Article 16
EU AI Act Article 16 — Provider Obligations Checklist
Article 16 of Regulation (EU) 2024/1689 lists the obligations of providers of high-risk AI systems. The thirteen-point checklist, what each item means, and how to evidence compliance.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 16 actually requires
Article 16 of Regulation (EU) 2024/1689 lists the thirteen obligations of providers of high-risk AI systems. It is the cross-reference index for the rest of Chapter III Section 3.
The thirteen obligations (paraphrased)
Providers shall:
- (a) Ensure their high-risk AI systems comply with the requirements set out in Section 2 (Articles 8–15).
- (b) Indicate on the system, packaging or accompanying documentation the provider's name, registered trade name or trade mark, and contact address.
- (c) Have a quality management system in place per Article 17.
- (d) Keep the documentation referred to in Article 18 — for 10 years from placement.
- (e) Keep the Article 19 automatic logs when those logs are under their control.
- (f) Ensure the system undergoes the relevant conformity assessment procedure per Article 43 before placement.
- (g) Draw up the EU declaration of conformity per Article 47.
- (h) Affix the CE marking per Article 48 where applicable.
- (i) Comply with the registration obligations referred to in Article 49(1) — EU Database entry.
- (j) Take corrective actions and provide information as required by Article 20.
- (k) Demonstrate, on reasoned request from a national competent authority, the conformity of the high-risk AI system with Section 2 requirements.
- (l) Ensure the high-risk AI system complies with accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882.
- (m) Where the provider is established outside the Union, designate by written mandate an authorised representative established in the Union per Article 22.
Who is covered
Article 16 applies to all providers of high-risk AI systems as defined in Article 3(3). Article 25 extends the obligations to entities promoted to provider through brand-on-it, substantial modification, or intended-purpose change.
What to do
Treat Article 16 as a one-page assurance dashboard for your compliance programme. Each item maps to a specific evidence pack:
| Obligation | Evidence |
|---|---|
| 16(c) QMS | Article 17 QMS manual |
| 16(d) docs retention | 10-year retention policy + storage location |
| 16(f) conformity assessment | Annex IV / Article 43 outcome |
| 16(g) declaration of conformity | Signed Article 47 document |
| 16(i) registration | EU Database entry ID |
| 16(j) corrective actions | Documented procedure + activation records |
| 16(m) EU representative | Written mandate, representative contact details |
Inline crosswalk
- ISO/IEC 42001:2023 Clause 5 — Leadership.
- ISO/IEC 42001:2023 Annex A.10 — Third-party relationships (for 16(m) and supplier coordination).
- NIST AI RMF GOVERN 2.1 — Roles, responsibilities, lines of communication for AI risk management.
Common mistakes
- Skipping 16(m) — non-EU providers without an authorised representative cannot lawfully place systems on the EU market.
- Late conformity assessment — Article 16(f) is before placement on the market.
- Generic "CEO" signature on the Article 47 declaration. Use a named accountable role.
Penalties
Article 99(4) — up to €15 million or 3% of worldwide annual turnover.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 17 · Starter tier · medium
Set up quality management system (QMS)
Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.
Article 43 · Starter tier · critical
Complete conformity assessment procedure
Required before placing a high-risk system on the market. Internal self-assessment for most Annex III; notified body for §1 biometrics.
Article 49 · Starter tier · medium
Register high-risk system in EU database
Public transparency register. Must be updated annually. Filing is online via the EU AI Office portal.
Article 16 · Pro tier · critical
Appoint authorised representative in EU (non-EU providers)
Article 22 requires non-EU providers to designate a written-mandate representative established in the Union before placement on market.
Article 16 · Pro tier · medium
Document corrective-action procedure for detected non-conformities
Article 16(j) requires providers to take necessary corrective actions (withdrawal, disabling, recall) when non-conformity is found.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art17-qms | ISO/IEC 42001:2023 Clause 4 — Context of the organisation | Article 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context. |
art17-qms | ISO/IEC 42001:2023 Clause 5 — Leadership and AI policy | A QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements. |
art17-qms | ISO/IEC 42001:2023 Clause 9 — Performance evaluation | QMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9. |
art43-conformity | ISO/IEC 42001:2023 Clause 9.2 — Internal audit | Internal self-assessment (Article 43 §1 path) and independent review map onto the internal-audit programme of Clause 9.2. |
art49-eudb | ISO/IEC 42001:2023 Annex A.8.3 — External reporting | Filing in the EU AI Office public register evidences Annex A.8 external transparency to interested parties. |
art16-registered-office | ISO/IEC 42001:2023 Annex A.10.2 — Allocation of responsibilities with suppliers and partners | A written-mandate EU representative is the allocation-of-responsibilities control in Annex A.10 third-party relationships. |
art16-corrective-actions | ISO/IEC 42001:2023 Clause 10.2 — Nonconformity and corrective action | Article 16(j) corrective-action procedure for non-conformities directly satisfies Clause 10.2. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art17-qms | NIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures | A QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2. |
art17-qms | NIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documented | QMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects. |
art43-conformity | NIST AI RMF GOVERN 4.1 — Organizational practices are in place to foster a critical thinking and safety-first mindset; effective challenge for AI deployment is in place | Conformity assessment is the documented effective-challenge step before deployment that GOVERN 4.1 mandates. |
art49-eudb | NIST AI RMF GOVERN 5.1 — Organizational policies and practices are in place to collect, consider, prioritize, and integrate external feedback | Public registration enables the external-feedback intake GOVERN 5.1 expects organisations to operationalise. |
art16-registered-office | NIST AI RMF GOVERN 6.1 — Policies and procedures are in place to address AI risks and benefits arising from third-party software and data | Designating a written-mandate EU representative is part of the third-party-relationship governance GOVERN 6.1 covers. |
art16-corrective-actions | NIST AI RMF MANAGE 2.4 — Mechanisms are in place and applied to supersede, disengage, or deactivate existing AI systems that demonstrate performance or outcomes inconsistent with intended use | Article 16(j) withdrawal/disabling/recall procedure is the supersede/deactivate mechanism MANAGE 2.4 mandates. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.