Article 12 Evidence Readiness

Seven technical questions for deployers and providers who already suspect high-risk scope. This is not a legal compliance checker — it separates what Article 12 actually requires (automatic lifetime recording and retention) from evidence-quality controls that make logs easier to defend under scrutiny.

This checks technical logging and evidence quality for high-risk Article 12 scope — not legal classification. Article 12 requires automatic lifetime recording; cryptographic integrity is optional under the Act and marked as such in the questions. For role and risk tier, use the FLI Compliance Checker.

1. Is logging automatic at the inference boundary (no per-event human toggle)?
2. Can you retain and export logs for at least six months (longer where sector law applies)?
3. Are records tamper-evident (signatures, append-only chain, or equivalent)? — not required by Article 12 text, but hard to defend mutable rows under scrutiny
4. Can a third party verify records without trusting your database administrator? — evidence-quality control, not a statutory Art. 12 field
5. For multi-step agents: are tool calls and human review in the same session chain?
6. Do you store commitments or hashes for sensitive prompts — not raw PII in the evidence layer?
7. Can you produce a self-contained evidence pack with offline verification instructions? — market practice, not prescribed by Article 12

After your score

Map gaps to the Article 12 hub, Article 50 transparency guide, or talk to our team about SDK instrumentation.

This guide supports qualification and architecture planning — it is not legal advice. Work with your legal and compliance teams on classification, DPAs, and deployment approvals. See also our Regulatory & Compliance page.