EU AI Act guide · updated 2 August 2026

You don't build AI — you use it. Deployer obligations under Article 26

The most expensive misunderstanding in the EU AI Act market right now: “we don’t build AI, we just use it — compliance is our vendor’s problem.” Article 26 says otherwise. Any company that deploys a high-risk AI system under its own authority — the HR team running CV screening, the bank running a credit model, the insurer pricing life policies — carries its own obligation set, enforceable since 2 August 2026, in the €15M / 3% penalty tier.

A typical mid-size company deploys more Annex III AI than it thinks: applicant tracking with candidate ranking, performance-review analytics, credit decisioning, fraud scoring that gates essential services. The first deployer obligation is knowing your inventory — the high-risk test applies to tools you buy, not just tools you build.

The Article 26 duty stack

Use per the provider's instructions

Operate the system within its documented intended purpose — going beyond it can make you the provider (Art. 25).

Assign competent human oversight

Named people, with the training, competence, authority and support to actually intervene — not a checkbox reviewer.

Control input data

Where you control inputs, ensure they are relevant and sufficiently representative for the system's intended purpose.

Monitor and escalate

Watch operation per the instructions for use; on signs of Article 79 risk, suspend use and inform the provider and the market-surveillance authority; report serious incidents.

Keep the logs

Retain automatically generated logs under your control for at least six months (longer where other law requires).

Tell your workers first

Before using a high-risk system in the workplace, inform affected workers and their representatives.

Inform affected people

People subject to decisions made or materially informed by an Annex III system must be told the system is in use; Article 86 gives them a right to an explanation of its role in the decision.

Run a FRIA if you're in scope

Public bodies, providers of public services, and deployers of credit-scoring or life/health-insurance-pricing systems must complete a fundamental rights impact assessment before first use (Art. 27).

What this looks like as actual work

For most deployers the gap list is shorter than it sounds, but none of it is optional:

  • Inventory vendor AI tools and classify them (an afternoon with a structured assessment, not a quarter).
  • For each high-risk tool: name the oversight owner, train them, record the training.
  • Ask the vendor for their instructions for use and conformity documents — their Article 13 duty is to give you what your Article 26 duties need.
  • Turn on and retain logging; calendar the six-month floor.
  • Notify workers/representatives before workplace use — a memo, not a project.
  • Check whether the FRIA applies to you; if so, complete it before first use.

Check your deployer exposure — assess a vendor tool in 10 minutes

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Deployer compliance is the rare part of the AI Act that is mostly organisational rather than technical — which means it is fast to close, and correspondingly hard to explain not having closed once an authority asks. Start with the inventory; the rest follows in order on the checklist.

Frequently asked questions

Our vendor says their tool is AI Act compliant. Doesn't that cover us?

No. Provider compliance and deployer compliance are separate obligation sets. The vendor owes documentation, conformity assessment and CE marking; you — the deployer — owe human oversight, input-data control, monitoring, log retention and worker notification under Article 26. A compliant vendor makes your job easier; it does not do your job.

Which everyday tools make a company a high-risk deployer?

The common ones: CV-screening and candidate-ranking features in applicant tracking systems, AI-assisted performance evaluation or task-allocation tools, credit-scoring engines, and AI risk-pricing for life or health insurance. If a tool influences who gets hired, promoted, fired, lent to or insured, assume Annex III until the analysis says otherwise.

Can we be both provider and deployer?

Yes, and many companies are — build an internal hiring model and use it, and you hold both obligation sets. Also watch Article 25: a deployer that puts its name on a high-risk system, or substantially modifies one, can become its provider with the full provider stack.

When did deployer obligations become enforceable?

2 August 2026, together with the rest of the Annex III high-risk regime and its penalty tier — breaches sit in the €15M / 3% band.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.