Privacy log (AI Act)

A timestamped record of every change to your guardrail policies and every time a guardrail warned, redacted or blocked something - filterable, exportable, and ready to support your EU AI Act documentation.

3 min read · Updated 28 September 2026

When someone asks “how do you control what goes into AI?”, the honest answer needs evidence. The Privacy Log (AI Act) is that evidence: a record of changes made to your workspace’s guardrail policies and settings, and of every time a guardrail acted on sensitive data. It helps you document how AI is used and governed in your company.

What is recorded

Kind of eventActionsExample
Policy changesCreated, Updated, DeletedAn admin changes a detector from Warn to Redact.
Guardrail triggersWarned, Redacted, BlockedThe sensitive info guardrail redacts a phone number.

Reading an entry

Each entry shows:

  • The source, for example Sensitive info guardrail.
  • The action as a badge: Warned, Redacted, Blocked - or the kind of policy change.
  • What it acted on, for example “Redacted: Government ID” or “Redacted: Phone number”.
  • The surface where it happened, for example “Surface: model output”. Surfaces match the guardrail settings: user input, tool data and model output.
  • Who or what caused it. Automatic guardrail actions show System.
  • When, to the minute.

Entries name the type of data - “Phone number” - rather than showing the value, so reading the log does not expose what the guardrail protected.

Find what you need

  1. Open the Privacy Log

    On the Workspace page, select Privacy Log (AI Act). The newest entries are at the top.

  2. Filter

    Use All areas to narrow to one area, and All actions to show only, say, Blocked events or policy changes. Use the refresh button to load the latest entries.

  3. Export

    Select Export to download the record, for example to attach to an internal audit or to keep with your AI governance documentation.

Using the log for EU AI Act documentation

If your organisation needs to document how it uses and governs AI - for example for the EU AI Act - the Privacy Log gives you part of that picture, ready-made:

  • Your controls, with history. Policy changes are recorded with a timestamp, so you can show when your rules changed and what protection was in place over time.
  • Proof the controls work. Triggers show your guardrails acting on real traffic, not just existing on paper.
  • A basis for review. A periodic export - monthly or quarterly - is a simple, repeatable record for your compliance file.

Combine it with the other records StickyPrompts keeps: Usage Statistics for who used which models, Model & Provider Access for which models were approved, and Data residency for where data was stored and processed.

Use it day to day, too

The log is not only for auditors. Read it weekly while you tune your guardrails:

  • Many Warned entries for one detector? Consider moving it to Redact.
  • Blocked entries clustered around one team? A short conversation about what to paste into AI often helps more than a stricter rule.
  • A policy change you did not expect? The entry shows when it happened.