ENTRY № 40 · COMPLIANCE CHECKLIST · EU AI ACT · NYDFS · SR 26-2
PUBLISHED 2026-06-04 · UPDATED 2026-06-10 · ~12-MIN READ · WARRANT COMPLIANCE

What records must an AI agent keep to satisfy a regulator?

An AI agent in a regulated industry must keep an automatic event record of what it did, retained for a hard floor of at least six months. Under the EU AI Act, Article 12(1) of Regulation (EU) 2024/1689 requires automatic recording of events over the lifetime of a high-risk system; Article 19(1) sets the provider retention floor and Article 26(6) the matching deployer floor, both at least six months. NYDFS 23 NYCRR § 500.6(a)(2) demands an audit trail designed to detect cybersecurity events. SR 26-2 (17 April 2026), which supersedes SR 11-7, demands nothing of the agent at all — footnote 3 to its § II puts generative and agentic AI outside scope, and leaves the bank to set its own bar under general safety and soundness. This is the record set, mapped clause by clause to what a deployer can act on this quarter, and marked where the clause is missing.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.

RECORD SET
Art. 12· § 1
Automatic event recording over the lifetime of a high-risk AI system.
RETENTION FLOOR
≥ 6months
Article 19(1) provider floor and Article 26(6) deployer floor. Sectoral law often runs longer.
US AUDIT TRAIL
§ 500.6(a)(2)
NYDFS 23 NYCRR audit trail to detect and respond to cybersecurity events.
01 · THE RECORD SET

The record set, in one paragraph.

The regulator's question is narrow. Show me what the agent did, prove the record is intact, and prove you kept it long enough. Three regimes ask it three ways. The EU AI Act asks for an automatic event record over the lifetime of the high-risk system. NYDFS asks for an audit trail that detects cybersecurity events at the operation level. US bank model risk guidance asks nothing of the agent itself: SR 26-2 § II footnote 3 places generative and agentic AI models outside its scope, so no US model-risk clause compels a per-decision record from a bank AI agent — the two clauses that do compel one are the EU's and New York's. Warrant answers all three with a single unit — a record mapped to a specific obligation, kept for at least the retention floor, independently verifiable without contacting Warrant — and that convergence is Warrant's conservative design choice, not a requirement the three regimes share.

This entry is structured as the regulator's question, the record artifact that answers it, and the article that demands it. Run the list against a production agent and the gaps are the gaps an inspection finds first.

EU
An automatic event record of every relevant action, over the lifetime of the high-risk system, retained at least six months. DEMANDED BY · Article 12(1) record-keeping; Article 19(1) and Article 26(6) retention.
NY
An audit trail designed to detect and respond to cybersecurity events, showing what was accessed, by which agent, under what authorization, and when. DEMANDED BY · 23 NYCRR § 500.6(a)(2). Reading that clause against an AI deployment is Warrant's inference from the regulation; the 16 October 2024 Industry Letter does not cite it.
US
No clause. SR 26-2 § II n.3 excludes generative and agentic AI from scope, and its documentation subsection is two hortatory sentences. NOT DEMANDED BY · SR 26-2 (17 April 2026, supersedes SR 11-7). The bank sets this bar itself, against the general safety-and-soundness expectation footnote 1 preserves.
02 · EU AI ACT ARTICLE 12

EU AI Act Article 12 · the event record over the lifetime.

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. Regulation (EU) 2024/1689 · Article 12(1) · 13 June 2024

Article 12(1) binds providers of high-risk AI systems to automatic event recording over the lifetime of the system. For Annex III standalone high-risk systems the application date is 2 December 2027 (deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus; Regulation (EU) 2026/1744, OJ 24 July 2026). Non-compliance is reachable under Article 99(4) at up to EUR 15 million or 3 percent of global annual turnover. The line-by-line read is in Article 12, line by line.

