Article 26: Obligations of deployers of high-risk AI systems
Praxikon tracks Article 26 (Obligations of deployers of high-risk AI systems) under the EU AI Act, citing the source for every statement.
Application dates
- : Obligations for high-risk systems listed in Annex III
- : Obligations for high-risk systems linked to Annex I
Article 26 is the practical obligations article for organisations deploying high-risk AI systems in Europe. It turns compliance into operating rules: follow instructions, organise oversight, control input data and watch for incidents.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Official guidance on this article
3- Regulation (EU) 2026/1744, Digital Omnibus on AIMoves deployer obligations in Section 3 to 2 December 2027 for Annex III and 2 August 2028 for Annex I.PublishedRegulationEuropean Parliament and Council of the European Union24 Jul 2026
- AI Literacy - Questions & AnswersLinks AI literacy to the requirement that deployers of high-risk systems designate personnel with sufficient competence and authority for human oversightPublishedQ&AEuropean Commission, DG CONNECT27 Jul 2026
- Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)Translates the question of who bears what obligations in a generative AI chain into the data protection law division of roles, which aligns with the obligations of the deployer under the AI ActPublishedGuidelinesEDPS (European Data Protection Supervisor)28 Oct 2025
What does this mean for you?
Provider+
Deployer+
SME / Startup+
Public Sector+
Compliance checklist
- Technical and organisational measures taken
- Input data verified for relevance
- AI system operation is monitored
- Logs retained in accordance with Art. 19
- Affected persons informed about AI use
- FRIA conducted (if required, Art. 27)
- Staff with AI literacy (Art. 4)
Want to save your progress? Create an account
Related recitals
Whilst risks related to AI systems can result from the way such systems are designed, risks can as well stem from how such AI systems are used. Deployers of high-risk AI system therefore play a critic…
Any processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allo…
Related tools
Related enforcement
- •
- •
Related blog posts
Cross-references
Annexes
Frequently asked questions
What are the obligations for deployers of high-risk AI?+
Do I need to conduct a FRIA as a deployer?+
What should I do in case of an incident with high-risk AI?+
What should I as deployer do if my AI vendor goes bankrupt?+
When do I as deployer become a provider myself under the AI Act?+
Do I as deployer need to retain the input and output data of the AI system?+
What Article 26 requires in practice
Connections
What connects to Article 26 AI Act
Themes where this returns
- Assessing risks in advance: DPIA and FRIA
- Automated decisions and human oversight
- Keeping records: record of processing, technical documentation and logs
- Reporting: data breaches and serious incidents
- Rights of people: access and explanation of decisions
- Transparency: informing people
- Who is responsible: roles in both laws
The counterpart in the other law
- Article 4 GDPR: Definitions
- Article 5 GDPR: Principles relating to processing of personal data
via Keeping records: record of processing, technical documentation and logs
- Article 12 GDPR: Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 13 GDPR: Information to be provided where personal data are collected from the data subject
- Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
- Article 15 GDPR: Right of access by the data subject
- Article 22 GDPR: Automated individual decision-making, including profiling
- Article 24 GDPR: Responsibility of the controller
- Article 28 GDPR: Processor
- Article 30 GDPR: Records of processing activities
via Keeping records: record of processing, technical documentation and logs
- Article 33 GDPR: Notification of a personal data breach to the supervisory authority
- Article 34 GDPR: Communication of a personal data breach to the data subject
- Article 35 GDPR: Data protection impact assessment
- Article 36 GDPR: Prior consultation
GDPR interpretation that also applies here6 of 27
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt · via Transparency: informing people
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij · via Transparency: informing people
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB) · via Transparency: informing people
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB) · via Transparency: informing people
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB) · via Assessing risks in advance: DPIA and FRIA
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB) · via Assessing risks in advance: DPIA and FRIA