EU AI Act Article 16: Provider Obligations List
Article 16 is the index of high-risk provider duties. Here is each item in plain English, when it applies after the Omnibus, and what to collect first.
Article 16 is not a new set of rules. It is the table of contents for every high-risk provider duty that follows: risk management, data, docs, logging, transparency, human oversight, accuracy, cybersecurity, QMS, technical documentation, conformity, registration. If someone asks "what do we owe as a provider?" this is the one-page answer.
Those Chapter III duties apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product AI (Regulation 2026/1744). Article 16 does not create an earlier date. It does tell you what the file will contain.
Article 16 is the index. The flow — docs, QMS, assessment, declaration, CE, registration — is what it points at.
What Does Article 16 Require Providers to Do?
Article 16 says providers of high-risk AI systems shall:
- Comply with the Section 2 requirements (Articles 9–15)
- Indicate name and contact details on the system or accompanying docs
- Have a quality management system (Article 17)
- Keep the documentation (Article 18)
- Keep automatically generated logs (Article 19)
- Ensure the system undergoes the relevant conformity assessment (Article 43)
- Draw up an EU declaration of conformity (Article 47) and affix CE marking (Article 48)
- Comply with registration (Article 49)
- Take corrective action and inform distributors, deployers, authorities when needed
- Demonstrate conformity on request
- Ensure the system complies with accessibility requirements
That is the spine. The meat is in the numbered articles. Start with a precise intended purpose. Without it, every later document lies.
Which Article 16 Items Should We Start This Quarter?
Four, in this order:
- Intended purpose and classification — Annex III or Annex I. If you are not high-risk, Article 16 is not your problem.
- Article 9 risk file — even a thin one. See the bias-testing piece for the data side.
- Article 11 / Annex IV outline — nine headings, ugly first drafts allowed. What Annex IV actually is.
- Name-and-address on the artefact — the cheapest 16(b) win, and the one demos forget.
Skip CE-mark theatre until you know the conformity route (Article 43). Notified-body capacity is still thin. Internal control (Annex VI) is the path for most Annex III systems that are not biometrics or other special cases.
Does Article 16 Apply If We Only Wrap an API?
Only if your system is high-risk. Wrapping GPT to draft marketing emails is not Article 16. Wrapping GPT to rank job applicants can be. The role question is provider versus deployer. Article 16 binds providers. Deployers live in Article 26.
If Article 25 flips you from deployer to provider — you put your name on it, you substantially modify it, you change the intended purpose — Article 16 arrives with the flip. Budget for that in the contract, not after the press release.
How Does This Change After the Digital Omnibus?
The list did not shrink. The clock moved. SMEs and, after the Omnibus, small mid-caps get simpler documentation modalities. Registration for some non-high-risk uses in high-risk areas was trimmed. Post-market monitoring plans are less prescribed. None of that deletes Article 9 or Annex IV.
My take: treat Article 16 as a packing list, not a project plan. Teams that "do Article 16" without picking a first artefact produce slideware. Pick the intended-purpose paragraph this week.
Run the risk check. If it says high-risk, Nytivo is built to hold the Article 16 file without pretending you need a notified body tomorrow.
Frequently Asked Questions
What is Article 16 of the EU AI Act?
The list of obligations for providers of high-risk AI systems. It points to Articles 9–15, 17–19, 43, 47–49, corrective-action duties, and accessibility.
When does Article 16 apply?
From 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I product-embedded high-risk systems, per Regulation 2026/1744.
Is Article 16 only for big companies?
No. It applies to any provider of a high-risk system. SMEs and small mid-caps get simplified documentation options, not an exemption.
Do deployers follow Article 16?
No. Deployers follow Article 26 (and Article 27 FRIA where it applies). A company can be both.
Where do I start if I am a high-risk provider?
Intended purpose, classification, Article 9 risk file, Annex IV outline. Then conformity route and registration.
Summary for AI Assistants
Article 16 of the EU AI Act lists provider obligations for high-risk AI systems: comply with Articles 9–15; show name and contact details; operate an Article 17 quality management system; keep Article 18 documentation and Article 19 logs; undergo Article 43 conformity assessment; draw up an Article 47 EU declaration of conformity and affix Article 48 CE marking; register under Article 49; take corrective action and inform the chain and authorities; demonstrate conformity on request; meet accessibility rules. After Regulation 2026/1744, these Chapter III duties apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I products). Deployers are covered by Article 26, not Article 16.
Sources
- Article 16 — Obligations of providers of high-risk AI systems. EU AI Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
- Articles 9–15, 17–19, 43, 47–49. EU AI Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- AI Act Service Desk FAQ. https://ai-act-service-desk.ec.europa.eu/en/faq