Article 26

EU AI Act Article 26 — Deployer Obligations

Article 26 of Regulation (EU) 2024/1689 sets the obligations on deployers of high-risk AI systems. Use per IFU, human oversight assignment, input-data quality, monitoring, and worker-information duties.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 26 actually requires

Article 26 of Regulation (EU) 2024/1689 lists the obligations on deployers of high-risk AI systems — the entities that use AI systems under their authority within the Union.

The principal obligations

  • 26(1) — Take appropriate technical and organisational measures to ensure use of the system in accordance with the Article 13 instructions for use.
  • 26(2) — Assign human oversight to natural persons who have the necessary competence, training, authority and support to perform the Article 14 tasks.
  • 26(3) — These obligations are without prejudice to other deployer obligations under Union or national law and do not affect the deployer's discretion over how to organise its resources, provided the human-oversight measures referred to in Article 14 are met.
  • 26(4) — To the extent the deployer exercises control over input data, ensure that input data is relevant and sufficiently representative in view of the intended purpose.
  • 26(5)Monitor the operation of the high-risk AI system based on the IFU and, where relevant, inform providers in accordance with Article 72; if there is reason to consider that use may pose a risk under Article 79(1), inform the provider, the importer or distributor and the relevant market surveillance authority without undue delay and suspend the use of the system. If a serious incident has been identified, the deployer also informs first the provider and then the relevant authorities under Article 73.
  • 26(6)Keep the Article 12 automatic logs, to the extent such logs are under deployer control, for a period appropriate to the intended purpose of at least six months unless otherwise provided.
  • 26(7) — Workplace deployer obligation: before putting into service or use a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system, in accordance with national rules and practices.
  • 26(8) — Deployers that are public authorities or Union institutions shall comply with the Article 49 registration obligations. If the high-risk system is not registered, the deployer must not use it and shall inform the provider or the distributor.
  • 26(9) — Where applicable, use the information provided under Article 13 to comply with the deployer's obligation to carry out a DPIA under Article 35 GDPR or Article 27 of Directive (EU) 2016/680.
  • 26(10) — In specific Annex III §1 biometric law-enforcement contexts, deployers must request authorisations under additional conditions (real-time RBI etc.).
  • 26(11) — Without prejudice to Article 50, deployers of high-risk systems referred to in Annex III making decisions or assisting in decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system, where applicable.
  • 26(12) — Deployers shall cooperate with relevant competent authorities in any action those authorities take in relation to the high-risk AI system.

Who is covered

Every entity using a high-risk AI system under its authority within the Union — banks, hospitals, ministries, schools, employers, insurers, law-enforcement agencies. Deployer status is independent of whether you bought the system commercially or built it in-house.

What to do

  • Map your obligation under Article 26 against your operational reality. Where you are not yet compliant, set a 90-day plan with named owners.
  • For workplace deployments under Article 26(7): consult workers' representatives before put-into-service.
  • For public-sector deployers: register in the EU Database under Article 49 + 26(8).
  • For Article 27 covered deployers: perform the FRIA in addition to Article 26.

Inline crosswalk

  • ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems.
  • ISO/IEC 42001:2023 Annex A.9.2 — Human oversight.
  • NIST AI RMF MANAGE 4.1 — Post-deployment monitoring plans implemented.
  • NIST AI RMF GOVERN 3.2 — Roles and responsibilities for human-AI configurations.

Penalties

Article 99(4)(c) — up to €15 million or 3% of worldwide annual turnover.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 26 · Pro tier · high

    Ensure input data is relevant and representative of intended purpose

    Article 26(4) makes deployers responsible for the quality of input data they feed into a high-risk system, insofar as they exercise control over it.

  • Article 26 · Pro tier · high

    Deployer-side monitoring plan; report serious issues to provider

    Article 26(5) requires deployers to monitor operation in line with the instructions for use and inform the provider of any serious incident or risk.

  • Article 26 · Pro tier · high

    Assign human oversight to competent, trained, and authorised persons

    Article 26(2) requires deployers to assign human oversight to natural persons with the necessary competence, training, authority, and support.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art26-deployer-input-dataISO/IEC 42001:2023 Annex A.7.4 — Quality of data for AI systemsDeployer-side input-data quality control is the same data-quality objective applied to operations.
art26-deployer-monitoringISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systemsDeployer-side monitoring with provider escalation is the operational monitoring control in Annex A.6.2.8.
art26-deployer-human-oversightISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systemsArticle 26(2) competent and trained oversight by deployers is the human-oversight control of Annex A.9.2.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art26-deployer-input-dataNIST AI RMF MEASURE 2.10 — Privacy risk of the AI system — as identified in the MAP function — is examined and documentedDeployer-controlled input-data relevance and provenance assessment is part of the privacy-and-data examination in MEASURE 2.10.
art26-deployer-monitoringNIST AI RMF MANAGE 4.1 — Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI ActorsArticle 26(5) deployer monitoring with provider escalation is the deployer-side leg of MANAGE 4.1 monitoring.
art26-deployer-human-oversightNIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurationsAssigning competent and trained oversight personnel is the human-AI role differentiation GOVERN 3.2 mandates.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.