just by an IAM policy an admin can change?
Are these records retained for the multi-year horizon high-risk systems require?
Can you hand an auditor a self-contained bundle they can verify independently?