Long-Horizon Compatibility Contracts for AI Audit Trails

The EU Artificial Intelligence Act obliges providers of high-risk AI systems to build logging into their systems "over the lifetime of the system" (Article 12), to keep the resulting logs for a period appropriate to the intended purpose, of at least six months unless other Union or national law provides otherwise (Article 19; Article 26(6) for deployers), and to keep technical and quality-management documentation at the disposal of authorities for ten years after the system is placed on the market (Article 18). Following the 2026 Digital Omnibus on AI, these obligations apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028. The Act says what must be kept and for how long. It is silent on a question that every long-lived digital record eventually faces: will anyone still be able to check it? This paper argues that the evidentiary value of an AI audit record is a function of two things, not one: the record, and the continued existence of a verifier that can interpret it and reach the same verdict that would have been reached on the day the record was made. Record formats are revised, cryptographic algorithms are retired on published timetables that fall inside the Act's retention window, vendors exit markets, and verification software stops being maintained. None of these events deletes a record; each can silently turn it into bytes that prove nothing. The digital-preservation and long-term-signature communities have understood this for three decades, and EU law already recognises it for electronic signatures. We argue that the practice of AI audit logging has yet to absorb the lesson. We propose that any party producing AI audit records for regulatory purposes publish a compatibility contract comprising four commitments: (C1) an explicitly versioned proof format, (C2) a stated negotiation rule that determines what a verifier does when it meets a record version other than its own, including refusal on unknown versions, (C3) a published long-term-support window tied to the retention horizon rather than to the vendor's release cadence, and (C4) a governed procedure for the rare cases in which compatibility must be broken. We state each commitment normatively, derive a checklist that a market-surveillance authority, notified body or procurement officer could apply without access to source code, and relate the proposal to ISO/IEC 42001, the OAIS reference model, ETSI long-term signature preservation standards and the eIDAS Regulation. This is a position paper. It reports no measurements, and its limitations, including its single-vendor perspective, are set out explicitly.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23056714
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Long-Horizon Compatibility Contracts for AI Audit Trails

Harish Kumar
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

Long-Horizon Compatibility Contracts for AI Audit Trails

Harish Kumar
article en

Abstract

The EU Artificial Intelligence Act obliges providers of high-risk AI systems to build logging into their systems "over the lifetime of the system" (Article 12), to keep the resulting logs for a period appropriate to the intended purpose, of at least six months unless other Union or national law provides otherwise (Article 19; Article 26(6) for deployers), and to keep technical and quality-management documentation at the disposal of authorities for ten years after the system is placed on the market (Article 18). Following the 2026 Digital Omnibus on AI, these obligations apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028. The Act says what must be kept and for how long. It is silent on a question that every long-lived digital record eventually faces: will anyone still be able to check it? This paper argues that the evidentiary value of an AI audit record is a function of two things, not one: the record, and the continued existence of a verifier that can interpret it and reach the same verdict that would have been reached on the day the record was made. Record formats are revised, cryptographic algorithms are retired on published timetables that fall inside the Act's retention window, vendors exit markets, and verification software stops being maintained. None of these events deletes a record; each can silently turn it into bytes that prove nothing. The digital-preservation and long-term-signature communities have understood this for three decades, and EU law already recognises it for electronic signatures. We argue that the practice of AI audit logging has yet to absorb the lesson. We propose that any party producing AI audit records for regulatory purposes publish a compatibility contract comprising four commitments: (C1) an explicitly versioned proof format, (C2) a stated negotiation rule that determines what a verifier does when it meets a record version other than its own, including refusal on unknown versions, (C3) a published long-term-support window tied to the retention horizon rather than to the vendor's release cadence, and (C4) a governed procedure for the rare cases in which compatibility must be broken. We state each commitment normatively, derive a checklist that a market-surveillance authority, notified body or procurement officer could apply without access to source code, and relate the proposal to ISO/IEC 42001, the OAIS reference model, ETSI long-term signature preservation standards and the eIDAS Regulation. This is a position paper. It reports no measurements, and its limitations, including its single-vendor perspective, are set out explicitly.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.