Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

ClauseWatch is a prototype legal-research agent that answers AI-regulation questions by retrieving structured obligations alongside legal source text. Its defining choice is not to force conflicting rules into one number: it is designed to show the relevant provisions, identify the tension, and make clear whether a decision resolving it has been recorded. The project is a demonstration, not a complete compliance product.

What ClauseWatch does

The project’s worked question is: “How long must you keep AI system logs under the EU AI Act?” Its example asks how long a provider of a high-risk biometric access-control system must keep automatically generated logs, and from when. ClauseWatch combines a structured dataset with a knowledge base of legal provisions, queries them when answering, and preserves tool calls with saved runs so readers can inspect the answer’s trail. The project author, Oleg VDV, describes a small, deliberately curated demonstration rather than a comprehensive compliance system. Project and demonstration details.

How it represents legal obligations and disagreement

ClauseWatch’s content model keeps several kinds of information separate rather than treating a legal rule as an isolated number:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Instrument and provision: the legal instrument and the citable text supporting a claim.
  • Normalized requirement: a structured representation of what the provision requires.
  • Claim: whether a rule acts as a floor, a ceiling, or a duty with no stated period.
  • Conflict: a relationship between claims that can record a resolution, rationale, decider, and date.
  • System profile: details such as the system’s role, jurisdiction, and risk class that shape the question.

This structure can make unresolved disagreement visible as data. The project author’s instruction is: “Never fill a gap from your own legal knowledge. If it is not in the dataset or the knowledge base, say that it is not there.” That is a design instruction attributed to the author, not a guarantee that every answer is complete or legally correct.

What the EU AI Act says about log retention

Article 26(6) of Regulation (EU) 2024/1689 says deployers of high-risk AI systems must keep automatically generated logs to the extent those logs are under their control, for a period appropriate to the intended purpose and “of at least six months.” The provision qualifies that minimum with an exception where applicable Union or national law provides otherwise, particularly Union data-protection law. The six-month figure is a statutory minimum in this qualified context—not a universal retention answer for every AI system, actor, or log. Official EU AI Act text, Article 26(6).

Why the GDPR also matters

GDPR Article 5(1)(e) requires identifiable personal data to be kept “for no longer than is necessary” for the purposes of processing. It also provides specified exceptions for longer storage for archiving in the public interest, scientific or historical research, or statistical purposes, subject to safeguards. Official GDPR text, Article 5(1)(e).

These provisions should not be reduced to a claim that the GDPR automatically cancels the AI Act’s minimum or that the two rules are necessarily irreconcilable. Article 26(6) itself refers to cases where applicable law provides otherwise. Applying that qualification requires examining the actual role, system classification, log contents, purpose, and applicable law. The project’s example does not establish a universal retention period for a real deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a useful answer needs to establish

A log-retention answer depends on facts that a single numeric lookup can miss. At minimum, the question needs to establish:

  • Actor: whether the organization is acting as a provider, deployer, or in another capacity relevant to the provision.
  • System category: whether the system is legally classified as high-risk and, where relevant, which category applies.
  • Jurisdiction and applicable rules: which Union or national provisions govern the deployment.
  • Log scope and control: whether the records are automatically generated logs and are under the deployer’s control.
  • Data and purpose: whether the logs contain identifiable personal data and why they are retained.
  • Timing: which application provisions and amendments apply to the system at the relevant time.

The project’s worked prompt asks “from when,” but the cited Article 26(6) text establishes a retention duration, not a universal starting point for every scenario. The project description does not settle that timing question for an individual deployment. Application dates and later amendments are time-sensitive; the consolidated Article 113 and relevant amendments should be checked for the particular system category. The official consolidated text cited here was updated on 27 July 2026.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the prototype does—and does not—establish

The author reports building with a code repository, public dataset, and Studio. The author also reports that knowledge-base and LLM features require a Context token and describes a no-model mode. These are implementation and access details reported by the project author and may change; they are not independent verification of current availability or performance. The project describes its material as deliberately small and curated. No independent accuracy benchmark, user study, adoption figure, or project-performance statistic is established by the cited material.

ClauseWatch is most useful as a demonstration of how a legal-research tool can preserve source traceability and model disagreement explicitly. Its output should not be treated as an individualized compliance determination: a real answer needs the facts of the deployment and the applicable, current legal text.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.