Article 26
EU AI Act Article 26 — Deployer Obligations
Article 26 of Regulation (EU) 2024/1689 sets the obligations on deployers of high-risk AI systems. Use per IFU, human oversight assignment, input-data quality, monitoring, and worker-information duties.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 26 actually requires
Article 26 of Regulation (EU) 2024/1689 lists the obligations on deployers of high-risk AI systems — the entities that use AI systems under their authority within the Union.
The principal obligations
- 26(1) — Take appropriate technical and organisational measures to ensure use of the system in accordance with the Article 13 instructions for use.
- 26(2) — Assign human oversight to natural persons who have the necessary competence, training, authority and support to perform the Article 14 tasks.
- 26(3) — These obligations are without prejudice to other deployer obligations under Union or national law and do not affect the deployer's discretion over how to organise its resources, provided the human-oversight measures referred to in Article 14 are met.
- 26(4) — To the extent the deployer exercises control over input data, ensure that input data is relevant and sufficiently representative in view of the intended purpose.
- 26(5) — Monitor the operation of the high-risk AI system based on the IFU and, where relevant, inform providers in accordance with Article 72; if there is reason to consider that use may pose a risk under Article 79(1), inform the provider, the importer or distributor and the relevant market surveillance authority without undue delay and suspend the use of the system. If a serious incident has been identified, the deployer also informs first the provider and then the relevant authorities under Article 73.
- 26(6) — Keep the Article 12 automatic logs, to the extent such logs are under deployer control, for a period appropriate to the intended purpose of at least six months unless otherwise provided.
- 26(7) — Workplace deployer obligation: before putting into service or use a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system, in accordance with national rules and practices.
- 26(8) — Deployers that are public authorities or Union institutions shall comply with the Article 49 registration obligations. If the high-risk system is not registered, the deployer must not use it and shall inform the provider or the distributor.
- 26(9) — Where applicable, use the information provided under Article 13 to comply with the deployer's obligation to carry out a DPIA under Article 35 GDPR or Article 27 of Directive (EU) 2016/680.
- 26(10) — In specific Annex III §1 biometric law-enforcement contexts, deployers must request authorisations under additional conditions (real-time RBI etc.).
- 26(11) — Without prejudice to Article 50, deployers of high-risk systems referred to in Annex III making decisions or assisting in decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system, where applicable.
- 26(12) — Deployers shall cooperate with relevant competent authorities in any action those authorities take in relation to the high-risk AI system.
Who is covered
Every entity using a high-risk AI system under its authority within the Union — banks, hospitals, ministries, schools, employers, insurers, law-enforcement agencies. Deployer status is independent of whether you bought the system commercially or built it in-house.
What to do
- Map your obligation under Article 26 against your operational reality. Where you are not yet compliant, set a 90-day plan with named owners.
- For workplace deployments under Article 26(7): consult workers' representatives before put-into-service.
- For public-sector deployers: register in the EU Database under Article 49 + 26(8).
- For Article 27 covered deployers: perform the FRIA in addition to Article 26.
Inline crosswalk
- ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems.
- ISO/IEC 42001:2023 Annex A.9.2 — Human oversight.
- NIST AI RMF MANAGE 4.1 — Post-deployment monitoring plans implemented.
- NIST AI RMF GOVERN 3.2 — Roles and responsibilities for human-AI configurations.
Penalties
Article 99(4)(c) — up to €15 million or 3% of worldwide annual turnover.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 26 · Pro tier · high
Ensure input data is relevant and representative of intended purpose
Article 26(4) makes deployers responsible for the quality of input data they feed into a high-risk system, insofar as they exercise control over it.
Article 26 · Pro tier · high
Deployer-side monitoring plan; report serious issues to provider
Article 26(5) requires deployers to monitor operation in line with the instructions for use and inform the provider of any serious incident or risk.
Article 26 · Pro tier · high
Assign human oversight to competent, trained, and authorised persons
Article 26(2) requires deployers to assign human oversight to natural persons with the necessary competence, training, authority, and support.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art26-deployer-input-data | ISO/IEC 42001:2023 Annex A.7.4 — Quality of data for AI systems | Deployer-side input-data quality control is the same data-quality objective applied to operations. |
art26-deployer-monitoring | ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems | Deployer-side monitoring with provider escalation is the operational monitoring control in Annex A.6.2.8. |
art26-deployer-human-oversight | ISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systems | Article 26(2) competent and trained oversight by deployers is the human-oversight control of Annex A.9.2. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art26-deployer-input-data | NIST AI RMF MEASURE 2.10 — Privacy risk of the AI system — as identified in the MAP function — is examined and documented | Deployer-controlled input-data relevance and provenance assessment is part of the privacy-and-data examination in MEASURE 2.10. |
art26-deployer-monitoring | NIST AI RMF MANAGE 4.1 — Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI Actors | Article 26(5) deployer monitoring with provider escalation is the deployer-side leg of MANAGE 4.1 monitoring. |
art26-deployer-human-oversight | NIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurations | Assigning competent and trained oversight personnel is the human-AI role differentiation GOVERN 3.2 mandates. |
Related
Article 14
EU AI Act Article 14 — Human Oversight Requirements
Article 27
EU AI Act Article 27 — Fundamental Rights Impact Assessment (FRIA)
Article 13
EU AI Act Article 13 — Transparency and Instructions for Use
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Articles 6 / 16 / 25 / 53
EU AI Act for SaaS — Are You a Provider, Deployer, or Both?
Article 27
FRIA Explained — Fundamental Rights Impact Assessment Under Article 27
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.