What the record has to capture is set by Article 12(2). Paragraph 2(a) covers situations that may result in the system presenting a risk under Article 79(1) or a substantial modification. Paragraph 2(b) covers facilitation of post-market monitoring under Article 72. Paragraph 2(c) covers monitoring of the operation under Article 26(5). The record is event-shaped, not request-shaped: it must be addressable by deployment, by version, and by the action the agent took, not just by the HTTP call that carried it.

For an autonomous agent that takes many consequential actions in one run, whether the record is one running log or a discrete record per action is the open boundary. That question is read in full at does Article 12 require a record per agent action.

03 · THE SIX-MONTH FLOOR

The retention floor · at least six months, on two sides.

The providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data. Regulation (EU) 2024/1689 · Article 19(1) · 13 June 2024

Article 19(1) is the provider floor. The provider keeps the Article 12 logs for a period appropriate to the intended purpose, of at least six months, unless Union or national law requires longer. Article 26(6) is the deployer mirror. The deployer keeps the logs that come under its control, for the same appropriate period, of at least six months. The two floors run in parallel. The detail of the deployer side is in the Article 26 deployer obligations, line by line.

19(1)
PROVIDER FLOOR
Provider keeps the Article 12 logs under its control for at least six months, appropriate to the intended purpose.
26(6)
DEPLOYER FLOOR
Deployer keeps the logs under its control for at least six months, the deployer-side mirror of Article 19(1).

Six months is a floor, not a ceiling. Sectoral law pushes the actual horizon longer wherever it speaks. MiFID II Article 16(7) requires records of telephone conversations and electronic communications relating to transactions and client orders, and those records shall be kept for a period of five years and, where requested by the competent authority, for a period of up to seven years. The Medical Device Regulation Article 10(8) runs at least ten years after the last device covered by the declaration of conformity was placed on the market, and at least fifteen for implantable devices. A six-month rolling window destroyed twelve months ago is not an answer to a regulator's request twelve months and one day after the event. The phrase in particular in Union law on the protection of personal data is the GDPR carve-back: where logs contain personal data, storage-limitation under GDPR caps the upper bound, and the deployer settles on a per-use-case number that satisfies both regimes.

04 · NYDFS 500.6(a)(2)

NYDFS · the audit trail at the operation level.

Each covered entity shall securely maintain systems that, to the extent applicable and based on its risk assessment ... include audit trails designed to detect and respond to cybersecurity events that have a reasonable likelihood of materially harming any material part of the normal operations of the covered entity. 23 NYCRR § 500.6(a)(2) · Second Amendment · effective 1 November 2023

The 16 October 2024 NYDFS Industry Letter imposes no new rule. In its own words it "does not impose any new requirements beyond obligations that are in DFS's cybersecurity regulation codified at 23 NYCRR Part 500", and it explains instead how Covered Entities should use the Part 500 framework against four AI-related risk categories, working them mainly through § 500.11, third-party and vendor management. Note what it does not do: the Letter cites neither § 500.6 nor § 500.17. Reading § 500.6(a)(2) onto an AI deployment is an inference from the regulation's own text, not an instruction in the Letter, and it is marked as Warrant's throughout. Read against an AI agent, a standard application log does not satisfy: it records that a request returned a status code, not what was accessed or under what authorization. The full reading is in standard API call logs do not satisfy 23 NYCRR § 500.6.

The audit trail has to answer four questions about each operation the agent performed. What was accessed — the specific nonpublic-information element, not a request hash. By which agent — the model identifier and provider, not "the chatbot". Under what authorization — the policy and purpose limitation the action satisfied. When — a timestamp the covered entity cannot retroactively change. The retention side is its own clock: § 500.6(b) runs five years for the (a)(1) reconstruction records and three years for the (a)(2) audit-trail records.

"The regulator does not ask for the log. It asks for the record of what the agent did, and proof you kept it."Warrant Compliance · 2026-06-04
05 · SR 26-2 DOCUMENTATION

SR 26-2 · the documentation obligation that left.

