Logsiegel

Regulations

What regulations require of AI logs, and how much of that Logsiegel covers

Logsiegel is an evidence layer for AI systems and agents, not a compliance product. But many regulations ask for exactly what a tamper-evident action trail delivers: traceable, unaltered records you can show. These pages sort that out per regulation, with references, and say just as plainly what Logsiegel does not cover.

Every page follows the same format: who the regulation applies to, what it literally requires in terms of records (with a reference), what Logsiegel contributes today, what is in progress, what Logsiegel does not do, and how you actually put it to work. No conformity promises. Whether a receipt is enough for your review is decided by your review.

EU AI Act

Automatic event logs over the lifetime of a high-risk system, retention by provider and deployer, traceability for supervision and post-market monitoring.

Read the page →

GDPR

Accountability, integrity of processing, contesting automated decisions, and the apparent contradiction between the duty to erase and an append-only trail.

Read the page →

DORA

Detecting anomalous activities, recording all ICT-related incidents, logging under the regulatory technical standards, and audit rights against ICT third-party providers that use AI.

Read the page →

NIS2 / critical infrastructure

Risk management measures you have to evidence, staged incident reporting, supply chain security, and the logging requirements the German Federal Office for Information Security sets for operators of critical installations such as hospitals.

Read the page →

ISO/IEC 27001

Producing, protecting and retaining logs, collecting evidence so that it can hold up in court, protecting records against falsification, synchronizing clocks.

Read the page →

ISO/IEC 42001

The first management system built specifically for AI: event logs at least during use, operation and monitoring, handling of incidents, accountability toward affected people.

Read the page →

GoBD

Unalterability, traceability and verifiability, logging of changes, process documentation: the principles apply just as much when it is not a person but an agent that captures documents or prepares postings.

Read the page →

eIDAS

Not a duty but an offer: eIDAS says what evidentiary weight qualified time stamps and qualified electronic ledgers carry. Logsiegel is built so that it can plug into that.

Read the page →

At a glance

RegulationRequirementLogsiegel today
EU AI ActAutomatic logging (Art. 12), retention of at least 6 months by the provider (Art. 19) and the deployer (Art. 26(6))Tamper-evident event trail, provable retention, single-entry receipts, dossier export
GDPRAccountability (Art. 5(2)), integrity (Art. 32), erasure (Art. 17), contesting automated decisions (Art. 22)A receipt per decision, erasure by crypto-shredding without breaking the chain, no raw data in the trail
DORADetection (Art. 10), incident recording (Art. 17), logging protected against alteration (RTS 2024/1774, Art. 12), third-party auditability (Art. 28 ff.)A tamper-evident trail per AI action, receipts for supervisors and clients, incident reconstruction
NIS2 / critical infrastructureMeasures including incident handling and supply chain (Art. 21), reporting within 24 h / 72 h / 1 month (Art. 23), logging under BSI IT-GrundschutzProvable records of what the AI did, for incident reports and audits, receipts for suppliers and authorities
ISO/IEC 27001Logging protected against tampering (A.8.15), collection of evidence (A.5.28), protection of records (A.5.33), time (A.8.17)Tamper-evident logs as ISMS evidence, receipts as secured evidence
ISO/IEC 42001AI system event logs (A.6.2.8), operation and monitoring (A.6.2.6), incidents (A.8.4)A tamper-evident event trail per AI action, receipts for affected people and auditors
GoBDUnalterability (para. 58 et seq.), traceability (para. 30 et seq.), change log, process documentation (para. 151 et seq.)A provable record of what the agent did, when, and with which document, alongside the accounting system
eIDASLegal effect of time stamps (Art. 41), presumption of ordering and integrity for qualified ledgers (Art. 45k), requirements (Art. 45l)Signed checkpoints with the operator's own time; qualified anchoring planned

Legal status September 2026. This page is a technical assessment by the project, not legal advice and not a conformity statement. Please check the references against the current text of the law. Corrections welcome via GitHub issue.