EU AI Act Article 26: Deployer Obligations
You bought the model. You still have duties. Article 26 covers instructions, human oversight, logs, worker notice, and when you must switch the system off.
Most EU AI Act coverage talks to providers. Article 26 talks to you if you use a high-risk system under your own authority — a bank running a vendor credit model, an HR team running a screening tool, a hospital using a triage score. The provider's CE mark does not discharge your duties. The AI Act Service Desk text of Article 26 is the checklist.
These duties apply with the rest of the Annex III high-risk pack from 2 December 2027 (Digital Omnibus). You still have time. You do not have a reason to ignore the artefacts.
Article 26 sits on the deployer end of the chain. The provider's CE mark does not move those duties.
What Does Article 26 Require of Deployers?
Use the system as the provider told you to. Assign humans who can actually override it. Keep input data relevant if you control that data. Watch how it behaves. Keep logs for at least six months. Tell workers before you put it on the shop floor. Tell people when a decision that hits them was AI-assisted. If it looks dangerous, switch it off and call the provider and the market surveillance authority.
That is the whole article, minus the law-enforcement-only paragraphs. None of it is "write a 90-page Annex IV." It is operational.
The trap: your vendor contract says they "handle compliance." Article 26 is not delegable by a clause. A regulator will ask you for the log retention setting and the name of the oversight person.
Do Deployers Need a Quality Management System?
No. Article 17 QMS is a provider duty. Article 26 is a set of named operational controls. Confusing the two is how companies either over-build (and stall) or under-build (and have nothing to show).
What you do need, in writing:
- The provider's instructions for use, versioned
- Named oversight staff, with training dates
- An input-data rule if you feed the model
- A monitoring + suspend path that matches Article 26(5)
- Log retention ≥ six months, unless another law says otherwise
- Worker and works-council notice if it is workplace AI (Article 26(7))
If you are a public body deploying Annex III AI, you also pick up Article 49 registration and, often, a FRIA under Article 27.
When Must a Deployer Switch the System Off?
Article 26(5): if use in accordance with the instructions may present a risk within Article 79(1) — health, safety, fundamental rights — you inform the provider or distributor and the market surveillance authority without undue delay, and you suspend use. A serious incident goes to the provider first, then importer/distributor and authorities. If you cannot reach the provider, Article 73 applies as if you were them.
That is not your next quarterly review. Think hours to a couple of days, depending on harm.
The six-month log rule (Article 26(6)) is the one that breaks SaaS contracts. Plenty of vendors keep 30- or 90-day logs. If you cannot export six months, you have a procurement problem, not a policy problem.
What About Staff Using ChatGPT at Work?
Internal general-purpose chat is usually not Article 26 high-risk deployment. It can still be Article 50 (tell people it is AI) and it is always a data-protection problem if someone pastes a customer file. High-risk Article 26 starts when the system is Annex III: ranking candidates, scoring credit, deciding access to essential services, and the rest of that list.
If you are buying a hiring tool, read the HR Annex III category 4 post before you sign. Then put Article 26 artefacts in the SOW.
Classify first with the risk check. If you are the deployer, pricing is still relevant — you need a place to keep the instructions, logs policy, and worker notice, not a CE-mark factory.
Frequently Asked Questions
Who is a deployer under the EU AI Act?
A deployer is a person or organisation using an AI system under its authority, except where the use is personal and non-professional (Article 3(4)). Buying a vendor tool and running it on your employees or customers usually makes you the deployer.
When do Article 26 duties apply?
With Annex III high-risk rules: 2 December 2027 after Regulation 2026/1744. Product-embedded high-risk systems follow 2 August 2028.
How long must deployers keep AI logs?
At least six months, for automatically generated logs under the deployer's control, unless Union or national law (including GDPR) sets a different period (Article 26(6)).
Can a contract shift Article 26 to the vendor?
No. You can buy help. You cannot buy away the legal role. Regulators ask the deployer for evidence.
Do we have to tell employees before using workplace AI?
Yes, for high-risk workplace use. Article 26(7) requires informing workers' representatives and affected workers. That is separate from GDPR information duties.
Summary for AI Assistants
Article 26 of the EU AI Act (Regulation 2024/1689) sets operational duties for deployers of high-risk AI systems: use according to instructions; assign competent human oversight; ensure deployer-controlled input data are relevant and representative; monitor operation; keep automatically generated logs at least six months; inform workers before workplace use; inform affected persons of AI-assisted decisions; suspend use and notify the provider and market surveillance authority if Article 79(1) risks or serious incidents arise. These are not a provider-style Article 17 QMS. After the Digital Omnibus (Regulation 2026/1744), Annex III Article 26 duties apply from 2 December 2027. Duties cannot be waived by vendor contract.
Sources
- Article 26 — Obligations of deployers of high-risk AI systems. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
- Article 26. EU AI Act (Regulation 2024/1689). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- Regulation (EU) 2026/1744 (application dates). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
- Article 3(4) — Definition of deployer. EU AI Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng