AI_ACTArt. 12voice-validated

AI_ACT Art12: Art. 12

AI_ACT

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the duration of the lifetime of the system. The logging capabilities shall ensure a level of traceability of the AI system's functioning that is appropriate to the intended purpose, including for post-incident investigation, fundamental rights impact assessment, and supervisory authority access.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T1070.0011.0 The control mandates automatic recording of events. Clearing Windows Event Logs directly counters this requirement, hindering post-incident investigation. Art. 12 requires traceability for investigation.
100%
T1070.0021.0 The control mandates automatic recording of events. Clearing Linux/macOS Event Logs directly counters this requirement, hindering post-incident investigation. Art. 12 requires traceability for investigation.
100%
T1070.0030.9 The control requires event recording for traceability. Clearing command history removes critical forensic evidence, directly impeding post-incident investigation as per Art. 12.
90%
T1070.0040.9 The control mandates event recording. Deleting log files directly undermines the traceability and post-incident investigation capabilities required by Art. 12.
90%
T1562.0010.8 The control requires traceability. Disabling system firewalls can prevent logging of network activity, reducing the system's ability to record events for post-incident investigation as per Art. 12.
80%
T1562.0040.8 The control requires traceability. Disabling antivirus can prevent the logging of malicious activity, reducing the system's ability to record events for post-incident investigation as per Art. 12.
80%
T14850.9 The control mandates event recording and traceability. Data destruction, especially of logs or systems containing logs, directly prevents post-incident investigation as required by Art. 12.
90%
T14900.9 The control requires traceability for post-incident investigation. Inhibiting system recovery, including log backups, directly undermines the ability to reconstruct events as per Art. 12.
90%
T10030.8 The control requires automatic recording of events. OS credential dumping is a critical event that must be logged to ensure traceability and aid post-incident investigation as per Art. 12.
80%
T10870.8 The control requires event recording. Account discovery activities should be logged to maintain traceability and support post-incident investigation, as specified in Art. 12.
80%
T10710.8 The control requires event recording. Command and Control (C2) communications, even if encrypted, should generate network logs to ensure traceability and aid post-incident investigation as per Art. 12.
80%
T10410.8 The control requires event recording. Exfiltration over C2 channels should be detectable via network logs to ensure traceability and aid post-incident investigation as per Art. 12.
80%
T1547.0010.8 The control requires event recording. The installation of persistence mechanisms, such as registry run keys, must be logged to ensure traceability and aid post-incident investigation as per Art. 12.
80%
T1136.0010.8 The control requires event recording. The creation of local accounts is a security-relevant event that must be logged to ensure traceability and aid post-incident investigation as per Art. 12.
80%
T10590.8 The control requires event recording. Execution of commands via scripting interpreters must be logged to ensure traceability and aid post-incident investigation as per Art. 12.
80%

Defending mitigations · 5

MitigationWhat it doesConfidence
M10471.0 The control explicitly mandates 'automatic recording of events (logs)'. Implementing robust audit mechanisms directly fulfills this requirement for traceability and post-incident investigation as per Art. 12.
100%
M10280.9 The control requires event recording. Proper operating system configuration includes enabling and securing logging features, which is essential for traceability and post-incident investigation as per Art. 12.
90%
M10380.9 The control requires event recording. Effective user account management ensures that all account-related activities are logged, providing critical traceability for post-incident investigation as per Art. 12.
90%
M10490.8 The control requires event recording. Antivirus/antimalware solutions log detected threats and actions, contributing to the overall traceability needed for post-incident investigation as per Art. 12.
80%
M10390.8 The control requires event recording. Data Loss Prevention (DLP) systems log attempts at data exfiltration, providing crucial traceability for post-incident investigation and compliance with Art. 12.
80%

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-2231.0 The control requires 'automatic recording of events'. Omission of security-relevant information directly violates this, preventing traceability and post-incident investigation as per Art. 12.
100%
CWE-7781.0 The control mandates 'automatic recording of events' and 'traceability'. Insufficient logging directly undermines these requirements, hindering post-incident investigation as per Art. 12.
100%
CWE-3450.9 The control requires traceability for post-incident investigation. Insufficient verification of data authenticity allows log tampering, compromising the integrity and reliability of recorded events as per Art. 12.
90%
CWE-2840.9 The control requires event recording for traceability. Improper access control on log files allows unauthorized modification or deletion, directly undermining post-incident investigation as per Art. 12.
90%
CWE-2000.8 The control requires event recording. Exposure of sensitive information in logs to unauthorized actors can compromise investigations or violate privacy, hindering the intended purpose of traceability as per Art. 12.
80%
CWE-5320.8 The control requires event recording for traceability. Inclusion of excessive sensitive information in log files can complicate sharing and analysis, potentially hindering post-incident investigation as per Art. 12.
80%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0185 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation