Deployer Obligations under Art. 26 EU AI Act

Art. 26 EU AI Act sets out deployer obligations: human oversight, logging, and incident reporting. What businesses must actually implement in practice.

Who actually is a “deployer”?

Anyone who does not develop a high-risk AI system themselves but uses it within the course of their own activity is a deployer within the meaning of the EU AI Act – for example, an HR department using AI-supported CV screening, or a bank using a credit-scoring system from a third-party provider. Art. 26 addresses precisely this role and is therefore more relevant for most companies than the providers’ obligations, since in practice you are more often a user than a manufacturer of an AI system.

Use in accordance with instructions and human oversight

Art. 26(1) requires appropriate technical and organisational measures to ensure the system is used in accordance with the accompanying instructions for use. That sounds self-evident, but in practice it is not: anyone who fails to read, archive or pass on instructions to operational teams is already in breach of paragraph 1 – regardless of whether anything actually goes wrong.

Paragraph 2 requires you to assign human oversight to natural persons who have the “necessary competence, training and authority”. A mere formality – such as an email saying “you are now responsible” – is not enough. What is needed is documented training, clearly defined intervention rights, and genuine organisational authority to stop or correct the system’s decisions. A typical gap: the oversight person is named but neither trained nor given the authority to issue instructions, so oversight is effectively meaningless.

Input data, monitoring and reporting obligations

Where you have control over the input data, paragraph 4 requires this data to be relevant and sufficiently representative for the intended purpose. This mainly concerns cases where you feed your own datasets into a third party’s system – here you bear responsibility for quality and representativeness, not the provider.

Paragraph 5 requires ongoing monitoring of operation on the basis of the instructions for use. If there is reason to believe that use in accordance with the instructions gives rise to a risk within the meaning of Art. 79(1), you must suspend use without delay and inform the provider or the market surveillance authority, as applicable. In the event of a serious incident, a staged reporting chain applies: first the provider, then importers or distributors, and the competent authorities. Financial institutions can fulfil this monitoring obligation through existing governance requirements under financial services law – a duplicate system is then not required.

Logging and informing employees

Paragraph 6 requires you to keep the logs automatically generated by the system for at least six months, insofar as they are under your control and unless other Union law – such as data protection law – provides for different retention periods. In practice, clear allocation of responsibility is often missing: who exactly is responsible for archiving logs if the system is run by a third-party provider? Without contractual clarification, this creates a gap that may be impossible to close in an emergency – for instance, in response to a market surveillance request.

If you use a high-risk AI system in the workplace, paragraph 7 requires you to inform employee representatives and affected staff before putting the system into operation – in accordance with the relevant co-determination rules. This obligation is regularly overlooked because it sits more within employment law than AI law and is often not assigned to anyone in compliance projects.

In addition, paragraph 9 requires you to use the information provided by the provider under Art. 13 to fulfil your own obligations regarding data protection impact assessments under Art. 35 GDPR. AI compliance and data protection compliance are thus explicitly interlinked here – anyone who carries out a DPIA without drawing on the provider’s information misses out on a simplification the legislator intended.

Typical gaps at a glance

In advisory practice, the same patterns recur time and again: named but unqualified oversight persons; no contractual clarification of logging obligations for cloud or SaaS solutions; no escalation chain for serious incidents; forgotten notification of employee representatives. Each of these gaps may seem minor on its own – but together they amount to significant liability risk once a high-risk AI system is deployed in production.

Whether your company qualifies as a deployer of a high-risk AI system, and which of the obligations under Art. 26 specifically apply to you, can be clarified within minutes using our free risk check at /einstufung.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.