By Rafael Luque Ocaña

The Article 17 quality management system isn't yours to set up

Article 17 requires a documented quality management system for high-risk AI systems. It applies to providers, and its content is about product design and development — nothing a deploying company can put in place.

Among the AI Act obligations that turn up on task lists for companies using AI, the Article 17 quality management system is one of those that generates the most work and applies the least.

We've already covered why it shows up where it doesn't belong: the article gets cited, not the subject. What matters here is the other half — what Article 17 actually asks for, and why a deploying company can't comply with it even if it tried.

What the article requires

Paragraph 1 names the subject in its opening line: "Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation."

And it adds the form: that system "shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions."

It then lists what it must include at a minimum. The first few points are enough to see what it's actually talking about:

  • A strategy for regulatory compliance, including conformity assessment procedures and the management of modifications to the system.
  • The techniques and systematic actions to be used for the design and for design control and verification.
  • Those to be used for development and for quality assurance.
  • Examination, test and validation procedures before, during and after development, and how often they are carried out.
  • The applicable technical specifications and standards, and what means will be used when harmonised standards don't cover all the requirements.
  • Data management systems and procedures: acquisition, collection, analysis, labelling.

Why it can't be passed on to the deployer

No legal argument is needed. The content of the list is enough.

Design, pre-deployment validation, technical specifications, conformity assessment. All of that happens before the system exists as a product on the market. A company that procures an AI tool doesn't design or develop anything: it receives something finished and decides whether to use it, and for what.

Asking it to "put a quality management system in place" under Article 17 amounts to asking it to document engineering decisions it never made, about training data it never saw, following test procedures it never ran.

And conformity assessment — which appears in the first point of the list — is a piece of the provider's regime that a deployer never carries out, under any circumstances.

What actually is yours, and how much it resembles the other thing

Article 17 not being yours doesn't mean you have nothing to document. It means what's yours is something else, and mixing the two up fills folders with material that's no use to anyone.

The deployer's obligations run through Article 26 and its surrounding provisions: using the system in accordance with its instructions, assigning human oversight to people with the necessary competence and authority, retaining the logs the system generates, and being able to show who decided what and when. It's a regime of use, not of construction.

The difference shows in the kind of evidence each one produces. Article 17's regime produces product documentation. Yours produces decision trails — which is exactly the distinction between ticking a box and having evidence.

What to do about Article 17 if you're a deployer

One thing, and it isn't setting it up: asking about it.

A provider of a high-risk system must have that quality management system in place and must be able to demonstrate it. Having it isn't your obligation, but knowing whether they have it is your diligence — especially if the system you're deploying falls under Annex III and is going to be your responsibility to use.

It's one of the questions worth settling before signing, not two years later, alongside the others an AI provider should be able to answer in writing. And the answer — whether they have it or not — is exactly the kind of thing worth noting down with its date: not because any rule requires it today, but because it's what someone will ask you for when they want to know why you chose that provider.

The cost of taking on someone else's obligations

A task list that includes Article 17 isn't just longer: it shifts the effort. The hours a mid-sized company spends drafting a quality management system that isn't its to draft are hours it doesn't spend on what it will actually be asked about — which systems it uses, for what purpose, who's accountable for each one, and when it was last reviewed.

And that substitution is hard to spot from the inside, because pointless work looks a lot like necessary work: it also produces documents, also takes time, also feels like progress. The difference only shows up the day someone asks, and then the thick folder doesn't answer the simple question.

Content in accordance with Article 17 of Regulation (EU) 2024/1689.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.