Adequate documentation helps to support effective model risk management. For example, documentation can help maximize the likelihood of continuity of operations, including supporting the tracking of recommendations, responses, and exceptions; it can also be used to more effectively help manage any model remediation efforts. SR 26-2 attachment · § VI, Documentation — the subsection in full, both sentences

The fourth pillar of US bank model risk guidance is documentation, and in 2026 it got weaker on both axes. SR 26-2, issued 17 April 2026 (OCC Bulletin 2026-13) by the Federal Reserve / OCC / FDIC, is the current guidance: it supersedes and replaces SR 11-7 (the 4 April 2011 letter, with OCC Bulletin 2011-12 the same day, adopted by FDIC through FIL-22-2017) and SR 21-8. Footnote 3 to its § II states that generative AI and agentic AI models are not within the scope of the guidance. And the documentation subsection quoted above is the whole subsection: two sentences, both permissive, and the SR 11-7 standard that documentation be detailed enough for parties unfamiliar with a model to understand how it operates did not survive into the new text. A deployer looking for the clause that forces a per-decision record out of a US bank agent will not find one here. The line-by-line read is in SR 26-2 / SR 11-7, line by line.

For an AI agent, the documentation record is three layers. The development record — the agent's tool-selection logic, prompt template, retrieval policy, scope of use, and limitations, which are bank artifacts even when a vendor supplies the foundation model. The validation record — the ongoing-monitoring cadence and the triggers that force re-validation. And the per-decision record — what the agent did and the alternatives it weighed, which no US model risk letter now requires and which the examiner will nonetheless ask about. An agent excluded from the guidance is not an agent excluded from examination. Footnote 1 keeps supervisory action available for unsafe or unsound practices, and the bank arrives at that conversation holding whatever record it decided to keep.

06 · THE DEPLOYER CHECKLIST

The checklist · question, record, clause.

The mapping below is the whole entry in one table. Each row is a question a regulator asks, the record artifact that answers it, and the clause that demands it. A deployer can run this against a production agent and treat any empty record cell as a finding.

Regulator question The record artifact Clause
What did the agent do? Automatic event record per action over the lifetime of the system: actions[*] (action_id, actor, action, subject) in the evidence schema. Art. 12(1)
Was each action within its remit? Per-action authorization record: authorizations[*] — within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification. Art. 12(2)(c) · 500.6(a)(2)
Can you detect a risk or modification? Risk-situation record per action, flagging deviation from intended purpose and substantial modification. Art. 12(2)(a)
Did you keep it long enough? Retention proof: provider-controlled logs at least six months; deployer-controlled logs at least six months. Art. 19(1) · 26(6)
What was accessed, and under what authority? Operation-level audit trail: subject accessed, agent identity and provider, authorization satisfied, immutable timestamp. 500.6(a)(2)
Can you reconstruct the decision? Documentation record: development, validation, and per-decision records that let informed parties understand the model. No clause · SR 26-2 § II n.3 excludes the agent; general safety and soundness applies

Read the Clause column as the demand, not as what a package cites. The § 500.6(a)(2) rows are Warrant's reading of the regulation. The obligation corpus carries no § 500.6 table, so a package reports NYDFS Part 500 as classified and in scope, not evaluated, and no package asserts a § 500.6 citation.

The structural choice a deployer makes now is whether each of these records lives inside the agent or in a record layer downstream of the decision. A record mapped to a specific obligation, kept past the retention floor, and independently verifiable without contacting Warrant satisfies the question in every column at once.

W
Sample evidence package · Warrant registerINDEPENDENTLY VERIFIABLE WITHOUT CONTACTING WARRANT
→ /v/7de85ceaeac42a47
07 · FAQ

Questions a compliance officer asks first.

What records must an AI agent keep to satisfy a regulator?

