AI Act · Article 26
As of 6 October 2026, after the Digital Omnibus
Deployer obligations under Article 26 of the AI Act
Most companies do not build high-risk AI, they use it. That makes them deployers. This page walks through what Article 26 requires, paragraph by paragraph, when it applies and how to keep track.
Short answer
A deployer is anyone who uses an AI system under their own authority (Art. 3(4)). If you use a high-risk AI system, for example for candidate selection, Article 26 sets out your duties in twelve paragraphs: follow the instructions for use, assign human oversight, check input data, monitor operation, keep logs for at least six months, and inform employees and affected people. For Annex III systems these duties apply from 2 December 2027 (Art. 113(3)(c) as amended by Regulation (EU) 2026/1744). Infringing Art. 26 can lead to fines of up to EUR 15 million or 3 % of worldwide annual turnover (Art. 99(4)(e)); for SMEs, including start-ups, the lower of the two applies (Art. 99(6)). Since the Digital Omnibus, this also applies to small mid-caps (Art. 3(14b)), but only for fines under paragraphs 4 and 5 (Art. 99(6a)).
Clarify your role
Deployer or provider?
Article 26 only addresses deployers. Providers are subject to the much broader obligations of Article 16. Your role depends on how you use the system, not on who wrote the code.
Where a deployer becomes a provider under Art. 25(1), the original provider no longer counts as provider of that specific system. It must still cooperate closely with the new provider and supply the information and the reasonably expected technical access (Art. 25(2) as amended by Regulation (EU) 2026/1744).
| Role | Definition | Source |
|---|---|---|
| Provider | Develops an AI system, or has it developed, and places it on the market or puts it into service under its own name or trademark, for payment or free of charge. | Art. 3(3) |
| Deployer | Uses an AI system under its own authority, except in the course of a personal non-professional activity. | Art. 3(4) |
| Deployer becomes provider | Puts its name or trademark on a high-risk system already on the market, makes a substantial modification that leaves it high-risk, or changes the intended purpose of a non-high-risk system so that it becomes high-risk. Contracts may allocate the obligations differently. | Art. 25(1)(a) to (c) |
In practice: if you only use a purchased high-risk system, you stay a deployer. If you resell it under your own product name or change its intended purpose, you become a provider. Check this before deployment and record the role in your AI inventory.
Obligations
The Article 26 obligations, paragraph by paragraph
The duties apply to deployers of high-risk AI systems within the meaning of Article 6. For systems that only fall under Article 50 or Article 4, Article 26 does not apply.
Art. 26(1)
Use according to the instructions
Take appropriate technical and organisational measures so that the system is used in accordance with the accompanying instructions for use and with paragraphs 3 and 6.
Art. 26(2)
Assign human oversight
Assign human oversight to natural persons with the necessary competence, training and authority, and give them the necessary support.
Art. 26(3)
Other obligations remain
Paragraphs 1 and 2 do not affect other deployer obligations under Union or national law, nor the freedom to organise your own resources.
Art. 26(4)
Check input data
To the extent you exercise control over the input data, make sure it is relevant and sufficiently representative for the intended purpose of the system.
Art. 26(5)
Monitor and report
Monitor operation on the basis of the instructions for use and, where relevant, inform the provider (Art. 72). If you have reason to consider that use may present a risk within the meaning of Art. 79(1), inform the provider or distributor and the market surveillance authority without undue delay and suspend use. For a serious incident, inform first the provider, then the importer or distributor and the authorities. For financial institutions the monitoring duty is deemed fulfilled under the conditions of the second subparagraph.
Art. 26(6)
Keep logs
Keep the automatically generated logs, to the extent they are under your control, for at least six months unless Union law (in particular data protection law) or national law provides otherwise.
Art. 26(7)
Inform workers
Employers must inform workers' representatives and the affected workers before a high-risk AI system is put into service or used at the workplace, in line with Union and national rules and practices.
Art. 26(8)
Registration for Union bodies
Applies only to Union institutions, bodies, offices and agencies as deployers: registration under Art. 49, and no use of systems that are not registered.
Art. 26(9)
Data protection impact assessment
Where applicable, use the information provided under Art. 13 to comply with the obligation to carry out a data protection impact assessment under Art. 35 GDPR or Art. 27 of Directive (EU) 2016/680.
Art. 26(10)
Post-remote biometric identification
Concerns law enforcement: authorisation within 48 hours from a judicial or administrative authority, documentation and annual reports. Usually irrelevant for companies.
Art. 26(11)
Inform affected persons
Deployers of Annex III systems that make or assist in making decisions about natural persons inform those persons that they are subject to the use of the system (without prejudice to Art. 50).
