AI_ACTArt. 12voice-validated
AI_ACT Art12: Art. 12
AI_ACT
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
High-risk AI systems shall technically allow for the automatic recording of events (logs) over the duration of the lifetime of the system. The logging capabilities shall ensure a level of traceability of the AI system's functioning that is appropriate to the intended purpose, including for post-incident investigation, fundamental rights impact assessment, and supervisory authority access.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1070.001 | 1.0 The control mandates automatic recording of events. Clearing Windows Event Logs directly counters this requirement, hindering post-incident investigation. Art. 12 requires traceability for investigation. | 100% |
| T1070.002 | 1.0 The control mandates automatic recording of events. Clearing Linux/macOS Event Logs directly counters this requirement, hindering post-incident investigation. Art. 12 requires traceability for investigation. | 100% |
| T1070.003 | 0.9 The control requires event recording for traceability. Clearing command history removes critical forensic evidence, directly impeding post-incident investigation as per Art. 12. | 90% |
| T1070.004 | 0.9 The control mandates event recording. Deleting log files directly undermines the traceability and post-incident investigation capabilities required by Art. 12. | 90% |
| T1562.001 | 0.8 The control requires traceability. Disabling system firewalls can prevent logging of network activity, reducing the system's ability to record events for post-incident investigation as per Art. 12. | 80% |
| T1562.004 | 0.8 The control requires traceability. Disabling antivirus can prevent the logging of malicious activity, reducing the system's ability to record events for post-incident investigation as per Art. 12. | 80% |
| T1485 | 0.9 The control mandates event recording and traceability. Data destruction, especially of logs or systems containing logs, directly prevents post-incident investigation as required by Art. 12. | 90% |
| T1490 | 0.9 The control requires traceability for post-incident investigation. Inhibiting system recovery, including log backups, directly undermines the ability to reconstruct events as per Art. 12. | 90% |
| T1003 | 0.8 The control requires automatic recording of events. OS credential dumping is a critical event that must be logged to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
| T1087 | 0.8 The control requires event recording. Account discovery activities should be logged to maintain traceability and support post-incident investigation, as specified in Art. 12. | 80% |
| T1071 | 0.8 The control requires event recording. Command and Control (C2) communications, even if encrypted, should generate network logs to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
| T1041 | 0.8 The control requires event recording. Exfiltration over C2 channels should be detectable via network logs to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
| T1547.001 | 0.8 The control requires event recording. The installation of persistence mechanisms, such as registry run keys, must be logged to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
| T1136.001 | 0.8 The control requires event recording. The creation of local accounts is a security-relevant event that must be logged to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
| T1059 | 0.8 The control requires event recording. Execution of commands via scripting interpreters must be logged to ensure traceability and aid post-incident investigation as per Art. 12. | 80% |
Defending mitigations · 5
| Mitigation | What it does | Confidence |
|---|---|---|
| M1047 | 1.0 The control explicitly mandates 'automatic recording of events (logs)'. Implementing robust audit mechanisms directly fulfills this requirement for traceability and post-incident investigation as per Art. 12. | 100% |
| M1028 | 0.9 The control requires event recording. Proper operating system configuration includes enabling and securing logging features, which is essential for traceability and post-incident investigation as per Art. 12. | 90% |
| M1038 | 0.9 The control requires event recording. Effective user account management ensures that all account-related activities are logged, providing critical traceability for post-incident investigation as per Art. 12. | 90% |
| M1049 | 0.8 The control requires event recording. Antivirus/antimalware solutions log detected threats and actions, contributing to the overall traceability needed for post-incident investigation as per Art. 12. | 80% |
| M1039 | 0.8 The control requires event recording. Data Loss Prevention (DLP) systems log attempts at data exfiltration, providing crucial traceability for post-incident investigation and compliance with Art. 12. | 80% |
Underlying weaknesses · 6
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-223 | 1.0 The control requires 'automatic recording of events'. Omission of security-relevant information directly violates this, preventing traceability and post-incident investigation as per Art. 12. | 100% |
| CWE-778 | 1.0 The control mandates 'automatic recording of events' and 'traceability'. Insufficient logging directly undermines these requirements, hindering post-incident investigation as per Art. 12. | 100% |
| CWE-345 | 0.9 The control requires traceability for post-incident investigation. Insufficient verification of data authenticity allows log tampering, compromising the integrity and reliability of recorded events as per Art. 12. | 90% |
| CWE-284 | 0.9 The control requires event recording for traceability. Improper access control on log files allows unauthorized modification or deletion, directly undermining post-incident investigation as per Art. 12. | 90% |
| CWE-200 | 0.8 The control requires event recording. Exposure of sensitive information in logs to unauthorized actors can compromise investigations or violate privacy, hindering the intended purpose of traceability as per Art. 12. | 80% |
| CWE-532 | 0.8 The control requires event recording for traceability. Inclusion of excessive sensitive information in log files can complicate sharing and analysis, potentially hindering post-incident investigation as per Art. 12. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0185 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation