Guide · Roles · Article 26

What does a deployer owe under Article 26 of the EU AI Act?

A deployer of a high-risk AI system uses it in accordance with its instructions for use, assigns human oversight to competent people, monitors it, keeps its logs and informs the people it affects (Article 26). Those duties attach to high-risk systems only, from 2 December 2027 for Annex III systems (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).

Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article 26 was not amended.

The short answer

  • Only for high-risk systems. Article 26 is headed "Obligations of deployers of high-risk AI systems". A general-purpose assistant used for drafting owes Article 4, not Article 26.
  • Every day it runs: use it as instructed (Article 26(1)), assign human oversight to people with the necessary competence, training, authority and support (Article 26(2)), and check the input data you control (Article 26(4)).
  • Watching it: monitor it, inform and suspend on a risk, report serious incidents (Article 26(5)), and keep its logs for at least six months (Article 26(6)).
  • Telling people: workers before workplace use (Article 26(7)), and the people an Annex III system decides about (Article 26(11)).
  • The date: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as replaced).

Which systems does Article 26 cover?

High-risk ones, and only those. A system is high-risk under Article 6(1) when it is a product, or the safety component of a product, covered by the legislation in Annex I and that product must undergo a third-party conformity assessment under it, or under Article 6(2) when Annex III lists its use, unless Article 6(3) takes an Annex III system out, which it never does for a system that profiles natural persons. Whether you are the deployer at all is a question of its own: Article 3, point (4) makes it whoever uses a system under its authority, outside a personal non-professional activity.

Two duties do not wait for high-risk. The AI literacy duty in Article 4 binds the deployers of every AI system, and Article 50 adds disclosure duties for some systems whatever their tier.

What must a deployer do while the system runs?

Article 26(1) has the deployer take appropriate technical and organisational measures to use the system in accordance with the instructions for use. Article 26(2) has it assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Article 26(3) adds that both are without prejudice to other deployer obligations under Union or national law, and to the deployer's freedom to organise its own resources and activities to implement the oversight measures the provider indicates. Where the deployer controls the input data, Article 26(4) has it ensure the data is relevant and sufficiently representative in view of the system's intended purpose.

Monitoring is Article 26(5). The deployer monitors operation on the basis of the instructions for use and, where relevant, informs providers in accordance with Article 72. If it has reason to consider that use in accordance with the instructions may result in a risk within the meaning of Article 79(1), it informs the provider or distributor and the relevant market surveillance authority without undue delay, and suspends use. A serious incident goes immediately to the provider first, then to the importer or distributor and the relevant market surveillance authorities; if the provider cannot be reached, Article 73 applies mutatis mutandis. The duty does not cover sensitive operational data of deployers that are law enforcement authorities. For financial institutions subject to internal governance requirements under Union financial services law, the monitoring duty is deemed fulfilled by complying with those rules.

Article 26(6) has the deployer keep the logs the system automatically generates, to the extent they are under its control, for a period appropriate to the intended purpose and of at least six months, unless applicable Union or national law, in particular on personal data, provides otherwise. Financial institutions keep them as part of the documentation their financial services law requires.

Who must the deployer tell?

Workers first. Before putting into service or using a high-risk system at the workplace, a deployer that is an employer informs the workers' representatives and the affected workers that they will be subject to it, where applicable in accordance with Union and national law and practice on informing workers (Article 26(7)). Then the people the system decides about: a deployer of an Annex III system that makes or assists in making decisions related to natural persons informs them that they are subject to it, without prejudice to Article 50, and for law enforcement Article 13 of Directive (EU) 2016/680 applies (Article 26(11)). What Article 13 has the provider give you is what these notices are built from.

A deployer that is a public authority or a Union institution, body, office or agency complies with the registration obligations in Article 49, and does not use a system it finds unregistered in the EU database; it informs the provider or the distributor instead (Article 26(8)). Every deployer cooperates with the relevant competent authorities in any action they take in relation to the system to implement the Regulation (Article 26(12)).

What else does Article 26 reach?

Two paragraphs most deployers will not meet. Article 26(9) has deployers use the information provided under Article 13, where applicable, to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680. Article 26(10) governs post-remote biometric identification in the targeted search for a person suspected or convicted of a criminal offence, under conditions that include an authorisation by a judicial authority or by an administrative authority whose decision is binding and subject to judicial review. Read it in full if it applies to you.

A fundamental rights impact assessment is not Article 26. It is Article 27(1), for bodies governed by public law, private entities providing public services and deployers of points 5(b) and (c) of Annex III, except for systems in the area in point 2 of Annex III.

When do the Article 26 duties apply?

Article 26 is in Chapter III, Section 3. Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, applies Sections 1, 2 and 3, with the exception of Article 6(5), from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I.

For a system placed on the market or put into service before that date, Article 111(2), as replaced, applies the Regulation only if the system is then subject to significant changes in its design. Article 111(2) keeps one exception: providers and deployers of high-risk systems intended to be used by public authorities take the necessary steps to comply by 2 August 2030.

What does Complipath do here, and what does it not?

The AI inventory records each system with its classification and the article behind it, so the high-risk ones, the only ones Article 26 reaches, are visible. Each duty that follows carries an owner, a status and a date, and the evidence for it is linked with the passage and its page. Complipath does not monitor a system in operation, keep its logs or report serious incidents: the rows for post-market monitoring (Article 72) and serious incident reporting (Article 73) in its status table say Not supported.

What this means for you

If you're a deployer: list the systems first, then mark the high-risk ones; Article 26 is a list of things to do for those alone. Ask each provider for the instructions for use now, because paragraphs 1, 2, 5 and 6 are measured against them.

If you're a provider: your customers' Article 26 duties are built from what you give them, the instructions for use under Article 13 and the logs under Article 12. When a deployer becomes a provider is the same line crossed in the other direction.

FAQ

Does Article 26 apply to us if we only use ChatGPT? Not for drafting, summarising or answering questions: Article 26 binds deployers of high-risk AI systems. Article 4 on AI literacy applies to every use. If you use a general-purpose assistant for a purpose Annex III lists, such as screening applicants, Article 25(1), point (c) can make you the provider of a high-risk system.

How long must a deployer keep the logs? For a period appropriate to the system's intended purpose and of at least six months, to the extent the logs are under the deployer's control, unless applicable Union or national law, in particular on personal data, provides otherwise (Article 26(6)). Financial institutions keep them with the documentation their financial services law requires.

Do we have to tell employees before using a high-risk system? Yes, if you are their employer and the system is used at the workplace. Article 26(7) has you inform the workers' representatives and the affected workers before putting it into service or using it, where applicable in accordance with Union and national law and practice on informing workers.

Can we contract the Article 26 duties out to the provider? No. Article 26 puts them on the deployer. Article 26(3) preserves your freedom to organise your own resources and activities to implement the oversight measures the provider indicates; it does not move the duties. A contract can allocate cost and cooperation, and the provider's instructions for use are what most of the duties are measured against.

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 3, point (4), Article 6, Article 25(1), Article 26, Article 27(1), Article 49, Article 111(2) and Article 113; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 4, Article 111(2) and Article 113, third paragraph, point (c). Article 26 was not amended.

Where this question meets the product: the EU AI Act by tool, industry and country. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextEU AI Act provider obligations (Article 16)Article 16Article 27 fundamental rights impact assessmentArticle 27EU AI Act database registration (Article 49)Article 49 and Annex VIII

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free