Skip to content

Regulation Tracker / EU AI Act / Chapter III · Section 3

Article 26
Obligations of deployers of high-risk AI systems

Chapter III — Classification rules for high-risk AI systems, Section 3 — Obligations of providers of high-risk AI systems. 12 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 12 reach legal practice directly.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 391 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 12 of the duties below now apply later than Article 113 originally provided; each shows both dates.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6.

2. Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

3. The obligations set out in paragraphs 1 and 2, are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider.

4. Without prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.

5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.

6. Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data.

7. Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives.

8. Deployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. When such deployers find that the high-risk AI system that they envisage using has not been registered in the EU database referred to in Article 71, they shall not use that system and shall inform the provider or the distributor.

9. Where applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680.

10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence.

11. Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply.

12. Deployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement this Regulation.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 26(1)RequirementHigh-risklegal practice

    Deployers must take appropriate technical and organisational measures to ensure high-risk AI systems are used in accordance with the accompanying instructions for use, pursuant to paragraphs 3 and 6.

    "Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for law firms, courts, in-house teams and public authorities deploying high-risk legal AI according to vendor instructions.
    See
    Annex III point 8
  2. Art. 26(2)Human oversightHigh-risklegal practice

    Deployers must assign human oversight to natural persons with the necessary competence, training, authority and support.

    "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Human oversight competence, authority and support are central for legal staff, judges or public servants supervising high-risk AI.
    See
    Annex III point 8
  3. Art. 26(3)Scope or definitionHigh-risklegal practice

    Article 26(1) and (2) do not prejudice other deployer obligations under Union or national law or the deployer’s freedom to organise resources and activities for provider-indicated human oversight.

    "The obligations set out in paragraphs 1 and 2, are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Legal deployers keep flexibility in organising oversight resources but remain subject to other Union and national obligations.
    See
    Annex III point 8
  4. Art. 26(4)Data governanceHigh-risklegal practice

    Where the deployer controls input data, the deployer must ensure the input data is relevant and sufficiently representative in view of the high-risk AI system’s intended purpose.

    "Without prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Important where law firms, courts or legal departments control prompts, case data or other input data for high-risk systems.
    See
    Annex III point 8
  5. Art. 26(5)MonitoringHigh-risklegal practice

    Deployers must monitor operation using instructions, inform providers where relevant, notify and suspend use when Article 79 risk is suspected, and immediately escalate serious incidents.

    "Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of"
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — High for legal deployers because monitoring, suspension and incident escalation can affect client, court or public-service use.
    See
    Art. 72 · Art. 73 · Art. 79(1)
  6. Art. 26(6)Record keepingHigh-risklegal practice

    Deployers must keep automatically generated logs under their control for a period appropriate to intended purpose and at least six months unless Union or national law provides otherwise.

    "Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection"
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — High for legal deployers because logs support auditability, evidence, accountability and regulatory review, with at least six-month retention.
    See
    Annex III point 8
  7. Art. 26(7)Information to personsHigh-risklegal practice

    Employer deployers must inform workers’ representatives and affected workers before putting into service or using a high-risk AI system at the workplace.

    "Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and"
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for law firms, courts and legal departments as employers using high-risk AI in the workplace.
    See
    Annex III point 8
  8. Art. 26(8)RegistrationHigh-risklegal practice

    Public-authority and Union-institution deployers must comply with Article 49 registration obligations and must not use an envisaged high-risk AI system that is absent from the EU database.

    "Deployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. When such deployers find that the high-risk AI system that they envisage using has not been registered in the EU database referred to in Article 71, they shall not use that system and"
    Who
    Deployer, Public-authority deployer, Union institution
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for courts, regulators and other public-authority deployers that must verify EU database registration before use.
    See
    Art. 49 · Art. 71
  9. Art. 26(9)DocumentationHigh-risklegal practice

    Where applicable, deployers must use Article 13 information to comply with data protection impact assessment duties under GDPR or Directive (EU) 2016/680.

    "Where applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Important where legal deployers must align AI Act information with GDPR or law-enforcement data protection impact assessments.
    See
    Art. 13
  10. Art. 26(10)Human oversightHigh-risklegal practice

    Deployers using post-remote biometric identification for targeted criminal investigations must obtain ex ante or prompt binding judicial or administrative authorisation, with each use strictly necessary for a specific offence investigation.

    "Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or"
    Who
    Deployer, Public-authority deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Highly relevant to criminal investigations and judicial authorisation of post-remote biometric identification.
    See
    Annex III point 8
  11. Art. 26(11)Information to personsHigh-risklegal practice

    Deployers of Annex III high-risk AI systems making or assisting decisions about natural persons must inform those persons that they are subject to use of the high-risk AI system.

    "Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive"
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Direct for high-risk legal or public-sector AI making or assisting decisions about natural persons, including judicial or administrative contexts.
    See
    Annex III
  12. Art. 26(12)Cooperation with authoritiesHigh-risklegal practice

    Deployers must cooperate with relevant competent authorities in actions those authorities take concerning the high-risk AI system to implement the Regulation.

    "Deployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement this Regulation."
    Who
    Deployer
    From
    (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal practice directly — Legal deployers must cooperate with regulators in actions concerning their high-risk AI systems.
    See
    Annex III point 8

Cite

Regulation (EU) 2024/1689, Article 26 (Obligations of deployers of high-risk AI systems), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-26, accessed 2026-09-08, CC BY 4.0.