Records of AI system operation are automatically generated entries about its use – when the system was activated, what inputs it worked with, what outputs it provided, and who intervened in the decision-making. For high-risk systems, this is an obligation whose purpose is traceability: without records, it is impossible to investigate an incident, demonstrate that human oversight was carried out, or defend a decision before a supervisory authority or a court. They should be kept for a reasonable period corresponding to the purpose of the system. At the same time, however, the records themselves may contain personal data, and so they are subject to data protection rules, including restrictions on access and deletion deadlines. Companies must reconcile these two requirements already at the design stage of the solution. The scope of the data recorded is therefore determined in advance, not only after the first incident.
See also: AI system monitoring, AI system incident, Data retention and deletion.