🤖AI Workload Compliance EU-AIACT-ART17Rule: AIACT-004critical

AI Audit Logging

Description

High-risk AI systems shall record events relevant to risk assessment (EU AI Act Article 17). EchelonGraph verifies cloud audit logging is enabled (CloudTrail / Cloud Audit Logs / Activity Log) on the cloud hosting the AI namespace.

⚠️ Risk Impact

Without audit logging, you cannot reconstruct what data the model trained on, who deployed it, or how it was modified — exactly the events EU AI Act regulators investigate after an incident.

🔍 How EchelonGraph Detects This

AIACT-004Automated scanner rule

EchelonGraph's Tier 1 Cloud Scanner automatically checks for this condition across all connected cloud accounts. Violations are flagged as critical-severity findings with remediation guidance.

🔧 Remediation

Enable CloudTrail / Cloud Audit Logs Data Access / Azure Diagnostic Settings covering the cloud hosting the AI namespace.

🔗 Cross-Framework References

NIST-AU-2SOC2-CC7.1

Automate AI Workload Compliance EU-AIACT-ART17 compliance

EchelonGraph continuously monitors this control across all your cloud accounts.

Start Free →