Regulations
What regulations require of AI logs, and how much of that Logsiegel covers
Logsiegel is an evidence layer for AI systems and agents, not a compliance product. But many regulations ask for exactly what a tamper-evident action trail delivers: traceable, unaltered records you can show. These pages sort that out per regulation, with references, and say just as plainly what Logsiegel does not cover.
Every page follows the same format: who the regulation applies to, what it literally requires in terms of records (with a reference), what Logsiegel contributes today, what is in progress, what Logsiegel does not do, and how you actually put it to work. No conformity promises. Whether a receipt is enough for your review is decided by your review.
EU AI Act
Automatic event logs over the lifetime of a high-risk system, retention by provider and deployer, traceability for supervision and post-market monitoring.
Read the page →GDPR
Accountability, integrity of processing, contesting automated decisions, and the apparent contradiction between the duty to erase and an append-only trail.
Read the page →DORA
Detecting anomalous activities, recording all ICT-related incidents, logging under the regulatory technical standards, and audit rights against ICT third-party providers that use AI.
Read the page →NIS2 / critical infrastructure
Risk management measures you have to evidence, staged incident reporting, supply chain security, and the logging requirements the German Federal Office for Information Security sets for operators of critical installations such as hospitals.
Read the page →ISO/IEC 27001
Producing, protecting and retaining logs, collecting evidence so that it can hold up in court, protecting records against falsification, synchronizing clocks.
Read the page →ISO/IEC 42001
The first management system built specifically for AI: event logs at least during use, operation and monitoring, handling of incidents, accountability toward affected people.
Read the page →GoBD
Unalterability, traceability and verifiability, logging of changes, process documentation: the principles apply just as much when it is not a person but an agent that captures documents or prepares postings.
Read the page →eIDAS
Not a duty but an offer: eIDAS says what evidentiary weight qualified time stamps and qualified electronic ledgers carry. Logsiegel is built so that it can plug into that.
Read the page →At a glance
| Regulation | Requirement | Logsiegel today |
|---|---|---|
| EU AI Act | Automatic logging (Art. 12), retention of at least 6 months by the provider (Art. 19) and the deployer (Art. 26(6)) | Tamper-evident event trail, provable retention, single-entry receipts, dossier export |
| GDPR | Accountability (Art. 5(2)), integrity (Art. 32), erasure (Art. 17), contesting automated decisions (Art. 22) | A receipt per decision, erasure by crypto-shredding without breaking the chain, no raw data in the trail |
| DORA | Detection (Art. 10), incident recording (Art. 17), logging protected against alteration (RTS 2024/1774, Art. 12), third-party auditability (Art. 28 ff.) | A tamper-evident trail per AI action, receipts for supervisors and clients, incident reconstruction |
| NIS2 / critical infrastructure | Measures including incident handling and supply chain (Art. 21), reporting within 24 h / 72 h / 1 month (Art. 23), logging under BSI IT-Grundschutz | Provable records of what the AI did, for incident reports and audits, receipts for suppliers and authorities |
| ISO/IEC 27001 | Logging protected against tampering (A.8.15), collection of evidence (A.5.28), protection of records (A.5.33), time (A.8.17) | Tamper-evident logs as ISMS evidence, receipts as secured evidence |
| ISO/IEC 42001 | AI system event logs (A.6.2.8), operation and monitoring (A.6.2.6), incidents (A.8.4) | A tamper-evident event trail per AI action, receipts for affected people and auditors |
| GoBD | Unalterability (para. 58 et seq.), traceability (para. 30 et seq.), change log, process documentation (para. 151 et seq.) | A provable record of what the agent did, when, and with which document, alongside the accounting system |
| eIDAS | Legal effect of time stamps (Art. 41), presumption of ordering and integrity for qualified ledgers (Art. 45k), requirements (Art. 45l) | Signed checkpoints with the operator's own time; qualified anchoring planned |
Legal status September 2026. This page is a technical assessment by the project, not legal advice and not a conformity statement. Please check the references against the current text of the law. Corrections welcome via GitHub issue.