Free template · Word · English and Dutch
High-risk AI assessment template for deployers: the Article 26 EU AI Act file
A high-risk AI file is the evidence file of the deployer, the organisation using an Annex III AI system under its own authority. For each system it records the role, the classification, the Article 26 obligations, the fundamental rights impact assessment (FRIA) test of Article 27 and Article 86 explanations. Articles 26 and 27 apply to Annex III systems from 2 December 2027.
- Last checked against the law
- Editor
- Zahed Ashkara, jurist, privacy and AI
- Version and template ID
- 2.0 ·
praxikon:template:high-risk-assessment - Legal basis
- Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744; Regulation (EU) 2016/679 (GDPR)
Who is this template for?
- Organisations that use an AI system listed in Annex III, for example in recruitment, credit scoring or admission to educationObligations of the deployer (Article 26(1) to (12))
- Employers that use AI in the workplaceInform workers' representatives and affected workers in advance (Article 26(7)); national labour law may add consultation or consent
- Public authorities and public bodiesRegistration of use in the EU database (Article 26(8) and Article 49(3)) and the fundamental rights impact assessment (Article 27)
- Banks, lenders and life and health insurersFundamental rights impact assessment for Annex III point 5(b) and (c) (Article 27(1))
- Data protection officers and privacy officersDPIA using the provider's information (Article 26(9); Article 35 GDPR) and bias testing (Article 4a)
- Procurement and contract managersWhat you need from the provider (Article 13(3)) and nine contract clauses
What is inside
- Timeline of what applies when, from the prohibited practices (since 2 February 2025) to 2 August 2030 (introduction)
- Decision box: do you remain the deployer or become the provider under Article 25(1) (chapter 1)
- Annex III table by point with what matters for the deployer, the Article 6(3) test and the Article 111(2) test for existing systems (chapter 2)
- Checklist of what you need from the provider before use (chapter 3)
- All twelve paragraphs of Article 26 with an overview table, model clauses 4.1 to 4.10, reporting deadlines and model texts for workers and affected persons (chapter 4)
- Fundamental rights impact assessment test under Article 27, with a decision box and six fictional situations (chapter 5)
- Explanation procedure and model reply under Article 86 (chapter 6)
- Checklist for bias testing with special categories of personal data under Article 4a (chapter 7)
- Evidence overview per obligation with location, owner and date last checked (chapter 8)
- Plan to 2 December 2027 (chapter 9)
- Nine contract clauses for procurement (chapter 10)
- Fictional worked example of CV screening at a logistics company (chapter 11) and an adoption block (chapter 12)
How to use the template
- Keep one file per high-risk system and first use chapter 1 to confirm that you remain the deployer.
- Classify the system with chapter 2 and record the outcome in your AI register as well.
- Request the instructions for use and the Article 13(3) information from the provider (chapter 3), and include the clauses from chapter 10 when you procure or renew.
- Work through the model clauses for each paragraph of Article 26, appoint oversight persons and inform workers and their representatives.
- Run the fundamental rights impact assessment test, set up the explanation procedure and update the evidence overview in chapter 8 every quarter.
- Have the file adopted and review it at every update from the provider and at least once a year.
Common mistakes
- Putting the provider's obligations in your own file. Risk management, technical documentation and CE marking (Article 16) rest on the provider; the deployer records how it meets Article 26.
- Assuming every deployer needs a fundamental rights impact assessment. Article 27 applies only to bodies governed by public law, private entities providing public services and deployers of systems under Annex III point 5(b) and (c); point 2 (critical infrastructure) is excluded.
- Relying on Article 6(3) while the system profiles people. A score or ranking per person is profiling, and the system is then always high-risk.
- Informing only the provider when there is a risk. Article 26(5) also requires you to inform the market surveillance authority and to suspend use.
- Using a general-purpose AI tool for an Annex III purpose, such as ranking job applicants. You may then become the provider of a high-risk system yourself (Article 25(1)(c)).
When do you need legal advice?
- You adapt the system or use it differently. Your own name on it, a substantial modification or a new Annex III purpose: you then become the provider yourself (Article 25(1)), with the obligations of Article 16.
- You want to rely on Article 111(2) or Article 6(3). Both routes are narrow. As deployer you must be able to show the facts, and an update from the provider can significantly change the design.
- The fundamental rights impact assessment, the DPIA and the GDPR overlap. You are a public body, assess creditworthiness or price life or health insurance, may take automated decisions (Article 22 GDPR) or want to use special categories of personal data for bias testing (Article 4a).
Frequently asked questions
What must a deployer of high-risk AI do?
Article 26 requires, among other things: use in accordance with the instructions for use, human oversight by competent and authorised persons, relevant and sufficiently representative input data to the extent you control it, monitoring and, in case of a risk, informing the provider or distributor and the market surveillance authority and suspending use, keeping logs for at least six months, informing workers in advance, and informing persons when the system makes or assists in decisions about them. Public authorities also register their use in the EU database.
When do the Article 26 obligations apply?
From 2 December 2027 for systems listed in Annex III and from 2 August 2028 for systems under Annex I, Section A. These dates follow from Regulation (EU) 2026/1744, in force since 27 July 2026. For systems already on the market or in service before then, Article 111(2) applies: the obligations apply only after a significant change in design, and systems intended for public authorities must comply by 2 August 2030. The prohibited practices have applied since 2 February 2025.
Does every deployer need a fundamental rights impact assessment (FRIA)?
No. From 2 December 2027 Article 27 applies to bodies governed by public law and private entities providing public services that use an Annex III system (except point 2), and to every deployer of a system for creditworthiness or for risk assessment and pricing in life and health insurance (Annex III point 5(b) and (c)). A DPIA under Article 35 GDPR may still be required.
When does a deployer become the provider?
Under Article 25(1), when you put your name or trademark on a high-risk system, make a substantial modification so that it remains high-risk, or use a system that is not high-risk for an Annex III purpose. You then take on the obligations of Article 16, such as conformity assessment and technical documentation.
What is the fine for breaching Article 26?
The AI Act sets a maximum of EUR 15 million or 3 per cent of worldwide annual turnover, whichever is higher, for the Article 26 obligations (Article 99(4), point (e)). For SMEs, start-ups and small mid-cap enterprises the lower of the two applies. Each Member State lays down its penalties within those limits. On 6 October 2026 the Netherlands, for example, had not yet designated its AI Act authorities by law.
May I adapt the template and share it within my organisation?
Yes. You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
Use and credit
You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
How to cite this template: Source: Praxikon, High-risk AI assessment template for deployers: the Article 26 EU AI Act file, version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/high-risk-assessment
This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.
Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597