Article 16: the twelve duties of a provider of a high-risk AI system
Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.
Article 16 requires providers of high-risk AI systems to do twelve things.
Praxikon tracks Article 16: the twelve duties of a provider of a high-risk AI system under the EU AI Act, checked against the official source on 8 August 2026, citing the source for every statement.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Review status: placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
From source to evidence
Why this obligation applies, what it asks of you, and what you show for it.
Applies
Upcoming · 2 December 2027
For whom
Provider of an AI system
What you do
Assign an internal owner and a date to each point of Article 16
What you record
Provider dossier per high-risk AI system
Official source
Who this is relevant to
When this applies
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
What the official source establishes
Article 16 requires providers of high-risk AI systems to do twelve things. They must ensure their systems comply with the requirements of Chapter III, Section 2 (point (a)); indicate on the system or, where that is not possible, on its packaging or accompanying documentation, their name, registered trade name or registered trade mark and the address at which they can be contacted (point (b)); have a quality management system in place complying with Article 17 (point (c)); keep the documentation referred to in Article 18 (point (d)); keep the automatically generated logs referred to in Article 19 when under their control (point (e)); ensure the system undergoes the conformity assessment procedure referred to in Article 43 prior to being placed on the market or put into service (point (f)); draw up an EU declaration of conformity in accordance with Article 47 (point (g)); affix the CE marking in accordance with Article 48 (point (h)); comply with the registration obligations referred to in Article 49(1) (point (i)); take the necessary corrective actions and provide the information required under Article 20 (point (j)); upon a reasoned request of a national competent authority, demonstrate conformity with the requirements of Section 2 (point (k)); and ensure the system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 (point (l)).
Our interpretation
The official source remains authoritative. This general interpretation is not legal advice.
Article 16 reads like a table of contents and is therefore often planned as a single roadmap line. It is twelve separate duties with widely differing lead times: building a quality management system takes months, affixing a CE marking takes a day. The bigger trap sits in Article 25(1): anyone who puts their own brand on an existing high-risk system, substantially modifies it, or changes the intended purpose of a non-high-risk system so that it becomes high-risk counts as a provider and inherits all twelve points without ever having built anything. In the branding scenario of point (a) this applies without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated, but you must have made and be able to show those arrangements in advance. In practice this catches parties that white-label AI or apply a general-purpose model to an Annex III use case.
What you can do now
First determine whether you are a provider or whether Article 25 makes you one, then work out the twelve points as twelve separate work packages with an owner and a date. Start with points (c) and (f), because they set the lead time of the whole track.
- 01
Assign an internal owner and a date to each point of Article 16
Translate the twelve points (a) to (l) into twelve named owners with a start date, so that no point falls between product management, quality and legal.
What to retain
Provider dossier per high-risk AI system
One dossier per system holding the documentation, the logs, the EU declaration of conformity and the registration record, in the version that applied at the moment of placing on the market.
Control and reassessment
Release gate before placing on the market
A hard block in your release or delivery process: no delivery without a completed conformity assessment, a signed EU declaration of conformity, an affixed CE marking and a completed registration.
Public tools
Full text of Article 16
The full legal text in the public AI Act Explorer.
Conditions and exceptions
- A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 16(a)-(l)
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Article 16: the twelve duties of a provider of a high-risk AI system", praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z, sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275, https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-09-07)
Short form
praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0 (sha256 69744054)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-16-provider-obligations-1-0-0,
author = {{Praxikon}},
title = {Article 16: the twelve duties of a provider of a high-risk AI system},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:article-16-provider-obligations},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
note = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275},
url = {https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations},
urldate = {2026-09-07},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0",
"type": "dataset",
"title": "Article 16: the twelve duties of a provider of a high-risk AI system",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:article-16-provider-obligations",
"URL": "https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
8
]
]
},
"accessed": {
"date-parts": [
[
2026,
9,
7
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Version history
v1.0.0
8 August 2026
Article 16: the twelve duties of a provider of a high-risk AI system
Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.
Corrections to this obligation
No substantive correction to this object has been recorded.
Open the correction logExecution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.
