Skip to main content
Praxikon
Comparisons

Comparison

Article 16 versus Article 26: what the provider owes and what the deployer owes

The difference

Article 16 addresses the provider: whoever places a high-risk AI system on the market under their own name or trademark has to build, document and monitor it so that it meets the requirements. Article 26 addresses the deployer: whoever puts such a system into use has to use it in line with the instructions, assign human oversight and keep monitoring how it behaves.

The official source remains authoritative. This is general interpretation and not legal advice about your situation.

The fields side by side

Every row comes from the objects themselves. Where a field is empty, it says so; we do not fill in an assumption where the source is silent.

Status

Article 16, provider
Upcoming
Article 26, deployer
Upcoming

Applies from

Article 16, provider
2 December 2027
Article 26, deployer
2 December 2027

Who carries the duty

Article 16, provider
Provider of an AI system
Article 26, deployer
Deployer, Body governed by public law

Who is affected

Article 16, provider
Not recorded
Article 26, deployer
Not recorded

Who supervises

Article 16, provider
Not recorded
Article 26, deployer
Market surveillance authority

When this applies

Article 16, provider
Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
Article 26, deployer
Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028.

Exceptions

Article 16, provider
A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
Article 26, deployer
Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law.

First actions

Article 16, provider
Assign an internal owner and a date to each point of Article 16
Article 26, deployer
Assign human oversight and give those people a mandate

Evidence that belongs with it

Article 16, provider
Provider dossier per high-risk AI system
Article 26, deployer
Deployment dossier: logs, worker information and information to affected persons

Control

Article 16, provider
Release gate before placing on the market
Article 26, deployer
Suspension and incident notification control

Version and review status

Article 16, provider
v1.0.0, placed against the official source
Article 26, deployer
v1.0.0, placed against the official source

Official sources and locators

Per side, the provisions the statements above rest on.

Article 16, provider

Article 26, deployer

Referring to these two objects

Each side has its own stable identifier, version and hash. Take them separately; you cite a comparison by citing the two objects.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 16: the twelve duties of a provider of a high-risk AI system",
praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275,
https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0 (sha256 69744054)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-16-provider-obligations-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 16: the twelve duties of a provider of a high-risk AI system},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-16-provider-obligations},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275},
  url          = {https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0",
    "type": "dataset",
    "title": "Article 16: the twelve duties of a provider of a high-risk AI system",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-16-provider-obligations",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 26: obligations of deployers of high-risk AI systems",
praxikon:eu:ai-act:obligation:article-26-deployer-obligations@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c,
https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-26-deployer-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-26-deployer-obligations@1.0.0 (sha256 0269a6f8)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-26-deployer-obligations-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 26: obligations of deployers of high-risk AI systems},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-26-deployer-obligations},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c},
  url          = {https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-26-deployer-obligations@1.0.0",
    "type": "dataset",
    "title": "Article 26: obligations of deployers of high-risk AI systems",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-26-deployer-obligations",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-26-deployer-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Execution

Record the classification in an AI register

The distinction between these two is a classification decision, and a classification without a register, an owner and a date cannot be defended afterwards. Praxikon does not carry that out; Embed AI guides the classification, the register and the reassessment in a fixed approach.

See the Embed AI approach

Unsure about your role itself rather than the duties that come with it? Work out whether you are a provider or a deployer