Skip to content

Regulation Guide

The EU AI Act Is In Force. High-Risk AI Logging Obligations Apply From August 2026.

Financial firms using AI for credit assessment, insurance pricing, or access to financial services are deploying high-risk AI under Annex III. Article 12 requires automatic logging of AI system events throughout the lifecycle. Supervisors may request those records.

Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, came into effect on 1 August 2024. It is the first comprehensive legal framework for AI anywhere in the world, and its obligations apply in phases through 2027. For financial firms, the most important rules concern high-risk AI systems. These include Article 12’s automatic logging requirement, Article 14’s human oversight obligation, and Annex III’s classification of credit assessment, insurance underwriting, and access to financial services as high-risk use cases. Firms deploying AI in those workflows must maintain records of AI system events.

At a Glance

EU AI ActInformation
Full nameRegulation (EU) 2024/1689 of the European Parliament and of the Council
Issued byEuropean Parliament and Council of the EU
Came into effect1 August 2024
Prohibited AI systems apply2 February 2025
GPAI obligations apply2 August 2025
High-risk AI (Annex III) applies2 August 2026
High-risk AI (Annex I) applies2 August 2027
Who it coversAI providers and deployers operating in the EU, or whose AI output is used in the EU
Key obligation for financial firmsArticle 12: automatic logging of events throughout a high-risk AI system’s lifecycle
Supervised byAI Office (European Commission); national market surveillance authorities

Who It Applies To

Providers are organizations that develop an AI system and place it on the EU market, including non-EU providers whose systems are used in the EU. Providers of high-risk systems bear the majority of obligations: risk management, technical documentation, logging design, and conformity assessment.

Deployers are organizations that use an AI system in a professional capacity. For example, a financial firm using a vendor’s credit-scoring AI is a deployer. Deployers of high-risk systems have their own obligations: maintaining logs the system generates, conducting fundamental rights impact assessments for certain use cases, and ensuring human oversight is in place.

General-purpose AI (GPAI) model providers (those building foundation models such as large language models) face obligations covering technical documentation, copyright compliance, and sometimes additional systemic-risk requirements. This may include adversarial testing, incident reporting, and cybersecurity measures. GPAI providers and the firms that deploy their models each carry their own compliance obligations. For most financial firms, what matters is whether their specific use case falls into a high-risk category, not which underlying model they use.

Risk Tiers

The Act classifies AI systems into four categories.

Prohibited (Chapter II, Article 5). Certain AI practices are banned outright: social scoring systems, manipulative AI designed to distort behavior, real-time biometric surveillance in public spaces (with narrow law enforcement exceptions), and AI that exploits vulnerable groups. These prohibitions applied from 2 February 2025.

High-risk (Chapter III, Annex III). AI systems in designated use cases must meet requirements for risk management, technical documentation, logging, and human oversight. For financial firms, high-risk use cases include credit assessment, insurance underwriting, and AI that determines access to financial products.

Limited risk. Chatbots and similar systems must inform users they are interacting with AI.

Minimal risk. The majority of commercial AI applications. No additional obligations.

Annex III: High-Risk Use Cases for Financial Firms

Relevant Annex III use cases include AI used for credit decisions, life and health insurance underwriting, access to financial products, employment decisions, and legal analysis. AI that profiles individuals in these use cases is always considered high risk. Firms claiming an Annex III exception must document that determination before the system is placed into service.

Article 12: The Logging Obligation

Article 12 requires high-risk AI systems to automatically record events relevant for identifying risks and substantial modifications throughout the system’s lifecycle.

At minimum, logging must enable identification of:

  • When the system was in operation, including the start and end of each period of use
  • The reference database used by the AI system to check or verify information during operation
  • The information the AI used to produce a risk rating or make a decision about an individual
  • The identity of individuals involved in result verification where human review is required

For a regulated financial firm, this means AI used in credit decisions, insurance underwriting, or access to financial services must generate records that can be produced to a supervisor on request. These records are an additional requirement alongside existing MiFID II and MAR communications retention requirements.

Article 14: Human Oversight

Article 14 requires deployers of high-risk AI systems to ensure that human oversight is operationally in place. Deployers must:

  • Assign individuals with the competence and authority to monitor, intervene, override, or stop the AI system
  • Monitor the system's operation and report serious incidents to the provider
  • Guard against automation bias: the risk that reviewers approve AI outputs without genuine scrutiny

Human oversight is not a compliance checkbox. Supervisors assessing an AI-related incident will look for evidence that oversight was exercised in practice, not just described in a policy.

Where AI Activity Retention Fits

The AI Act’s logging requirement applies at the system level, requiring high risk AI systems to generate records. The Act does not directly address what happens when the records are created, including retention period, the storage format, searchability, or how they are produced during exams or legal proceedings.

That gap is addressed by existing financial communications regulations.

Article 12 records are business records. For regulated financial firms, AI execution records generated by high-risk AI systems — the prompts submitted, the responses returned, the data inputs that influenced a credit decision, the tool calls an agent made — are the kind of records that examiners and litigants request. Retaining only an event log, without the underlying AI execution record, may satisfy Article 12 while leaving firms unable to reconstruct what occurred.

The execution record is broader than the event log. A system event log records that the AI ran and what inputs it received. An AI execution record captures what the AI actually did: the full prompt, the model’s response, any tool calls made, any data retrieved, and the execution context that determined what the AI was capable of doing at the time. The distinction matters when a regulator asks not just “did the AI run?” but “what did it do, and what could it have done?”

MiFID II and DORA apply simultaneously. For EU investment firms, the AI Act’s logging obligation runs alongside MiFID II’s communications retention requirements and DORA’s ICT risk management framework. Where AI supports regulated activities, such as client communications, order flow analysis, or investment decisions, the MiFID II record and the AI execution record may both be required. A firm that captures the resulting communication but not the AI interaction that produced it may have a gap in its MiFID II archive.

How Comma Addresses EU AI Act Obligations

AI activity retention for high risk AI. Comma captures the full AI execution record, including prompts, responses, tool calls, agent actions, and execution context such as the harness, model version, system prompt, and available tools. This record satisfies Article 12’s logging requirement and gives supervisors the reconstruction context they need.

Execution context capture. Comma captures execution context alongside each captured event: which AI model ran, under what system prompt, with what tool surface, through what execution harness. A firm can demonstrate not just what its AI did, but what it was configured to do and what it was permitted to do when it did it.

Turn-by-turn review for human oversight. Comma surfaces AI activity for compliance reviewers in a turn-by-turn review format. Each interaction is presented as a reviewable record with the full prompt, response, and any tool calls or agent actions on that turn. Reviewers can flag interactions, escalate for additional review, and document supervision decisions.

Cross-channel reconstruction context. Where AI is used alongside regulated communications — a client email drafted with AI assistance, an investment recommendation informed by an AI analysis — Comma captures both the AI execution record and the communications record in a single archive. The cross-channel timeline gives supervisors and reviewers complete reconstruction context without manual correlation across separate systems.

Capability summary:

  • Tool-call capture with full request, response, timing, and identity — Available now via Arc Relay
  • Execution context capture (harness identity, model identity, system prompt, tool surface) — Available now via Arc Relay for MCP-driven flows; demo available for enterprise and self-hosted AI
  • ChatGPT Enterprise, M365 Copilot, and Claude Enterprise AI capture — Demo available
  • Agent-run reconstruction and cross-channel timeline — Demo available
  • Turn-by-turn review for compliance supervisors — Demo available

FAQ about the EU AI Act

Does the EU AI Act apply to non-EU financial firms?
Yes, where the AI system's output is used in the EU. A US-based asset manager using AI to make decisions affecting EU clients is in scope. So is a non-EU provider placing an AI system on the EU market. The Act follows the output, not the origin.
When do high-risk AI obligations actually kick in for financial firms?
Most high-risk AI provisions under Annex III, including Article 12 logging and Article 14 human oversight, apply from 2 August 2026. Firms using AI for credit assessment, insurance, or access to financial services should be preparing now. Logging infrastructure, oversight procedures, and technical documentation all require lead time.
Is a large language model used to draft client communications high-risk?
Not automatically. The high-risk classification depends on the use case, not the underlying technology. An LLM used to draft a client email is generally not high-risk. An LLM integrated into a credit decision workflow or insurance underwriting is likely high-risk under Annex III. The firm deploying the AI, not the model provider, is responsible for that assessment.
What is the relationship between GPAI models and high-risk AI obligations?
GPAI model providers have their own obligations under the Act. A financial firm deploying those models in a high-risk use case remains responsible for its own logging and oversight obligations. The GPAI provider's compliance does not discharge the deploying firm's obligations. Both layers apply.
How does the EU AI Act interact with MiFID II and DORA?
All three apply simultaneously to EU investment firms. MiFID II governs retention of communications relating to financial instruments. DORA governs operational resilience of the ICT systems supporting those activities. The AI Act adds logging and oversight obligations for high-risk AI in those workflows. A single AI-assisted communication can trigger all three: a MiFID II record, a DORA event log, and an AI Act execution record. Firms that treat these as separate programs will have gaps.
What is a fundamental rights impact assessment and who must conduct one?
Article 27 requires deployers of certain high-risk AI systems to conduct a fundamental rights impact assessment before deployment. This applies to public bodies and private operators in areas including credit, insurance, and essential services. The assessment must document the system's purpose, the population affected, the rights at risk, and steps to mitigate harm. It must be registered in the EU database and provided to authorities on request.
Are there lighter-touch obligations for smaller firms?
Yes. The AI Act includes provisions to reduce compliance costs for small and medium-sized enterprises (SMEs). National regulatory sandboxes allow AI testing outside normal regulatory structures, with priority access for SMEs at no charge. Fees must be proportional to firm size. The Commission is developing simplified documentation forms for small and microenterprises. These provisions reduce costs but do not change underlying obligations. A small firm deploying AI in a high-risk use case must still meet logging and oversight requirements.

See how Comma keeps you compliant

Last updated: