Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, came into effect on 1 August 2024. It is the first comprehensive legal framework for AI anywhere in the world, and its obligations apply in phases through 2027. For financial firms, the most important rules concern high-risk AI systems. These include Article 12’s automatic logging requirement, Article 14’s human oversight obligation, and Annex III’s classification of credit assessment, insurance underwriting, and access to financial services as high-risk use cases. Firms deploying AI in those workflows must maintain records of AI system events.
At a Glance
| EU AI Act | Information |
|---|---|
| Full name | Regulation (EU) 2024/1689 of the European Parliament and of the Council |
| Issued by | European Parliament and Council of the EU |
| Came into effect | 1 August 2024 |
| Prohibited AI systems apply | 2 February 2025 |
| GPAI obligations apply | 2 August 2025 |
| High-risk AI (Annex III) applies | 2 August 2026 |
| High-risk AI (Annex I) applies | 2 August 2027 |
| Who it covers | AI providers and deployers operating in the EU, or whose AI output is used in the EU |
| Key obligation for financial firms | Article 12: automatic logging of events throughout a high-risk AI system’s lifecycle |
| Supervised by | AI Office (European Commission); national market surveillance authorities |
Who It Applies To
Providers are organizations that develop an AI system and place it on the EU market, including non-EU providers whose systems are used in the EU. Providers of high-risk systems bear the majority of obligations: risk management, technical documentation, logging design, and conformity assessment.
Deployers are organizations that use an AI system in a professional capacity. For example, a financial firm using a vendor’s credit-scoring AI is a deployer. Deployers of high-risk systems have their own obligations: maintaining logs the system generates, conducting fundamental rights impact assessments for certain use cases, and ensuring human oversight is in place.
General-purpose AI (GPAI) model providers (those building foundation models such as large language models) face obligations covering technical documentation, copyright compliance, and sometimes additional systemic-risk requirements. This may include adversarial testing, incident reporting, and cybersecurity measures. GPAI providers and the firms that deploy their models each carry their own compliance obligations. For most financial firms, what matters is whether their specific use case falls into a high-risk category, not which underlying model they use.
Risk Tiers
The Act classifies AI systems into four categories.
Prohibited (Chapter II, Article 5). Certain AI practices are banned outright: social scoring systems, manipulative AI designed to distort behavior, real-time biometric surveillance in public spaces (with narrow law enforcement exceptions), and AI that exploits vulnerable groups. These prohibitions applied from 2 February 2025.
High-risk (Chapter III, Annex III). AI systems in designated use cases must meet requirements for risk management, technical documentation, logging, and human oversight. For financial firms, high-risk use cases include credit assessment, insurance underwriting, and AI that determines access to financial products.
Limited risk. Chatbots and similar systems must inform users they are interacting with AI.
Minimal risk. The majority of commercial AI applications. No additional obligations.
Annex III: High-Risk Use Cases for Financial Firms
Relevant Annex III use cases include AI used for credit decisions, life and health insurance underwriting, access to financial products, employment decisions, and legal analysis. AI that profiles individuals in these use cases is always considered high risk. Firms claiming an Annex III exception must document that determination before the system is placed into service.
Article 12: The Logging Obligation
Article 12 requires high-risk AI systems to automatically record events relevant for identifying risks and substantial modifications throughout the system’s lifecycle.
At minimum, logging must enable identification of:
- When the system was in operation, including the start and end of each period of use
- The reference database used by the AI system to check or verify information during operation
- The information the AI used to produce a risk rating or make a decision about an individual
- The identity of individuals involved in result verification where human review is required
For a regulated financial firm, this means AI used in credit decisions, insurance underwriting, or access to financial services must generate records that can be produced to a supervisor on request. These records are an additional requirement alongside existing MiFID II and MAR communications retention requirements.
Article 14: Human Oversight
Article 14 requires deployers of high-risk AI systems to ensure that human oversight is operationally in place. Deployers must:
- Assign individuals with the competence and authority to monitor, intervene, override, or stop the AI system
- Monitor the system's operation and report serious incidents to the provider
- Guard against automation bias: the risk that reviewers approve AI outputs without genuine scrutiny
Human oversight is not a compliance checkbox. Supervisors assessing an AI-related incident will look for evidence that oversight was exercised in practice, not just described in a policy.
Where AI Activity Retention Fits
The AI Act’s logging requirement applies at the system level, requiring high risk AI systems to generate records. The Act does not directly address what happens when the records are created, including retention period, the storage format, searchability, or how they are produced during exams or legal proceedings.
That gap is addressed by existing financial communications regulations.
Article 12 records are business records. For regulated financial firms, AI execution records generated by high-risk AI systems — the prompts submitted, the responses returned, the data inputs that influenced a credit decision, the tool calls an agent made — are the kind of records that examiners and litigants request. Retaining only an event log, without the underlying AI execution record, may satisfy Article 12 while leaving firms unable to reconstruct what occurred.
The execution record is broader than the event log. A system event log records that the AI ran and what inputs it received. An AI execution record captures what the AI actually did: the full prompt, the model’s response, any tool calls made, any data retrieved, and the execution context that determined what the AI was capable of doing at the time. The distinction matters when a regulator asks not just “did the AI run?” but “what did it do, and what could it have done?”
MiFID II and DORA apply simultaneously. For EU investment firms, the AI Act’s logging obligation runs alongside MiFID II’s communications retention requirements and DORA’s ICT risk management framework. Where AI supports regulated activities, such as client communications, order flow analysis, or investment decisions, the MiFID II record and the AI execution record may both be required. A firm that captures the resulting communication but not the AI interaction that produced it may have a gap in its MiFID II archive.
How Comma Addresses EU AI Act Obligations
AI activity retention for high risk AI. Comma captures the full AI execution record, including prompts, responses, tool calls, agent actions, and execution context such as the harness, model version, system prompt, and available tools. This record satisfies Article 12’s logging requirement and gives supervisors the reconstruction context they need.
Execution context capture. Comma captures execution context alongside each captured event: which AI model ran, under what system prompt, with what tool surface, through what execution harness. A firm can demonstrate not just what its AI did, but what it was configured to do and what it was permitted to do when it did it.
Turn-by-turn review for human oversight. Comma surfaces AI activity for compliance reviewers in a turn-by-turn review format. Each interaction is presented as a reviewable record with the full prompt, response, and any tool calls or agent actions on that turn. Reviewers can flag interactions, escalate for additional review, and document supervision decisions.
Cross-channel reconstruction context. Where AI is used alongside regulated communications — a client email drafted with AI assistance, an investment recommendation informed by an AI analysis — Comma captures both the AI execution record and the communications record in a single archive. The cross-channel timeline gives supervisors and reviewers complete reconstruction context without manual correlation across separate systems.
Capability summary:
- Tool-call capture with full request, response, timing, and identity — Available now via Arc Relay
- Execution context capture (harness identity, model identity, system prompt, tool surface) — Available now via Arc Relay for MCP-driven flows; demo available for enterprise and self-hosted AI
- ChatGPT Enterprise, M365 Copilot, and Claude Enterprise AI capture — Demo available
- Agent-run reconstruction and cross-channel timeline — Demo available
- Turn-by-turn review for compliance supervisors — Demo available
