COMPLIPATHDOC complipath.io/guides/ai-act-transparency-obligationsRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Requirements ·By Yobel Tzegai ·Updated 20 August 2026

What are the EU AI Act's transparency obligations toward deployers under Article 13?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

Article 13 requires providers of high-risk AI systems to make operation "sufficiently transparent to enable deployers to interpret a system's output and use it appropriately", and to ship instructions for use containing at least the information listed in Article 13(3). This is provider-to-deployer transparency — not the user-facing Article 50 duties.

Quick answer

Is Article 13 the same as the AI Act's chatbot transparency rules?

No — searches for "AI Act transparency obligations" constantly land on the wrong article. Article 50, in Chapter IV, makes providers and deployers disclose AI to the people exposed to it: chatbot disclosure, synthetic-content marking, deep-fake labels. Article 13, in Section 2 of Chapter III, runs between businesses: the provider of a high-risk system must equip the deployer — the organisation operating the system — to understand and control it. A recruitment tool can owe both at once; neither substitutes for the other. Article 50 is covered in the limited-risk transparency guide; everything below is Article 13.

What does Article 13(1) require in the system's design?

Article 13(1) requires that high-risk AI systems "be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system's output and use it appropriately". That is a product requirement, not a documentation one — a score with no indication of what drove it, shipped with a polished manual, still fails "designed and developed".

The benchmark is functional: Article 13(1)'s second sentence requires "an appropriate type and degree of transparency" with a view to achieving compliance with "the relevant obligations of the provider and deployer set out in Section 3" — the obligations in Articles 16 to 27. Transparency is sufficient when the deployer can discharge its duties: use the system per instructions, monitor it, oversee it. "Appropriate type and degree" also means the Act mandates no particular explainability technique — the test is whether the deployer can interpret and use the output.

What standard must the instructions for use meet?

Article 13(2) requires that high-risk systems "be accompanied by instructions for use in an appropriate digital format or otherwise" — digital delivery is expressly allowed — containing "concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers".

Read the adjectives as a test — each fails a familiar document. "Concise" fails the 200-page PDF assembled to be safe; "complete" fails the quick-start guide that omits limitations; "correct" fails marketing claims about accuracy; "comprehensible to deployers" fails a data-science appendix aimed at your ML team rather than the compliance lead who will operate the system. Concise and complete is the hard pair: structure over volume.

The Act defines the artefact: "instructions for use" means "the information provided by the provider to inform the deployer of, in particular, an AI system's intended purpose and proper use" (Article 3, point (15)). And the definition cuts the other way too: under Article 3, point (12), the system's "intended purpose" is specified by information the provider supplies "in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation" — three channels, read together. So the instructions co-define the scope of use your compliance story rests on — and with it reasonably foreseeable misuse, which Article 3, point (13) measures against intended purpose as a whole. They cannot narrow that scope below what your sales materials already claim.

What must the instructions for use contain?

Article 13(3) sets a floor — "at least the following information":

The seven sub-points of Article 13(3), point (b)

Mind the qualifiers, both ways. Points (a), (b)(i), (b)(ii), (b)(iii), (d) and (e) carry no condition on the item itself — point (a)'s "where applicable" attaches only to the authorised representative — so they are always due. Points (b)(iv) and (b)(vii) apply "where applicable", (b)(v) and (b)(vi) "when appropriate", (c) "if any", (f) "where relevant". As a matter of evidence rather than statute, record why you skipped a conditional item; an unconditional item cannot be skipped at all.

Who reads the instructions after you ship them?

More parties than most providers expect — thin instructions surface as someone else's compliance failure. Importers must verify the system is accompanied by instructions for use before placing it on the market (Article 23(1), point (c)) and keep a copy for 10 years (Article 23(5)); distributors verify the same before making it available (Article 24(1)). Deployers must use the system "in accordance with the instructions for use" (Article 26(1)), monitor its operation "on the basis of the instructions for use" (Article 26(5)), and, where applicable, use the Article 13 information for their data protection impact assessments (Article 26(9)). Deployers required to run a fundamental rights impact assessment under Article 27 must identify specific risks of harm "taking into account the information given by the provider pursuant to Article 13" (Article 27(1), point (d)). The technical documentation loops in: point 1(h) of Annex IV requires the instructions for use themselves, and point 2(e) an assessment of the human oversight measures needed in accordance with Article 14, including the technical measures needed to facilitate interpretation of the outputs, in accordance with Article 13(3), point (d). Every gap you leave propagates down that chain.

What this means for you

If you're a provider: Article 13 applies from 2 December 2027 to Annex III systems and from 2 August 2028 to Annex I systems (Article 113, third paragraph, point (c)) — the full obligation set is in the high-risk overview. Draft the instructions against Article 13(3) item by item: unconditional items complete, each conditional item answered or waived with reasons, accuracy metrics matching what testing showed rather than what sales claims, and misuse scenarios from your Article 9 risk work under point (b)(iii). Then check Article 13(1) separately — instructions cannot cure an output nobody can interpret. Complipath's requirements checklist tracks every obligation the classification triggers, with status, owner, evidence link and notes — for Article 13, the evidence is the current instructions-for-use version itself.

If you're a deployer: The instructions for use are the document your own duties are measured against: Article 26(1) obliges you to use the system in accordance with them, Article 26(5) to monitor on their basis. Before contracting, test it against the Article 13(3) list — no accuracy metrics, no limitations, no oversight measures means the provider has a Section 2 problem and you have no basis for compliant operation. If your organisation owes a DPIA or an Article 27 fundamental rights impact assessment, this document is the input the law points you to (Article 26(9); Article 27(1), point (d)).

Which of your systems ship instructions for use?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Does Article 13 cover telling end users they are interacting with AI? No. That is Article 50, in Chapter IV: chatbot disclosure, content marking, deep-fake labels. Article 13 runs from the provider to the deployer of a high-risk system — the organisation operating it — through design transparency and instructions for use. A system can owe both at once.

Do the instructions for use have to be a printed document? No. Article 13(2) requires instructions "in an appropriate digital format or otherwise" — digital delivery is expressly permitted. What is fixed is the quality standard — concise, complete, correct and clear information, relevant, accessible and comprehensible to deployers — plus the minimum content listed in Article 13(3).

Is every item in Article 13(3) mandatory for every high-risk system? The list is a floor — "at least" — but several items are conditional on their own terms: explainability capabilities and interpretation information "where applicable", group-specific performance and input-data specifications "when appropriate", pre-determined changes "if any", log mechanisms "where relevant". As a matter of evidence, record why a conditional item does not apply; never skip an unconditional one.

When does Article 13 start to apply? Not yet. Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744, sets 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems high-risk under Article 6(1) and Annex I — products covered by the Union harmonisation legislation listed in Annex I, or their safety components.


Sources: Regulation (EU) 2024/1689, Articles 3, 6, 9, 12, 13, 14, 15, 16, 23, 24, 26, 27, 50 and 113, and Annex IV (EUR-Lex), as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 113, third paragraph, point (c). Article 13 itself is unamended; only its date of application moved. Article 50's own application date is unchanged, and Article 27(1), point (d) — the fundamental rights impact assessment cross-reference relied on here — was not among the Article 27 paragraphs the amending regulation replaced. The Article 40 harmonised standards expected to concretise the Section 2 requirements — including what "sufficiently transparent" means in practice — were still incomplete at the time of writing; the obligations apply regardless.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.