Article 26 — Obligations of deployers of high-risk AI systems
APPLIES DEC 2, 2027 WAS 2026-08-02 AMENDED BY OMNIBUS
Chapter III · High-risk tier
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
Source: EUR-Lex · CELEX 32024R1689
Verified 2026-07-16
PLAIN-LANGUAGE SUMMARY — ORIGINAL INTERPRETATION, NOT THE OFFICIAL TEXT
Deployers must use a high-risk system according to its instructions and assign trained, competent people to oversee it. Where they control input data, they ensure it fits the system's purpose. They monitor operation, suspend use and alert the provider and authorities when risk emerges, report serious incidents, and keep logs for at least six months. Workers are told beforehand, and people subject to Annex III decisions must be informed. Public authority deployers must also meet the registration duty.
AMENDED BY THE DIGITAL OMNIBUS ON AI
This provision's application date moved under the Omnibus. It now applies from 2027-12-02 (originally 2026-08-02). Source: Omnibus final text (OJ pending) · verified 2026-07-16
AT A GLANCE
Chapter: III — High-risk AI systems
Applies: Dec 2, 2027
Tier: High-risk tier
PENALTY EXPOSURE
€15M or 3%
of worldwide turnover — see Art. 99 penalties framework.
← PREVIOUS · ART. 25 Responsibilities along the AI value chain NEXT · ART. 27 → Fundamental rights impact assessment for high-risk AI systems
ELSEWHERE IN CHAPTER III — High-risk AI systems