Questionnaire answers · Security · Article 12(1) · Article 26(6) · Article 72(1)

How to answer logging and monitoring questions in a supplier questionnaire

The short answer

Say what the AI features log, how long the logs are kept, who watches them and what triggers an alert, and show a sample. A high-risk AI system must technically allow the automatic recording of events over its lifetime (Article 12(1)), the deployer keeps the logs under its control (Article 26(6)) and monitors the system's operation (Article 26(5)). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“What do you log for the AI features?”
  2. Q2“How long do you keep the logs?”
  3. Q3“Who monitors the AI system in operation?”
  4. Q4“Can we receive the logs for our account?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: What do you log for the AI features?

Direct answerYes, partly or no first
Each request to the AI feature: time, user, input size, the model version that answered and whether the user accepted the output.
ControlWhat you actually do
Logging is on in the service configuration and is not optional per customer.
ScopeWhich AI systems
Every AI feature. Prompt contents are not logged; their size and hash are.
EvidenceWhat you can show
A redacted sample of one day's log and the logging configuration, dated 1 October 2026.
ExceptionsBe honest
None.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The logging configuration and a redacted sample.
  • The retention setting for the logs, with the period.
  • Who reviews the logs and what triggers an alert.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 12(1)
  • a high-risk system technically allows the automatic recording of events over its lifetime, and the logging enables recording events relevant for identifying situations that may present a risk or a substantial modification, for post-market monitoring under Article 72 and for monitoring the operation under Article 26(5).
  • Article 12(3) sets a minimum for the systems in point 1(a) of Annex III.
Read Article 12 on EUR-Lex ↗

Article 26(6) for deployers and Article 19(1) for providers: the logs under their control are kept for a period appropriate to the intended purpose, of at least six months, unless Union or national law provides otherwise, in particular on the protection of personal data.

Article 72(1) and (3), as replaced by Regulation (EU) 2026/1744: the provider establishes and documents a post-market monitoring system, proportionate to the nature of the AI technologies and the risks, based on a plan that is part of the technical documentation, and the Commission is to adopt guidance, including a template, by 2 September 2027.

Articles 12, 19 and 26 are in Chapter III, Sections 2 and 3, which apply from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).

What Complipath does

  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Post-market monitoring (Article 72) Not supported We found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five.
  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.

Questions

Does Complipath monitor our AI systems?

Complipath does not do your security work. It keeps the evidence and answers with a source. It does not watch your systems run, and post-market monitoring under Article 72 says Not supported in its status table. Inside Complipath, the audit log records who did what and when, and no one can edit or delete a line.

Are the AI Act's logs the same as an audit log?

Not necessarily. Article 12 is about the high-risk system recording its own events, so a risk, a substantial modification and its operation can be traced. An audit log of who changed what in a tool is a different record, often useful as evidence, but it is not the system's Article 12 logging.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.