This article is for anyone who deploys, or is going to deploy, a high-risk AI system and wants to see at a glance what Article 26 of the AI Act asks of them. It is the article that gathers the deployer's obligations, and it has twelve paragraphs. Not all of them bind everyone: some are addressed to a particular kind of deployer, and two do not concern a private company. Here are all twelve, who each one binds, and which post covers it.
Before the table, the date, which is the same for all of them. Article 26 applies from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I; it does not reach products under Annex I, Section B. Until then, what there is is preparation, and Regulation (EU) 2026/1744 did not amend Article 26: only the date from which it applies.
The twelve paragraphs
| Paragraph | Who it binds | What it asks | Where we cover it |
|---|---|---|---|
| 1 | Every deployer of a high-risk system | Technical and organisational measures to use it in accordance with its instructions for use | An agent with broad permissions can drift outside its intended purpose |
| 2 | Every deployer | Assign human oversight to people with the necessary competence, training and authority | When an agent chains actions, who's responsible? |
| 3 | No one: it is a saving clause | Paragraphs 1 and 2 are without prejudice to other obligations and to the freedom to organise one's own resources to implement the human oversight indicated by the provider | Pending: no post of its own |
| 4 | Whoever exercises control over the input data, to that extent | Input data relevant and sufficiently representative in view of the intended purpose | No post of its own; covered in minimal risk or high risk and what an authority can ask you |
| 5 | Every deployer | Monitor operation on the basis of the instructions for use and inform the provider; faced with a risk or a serious incident, inform along the chain | Post-market monitoring and serious incidents |
| 6 | Every deployer, for the logs under its control | Keep the logs the system generates automatically, for at least six months unless other law provides otherwise | AI agents: what to log |
| 7 | Only deployers who are employers | Inform workers' representatives and the affected workers before using the system at the workplace | AI in recruitment |
| 8 | Only public authorities and Union institutions, bodies, offices and agencies | Comply with the Article 49 registration obligations and not use a system that is not registered | Does not apply to a private company |
| 9 | Every deployer, where applicable | Use the provider's Article 13 information for the Article 35 GDPR impact assessment | The AEPD's Article 35(4) list |
| 10 | Only whoever uses post-remote biometric identification in a criminal investigation | Request judicial or administrative authorisation | Does not apply to a private company |
| 11 | Whoever deploys an Annex III system that makes or assists in making decisions about natural persons | Inform those people that they are subject to the system | Pending: no post of its own |
| 12 | Every deployer | Cooperate with the competent authorities in any action they take in relation to the system | What an authority can ask you |
How to read the table
The ones that bind everyone. Paragraphs 1, 2, 5, 6, 9 and 12 reach any deployer of a high-risk system, with the nuances each one carries: paragraph 6 is limited to the logs "to the extent such logs are under their control", and paragraph 9 applies "where applicable", that is, when there is an impact assessment to carry out. Paragraph 4 binds you to the extent that you control the input data; if the provider supplies them, they are not yours.
The ones that choose their addressee. Paragraph 7 only looks at whoever is an employer using the system at the workplace. Paragraph 11 only at whoever deploys an Annex III system that decides, or helps decide, about natural persons. A company can fall inside one and outside the other with the same system. And paragraph 11 applies "without prejudice to Article 50": informing people that they are subject to an Annex III system does not replace the Article 50 transparency notices, where those notices are due.
The ones that do not concern a private company. Paragraph 8 requires public authorities and Union institutions to register and not to use an unregistered system. Paragraph 10 governs post-remote biometric identification when searching for a person suspected or convicted of a criminal offence. They are worth knowing about so that they do not end up on a task list that is not yours.
The saving clause. Paragraph 3 adds nothing: it makes clear that paragraphs 1 and 2 do not displace other obligations or take away the freedom to organise one's own means. It is the reason human oversight can be organised in whatever way works best in each company.
The paragraph 5 chain
Paragraph 5 is the one that gets confused most often, because it mixes two things. The first is continuous: monitoring the system's operation on the basis of its instructions and telling the provider where relevant. The second is an event: if there are reasons to consider that the system presents a risk, or if a serious incident is identified, the deployer informs the provider first and then the importer or distributor and the market surveillance authority. Reporting under Article 73 is the provider's, but if you cannot reach the provider, Article 73 applies to you mutatis mutandis.
What the table does not include
Three things are often attributed to Article 26 and are not in it. The quality management system, the technical documentation and post-market monitoring belong to the provider, as we explain in the Article 17 quality management system isn't yours to set up. The fundamental rights impact assessment belongs to Article 27, with a different perimeter and a single date. And the inventory appears in no paragraph, even though almost none of them can be met without it.
Nor does Article 26 contain a post that has to be filled. The human oversight of paragraph 2 is assigned to people with competence, training and authority, but the Regulation does not create a position: the AI Officer is an internal role, useful and voluntary.
Where to start
If you deploy a high-risk system, sensible preparation follows the table in reverse: first know which systems you have and which of them are high-risk, then decide who oversees each one and where its logs are kept, and finally write down what you will do if something fails. The calendar has the dates, and the high-risk module organises the deployer's work.
And who checks all this? In Spain the main market surveillance authority is AESIA, but it is not alone and which one applies to you depends on the system: who enforces the AI Act in Spain and what a surveillance action looks like.
The paragraphs with no post of their own, 3 and 11, are on the blog's agenda. When they are published, this table will link to them.
This article is for informational purposes only and does not constitute legal advice.