Home · EU AI Act · Articles · Article 26
EU AI Act · Engineering reference

Article 26 — Deployer Obligations

Deployers of high-risk AI must use the system per the provider's instructions, assign competent human oversight, monitor operation, retain logs, and inform employees and affected persons.

Audit-survivable
38%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 26 sets the obligation stack for high-risk AI deployers (the customer using the system, not the provider building it). Use systems per instructions for use; assign human oversight to natural persons with the competence, training and authority needed; monitor operation; report serious incidents to providers; retain auto-generated logs for at least six months; inform employees who will be subject to the AI, and affected persons of natural persons subject to AI-supported decisions.

In engineering terms

Compared to provider obligations under Articles 9-15, deployer obligations are tractable — most enterprises can satisfy them with proportionate governance: a competent oversight function, log retention discipline, and clear staff communications. The risk is Article 25 conversion (see Article 25) — many self-perceived 'deployers' have Article 25 triggers they haven't catalogued.

Compliance checklist

  • ✓Use of high-risk AI conforms to provider's instructions
  • ✓Named human-oversight roles with documented competence
  • ✓Log retention (minimum 6 months) operationalised
  • ✓Serious-incident reporting workflow to providers
  • ✓Employee and affected-person notifications in place

Terms used here

EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 26?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →