Article 16

EU AI Act Article 16 — Provider Obligations Checklist

Article 16 of Regulation (EU) 2024/1689 lists the obligations of providers of high-risk AI systems. The thirteen-point checklist, what each item means, and how to evidence compliance.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 16 actually requires

Article 16 of Regulation (EU) 2024/1689 lists the thirteen obligations of providers of high-risk AI systems. It is the cross-reference index for the rest of Chapter III Section 3.

The thirteen obligations (paraphrased)

Providers shall:

  • (a) Ensure their high-risk AI systems comply with the requirements set out in Section 2 (Articles 8–15).
  • (b) Indicate on the system, packaging or accompanying documentation the provider's name, registered trade name or trade mark, and contact address.
  • (c) Have a quality management system in place per Article 17.
  • (d) Keep the documentation referred to in Article 18 — for 10 years from placement.
  • (e) Keep the Article 19 automatic logs when those logs are under their control.
  • (f) Ensure the system undergoes the relevant conformity assessment procedure per Article 43 before placement.
  • (g) Draw up the EU declaration of conformity per Article 47.
  • (h) Affix the CE marking per Article 48 where applicable.
  • (i) Comply with the registration obligations referred to in Article 49(1) — EU Database entry.
  • (j) Take corrective actions and provide information as required by Article 20.
  • (k) Demonstrate, on reasoned request from a national competent authority, the conformity of the high-risk AI system with Section 2 requirements.
  • (l) Ensure the high-risk AI system complies with accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882.
  • (m) Where the provider is established outside the Union, designate by written mandate an authorised representative established in the Union per Article 22.

Who is covered

Article 16 applies to all providers of high-risk AI systems as defined in Article 3(3). Article 25 extends the obligations to entities promoted to provider through brand-on-it, substantial modification, or intended-purpose change.

What to do

Treat Article 16 as a one-page assurance dashboard for your compliance programme. Each item maps to a specific evidence pack:

ObligationEvidence
16(c) QMSArticle 17 QMS manual
16(d) docs retention10-year retention policy + storage location
16(f) conformity assessmentAnnex IV / Article 43 outcome
16(g) declaration of conformitySigned Article 47 document
16(i) registrationEU Database entry ID
16(j) corrective actionsDocumented procedure + activation records
16(m) EU representativeWritten mandate, representative contact details

Inline crosswalk

  • ISO/IEC 42001:2023 Clause 5 — Leadership.
  • ISO/IEC 42001:2023 Annex A.10 — Third-party relationships (for 16(m) and supplier coordination).
  • NIST AI RMF GOVERN 2.1 — Roles, responsibilities, lines of communication for AI risk management.

Common mistakes

  • Skipping 16(m) — non-EU providers without an authorised representative cannot lawfully place systems on the EU market.
  • Late conformity assessment — Article 16(f) is before placement on the market.
  • Generic "CEO" signature on the Article 47 declaration. Use a named accountable role.

Penalties

Article 99(4) — up to €15 million or 3% of worldwide annual turnover.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 17 · Starter tier · medium

    Set up quality management system (QMS)

    Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.

  • Article 43 · Starter tier · critical

    Complete conformity assessment procedure

    Required before placing a high-risk system on the market. Internal self-assessment for most Annex III; notified body for §1 biometrics.

  • Article 49 · Starter tier · medium

    Register high-risk system in EU database

    Public transparency register. Must be updated annually. Filing is online via the EU AI Office portal.

  • Article 16 · Pro tier · critical

    Appoint authorised representative in EU (non-EU providers)

    Article 22 requires non-EU providers to designate a written-mandate representative established in the Union before placement on market.

  • Article 16 · Pro tier · medium

    Document corrective-action procedure for detected non-conformities

    Article 16(j) requires providers to take necessary corrective actions (withdrawal, disabling, recall) when non-conformity is found.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art17-qmsISO/IEC 42001:2023 Clause 4 — Context of the organisationArticle 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context.
art17-qmsISO/IEC 42001:2023 Clause 5 — Leadership and AI policyA QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements.
art17-qmsISO/IEC 42001:2023 Clause 9 — Performance evaluationQMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9.
art43-conformityISO/IEC 42001:2023 Clause 9.2 — Internal auditInternal self-assessment (Article 43 §1 path) and independent review map onto the internal-audit programme of Clause 9.2.
art49-eudbISO/IEC 42001:2023 Annex A.8.3 — External reportingFiling in the EU AI Office public register evidences Annex A.8 external transparency to interested parties.
art16-registered-officeISO/IEC 42001:2023 Annex A.10.2 — Allocation of responsibilities with suppliers and partnersA written-mandate EU representative is the allocation-of-responsibilities control in Annex A.10 third-party relationships.
art16-corrective-actionsISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective actionArticle 16(j) corrective-action procedure for non-conformities directly satisfies Clause 10.2.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art17-qmsNIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and proceduresA QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2.
art17-qmsNIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documentedQMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects.
art43-conformityNIST AI RMF GOVERN 4.1 — Organizational practices are in place to foster a critical thinking and safety-first mindset; effective challenge for AI deployment is in placeConformity assessment is the documented effective-challenge step before deployment that GOVERN 4.1 mandates.
art49-eudbNIST AI RMF GOVERN 5.1 — Organizational policies and practices are in place to collect, consider, prioritize, and integrate external feedbackPublic registration enables the external-feedback intake GOVERN 5.1 expects organisations to operationalise.
art16-registered-officeNIST AI RMF GOVERN 6.1 — Policies and procedures are in place to address AI risks and benefits arising from third-party software and dataDesignating a written-mandate EU representative is part of the third-party-relationship governance GOVERN 6.1 covers.
art16-corrective-actionsNIST AI RMF MANAGE 2.4 — Mechanisms are in place and applied to supersede, disengage, or deactivate existing AI systems that demonstrate performance or outcomes inconsistent with intended useArticle 16(j) withdrawal/disabling/recall procedure is the supersede/deactivate mechanism MANAGE 2.4 mandates.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.