In short
A qualified electronic ledger is a new EU trust service. It records data entries in a fixed order and makes any later change visible. The legal basis is Articles 45k and 45l of the eIDAS Regulation. The technical rules are set out in Implementing Regulation (EU) 2025/2531 and have applied since 6 January 2026. No one is required to use one. Germany currently has no authorised provider.
On this page
- → What is an electronic ledger?
- → Simple versus qualified
- → Where this is written in law
- → Article 45k: legal effect
- → Article 45l: the four requirements
- → What the technical rules require
- → What the legal effect is, and is not
- → Does my company have to use one?
- → What already applies to logging today
- → Who signs when a machine writes?
- → Market situation in Germany
- → What this means for AI agent operators
- → FAQ
- → Sources
What is an electronic ledger?
An electronic ledger is a continuous record of data entries. Think of a cash book.
It does three things:
- It establishes where an entry came from.
- It secures the unique, sequential order of entries.
- It makes any later change detectable.
The German term used by the supervisory authority is elektronisches Journal. It means the same thing.
Simple versus qualified: the difference
There are two levels.
The simple electronic ledger. Anyone may operate one. No authorisation, no assessment.
The qualified electronic ledger. Only an authorised trust service provider may operate one. In return, it carries a specific effect in court.
The difference is not in the technology. It is in the authorisation.
Where this is written in law
What
Legal act
In force since
The foundation for trust services
eIDAS Regulation, i.e. Regulation (EU) No 910/2014
2014
The amendment, often called “eIDAS 2.0”
Regulation (EU) 2024/1183
20 May 2024
Technical rules for ledgers
Implementing Regulation (EU) 2025/2531
6 Jan 2026
One note on reading these texts. Regulation (EU) 2024/1183 is not a standalone act. It amends the eIDAS Regulation. To read the rules that actually apply, read the eIDAS Regulation as amended. Articles 45k and 45l are there.
Article 45k of the eIDAS Regulation: legal effect
Paragraph 1 says an electronic ledger may not be denied legal effect in court on the sole ground that it is electronic. This applies to non-qualified ledgers too.
Paragraph 2 says a qualified electronic ledger enjoys a presumption. The sequential chronological order and the integrity of the entries are assumed to be correct. Anyone claiming otherwise has to prove it.
Article 45l of the eIDAS Regulation: the four requirements
Under Article 45l(1) of the eIDAS Regulation, a qualified electronic ledger must:
- (a) be created and managed by one or more qualified trust service providers,
- (b) establish the origin of the data entries,
- (c) ensure the unique sequential chronological ordering,
- (d) record data so that any later change is immediately detectable.
Points b, c and d are engineering. Point a is an authorisation. That is why point a is the real hurdle.
What the technical rules require
The detail sits in the annex to Implementing Regulation (EU) 2025/2531. The baseline standard is ETSI EN 319 401 v3.1.1, plus additional requirements. The key ones:
Distributed ledgers additionally have to meet ISO 23257:2022 and ISO/TS 23635:2022.
The point that matters
REQ-7.5-04 mandates a hash chain. Not as a recommendation. As a binding specification.
That is the real news in this act. The European legislator has now put in writing which technique counts for provable ordering. It is cryptographic chaining. A database table with a timestamp column does not meet it.
What the legal effect is, and what it is not
A qualified electronic ledger carries the presumption under Article 45k(2) of the eIDAS Regulation. Before any court in the EU, order and integrity are assumed to be correct.
What it does not carry:
- No presumption about content. Only about order and integrity.
- No presumption about the time. That comes only from a qualified timestamp, under Article 41(2) of the eIDAS Regulation.
- No statement about lawfulness. Whether what was recorded was correct is a separate question.
The ledger shows that nobody changed anything afterwards. Whether the recorded action was the right one is not what it answers.
Does my company have to use one?
No.
There is no obligation. No sector, no company and no public authority is required to use a qualified electronic ledger. There is also no date on which that changes.
Anyone who adopts one is buying evidentiary weight. They are not buying compliance.
This needs saying, because a deadline gets quoted online that belongs to a different topic.
Not to be confused: the December 2027 deadline belongs to the EUDI Wallet
Qualified electronic ledger
EUDI Wallet
Legal basis
eIDAS Regulation, Articles 45k and 45l
eIDAS Regulation, Article 5f(2)
Subject matter
Recording of data entries
Identification of people
Mandatory?
No
Yes
Deadline
None
Acceptance obligation from 24 December 2027
Both sit in the same regulation. Beyond that they have nothing to do with each other. Applying the deadline in Article 5f of the eIDAS Regulation to ledgers is simply wrong.
What already applies to logging today
Logging obligations have existed for a while. None of them require chaining:
- Article 12 of the EU AI Act: high-risk AI systems must technically allow for the automatic recording of events. No format is prescribed.
- Article 19 of the EU AI Act: providers must retain those logs for at least six months.
