Skip to main content
Module 02

Capitolo 10 di 14

Article 26

Deployer Obligations

~12 min read

Article 26 sets out the obligations that apply to deployers of high-risk AI systems. Deployers have a lighter obligation set than providers, but their responsibilities are nonetheless substantial -- particularly for organisations in the public sector or those making decisions about access to essential services.

Core Deployer Obligations

  • Use the AI system in accordance with the instructions for use provided by the provider (Article 26(1))
  • Assign human overseers with the competence, authority, and resources to perform oversight (Article 26(2))
  • Monitor the AI system for operation in line with instructions and report serious incidents (Article 26(5))
  • Inform the provider or distributor of any serious incident and the relevant market surveillance authority (Article 26(5))
  • Conduct a Fundamental Rights Impact Assessment (FRIA) where required under Article 26(9)
  • Keep logs automatically generated by the AI system for at least 6 months, unless other law requires longer retention

When Is a FRIA Required?

Article 26(9) triggers a mandatory FRIA for two categories of deployer: (1) bodies governed by public law or private bodies providing public services such as utilities, health services, or social protection; and (2) deployers of the credit assessment, insurance risk assessment, and life and health insurance systems listed in Annex III. The FRIA must be conducted before deploying the system and must be registered in the EU database under Article 49.

Regulation (EU) 2024/1689 — Article 26(9)

Before putting a high-risk AI system into service or using it in accordance with Article 27, deployers that are bodies governed by public law, or private bodies providing public services, ... shall perform a fundamental rights impact assessment for the use case at hand.

Module 2

Ch. 10: Deployer Obligations

Deployer Obligations — High-Risk AI Compliance | AZComply Academy