Skip to content

Regulation Tracker / EU AI Act / Chapter III · Section 3

Article 17
Quality management system

Chapter III — Classification rules for high-risk AI systems, Section 3 — Obligations of providers of high-risk AI systems. 10 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 5 reach legal practice directly.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 15 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 10 of the duties below now apply later than Article 113 originally provided; each shows both dates.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects:

  1. (a)a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system;
  2. (b)techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system;
  3. (c)techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the high-risk AI system;
  4. (d)examination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system, and the frequency with which they have to be carried out;
  5. (e)technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to ensure that the high-risk AI system complies with those requirements;
  6. (f)systems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purpose of the placing on the market or the putting into service of high-risk AI systems;
  7. (g)the risk management system referred to in Article 9;
  8. (h)the setting-up, implementation and maintenance of a post-market monitoring system, in accordance with Article 72;
  9. (i)procedures related to the reporting of a serious incident in accordance with Article 73;
  10. (j)the handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;
  11. (k)systems and procedures for record-keeping of all relevant documentation and information;
  12. (l)resource management, including security-of-supply related measures;
  13. (m)an accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph.

2. The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.

3. Providers of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law.

4. For providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law. To that end, any harmonised standards referred to in Article 40 shall be taken into account.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 17(1)Quality managementHigh-risklegal practice

    Providers must put in place a documented, systematic and orderly quality management system that ensures compliance with the Regulation.

    "Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects:"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for legal-AI vendors where the system is high-risk under Annex III point 8, including AI used by or for judicial authorities or similarly in ADR.
    See
    Art. 16(c) · Annex III point 8
  2. Art. 17(1) (a)Quality managementHigh-risklegal practice

    The quality management system must include a regulatory compliance strategy, including conformity assessment and modification-management procedures.

    "a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Legal-AI vendors need a compliance strategy for high-risk legal systems and changes that may affect conformity.
    See
    Art. 43 · Art. 16(c)
  3. Art. 17(1) (b-d)Quality managementHigh-risklegal practice

    The quality management system must cover design control and verification, development quality control and assurance, and examination, testing and validation procedures and frequency.

    "techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for legal-AI vendors engineering and testing systems used in judicial or legal decision-support contexts.
    See
    Art. 17(1)(b)-(d)
  4. Art. 17(1) (e)Quality managementHigh-risk

    The quality management system must identify technical specifications and standards, or other means, used to ensure compliance with Section 2 requirements.

    "technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to ensure that the high-risk AI system complies with those requirements;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI vendors selecting standards or controls for high-risk legal systems.
    See
    Chapter III Section 2 · Art. 40
  5. Art. 17(1) (f-g)Quality managementHigh-risklegal practice

    The quality management system must include data-management systems and procedures and the Article 9 risk management system.

    "systems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purpose of the placing on the market or the putting into service of high-risk AI systems;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Critical for legal-AI vendors managing legal datasets and fundamental-rights risks.
    See
    Art. 9 · Art. 10 · Art. 16(c)
  6. Art. 17(1) (h-i)Quality managementHigh-risklegal practice

    The quality management system must include post-market monitoring and serious-incident reporting procedures.

    "the setting-up, implementation and maintenance of a post-market monitoring system, in accordance with Article 72;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Relevant to legal-AI vendors after deployment in law firms, courts or public bodies where incidents may affect rights.
    See
    Art. 72 · Art. 73
  7. Art. 17(1) (j-m)Quality managementHigh-risk

    The quality management system must cover communications with authorities, notified bodies and stakeholders, record-keeping, resource management and management/staff accountability.

    "the handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI vendors maintaining authority-facing records, support processes and accountable governance.
    See
    Art. 17(1)(j)-(m)
  8. Art. 17(2)Quality managementHigh-risk

    Quality management aspects must be implemented proportionately to provider size while preserving the rigour and protection needed for high-risk AI compliance.

    "The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation."
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal-AI vendors or public bodies — Important for SME legal-AI vendors because proportionality does not reduce the required protection level.
    See
    Art. 16(c)
  9. Art. 17(3)Quality managementHigh-risk

    Providers subject to quality management obligations under sectoral Union law may include Article 17 aspects in those sectoral quality management systems.

    "Providers of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law."
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Institutional — Mostly relevant where legal-AI providers are already regulated under sectoral Union quality-management regimes.
    See
    Art. 16(c)
  10. Art. 17(4)Quality managementHigh-risk

    For financial-institution providers subject to Union financial-services governance rules, the quality management obligation is deemed fulfilled except for risk management, post-market monitoring and incident reporting points.

    "For providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes"
    Who
    Provider
    From
    (Regulation (EU) 2026/1744 (Digital Omnibus on AI), Art. 1(40), amending Art. 113(c)(i): Art. 6(2)/Annex III high-risk)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2): high-risk AI systems placed on the market or put into service before 2026-08-02 are covered only if they are subject to significant design changes from that date; providers and deployers of high-risk AI systems intended for public authorities must take necessary steps to comply by 2030-08-02. Art. 113(c) separately applies Article 6(1) and corresponding obligations from 2027-08-02. Date deferred by Regulation (EU) 2026/1744 (in force 27 July 2026); as enacted: 2026-08-02 (Art. 113 second subparagraph).
    Fine tier
    Art. 99(4)
    Legal practice
    Institutional — Relevant to legal-AI only where a financial institution provides high-risk AI; less direct to law firms or courts.
    See
    Art. 17(1)(g)-(i) · Art. 40

Cite

Regulation (EU) 2024/1689, Article 17 (Quality management system), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-17, accessed 2026-09-08, CC BY 4.0.