EU AI Act Art. 26 — Obligations of deployers of high-risk AI systems
Article 26 is the deployer's rulebook: use the system per its instructions, keep human oversight real, monitor for risks, inform workers — and know that certain choices can turn you into a provider.
At a glance
What this article requires
- Deployers must use high-risk AI in line with the provider's instructions for use.
- They must assign human oversight and monitor the system for risks in operation.
- Deployers must inform workers and their representatives when high-risk AI is used in the workplace.
- Deployers who materially modify a system, or use it for a different intended purpose, step into provider shoes.
- Deployers established outside the EU whose system output is used in the EU also fall under these duties.
Scope
Who this applies to
Any organisation using high-risk AI in the EU — this is the article most companies will actually live under, since most buy rather than build.
Obligations
What you must actually do
Operate within the instructions
Deviating from the provider's intended purpose or instructions is the fastest way to take on provider liability. Document your deployment decisions against them.
Run oversight and monitoring
Assign competent overseers, keep logs operating, and watch for risks, incidents, and drift. Report serious incidents and inform affected people per the Act.
Inform your workforce
Before deploying workplace AI, tell workers and their representatives they will be subject to the system. This pairs with FRIA (Art. 27) and GDPR consultation duties.
Know the provider trigger
If you materially modify the system, integrate it into a new product, or change its purpose, you inherit the provider obligations — documentation, conformity, CE marking.
Action plan
Practical first steps
- 1
Create a deployer compliance pack per system: instructions compliance check, oversight roster, log owner, incident process.
- 2
Run a pre-deployment review against the intended purpose — and refuse 'purpose creep' without reclassification.
- 3
Put worker-information notices and representative consultation on the calendar before go-live.
- 4
Contractually require providers to hand over the technical documentation and Art. 13 information you need.
Penalty exposure
Deployer failures sit in the general tier: up to €15 million or 3% of global annual turnover.
FAQ
Questions about Art. 26
When does a deployer become a provider?
Under Article 26(9), if you put your name on a system, materially modify it, or change its intended purpose, you take on provider obligations. Fine-tuning a model or repurposing a screening tool for a new context can cross the line.
Do I have duties if my AI is bought from a US vendor?
Yes. If the output of the high-risk AI is used in the EU, the deployer obligations apply to you regardless of where the vendor sits — and the vendor's non-compliance does not remove your duties.
Sources
Citations & further reading
Related
More article explainers
Wondering which articles apply to your AI?
Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.
Check my use casePreliminary EU AI Act clarity summary. Not legal advice.