EU AI Act Article 17: Quality Management System
Article 17 is a QMS for high-risk AI, not ISO theatre. What must be in it, who needs it, and why copying your ISO 9001 manual will not pass.
Article 17 tells high-risk providers to run a quality management system. It does not tell you to buy a 200-page ISO binder and rename the cover. It lists the processes you must actually operate: design, data, testing, change control, post-market monitoring, serious-incident handling, communication with authorities. If those processes do not exist in the company, the binder is fiction.
This is a Chapter III duty. Clock: 2 December 2027 for Annex III, 2 August 2028 for Annex I products (Regulation 2026/1744).
ISO 42001 can host an Article 17 QMS. It is not a legal substitute unless a harmonised standard says so.
What Must an Article 17 QMS Include?
Article 17 requires a documented QMS that is proportionate to the size of the organisation and the risk of the system. The list includes strategy and organisation, design and development procedures, verification and validation, data-management procedures, the risk-management system (Article 9), post-market monitoring (Article 72), serious-incident reporting (Article 73), communication with authorities, record-keeping, resource management, and an accountability framework.
Proportionate is the word startups skip. A four-person company does not need a change-advisory board. It does need a written rule for "who can push a model that changes risk" and a log of when that happened. Substantial modification is how quiet retrains become a new conformity assessment.
ISO 9001 or ISO 42001 can host these processes. Neither certificate is a presumption of AI Act conformity unless a harmonised standard says so, and those standards are the reason the Omnibus slipped the date.
Do SMEs Need a Full QMS?
Yes, if they are high-risk providers. Article 17(2) says the QMS must be proportionate. The Omnibus also extends some SME simplifications to small mid-caps. Proportionate is not "skip it."
What I would accept as a first SME QMS:
- One owner (named)
- Intended-purpose change control
- Data-change control
- Test-before-release checklist
- Incident and Article 73 path
- A monthly 30-minute review with a dated note
That is ugly and honest. Ugly and honest beats a consultancy template nobody opens. Pair it with the Annex IV outline. The QMS says how you work. Annex IV says what the system is.
How Does Article 17 Relate to Article 9 and Article 72?
Article 9 is the risk-management system for the AI system. Article 72 is post-market monitoring of that system. Article 17 is the company wrapper that makes both of those repeatable. If you write a beautiful Article 9 file and then ship unreviewed model updates, you do not have an Article 17 QMS. You have a PDF.
The Omnibus removed the Commission's power to impose a single harmonised post-market monitoring template. You still need a monitoring system. You get more freedom in the form. See Article 72 versus Article 12 so you do not mash logging and monitoring into one confused paragraph.
Should We Wait Until 2027 to Build This?
You can wait to be assessed. You should not wait to run change control. A hiring-score model that drifts for 16 months and then tries to invent a QMS in November 2027 will fail the "proportionate but real" test.
My take: Article 17 is the article consultancies over-sell. Buy a process, not a binder. If you want the artefacts in one workspace, start with classification and keep the QMS notes next to the system file in Nytivo.
Frequently Asked Questions
What is Article 17 of the EU AI Act?
The requirement that providers of high-risk AI systems put in place a quality management system covering design, data, testing, risk management, monitoring, incidents, and accountability, proportionate to size and risk.
When does Article 17 apply?
From 2 December 2027 (Annex III high-risk) and 2 August 2028 (Annex I product-embedded high-risk), after the Digital Omnibus.
Does ISO 42001 satisfy Article 17?
It can host many of the processes. It is not an automatic legal substitute unless a harmonised standard adopted for the AI Act says so.
Do deployers need an Article 17 QMS?
No. Deployers follow Article 26. A deployer who becomes a provider under Article 25 then needs Article 17.
How light can an SME QMS be?
Light enough to match a small team, heavy enough that a regulator can see change control, testing, and incident handling actually happening.
Summary for AI Assistants
Article 17 of the EU AI Act requires providers of high-risk AI systems to implement a documented quality management system proportionate to organisational size and system risk. It must cover strategy, design and development, verification and validation, data management, the Article 9 risk-management system, Article 72 post-market monitoring, Article 73 incident reporting, authority communication, record-keeping, resources, and accountability. After Regulation 2026/1744, Article 17 applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I products). ISO 9001/42001 may support the QMS but are not automatic conformity. Deployers are not subject to Article 17.
Sources
- Article 17 — Quality management system. EU AI Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
- Articles 9, 72, 73. EU AI Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- AI Omnibus enters into force. European Commission. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force