Deployer duties under Article 26, in order
What a deployer of a high-risk system owes, paragraph by paragraph — instructions, oversight, input data, monitoring, logs, workers, registration, the DPIA link, informing affected people — plus the FRIA, transparency and literacy duties that sit beside it.
A deployer uses a high-risk AI system under its own authority. Its duties are lighter than a provider's, but they are real, they are per system, and for Annex III systems they apply from 2 December 2027. Art. 26 is the core; a handful of other articles attach beside it.
Art. 26, paragraph by paragraph
| Paragraph | Duty |
|---|---|
| 26(1) | Take appropriate technical and organisational measures to use the system in accordance with its instructions for use. |
| 26(2) | Assign human oversight to natural persons who have the competence, training, authority and support to exercise it. |
| 26(3) | Paragraphs (1) and (2) are without prejudice to other Union or national law and to your freedom to organise your own resources — not an obligation in itself. |
| 26(4) | Where you control the input data, ensure it is relevant and sufficiently representative for the intended purpose. |
| 26(5) | Monitor the system's operation on the basis of the instructions and, where relevant, inform the provider under Art. 72. If you have reason to consider the system presents a risk in the Art. 79(1) sense, inform the provider or distributor and the market-surveillance authority without undue delay and suspend its use. If you identify a serious incident, inform the provider first, then the importer or distributor and the authorities. |
| 26(6) | Keep the automatically generated logs under your control for a period appropriate to the intended purpose and at least six months, unless other law provides otherwise. |
| 26(7) | Before putting a high-risk system into service at the workplace, inform workers' representatives and the affected workers that they will be subject to it. |
| 26(8) | Deployers that are public authorities or Union bodies register their use of the system in the EU database (Art. 49). |
| 26(9) | Use the information provided under Art. 13 to carry out any data protection impact assessment required by GDPR Art. 35. |
| 26(10) | Law-enforcement use of post-remote biometric identification needs judicial or administrative authorisation — in advance, or within 48 hours. |
| 26(11) | Where the system makes or assists in decisions about natural persons, inform those persons that they are subject to its use. |
| 26(12) | Cooperate with the competent authorities. |
Beside Art. 26
- Art. 27 — a fundamental-rights impact assessment before first use, for deployers that are public bodies or private providers of public services, and for every deployer of a credit-scoring or life and health insurance system. See FRIA, step by step.
- Art. 4 — AI literacy for the staff who operate the system, whatever its tier.
- Art. 50(3)–(4) — inform people exposed to an emotion-recognition or biometric-categorisation system, and disclose deep fakes and AI-generated text published on matters of public interest.
- Art. 86 — a person subject to a decision taken on the basis of an Annex III system's output that affects their rights has a right to an explanation of the system's role and the main elements of the decision.
- Art. 25 — put your own name on the system, substantially modify it or change its purpose, and you become the provider. See Am I a provider or a deployer?
In Veritome
A system classified as high-risk with the deployer role gets one obligation per paragraph that applies — the instructions record, the human-oversight assignment, the logging record with its six-month clock, the worker notification, the affected-persons notice — and the FRIA where the engine's rule matches your organisation and the Annex III area. The instructions for use your provider hands over can be received into the system record, which is what Art. 26(1) and 26(9) both start from. Where the Act lets existing work count — Art. 26(9)'s use of the instructions in the DPIA, Art. 26(5)'s monitoring deemed met by a financial institution's internal-governance rules — the obligation shows the route and lets you declare reliance without changing its status.