What the Article requires
Article 26 sets the obligation stack for high-risk AI deployers (the customer using the system, not the provider building it). Use systems per instructions for use; assign human oversight to natural persons with the competence, training and authority needed; monitor operation; report serious incidents to providers; retain auto-generated logs for at least six months; inform employees who will be subject to the AI, and affected persons of natural persons subject to AI-supported decisions.
In engineering terms
Compared to provider obligations under Articles 9-15, deployer obligations are tractable — most enterprises can satisfy them with proportionate governance: a competent oversight function, log retention discipline, and clear staff communications. The risk is Article 25 conversion (see Article 25) — many self-perceived 'deployers' have Article 25 triggers they haven't catalogued.
Compliance checklist
- ✓Use of high-risk AI conforms to provider's instructions
- ✓Named human-oversight roles with documented competence
- ✓Log retention (minimum 6 months) operationalised
- ✓Serious-incident reporting workflow to providers
- ✓Employee and affected-person notifications in place
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 26?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.