EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Article 26 is the deployer's rulebook: use the system per its instructions, keep human oversight real, monitor for risks, inform workers — and know that certain choices can turn you into a provider.

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • Deployers must use high-risk AI in line with the provider's instructions for use.
  • They must assign human oversight and monitor the system for risks in operation.
  • Deployers must inform workers and their representatives when high-risk AI is used in the workplace.
  • Deployers who materially modify a system, or use it for a different intended purpose, step into provider shoes.
  • Deployers established outside the EU whose system output is used in the EU also fall under these duties.

Scope

Who this applies to

Any organisation using high-risk AI in the EU — this is the article most companies will actually live under, since most buy rather than build.

Obligations

What you must actually do

Operate within the instructions

Deviating from the provider's intended purpose or instructions is the fastest way to take on provider liability. Document your deployment decisions against them.

Run oversight and monitoring

Assign competent overseers, keep logs operating, and watch for risks, incidents, and drift. Report serious incidents and inform affected people per the Act.

Inform your workforce

Before deploying workplace AI, tell workers and their representatives they will be subject to the system. This pairs with FRIA (Art. 27) and GDPR consultation duties.

Know the provider trigger

If you materially modify the system, integrate it into a new product, or change its purpose, you inherit the provider obligations — documentation, conformity, CE marking.

Action plan

Practical first steps

  1. 1

    Create a deployer compliance pack per system: instructions compliance check, oversight roster, log owner, incident process.

  2. 2

    Run a pre-deployment review against the intended purpose — and refuse 'purpose creep' without reclassification.

  3. 3

    Put worker-information notices and representative consultation on the calendar before go-live.

  4. 4

    Contractually require providers to hand over the technical documentation and Art. 13 information you need.

Penalty exposure

Deployer failures sit in the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 26

When does a deployer become a provider?

Under Article 26(9), if you put your name on a system, materially modify it, or change its intended purpose, you take on provider obligations. Fine-tuning a model or repurposing a screening tool for a new context can cross the line.

Do I have duties if my AI is bought from a US vendor?

Yes. If the output of the high-risk AI is used in the EU, the deployer obligations apply to you regardless of where the vendor sits — and the vendor's non-compliance does not remove your duties.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.