By Rafael Luque Ocaña

Article 26, paragraph by paragraph: what binds the deployer of high-risk AI, and which post covers each

The twelve paragraphs of Article 26 in one table: who each one binds and which post explains it. Two do not concern a private company.

This article is for anyone who deploys, or is going to deploy, a high-risk AI system and wants to see at a glance what Article 26 of the AI Act asks of them. It is the article that gathers the deployer's obligations, and it has twelve paragraphs. Not all of them bind everyone: some are addressed to a particular kind of deployer, and two do not concern a private company. Here are all twelve, who each one binds, and which post covers it.

Before the table, the date, which is the same for all of them. Article 26 applies from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I; it does not reach products under Annex I, Section B. Until then, what there is is preparation, and Regulation (EU) 2026/1744 did not amend Article 26: only the date from which it applies.

The twelve paragraphs

ParagraphWho it bindsWhat it asksWhere we cover it
1Every deployer of a high-risk systemTechnical and organisational measures to use it in accordance with its instructions for useAn agent with broad permissions can drift outside its intended purpose
2Every deployerAssign human oversight to people with the necessary competence, training and authorityWhen an agent chains actions, who's responsible?
3No one: it is a saving clauseParagraphs 1 and 2 are without prejudice to other obligations and to the freedom to organise one's own resources to implement the human oversight indicated by the providerPending: no post of its own
4Whoever exercises control over the input data, to that extentInput data relevant and sufficiently representative in view of the intended purposeNo post of its own; covered in minimal risk or high risk and what an authority can ask you
5Every deployerMonitor operation on the basis of the instructions for use and inform the provider; faced with a risk or a serious incident, inform along the chainPost-market monitoring and serious incidents
6Every deployer, for the logs under its controlKeep the logs the system generates automatically, for at least six months unless other law provides otherwiseAI agents: what to log
7Only deployers who are employersInform workers' representatives and the affected workers before using the system at the workplaceAI in recruitment
8Only public authorities and Union institutions, bodies, offices and agenciesComply with the Article 49 registration obligations and not use a system that is not registeredDoes not apply to a private company
9Every deployer, where applicableUse the provider's Article 13 information for the Article 35 GDPR impact assessmentThe AEPD's Article 35(4) list
10Only whoever uses post-remote biometric identification in a criminal investigationRequest judicial or administrative authorisationDoes not apply to a private company
11Whoever deploys an Annex III system that makes or assists in making decisions about natural personsInform those people that they are subject to the systemPending: no post of its own
12Every deployerCooperate with the competent authorities in any action they take in relation to the systemWhat an authority can ask you

How to read the table

The ones that bind everyone. Paragraphs 1, 2, 5, 6, 9 and 12 reach any deployer of a high-risk system, with the nuances each one carries: paragraph 6 is limited to the logs "to the extent such logs are under their control", and paragraph 9 applies "where applicable", that is, when there is an impact assessment to carry out. Paragraph 4 binds you to the extent that you control the input data; if the provider supplies them, they are not yours.

The ones that choose their addressee. Paragraph 7 only looks at whoever is an employer using the system at the workplace. Paragraph 11 only at whoever deploys an Annex III system that decides, or helps decide, about natural persons. A company can fall inside one and outside the other with the same system. And paragraph 11 applies "without prejudice to Article 50": informing people that they are subject to an Annex III system does not replace the Article 50 transparency notices, where those notices are due.

The ones that do not concern a private company. Paragraph 8 requires public authorities and Union institutions to register and not to use an unregistered system. Paragraph 10 governs post-remote biometric identification when searching for a person suspected or convicted of a criminal offence. They are worth knowing about so that they do not end up on a task list that is not yours.

The saving clause. Paragraph 3 adds nothing: it makes clear that paragraphs 1 and 2 do not displace other obligations or take away the freedom to organise one's own means. It is the reason human oversight can be organised in whatever way works best in each company.

The paragraph 5 chain

Paragraph 5 is the one that gets confused most often, because it mixes two things. The first is continuous: monitoring the system's operation on the basis of its instructions and telling the provider where relevant. The second is an event: if there are reasons to consider that the system presents a risk, or if a serious incident is identified, the deployer informs the provider first and then the importer or distributor and the market surveillance authority. Reporting under Article 73 is the provider's, but if you cannot reach the provider, Article 73 applies to you mutatis mutandis.

What the table does not include

Three things are often attributed to Article 26 and are not in it. The quality management system, the technical documentation and post-market monitoring belong to the provider, as we explain in the Article 17 quality management system isn't yours to set up. The fundamental rights impact assessment belongs to Article 27, with a different perimeter and a single date. And the inventory appears in no paragraph, even though almost none of them can be met without it.

Nor does Article 26 contain a post that has to be filled. The human oversight of paragraph 2 is assigned to people with competence, training and authority, but the Regulation does not create a position: the AI Officer is an internal role, useful and voluntary.

Where to start

If you deploy a high-risk system, sensible preparation follows the table in reverse: first know which systems you have and which of them are high-risk, then decide who oversees each one and where its logs are kept, and finally write down what you will do if something fails. The calendar has the dates, and the high-risk module organises the deployer's work.

And who checks all this? In Spain the main market surveillance authority is AESIA, but it is not alone and which one applies to you depends on the system: who enforces the AI Act in Spain and what a surveillance action looks like.

The paragraphs with no post of their own, 3 and 11, are on the blog's agenda. When they are published, this table will link to them.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Does it apply to minimal risk?

No. Article 26 binds deployers of high-risk AI systems. A minimal-risk system is reached by Articles 4 and 5 of the AI Act, and by the GDPR if it processes personal data.

Which one kicks in first?

All of them at once. Article 26 applies from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I; it does not reach products under Annex I, Section B. What is worth doing beforehand is knowing which systems you have and which of them are high-risk.

Which paragraphs do not concern me as a private company?

Paragraph 8, which binds public authorities and Union institutions, bodies, offices and agencies, and paragraph 10, which concerns post-remote biometric identification in a criminal investigation. Paragraph 7 only concerns you if you are an employer using the system at the workplace, and paragraph 11 if you deploy an Annex III system that makes or assists in making decisions about natural persons.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.