Deployer Obligations for High-Risk AI Systems — Article 26
Deployer obligations under EU AI Act Article 26: compliance checklist, FRIA requirement, and how Scanara structures and evidences deployer compliance work.
Under EU AI Act Article 26, deployers of high-risk AI systems have distinct compliance obligations separate from those of the AI system provider. A deployer is any organisation that uses a high-risk AI system in a professional context under its own authority. Key obligations include following instructions for use, implementing human oversight, maintaining logs, conducting a FRIA (if a public-sector body), and monitoring system performance in operation. Enforcement begins August 2, 2026 with fines up to €15 million or 3% of turnover.
Deployer vs Provider: Who Are You?
Provider
Develops and places the AI system on the EU market. Bears primary obligations: Articles 9–15, 17, conformity assessment, CE marking, Annex IV documentation. Technical and governance accountability.
Examples: AI software vendors, SaaS AI platforms, model developers.
Deployer
Uses a high-risk AI system in a professional context under its own authority. Bears operational obligations under Article 26: oversight, monitoring, instructions compliance, staff training, and FRIA (if public sector). Must not modify the system beyond provider instructions.
Examples: Hospitals using AI diagnostics, employers using AI screening, public authorities using AI in benefit decisions.
Important: An organisation can be both a provider and a deployer simultaneously — if you develop a high-risk AI system and also deploy it in your own operations. In that case, both Article 16 (provider) and Article 26 (deployer) obligations apply.
Article 26 Deployer Obligations Checklist
Follow provider instructions for use
Deploy and operate the AI system strictly within the conditions specified in the provider's instructions for use. Do not use the system for purposes beyond its intended scope.
Assign qualified human oversight
Ensure the persons assigned to human oversight have the necessary competence, training, and authority to monitor the AI system's outputs and intervene when necessary.
Implement human oversight measures
Implement the human oversight measures specified in the provider's instructions. Document the oversight procedures and ensure staff can apply them effectively in practice.
Conduct FRIA (public-sector deployers)
Bodies governed by public law and private entities providing public services must conduct a Fundamental Rights Impact Assessment before putting the system into operation.
Monitor system performance post-deployment
Monitor the AI system's operation and report to the provider any serious incidents or malfunctions. Maintain post-market monitoring data as required by the provider's monitoring plan.
Inform and train affected persons
Where the AI system interacts with or makes decisions about natural persons, provide appropriate transparency notices. Ensure staff who use or are affected by the system understand its capabilities and limitations.
Maintain operational logs
Retain logs generated by the AI system to the extent under your control, as required by Article 12. Logs must be retained for the period set out in applicable law or 6 months minimum.
Register in the EU database
Certain deployers (in areas of law enforcement, migration, justice, and democratic processes) must register their use of high-risk AI systems in the EU AI Act database under Article 49.
The FRIA Obligation for Deployers
Article 27 requires public-sector deployers to conduct a Fundamental Rights Impact Assessment before putting any Annex III high-risk AI system into operation. The FRIA must be registered in the EU AI Act database. It covers how the AI system may affect fundamental rights including non-discrimination, human dignity, data protection, and access to justice.
Read the full FRIA guide →Ongoing Monitoring Obligations
Performance monitoring
Monitor the AI system's performance against its specified purpose. Track output accuracy, bias indicators, and any degradation compared to the provider's validated performance benchmarks.
Serious incident reporting
Article 73 requires deployers to report serious incidents or malfunctions to the provider and, in some cases, directly to market surveillance authorities. Maintain an incident log with timestamps and corrective actions.
Log retention
Retain AI system-generated logs for at least 6 months or as specified by sector-specific law (e.g. healthcare, financial services). Logs are required for regulatory audits and incident investigations.
How Scanara Helps Deployers
Deployer obligation scanner
Scanara's deployer module scans your operational context against all Article 26 obligations — identifying missing oversight mechanisms, log retention gaps, and transparency notice absences.
FRIA automation
Auto-populate the Article 27 FRIA worksheet with your deployment context. Scanara flags when a FRIA is required and generates a pre-structured template for your legal team to complete.
Incident reporting scaffolding
Scanara's PMM dossier ships an Article 73 serious-incident section with statutory reporting timelines and an escalation matrix, plus a monitoring dashboard that tracks review cadence and overdue PMM dossiers.
Frequently Asked Questions
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.