Article 12 of the EU AI Act says high-risk AI systems must technically allow automatic recording of events (logs) over the lifetime of the system. It covers high-risk systems only. An internal assistant that searches docs over MCP doesn't become high-risk because it uses MCP. Per artificialintelligenceact.eu, the obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Check the current consolidated text on EUR-Lex for your own case; none of this is legal advice.
ISO/IEC 42001 is broader and vaguer. Control A.6.2.8 asks you to decide in which life-cycle phases event logging is enabled, and "while the AI system is in use" is the minimum.
For agents I'd put that logging at the tool call. The model only suggests things, and the tool call is where data actually changes. Before each call with side effects, record:
- who or what asked, and on whose behalf the agent acted
- the tool, the action, and the resource it touches
- the decision (allow, deny, or allow with approval) and the policy version behind it
- who approved it, if a human had to sign off
- what happened after the decision
Join those with one request ID. Log redacted parameters or hashes instead of raw prompts, so you can replay the decision later without hoarding data.
Disclosure: I work at Permit.io. We wrote up the Article 12 and ISO 42001 details, with a full field table for MCP tool calls:
Top comments (0)