TwinEthosRequest access

Control

High-risk AI system without automatic event logging (traceability)

A high-risk AI system must technically allow automatic recording of events (logs) over its lifetime, at a level of traceability appropriate to its purpose, enabling risk identification, post-market monitoring, and operational monitoring.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI decisions cannot be reconstructed after the fact · control id cond.high-risk-ai-no-event-logging

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in European Union (EU); next date 2027-12-02.

The guard to add

Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.

An audit event emitted automatically by the service at the decision boundary, where model output becomes a status change, score, or response, rather than left to callers: decision_id, timestamp, model and resolved model_version, an input reference (a pointer rather than raw personal data where possible), the output, the operator or user identity, and any human verification. Events go to a central store (CloudWatch Logs, Log Analytics, Cloud Logging, Loki) whose retention is set explicitly in IaC, not left to a console default, and monitoring queries over those events flag risk situations and drift.

Where it goes: 1 application source code, 4 infrastructure-as-code, 10 logs and telemetry.

What reviewers look for: on each high-risk decision path, a structured log or audit insert (audit_log.insert, a structlog logger bound with decision_id, an OpenTelemetry span with gen_ai.request.model and gen_ai.response.model) written before or with set_status or save; and the receiving log group's retention set in IaC at 180 days or more (retention_in_days >= 180, or 0 on aws_cloudwatch_log_group for never-expire).

Example (Python + OpenAI SDK + structlog), before:

def decide(app):
    resp = client.chat.completions.create(model=MODEL, messages=eligibility_prompt(app))
    applications.set_status(app.id, parse_decision(resp))

After:

log = structlog.get_logger()   # TimeStamper processor adds the timestamp

def decide(app):
    decision_id = str(uuid.uuid4())
    resp = client.chat.completions.create(model=MODEL, messages=eligibility_prompt(app))
    status = parse_decision(resp)
    log.info('ai_decision', decision_id=decision_id, model=resp.model,
             input_ref=f'applications/{app.id}', output=status, operator=current_operator())
    applications.set_status(app.id, status, decision_id=decision_id)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.