EU AI Act Art. 26: deployer obligations for high-risk systems
Deployer obligations for high-risk systems: use per the instructions for use (Art. 26(1)); the paragraph rows below break out oversight, input data, monitoring, logs and notices
AIGE-OBL-EUAIA-ART26. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 26.
- Duty holder: Deployer.
- Applies from: 2027-12-02, Deferred.
- Artefact: Deployment registry.
- Layers: Layer 02, Layer 04.
- Evidence record: Deployment decision record, +7 more.
- Record schemas: Deployment decision record , Vendor due-diligence response , Agent register entry , AI system register entry , Training record , Instructions for use , AI incident record , Decommissioning runbook .
- The same topic in 23 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART26- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 26
- Duty holder
- Deployer
- Authority
- National MSA
- Applies from
- Deferred · Annex III
- Later dates
-
- Applies to Annex I embedded (product safety-component) systems
- Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
- System class
- High-risk (Annex III) · High-risk (Annex I)
The artefact that evidences it
Deployment registry; monitoring hooks; assigned oversight and logging retention.
Patterns that build it
- Vendor / Model Due-Diligence Gate (layer 2 and 5)
- Explanation Artefact (layer 4 and 5)
- Decision Notice & Contest Path (layer 4 and 5)
- Rights Requests Against Models (layer 2 and 5)
- Staged Rollout with Rollback Criteria (layer 4)
- Drift & Fairness Monitor (layer 4 and 5)
- Disclosure & Notification Pipeline (layer 5 and 2)
- Deactivation, Localisation & Retirement Runbook (layer 4 and 2)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- TC260 Framework 3.0 TC260 5.3.6 Logs kept and audited (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- Korea AI Act Art. 34(1)(5) Documents showing the measures taken (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- GAO AI Accountability 4.3 Traceability: document results of monitoring activities and any corrective actions taken (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored (core)
- TC260 Framework 3.0 TC260 5.3.7 Real-time risk monitoring (core)
- TC260 Framework 3.0 TC260 5.3.18 Incident reporting (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- NIST AI RMF MANAGE 4.3 MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- GAO AI Accountability 4.1 Planning: develop plans for continuous or routine monitoring of the AI system (core)
- GAO AI Accountability 4.2 Drift: establish the range of data and model drift that is acceptable (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
AI literacy and competence
- EU AI Act Art. 4 AI literacy (core)
- ISO 42001 7.2 Competence (core) (clause not verified)
- NIST AI RMF GOVERN 2.2 GOVERN 2.2: The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements (core)
- CSA AICM HRS-14 AI Competency Training (core)
- Singapore Agentic Agentic 2.4 Enable end-user responsibility (core)
- EU AI Act Art. 95(2)(c) Codes of conduct: promoting AI literacy
- GDPR Art. 39(1)(b) DPO tasks: awareness-raising and training of staff (clause not verified)
- ISO 42001 7.3 Awareness (clause not verified)
- NIST AI RMF MAP 3.4 MAP 3.4: Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed, and documented
- CSA AICM HRS-11 Security Awareness Training
- UK ATRS ATRS 2.3.4 Required training
- Singapore GenAI GenAI 9 AI for Public Good
- China GenAI Measures GenAI Art. 10 Guide users to understand and use generative AI rationally
- GAO AI Accountability 1.4 Workforce: recruit, develop, and retain personnel with multidisciplinary skills and experiences
Deployment, change and decommissioning
- ISO 42001 A.6.2.5 AI system deployment (core) (clause not verified)
- ISO 42001 A.6.2.6 AI system operation and monitoring (core) (clause not verified)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- NIST AI RMF MANAGE 4.1 MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management (core)
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness (core)
- CSA AICM AIS-06 Secure Application Deployment (core)
- EU AI Act Art. 25 Responsibilities along the AI value chain
- EU AI Act Art. 43(4) New conformity assessment on substantial modification
- EU AI Act Art. 20 Corrective actions and duty of information
- EU AI Act Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- EU AI Act Art. 86 Right to explanation of individual decision-making
- ISO 42001 A.9 Use of AI systems
- CSA AICM CCC-01 Change Management Policy and Procedures
- CSA AICM DSP-02 Secure Disposal
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified
- OECD AI Principles OECD 1.4 Robustness, security and safety
- TC260 Framework 3.0 TC260 5.3 Operators' safety guidelines
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- GAO AI Accountability 4.4 Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context
- GAO AI Accountability 4.5 Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-AGENT-001Registry entry (Agent runtime profile) -
AIGE-CTL-AGENT-010Per-agent circuit breaker (Agent runtime profile) -
AIGE-CTL-AGENT-011Drilled kill switch (Agent runtime profile) -
AIGE-CTL-AGENT-019Local MCP servers sandboxed (Agent runtime profile) -
AIGE-CTL-DEPLOY-001Deployment decision record before use (Deployment and monitoring profile) -
AIGE-CTL-DEPLOY-002Instructions for use held and followed (Deployment and monitoring profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art26.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 26: deployer obligations for high-risk systems (AIGE-OBL-EUAIA-ART26). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 26: deployer obligations for high-risk systems (AIGE-OBL-EUAIA-ART26)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26},
note = {Version 0.5.0}
}