EU AI Act Article 12 Evidence Pack

Article‑12 Evidence Pack gives auditors and procurement a clear, exportable record of model behavior and decision provenance. This public preview shows the structure — full technical details are available under NDA.

What Article 12 Requires (Plain Language)

High-risk AI systems must technically allow automatic event logging over the system's lifetime, with logging that enables traceability of relevant events appropriate to the intended purpose (inputs, outputs, decisions, errors). Providers/deployers must be able to keep and surface those records.

Our Evidence Pack provides the technical infrastructure and documentation to meet these requirements with minimal integration effort.

Public Preview (1‑page)

See what auditors and procurement will receive — enough to evaluate compliance fit before requesting the full pack.

Public Preview includes:

  • • Sample event log schema (sanitized)
  • • One‑page NIST AI RMF crosswalk summary
  • • Redacted example event (token‑level signals)
  • • High‑level implementation checklist (no secrets)

What's inside:

  • Event-log schema (per-token/per-turn)
  • Export formats (JSON/CSV)
  • Retention policy options (≥6 months)
  • NIST AI RMF cross-walk (GOV/MAP/MEASURE/MANAGE)
  • Sample DPIA appendix stubs
  • Operational runbooks and implementation guides

Why it matters: Article 12 expects automatically generated logs under your control; we provide the artifacts to demonstrate that.(EUR-Lex),(NIST Publications)

Event Log Schema (JSON)

Structured logging format designed to slot into your SIEM systems.

  • • Timestamp, request_id, model_id + version
  • • Provider, route_decision, safety_event details
  • • Input/output bytes, latency_ms, integrity_hash
  • • Trigger/block reasons with policy context
→ Supports traceability + lifetime logging expectations

Retention & Export Playbook

Configurable retention with audit-ready export capabilities.

  • • Sane defaults (6-24 months) with custom overrides
  • • Customer-controlled retention buckets
  • • One-click export to CSV/Parquet formats
  • • Regulator/auditor-ready documentation
→ "Keep the records; produce on request"

NIST AI RMF Crosswalk

Alignment with US framework for dual compliance benefits.

  • • Mapping to Transparency/Explainability functions
  • • Generative AI Profile (AI-600-1) alignment
  • • Internal controls framework integration
  • • Cross-jurisdictional compliance support
→ Same telemetry, multiple framework compliance

Operational Runbooks

Step-by-step procedures for compliance operations.

  • • Verify proxy logging configuration
  • • Hash/verify artifacts for integrity
  • • Redact PII before third-party sharing
  • • Incident response and audit procedures
→ Practical implementation guidance

Security Posture & Scope

Deployment Security

  • Pure API proxy mode (no model weights)
  • Read-only adapters when you host models
  • • Never modify models in either deployment mode
  • • Per-request logs, not model internals exposure

Compliance Scope

  • • We provide the governance/observability layer
  • • Article 12 obligations remain with provider/deployer
  • • Our pack gives you the data and procedures
  • • NIST RMF transparency documentation alignment

Optional: ISO/IEC 42001 Alignment

Management system practices alignment available upon request. (We say "aligned with," not "certified" until formal certification.)

Get Your Evidence Pack

Ready to implement Article 12 compliance? Request the complete evidence pack with sample logs, implementation guides, and framework mappings.

JSON Schema
Event structure
Sample Logs
Redacted examples
NIST Crosswalk
Framework mapping

Contact: compliance@pleromaworks.com

Response time: 1-2 business days for evidence pack delivery

Standards Alignment: Aligned to EU AI Act Article‑12 record‑keeping and the NIST AI Risk Management Framework.