Art. 26(12)
Cooperate with authorities
Cooperate with the competent authorities in any action they take in relation to the high-risk system to implement the Regulation.
Checklist
Checklist for deployers of high-risk AI
A working list along the paragraphs. It does not replace an assessment of your specific case.
- System recorded in the AI inventory, role (deployer or provider) and risk class documented (Art. 3, Art. 6, Art. 25)
- Provider's instructions for use on file, internal usage rules derived from them (para. 1)
- People responsible for human oversight named, trained and empowered (para. 2, Art. 4)
- Input data checked for intended purpose and representativeness, as far as you control it (para. 4)
- Monitoring and reporting routes defined: provider, market surveillance authority, serious incidents (para. 5)
- Logs kept for at least six months, conflicts with deletion periods resolved (para. 6)
- Workers' representatives and employees informed before use at the workplace (para. 7)
- Data protection impact assessment checked, provider information used (para. 9, Art. 35 GDPR)
- Affected persons informed where the system makes or supports decisions about them (para. 11)
- Checked whether the fundamental rights impact assessment under Art. 27 applies to you (see below)
- Contact person for authorities named (para. 12)
- Evidence filed centrally: role, classification, oversight persons, information given, log concept
Deadlines
When do the deployer obligations apply?
The Regulation applies in general from 2 August 2026 (Art. 113). For the high-risk obligations, Regulation (EU) 2026/1744 has set new dates.
| Topic | Date | Source |
|---|---|---|
| High-risk AI under Art. 6(2) and Annex III (including Art. 26) | 2 December 2027 | Art. 113(3)(c)(i) as amended |
| High-risk AI under Art. 6(1) and Annex I (product safety components) | 2 August 2028 | Art. 113(3)(c)(ii) as amended |
| Systems placed on the market or put into service before Chapter III applies | Only if significantly changed in design afterwards; for systems intended to be used by public authorities, measures by 2 August 2030 | Art. 111(2) as amended |
| AI literacy (Art. 4) and prohibitions (Art. 5) | Since 2 February 2025 | Art. 113(3)(a) |
| Deployer transparency duties (Art. 50(3) and (4)) | 2 August 2026 | Art. 113(2) |
All dates at a glance: see our deadlines page. Whether an existing system falls under the transitional rule depends on its history of changes and should be checked case by case.
Article 27
Fundamental rights impact assessment: only for certain deployers
Before first use of a high-risk system under Art. 6(2), the following deployers must assess the impact on fundamental rights: bodies governed by public law, private entities providing public services, and deployers of systems under Annex III point 5(b) and (c), that is, creditworthiness assessment and risk assessment and pricing for life and health insurance. Systems in the area of Annex III point 2 are excluded (Art. 27(1)).
The assessment describes, among other things, the processes, period and frequency of use, affected groups of persons, specific risks of harm, human oversight and the measures to take if risks materialise (Art. 27(1)(a) to (f)). The results are notified to the market surveillance authority (para. 3). If a data protection impact assessment already exists, the fundamental rights impact assessment may refer to it or take over relevant parts (para. 4 as amended). Most private employers, for example when using recruiting software, are not covered.
We have a separate page on the data protection impact assessment, with a template.
Related obligations
What else applies: Articles 4, 50 and 5
Art. 4
AI literacy
Providers and deployers of AI systems take measures to support the AI literacy of their staff and other persons acting on their behalf. This applies to every AI system, not only to high-risk AI.
Art. 50(3) and (4)
Transparency when operating
Deployers of emotion recognition and biometric categorisation systems inform the persons exposed. Anyone generating deepfakes must disclose the artificial origin; the same applies to published texts on matters of public interest, except where there is human review with editorial responsibility.
Art. 5
Prohibited practices
Regardless of risk class, certain applications are banned, such as emotion recognition in the workplace (Art. 5(1)(f)).
Implementation
How SimpleAct supports deployers
Inventory
Record systems and roles
Every AI system with its intended purpose, role (deployer or provider) and risk class in one register. This is the basis for Article 26.
Classification
Recognise high-risk
The check walks through prohibitions, Annex III and the exemptions under Art. 6(3), so it is clear whether Article 26 applies at all.
Checklists
Work through the duties
Tasks per system, owners and status instead of loose spreadsheets.
Evidence
File the proof
Document training, information given to employees, the log concept and decisions on the system so they can be found when asked.
FAQ
Frequently asked questions on deployer obligations
More questions? We're happy to help. Send email · Get started
Sources and status
As of · SimpleAct editorial team
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal
Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.
Deployer obligations under control, system by system
AI inventory, role, classification and evidence in one place. We will show you what that looks like for your systems.