Three record sets, depending on the regime. Under the EU AI Act, Article 12(1) requires automatic recording of events over the lifetime of a high-risk AI system. Under NYDFS, 23 NYCRR § 500.6(a)(2) requires an audit trail designed to detect and respond to cybersecurity events. Under US bank model risk guidance the position is different in kind: SR 26-2 (17 April 2026, superseding SR 11-7) excludes generative and agentic AI models from scope at § II n.3, so the bank keeps the record under its own general governance practice rather than to a clause. In each case the record has to capture what the agent did at the operation level, not just that a request returned a status code.

How long must AI agent records be retained under the EU AI Act?

At least six months. Article 19(1) sets the provider retention floor at a period appropriate to the intended purpose, of at least six months, unless other Union or national law requires longer. Article 26(6) sets the matching deployer floor for logs under the deployer's control, also at least six months. Sectoral law often runs longer. MiFID II Article 16(7) keeps the records it covers for five years, and up to seven where the competent authority requests it. The Medical Device Regulation Article 10(8) runs at least ten years, and at least fifteen for implantable devices.

Do standard application logs satisfy the record-keeping rules?

Usually not. An application log that records HTTP method, status code, and latency is traffic-shaped. The audit trail NYDFS 23 NYCRR 500.6(a)(2) requires, and the event record EU AI Act Article 12(2) makes relevant, are operation-shaped: they must show what was accessed, by which agent, under what authorization, and when. A rolling 30-day application log also fails the six-month retention floor under Article 19(1) and Article 26(6).

Who keeps the records, the provider or the deployer?

Both, on different floors. The provider is responsible for the high-risk system being able to generate the logs automatically under Article 12(1), and retains them under Article 19(1). The deployer retains the logs that come under its control under Article 26(6). In practice a managed-service contract has to route an export feed to the deployer and leave a parallel retention duty with the provider, because neither floor discharges the other.

What does the SR 26-2 documentation pillar require for an AI agent?

Nothing, and that is the finding. SR 26-2 (17 April 2026) supersedes SR 11-7, and footnote 3 to its § II states that generative AI and agentic AI models are not within the scope of the guidance. Its documentation subsection runs two sentences, both permissive, and SR 11-7's standard that documentation be detailed enough for parties unfamiliar with a model to understand how it operates did not carry forward. No US model risk clause now compels a per-decision record from a bank AI agent. Footnote 3 routes the system to the banking organization's general risk management and governance practices; footnote 1 preserves supervisory action for unsafe or unsound practices. The bank sets the bar and defends it, in three layers: development record, validation record, per-decision record.

What happens if the records are not kept?

Under the EU AI Act, Article 16(a) routes Article 12 through provider obligations — providers must ensure that their high-risk AI systems are compliant with the requirements set out in Section 2, and Article 12 sits in that Section — and Article 99(4)(a) then reaches obligations of providers pursuant to Article 16, at up to EUR 15 million or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Under NYDFS, a missing 23 NYCRR § 500.6(a)(2) audit trail is a gap a regulator examining a cybersecurity event surfaces first, and it sits under the annual notice of compliance at 23 NYCRR § 500.17(b). Under US bank model risk guidance there is no clause to breach: SR 26-2 § II n.3 puts generative and agentic AI models outside scope, so the agentic system arrives at examination through general risk management and governance practice, with supervisory action for unsafe or unsound practices preserved by footnote 1.

08 · READ THE SOURCE

Read the source directly.

Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. The verbatim quotations of Article 12(1) and Article 19(1) reflect the official English-language text of Regulation (EU) 2024/1689 as published in the Official Journal of the European Union on 12 July 2024. The 23 NYCRR § 500.6(a)(2) text reflects the Second Amendment effective 1 November 2023. The documentation quotation is the § VI Documentation subsection of the SR 26-2 attachment in full, and footnote 3 to § II is quoted as published, both from federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf, retrieved 28 July 2026. SR 26-2 (17 April 2026, OCC Bulletin 2026-13) supersedes SR 11-7 (4 April 2011) and SR 21-8.