Skip to main content

Deployer Obligations for High-Risk AI Systems — Article 26

Deployer obligations under EU AI Act Article 26: compliance checklist, FRIA requirement, and how Scanara structures and evidences deployer compliance work.

Under EU AI Act Article 26, deployers of high-risk AI systems have distinct compliance obligations separate from those of the AI system provider. A deployer is any organisation that uses a high-risk AI system in a professional context under its own authority. Key obligations include following instructions for use, implementing human oversight, maintaining logs, conducting a FRIA (if a public-sector body), and monitoring system performance in operation. Enforcement begins August 2, 2026 with fines up to €15 million or 3% of turnover.

Deployer vs Provider: Who Are You?

Provider

Develops and places the AI system on the EU market. Bears primary obligations: Articles 9–15, 17, conformity assessment, CE marking, Annex IV documentation. Technical and governance accountability.

Examples: AI software vendors, SaaS AI platforms, model developers.

Deployer

Uses a high-risk AI system in a professional context under its own authority. Bears operational obligations under Article 26: oversight, monitoring, instructions compliance, staff training, and FRIA (if public sector). Must not modify the system beyond provider instructions.

Examples: Hospitals using AI diagnostics, employers using AI screening, public authorities using AI in benefit decisions.

Important: An organisation can be both a provider and a deployer simultaneously — if you develop a high-risk AI system and also deploy it in your own operations. In that case, both Article 16 (provider) and Article 26 (deployer) obligations apply.

Article 26 Deployer Obligations Checklist

Art 26(1)

Follow provider instructions for use

Deploy and operate the AI system strictly within the conditions specified in the provider's instructions for use. Do not use the system for purposes beyond its intended scope.

Art 26(2)

Assign qualified human oversight

Ensure the persons assigned to human oversight have the necessary competence, training, and authority to monitor the AI system's outputs and intervene when necessary.

Art 26(3)

Implement human oversight measures

Implement the human oversight measures specified in the provider's instructions. Document the oversight procedures and ensure staff can apply them effectively in practice.

Art 26(5)

Conduct FRIA (public-sector deployers)

Bodies governed by public law and private entities providing public services must conduct a Fundamental Rights Impact Assessment before putting the system into operation.

Art 26(6)

Monitor system performance post-deployment

Monitor the AI system's operation and report to the provider any serious incidents or malfunctions. Maintain post-market monitoring data as required by the provider's monitoring plan.

Art 26(7)

Inform and train affected persons

Where the AI system interacts with or makes decisions about natural persons, provide appropriate transparency notices. Ensure staff who use or are affected by the system understand its capabilities and limitations.

Art 26(9)

Maintain operational logs

Retain logs generated by the AI system to the extent under your control, as required by Article 12. Logs must be retained for the period set out in applicable law or 6 months minimum.

Art 26(10)

Register in the EU database

Certain deployers (in areas of law enforcement, migration, justice, and democratic processes) must register their use of high-risk AI systems in the EU AI Act database under Article 49.

The FRIA Obligation for Deployers

Article 27 requires public-sector deployers to conduct a Fundamental Rights Impact Assessment before putting any Annex III high-risk AI system into operation. The FRIA must be registered in the EU AI Act database. It covers how the AI system may affect fundamental rights including non-discrimination, human dignity, data protection, and access to justice.

Read the full FRIA guide →

Ongoing Monitoring Obligations

Performance monitoring

Monitor the AI system's performance against its specified purpose. Track output accuracy, bias indicators, and any degradation compared to the provider's validated performance benchmarks.

Serious incident reporting

Article 73 requires deployers to report serious incidents or malfunctions to the provider and, in some cases, directly to market surveillance authorities. Maintain an incident log with timestamps and corrective actions.

Log retention

Retain AI system-generated logs for at least 6 months or as specified by sector-specific law (e.g. healthcare, financial services). Logs are required for regulatory audits and incident investigations.

How Scanara Helps Deployers

Deployer obligation scanner

Scanara's deployer module scans your operational context against all Article 26 obligations — identifying missing oversight mechanisms, log retention gaps, and transparency notice absences.

FRIA automation

Auto-populate the Article 27 FRIA worksheet with your deployment context. Scanara flags when a FRIA is required and generates a pre-structured template for your legal team to complete.

Incident reporting scaffolding

Scanara's PMM dossier ships an Article 73 serious-incident section with statutory reporting timelines and an escalation matrix, plus a monitoring dashboard that tracks review cadence and overdue PMM dossiers.

See Scanara deployer compliance in action →

Frequently Asked Questions


How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.