- Section 30 of the German BSI Act (BSIG), which implements NIS-2: requires logging as part of risk management.
- The DORA Regulation: requires logs of ICT incidents.
A note on EU AI Act timing. The high-risk obligations were originally set for August 2026. The Digital Omnibus moved them, Annex III to 2 December 2027, Annex I to 2 August 2028. Many older articles still cite the earlier date.
So the obligation has not changed. The standard has. A log satisfies the duty. For proof, the EU decided in December 2025 which technique it considers sound.
The open question: who signs when a machine writes?
REQ-7.5-03 of Implementing Regulation (EU) 2025/2531 assumes that the users of a service sign their own entries, using a qualified certificate.
With AI agents, no human writes. An agent has no qualified certificate and cannot obtain one.
One plausible answer: the user in the sense of the regulation is not the agent but the company. A qualified electronic seal is issued to legal persons. The company seals through its gateway, and the agent acts in its name.
This has not been settled. Neither the regulation nor the supervisory authority has addressed it. Anyone recording agent activity for evidentiary purposes today is operating in a space the legislator has not yet worked through.
Market situation: Germany has no provider yet
The Bundesnetzagentur, Germany's supervisory authority for trust services, maintains the list of authorised providers. Its page on qualified electronic ledgers states (retrieved 7 August 2026) that there are no qualified providers in Germany yet.
The infrastructure is in place:
- Since 29 April 2026, the European trusted list runs on the TLv6 format. Only that version allows electronic ledgers to be registered at all.
- The German conformity assessment bodies exist, including datenschutz cert, SRC Security Research & Consulting, Deutsche Telekom Security and TÜV NORD CERT.
- The Bundesnetzagentur has published its procedure and application forms.
No piece is missing. Nobody has offered the service yet.
What this means for companies running AI agents
If you run agents in production today, you do not need a qualified electronic ledger. There is no obligation and there is no provider.
What has changed is the benchmark. If a dispute comes later, with a customer, an insurer, a regulator, there is now an officially described reference for what a defensible record looks like. It sits in REQ-7.5-04 of Implementing Regulation (EU) 2025/2531. And it calls for a chain.
Three practical steps, independent of any authorisation:
KYDE and cryptographic chaining
Kyde records agent activity in a cryptographic hash chain. Each entry carries its own hash and an Ed25519 signature. The export ships the canonicalised bytes, the entry hash, the signature and the public key.
This means the recipient verifies without asking us. An auditor, an insurer or opposing counsel recomputes the hash and checks the signature offline. We do not need to be present, and we cannot influence the result. Self-reported evidence is worth what the reporter is worth. This kind isn't.
This is the same technique that Implementing Regulation (EU) 2025/2531 prescribes in REQ-7.5-04 for qualified electronic ledgers. Kyde is not a qualified trust service provider and does not operate a qualified electronic ledger. The architecture follows the specification the European legislator chose for defensible recording.
For key storage, REQ-7.5-06 of the same regulation sets the benchmark: a certified cryptographic device at Common Criteria EAL 4 or above, or FIPS 140-3 Level 3 until the end of 2030. That is the standard our hardware roadmap is measured against.
See how the recording works: Kyde Zero Trust, evidence →
Frequently asked questions
Is a qualified electronic ledger mandatory? +
Since when do the technical rules apply? +
Where is this written in law? +
What is the difference between a simple and a qualified ledger? +
Does a qualified ledger have to be a blockchain? +
Are there providers in Germany yet? +
Does a qualified ledger satisfy the EU AI Act? +
Sources
- eIDAS Regulation as amended, Articles 45k and 45l
- Implementing Regulation (EU) 2025/2531 of 16 December 2025, annex
- Bundesnetzagentur, overview page on qualified electronic ledgers
- EU AI Act, Articles 12 and 19
- German BSI Act (BSIG), Section 30
Related resources
EU AI Act Compliance for AI Agents
Annex III classification, Articles 12, 14 and 26, and the six-step plan for building audit infrastructure that survives a market surveillance review.
What the EU AI Act Actually Requires for Audit Trails
Why provider-native logs fail, what tamper-evidence means structurally, and what the causal context requirement forces you to capture.
AI Agent Audit Trail
Log, ledger or chain. What separates an operational log from a record that can carry evidentiary weight.
DORA and AI Agents: Why Your LLM Provider's Log Doesn't Satisfy Article 30
For financial entities: how DORA Article 30 intersects with EU AI Act obligations, and why the requirements are additive.
Evidence Capture: The Six Questions Every Entry Answers
Who, what, when, where, why and how, sealed per entry with an Ed25519 signature and a SHA-256 hash-chain link.
KYDE Gateway
A chained record of every agent action, verifiable without us.
Kyde sits between your agents and every LLM provider and writes an Ed25519-signed, SHA-256 hash-chained entry for every action. Exports verify offline, against the public key, by whoever is asking. Kyde is not a qualified trust service provider. The recording technique is the one the European legislator selected.