What does a provider owe under Article 16 of the EU AI Act?
A provider of a high-risk AI system owes the twelve duties in Article 16: the Section 2 requirements, its name and contact address, a quality management system, documentation, the logs under its control, a conformity assessment, an EU declaration of conformity, the CE marking, registration, corrective action and information, proof of conformity on request and accessibility. They apply from 2 December 2027 for Annex III systems and from 2 August 2028 for systems under Section A of Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article 16 was not amended.
The short answer
- High-risk systems only, and none related to products under Section B of Annex I (Article 2(2), as replaced).
- The dates: 2 December 2027 for Annex III systems, 2 August 2028 for systems under Section A of Annex I (Article 113, third paragraph, point (c), as replaced).
- Section 5 runs earlier: Articles 43, 47, 48 and 49 have applied since 2 August 2026 (Article 113, second paragraph). How they operate before Article 16 applies is an open question.
Who is the provider, and which systems count?
Whether you are the provider is a question of its own. Article 2(2), as replaced, applies only Article 6(1), Article 60a and Articles 102 to 112 to systems related to products under Section B of Annex I, so not Article 16. For other Annex I systems, Article 2(13), as added, allows specific requirements or obligations in Articles 9 to 15 and 17 to 25 to be limited, on the conditions it sets and as delegated acts due by 2 August 2027 will specify.
What must the system itself meet?
Point (a) is compliance with the Section 2 requirements, Articles 8 to 15. Point (b) puts the provider's name, registered trade name or registered trade mark and contact address on the system or, where that is not possible, on its packaging or its accompanying documentation, as applicable. Point (l) requires compliance with accessibility requirements in accordance with Directives (EU) 2016/2102 and (EU) 2019/882.
What must the provider keep?
Point (c) is a quality management system in place which complies with Article 17. What it must cover, and how Article 17(2), as replaced, scales it for an SME or an SMC: the quality management system guide.
Point (d) is Article 18: the technical documentation, the quality management system documentation, the EU declaration of conformity and, where applicable, notified-body approvals of changes, decisions and other documents, kept at the disposal of the national competent authorities for 10 years after placing on the market or putting into service (Article 18(1)). Point (e) is the automatically generated logs under the provider's control, kept for a period appropriate to the intended purpose and of at least six months, unless applicable Union or national law provides otherwise, in particular Union law on the protection of personal data (Article 19(1)). Financial institutions keep the technical documentation and the logs within their financial services documentation (Article 18(3) and Article 19(2)).
Which procedures does Article 16 point to?
Point (f) is the Article 43 conformity assessment, before placing on the market or putting into service: internal control under Annex VI, with no notified body, for points 2 to 8 of Annex III (Article 43(2)); Annex VI or Annex VII for point 1, on the conditions in Article 43(1); the procedure of the Section A legislation of Annex I for systems it covers, including those also in Annex III, with the Section 2 requirements and the quality management system assessed as part of it (Article 43(3), as replaced). Our Article 43 guide has each route and when a new one is due.
Point (g) is drawing up an EU declaration of conformity in accordance with Article 47. What it states, and how long it is kept: the declaration of conformity guide.
Point (h) is the CE marking, affixed visibly, legibly and indelibly, or to the packaging or the accompanying documentation where that is not possible or not warranted (Article 48(3)).
Point (i) is compliance with the registration obligations referred to in Article 49(1). Which systems, by whom and when: the EU database registration guide.
What if something goes wrong, or an authority asks?
Point (j) is Article 20. A provider that considers or has reason to consider a system it placed on the market or put into service not in conformity immediately takes the necessary corrective actions to bring it into conformity, withdraw, disable or recall it, as appropriate. It informs the distributors and, where applicable, the deployers, the authorised representative and importers (Article 20(1)). If the system presents a risk within the meaning of Article 79(1), the provider, once aware, immediately investigates the causes, with the reporting deployer where applicable. It informs the competent market surveillance authorities and, where applicable, the certifying notified body (Article 20(2)).
Point (k): on a reasoned request of a national competent authority, the provider demonstrates conformity with the Section 2 requirements.
When do the Article 16 duties apply?
Article 16 is in Chapter III, Section 3, so the dates in the first paragraph apply (Article 113, third paragraph, point (c), as replaced).
Articles 43, 47, 48 and 49 are in Section 5, which no point of Article 113, third paragraph, names: they have applied since 2 August 2026, the general date in the second paragraph of Article 113, as have Articles 72 and 73 on post-market monitoring and serious incidents, whose duties attach to high-risk systems. The duties that point to Section 5, Article 16, points (f), (g), (h) and (i), apply later, as do the Section 1 rules that decide which systems are high-risk. Regulation (EU) 2026/1744 does not say how Section 5, or Articles 72 and 73, operate meanwhile: an open question we do not resolve.
A system placed on the market or put into service before "the date of application of Chapter III referred to in Article 113" is caught only if, as from that date, it is subject to significant changes in its design, unless it is a component of a large-scale IT system established by an act listed in Annex X, which Article 111(1) governs (Article 111(2), as replaced); the text does not say which of the Chapter's dates that is. In any case, the providers and deployers of high-risk systems intended to be used by public authorities take the necessary steps to comply by 2 August 2030. The legacy systems guide has the rest.
What does Complipath do here, and what does it not?
The AI inventory records each system with its classification and the article behind it. Each duty that follows carries an owner, a status and a date; evidence is linked with the passage and its page. The Annex IV documentation is drafted from the register and says which limbs it could not answer.
Conformity assessment (Article 43), post-market monitoring (Article 72) and serious incident reporting (Article 73): we found no support for these in what we have built. Declaration of conformity (Article 47): the Annex IV documentation asks for a copy of the declaration and you upload it; the plan says to issue it when the system is ready. The declaration itself is not drafted. EU database registration (Article 49) and the risk management system (Article 9) are each listed as a duty with its date. The registration itself is yours. There is no risk register to run the Article 9 cycle in. The full table is on what Complipath is.
What this means for you
If you're a provider: run points (f) and (g) per system, and date each system by whether it is high-risk under Annex III or Annex I.
If you're a deployer: Article 16 becomes yours where Article 25(1) makes you the provider of a system already placed on the market or put into service: you put your name or trademark on a high-risk system, "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated"; you modify it substantially and it remains high-risk; or you change its intended purpose so that it becomes high-risk. When a deployer becomes a provider has each case; your own duties are in Article 26.
FAQ
Does Article 16 apply before 2 December 2027? No. Article 16 is in Chapter III, Section 3, which applies from 2 December 2027 for Annex III systems and 2 August 2028 for Section A of Annex I (Article 113, third paragraph, point (c), as replaced). Articles 43, 47, 48 and 49 have applied since 2 August 2026 (Article 113, second paragraph); how they operate meanwhile is open.
Is the CE marking for a SaaS product a sticker? No. A high-risk system provided digitally uses a digital CE marking, and only if it can easily be accessed via the interface from which the system is accessed or via an easily accessible machine-readable code or other electronic means (Article 48(2)). Where applicable, the notified body's identification number follows it (Article 48(4)).
Must every high-risk system be registered in the EU database? No. Article 16, point (i) refers to Article 49(1), which covers Annex III systems except point 2; point 2 systems are registered at national level (Article 49(5)). A system high-risk only under Article 6(1) is outside it. A provider concluding under Article 6(3) that an Annex III system is not high-risk still registers, under Article 49(2).
Can a small provider run a lighter quality management system? A proportionate one. Article 17(2), as replaced by Regulation (EU) 2026/1744, makes the implementation proportionate to the size of the provider's organisation, in particular for an SME, including a start-up, or an SMC. Providers must still respect the degree of rigour and the level of protection required for their high-risk systems to comply.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 2(2) and (13), Article 6(1) and (3), Articles 8 to 15, Article 16, Article 17, Article 18, Article 19, Article 20, Article 25(1), Article 40, Article 43, Article 47, Article 48, Article 49, Article 60a, Article 71, Article 72, Article 73, Article 79(1), Articles 102 to 112, Article 111(1) and (2), Article 113 and Annexes I, III, V, VI, VII and X; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 2(2), added Article 2(13), inserted Article 6(1a), (1b) and (1c), replaced Article 10(1) and (6), deleted Article 10(5), replaced the second subparagraph of Article 11(1) and replaced Article 17(2), Article 43(3), Article 111(2) and Article 113, third paragraph, point (c). Article 16 was not amended.
Where this question meets the product: EU AI Act compliance for AI providers. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.