Praxikon
Article 26 of 11323%
Nederlands

Article 26: Obligations of deployers of high-risk AI systems

EU Official:
UpcomingAnnex III from 2 Dec 2027; Annex I from 2 Aug 2028
Title III: High-Risk AI Systems

Application dates

  • : Obligations for high-risk systems listed in Annex III
  • : Obligations for high-risk systems linked to Annex I

Article 26 is the practical obligations article for organisations deploying high-risk AI systems in Europe. It turns compliance into operating rules: follow instructions, organise oversight, control input data and watch for incidents.

Official text

||

Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.

Download AI Act (PDF)

Official guidance on this article

3

What does this mean for you?

Provider+
Article 26 addresses deployers. Under Article 13, the provider must still supply the instructions for use, capabilities, limitations and oversight measures needed for implementation. Also establish a channel for risk and incident reports from deployers.
Deployer+
Use the system according to the instructions, assign competent and trained people for human oversight, and monitor operation. Check input data only to the extent that you control it. Retain automatically generated logs under your control for at least six months, unless other Union or national law provides otherwise. Suspend use and report risks or serious incidents in accordance with Article 26(5).
SME / Startup+
Article 26 contains no general SME exemption. Good vendor management helps but does not replace your own duties. Record who exercises oversight, how monitoring and escalation work, which logs are available and when workers or other affected persons must be informed.
Public Sector+
In addition to Article 26, check the registration duty for public deployers in Article 49 and the FRIA in Article 27. If an intended high-risk system is absent from the required EU database, a public deployer must not use it and must inform the provider or distributor.

Compliance checklist

  • Technical and organisational measures taken
  • Input data verified for relevance
  • AI system operation is monitored
  • Logs retained in accordance with Art. 19
  • Affected persons informed about AI use
  • FRIA conducted (if required, Art. 27)
  • Staff with AI literacy (Art. 4)

Want to save your progress? Create an account

Related recitals

Related tools

Related enforcement

  • CNIL fines Amazon €32 million for AI employee monitoringCNIL · Dec 2023
  • Hungarian bank fined for AI-based customer profilingNAIH · Aug 2021

Related blog posts

Cross-references

Annexes

Frequently asked questions

What are the obligations for deployers of high-risk AI?+
Article 26 requires deployers to use the system according to the instructions, take appropriate measures, appoint competent and trained people for human oversight, monitor operation and follow the specific rules on input data, logs, information, risks and incidents.
Do I need to conduct a FRIA as a deployer?+
Only where Article 27 applies to your organisation and the specific Annex III system. The duty covers bodies governed by public law, private entities providing public services and the specific creditworthiness and life and health insurance uses in Annex III points 5(b) and 5(c).
What should I do in case of an incident with high-risk AI?+
Where a serious incident is identified, the deployer immediately informs the provider first, followed by the importer or distributor and the competent authorities. If use according to the instructions may present a risk within Article 79(1), it suspends use and reports without undue delay.
Do SMEs also need to comply with Article 26 of the AI Act?+
Article 26 of the AI Act does not provide a general exemption for SMEs. However, the AI Act includes supportive measures and potentially lighter obligations for small and medium-sized enterprises, depending on their role in the AI value chain.
How does Article 26 of the AI Act relate to the GDPR?+
Article 26 of the AI Act complements the GDPR. While the GDPR protects personal data, the AI Act focuses on the safety and trustworthiness of AI systems. Organisations must comply with both regulations when their AI system processes personal data.
What are the deadlines for Article 26 of the AI Act?+
Article 26 applies from 2 December 2027 to high-risk systems under Article 6(2) and Annex III, and from 2 August 2028 to systems under Article 6(1) and Annex I.
Does Article 26 of the AI Act also apply to AI systems I purchase?+
Yes, Article 26 of the AI Act may also be relevant when you purchase AI systems. As a deployer, you have your own obligations under the AI Act, regardless of whether you developed the system yourself or purchased it from a provider.
What is the difference between provider and deployer under Article 26 of the AI Act?+
Under Article 26 of the AI Act, the provider is the entity that develops or places the AI system on the market, while the deployer is the entity that uses the system under its own authority. Both roles carry different obligations.
What should I as deployer do if my AI vendor goes bankrupt?+
The deployer's own duties continue if the provider is unavailable. Assess whether the system can still be used, monitored and overseen according to the instructions and whether the required logs and reporting channels remain available. Suspend use if safe and compliant operation can no longer be ensured.
When do I as deployer become a provider myself under the AI Act?+
You become a provider as a deployer when you: place the AI system on the market under your own name, substantially change the intended purpose of an already marketed system, or make a substantial modification to the system. In those cases, all provider obligations apply.
Do I as deployer need to retain the input and output data of the AI system?+
Article 26 contains no general duty to retain all input and output data. Automatically generated logs under the deployer's control are retained for at least six months, unless other Union or national law provides a different period.