Spec section affected
§1 Problem, spec/trace-v0.2.md, line 61.
Problem
The line reads:
The EU AI Act mandates tamper-evident logging for high-risk AI (Article 12); under the current provisional timeline those obligations apply from around December 2027.
Two things are wrong with it, and the first matters more than the date.
Article 12 does not mandate tamper-evident logging. Article 12, titled "Record-keeping", opens: "High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system." Paragraph 2 requires that logging capabilities enable the recording of events relevant to identifying an Article 79(1) risk or a substantial modification, to the post-market monitoring referred to in Article 72, and to the monitoring referred to in Article 26(5). Paragraph 3 sets minimum log content for the systems in point 1(a) of Annex III. The obligation is that the system allow recording, and nothing in the provision speaks to the integrity of what is recorded.
The word "tamper" does not occur anywhere in Regulation (EU) 2024/1689, annexes included. Tamper-evidence is a property this specification supplies, and attributing it to the Regulation is the same class of error as the Annex IV attribution corrected in #310, which is a technical requirement read into a provision that does not impose it.
The applicability clause is superseded. Regulation (EU) 2026/1744 carries "of 8 July 2026" in its title line and "Done at Strasbourg, 8 July 2026" in its concluding formula, was published in the Official Journal on 24 July 2026, and its Article 4 provides that it enters into force on the third day following publication. The timeline is therefore no longer provisional. Its Article 1 point (40)(b) replaces Article 113, third paragraph, point (c) with: "Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I". Article 12 sits in Chapter III Section 2, so it takes those dates and the single date in the current text is no longer correct.
Since the surrounding paragraph is about who lands first, a third date is worth carrying: Article 1 point (39)(a) replaces Article 111(2), and the replacement requires providers and deployers of high-risk AI systems intended to be used by public authorities to comply by 2 August 2030.
Proposed change
Offered as a shape rather than as authored normative text, since this sits in the specification rather than in docs/.
The EU AI Act requires that high-risk AI systems technically allow the automatic recording of events over their lifetime (Article 12). Those obligations sit in Chapter III Section 2 and apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I, with providers and deployers of systems intended to be used by public authorities required to comply by 2 August 2030. Tamper-evidence is what this specification adds. Frameworks already in force, DORA for financial entities, HIPAA for healthcare, carry equivalent audit-trail requirements today.
Backward compatibility
Prose in §1 only. No field, value, wire format or algorithm changes, and no conformance vector is affected.
Motivation
§1 is where a reader forms their picture of what the Regulation requires and what this specification adds on top of it. As written it hands them a requirement the Regulation does not impose, and a date that has been superseded since July. Correcting it keeps the distinction the project already makes elsewhere, which is that the standard supplies properties the law does not, and it keeps the citation checkable by the next reader.
The comparison table row at line 56, "EU AI Act Annex IV / Article 12", is correct as it stands, since Annex IV is the documentation schedule doing documentation work there. It should not be swept by analogy with this correction.
Related issues or PRs
Raised by @lywinged in review of #310. Related follow-up in #313.
Source verification for this issue was AI-assisted. Article 12 and Article 113 of Regulation (EU) 2024/1689, and Article 1 points (39)(a) and (40)(b) and Article 4 of Regulation (EU) 2026/1744, were read against the Official Journal text before being quoted.
Spec section affected
§1 Problem,
spec/trace-v0.2.md, line 61.Problem
The line reads:
Two things are wrong with it, and the first matters more than the date.
Article 12 does not mandate tamper-evident logging. Article 12, titled "Record-keeping", opens: "High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system." Paragraph 2 requires that logging capabilities enable the recording of events relevant to identifying an Article 79(1) risk or a substantial modification, to the post-market monitoring referred to in Article 72, and to the monitoring referred to in Article 26(5). Paragraph 3 sets minimum log content for the systems in point 1(a) of Annex III. The obligation is that the system allow recording, and nothing in the provision speaks to the integrity of what is recorded.
The word "tamper" does not occur anywhere in Regulation (EU) 2024/1689, annexes included. Tamper-evidence is a property this specification supplies, and attributing it to the Regulation is the same class of error as the Annex IV attribution corrected in #310, which is a technical requirement read into a provision that does not impose it.
The applicability clause is superseded. Regulation (EU) 2026/1744 carries "of 8 July 2026" in its title line and "Done at Strasbourg, 8 July 2026" in its concluding formula, was published in the Official Journal on 24 July 2026, and its Article 4 provides that it enters into force on the third day following publication. The timeline is therefore no longer provisional. Its Article 1 point (40)(b) replaces Article 113, third paragraph, point (c) with: "Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I". Article 12 sits in Chapter III Section 2, so it takes those dates and the single date in the current text is no longer correct.
Since the surrounding paragraph is about who lands first, a third date is worth carrying: Article 1 point (39)(a) replaces Article 111(2), and the replacement requires providers and deployers of high-risk AI systems intended to be used by public authorities to comply by 2 August 2030.
Proposed change
Offered as a shape rather than as authored normative text, since this sits in the specification rather than in
docs/.Backward compatibility
Prose in §1 only. No field, value, wire format or algorithm changes, and no conformance vector is affected.
Motivation
§1 is where a reader forms their picture of what the Regulation requires and what this specification adds on top of it. As written it hands them a requirement the Regulation does not impose, and a date that has been superseded since July. Correcting it keeps the distinction the project already makes elsewhere, which is that the standard supplies properties the law does not, and it keeps the citation checkable by the next reader.
The comparison table row at line 56, "EU AI Act Annex IV / Article 12", is correct as it stands, since Annex IV is the documentation schedule doing documentation work there. It should not be swept by analogy with this correction.
Related issues or PRs
Raised by @lywinged in review of #310. Related follow-up in #313.
Source verification for this issue was AI-assisted. Article 12 and Article 113 of Regulation (EU) 2024/1689, and Article 1 points (39)(a) and (40)(b) and Article 4 of Regulation (EU) 2026/1744, were read against the Official Journal text before being quoted.