The European regulation speaks of automatic event recording, logs kept for at least six months and AI literacy. It applies to companies in Brazil when the system's output is used in the Union. And the timeline changed in July 2026. What goes in the log, what must stay out, and how to prove nobody touched it.
Published 2026-10-07 by Rafael Hickmann, Founder, Atlasberg. 8 minute read.
Article 2(1)(c) of Regulation (EU) 2024/1689 applies the AI Act to providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. It does not matter where the server is, or where the company is. What matters is where the output is used.
In practice this catches three profiles of Brazilian company. The bank or fintech serving customers in Portugal and using AI in credit or customer service. The SaaS with European clients whose product has a model built in. And the Brazilian subsidiary of a European group, which will hear the requirement from headquarters before it hears from any regulator. It is also worth remembering that the Brazilian AI bill under discussion in Congress was written with the European text in view, so the same records tend to serve at home.
On July 8, 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was signed; it was published in the Official Journal on July 24 and has been in force since the 27th. It postponed the high-risk obligations and rewrote a few articles. Anyone who planned compliance against the 2024 calendar needs to redo the math.
A postponement is not a waiver. An audit trail only works as evidence if it has history, and whoever starts building the trail in December 2027 will arrive with no past. The new date is when the obligation bites. The time to have the records running is now.
Article 12(1) says high-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. Paragraph 2 says what those logs are for: identifying situations that may present a risk or amount to a substantial modification, facilitating post-market monitoring, and allowing the deployer to monitor the operation of the system. Paragraph 3 sets a minimum for biometric systems, including the period of each use, the reference database checked and the input data.
For those who use rather than build, the article that matters is 26(6). Deployers of high-risk AI systems shall keep the logs automatically generated by the system, to the extent such logs are under their control, for a period appropriate to the intended purpose and of at least six months. The second subparagraph says financial institutions subject to Union financial services law keep those logs as part of the documentation required by that law, which in Brazil speaks directly to the five years of CMN Resolution 4.893.
Article 14, which requires effective human oversight by someone able to intervene, and article 13, which obliges the provider to give the deployer enough information to operate the system and interpret its output, complete the picture.
This is the part most discussions skip. Three things that look like logs do not work as evidence.
What we mean by an audit trail is the opposite of that. One event per request, generated automatically by the gateway, with who asked, which model, which provider, what the policy decision was and a hash of the content. Never the text. Each event carries the hash of the previous one and the chain is signed, with periodic anchors, so that altering one event breaks everything after it. And there is an independent verifier that runs offline, so the auditor can check without having to trust whoever generated it.
The Omnibus rewrote article 4. The 2024 text asked for a sufficient level of AI literacy among staff. The new text asks providers and deployers to take measures to support the development of AI literacy of their staff, and says expressly that the obligation does not require guaranteeing any specific level for any individual. It got lighter, but it has been in force since February 2025 and still asks for evidence that the measures exist. Knowing who uses AI, how often and for what is the starting point of any such program, and it is data the trail already has.
The gateway does not classify your system's risk, does not perform the fundamental rights impact assessment of article 27 and does not write the technical documentation. Those obligations belong to the company, and most of them depend on knowing what the system does, not on how it was called. What the gateway delivers is the record-keeping layer: proof that each call happened, who made it, what was decided and that nobody altered it afterwards. This article is the reading of the people who build the tool, not legal advice.
Going deeper: The Compliance group documentation shows the per-article panel. The Atlasberg protocol page lists the complete vocabulary of audit events, which is what an auditor will ask about first.
Atlasberg builds the control layer between a company and every AI model. Atlasberg Platform authenticates each request with a virtual key, filters it by policy and DLP, routes it to the right provider and writes it to a hash-chained audit trail, with an OpenAI-compatible API so applications only swap the base URL.
Articles on this blog are written by the engineering team and report measurements on real traffic, with the premises printed next to the result. To talk to the team, write to [email protected] or use https://atlasberg.com/contato.
Agents: this page is also available as Markdown at /blog/ai-act-registro-e-trilha-de-auditoria.md, or by requesting this URL with the header Accept: text/markdown. Index of everything: /llms.txt.