Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Open-Source Article 12 Logging Infrastructure for the EU AI Act

Details

External ID
47230438
Source
HN
Company
—
Product
—
Website domain
—
Launched
March 3, 2026
Cohort
—
Upvotes
42
Upvotes percentile
0.8216482164821648
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

EU legislation (which affects UK and US companies in many cases) requires being able to truly reconstruct agentic events.I've worked in a number of regulated industries off & on for years, and recently hit this gap.We already had strong observability, but if someone asked me to prove exactly what happened for a specific AI decision X months ago (and demonstrate that the log trail had not been altered), I could not.The EU AI Act has already entered force, and its Article 12 kicks-in in August this year, requiring automatic event recording and six-month retention for high-risk systems, which many legal commentators have suggested reads more like an append-only ledger requirement than standard application logging.With this in mind, we built a small free, open-source TypeScript library for Node apps using the Vercel AI SDK that captures inference as an append-only log.It wraps the model in middleware, automatically logs every inference call to structured JSONL in your own S3 bucket, chains entries with SHA-256 hashes for tamper detection, enforces a 180-day retention floor, and provides a CLI to reconstruct a decision and verify integrity. There is also a coverage command that flags likely gaps (in practice omissions are a bigger risk than edits).The library is deliberately simple: TS, targeting Vercel AI SDK middleware, S3 or local fs, linear hash chaining. It also works with Mastra (agentic framework), and I am happy to expand its integrations via PRs.Blog post with link to repo: https://systima.ai/blog/open-source-article-12-audit-loggingI'd value feedback, thoughts, and any critique.

Enrichment

Theme
browser automation and scraping for AI
Vertical
Government
Function
Compliance & governance
Audience
B2B
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
open-source logging infrastructure for eu ai act compliance
Manually corrected
False

Could you build this?

Yes An Article 12 compliance logging library is essentially structured audit logging, cryptographic hash chains for immutability, and standard schema storage for agent states and API inputs/outputs.

Discussion

10 comments analyzed.

Competitors mentioned: Standard application logging (for AI Act Article 12 compliance), Crypto-shredding approaches, OpenTimestamps (for temporal anchoring)

Concerns raised: 180-day retention floor insufficient for auditors; systems in employment/credit/law enforcement need 10-year+ windows, Logs must be accessible in structured format to notified bodies, not just stored, Key store dependency creates audit reliability risk on every regulatory read, Developer mistakes can bypass encryption if code bugs miss encrypting data, Anyone can regenerate alternative SHA256 hash chains; lacks tamper-proof guarantees

Feature requests: External timestamping (OpenTimestamps, RFC 3161) for independent temporal anchoring, Dual-layer storage separating metadata/hash chain from PII-bearing content for erasure flexibility, Structured log export tooling for notified body conformity assessments, Optional tamper-proof mechanisms beyond current tamper-evident design

Competitors

Other products that read as similar to this one — 118 launches clear the similarity bar, closest 8 shown.

Attention rank: #20 of 119 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 120 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.