Standards · 22 July 2026

What the EU AI Act actually asks of your agent logs

Strip away the noise and the EU AI Act asks two plain things of a high-risk AI system: keep a record of what it did, and keep a human genuinely able to intervene. Most of the anxiety around it comes from not separating those two questions from a third — whether the rules apply to you at all.

Article 12: automatic logging

The record-keeping requirement is less exotic than it sounds. A high-risk system has to log events automatically over its lifetime, to a degree that lets you trace what happened and identify situations where the system might have gone wrong. In practice that means each consequential event captured with enough context to reconstruct it after the fact — when it happened, what the system did, and enough surrounding detail that an investigator isn't guessing. Not a summary. A record you could hand to someone who wasn't in the room.

Article 14: human oversight

The oversight requirement is about capability, not ceremony. A person has to be able to understand what the system is doing, decide not to use its output, and intervene or stop it. A rubber-stamp "approve" button that a human clicks a hundred times an hour without real ability to reject is not oversight; it's theatre with an audit trail. Genuine oversight means the human can actually hold, edit, or refuse the action — and that their decision becomes part of the record from Article 12.

Neither article asks for a dashboard. They ask for a record you can trust and a human who can actually say no.

The question everyone skips: does it apply to you?

Here is where a lot of vendor messaging quietly overreaches. The logging and oversight duties attach to high-risk systems, and "high-risk" is a defined list, not a vibe. In the financial world the clearest case is AI used to evaluate the creditworthiness of a person, or to price and assess risk in life and health insurance — decisions made about individuals, with real consequences for them. An AI agent drafting sales outreach, or summarising a call, generally is not on that list.

That distinction matters more than it looks. It means "we help you comply with the EU AI Act" is, for a lot of deployments, answering a question the deployment didn't ask. And it means the honest version of a compliance claim has a border drawn around it: here is what the Act requires, here is the subset of your systems it actually governs, and here is where you still need your own counsel to make the call.

What we take from it

We build to the logging and oversight bar because it's simply good engineering for anything that acts — automatic, reconstructable records and a human who can genuinely intervene make a system safer whether or not a regulator is watching. So we apply that rigor by choice, across the board, ahead of the Act's high-risk deadline. What we don't do is tell you that applying it settles your legal status. Mapping to a requirement is not certifying compliance with it, and a company whose product is trust shouldn't blur the two.

The Act is more readable, and more reasonable, than its reputation. It asks for a record worth trusting and a human who can say no. If your agents already meet that bar, most of the work is proving it — which is a different, and more tractable, problem than it first appears.

Not legal advice

This is a plain-language reading for practitioners, not a legal opinion. Whether and how the EU AI Act applies to a specific system depends on facts we don't have; check with qualified counsel before relying on any of it.

← More from the Journal