What must a deployer of a high-risk AI system be able to show under Article 26?
From 2 December 2027 for systems classified as high-risk under Annex III, and from 2 August 2028 for those under Annex I, a deployer must meet the duties in Art. 26: human oversight, input data, monitoring, logs, cooperating with authorities and, for some systems, telling people they are subject to one. The records below are evidence of it.
David McMillan, Governed AI Deployment. Checked against the sources on .
§01Art. 26
The duties, and the controls the matrix maps to them
Each duty below is a paragraph of Art. 26, in its own words. Beside it are the controls whose row in the controls matrix cites it, and the record each leaves. A record is evidence toward a duty, not proof the duty was met.
Art. 26(2)
Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.
Art. 26(4)
Without prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.
Art. 26(5)
Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.
For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.
Art. 26(6)
Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data.
Deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law.
Art. 26(11)
Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply.
Art. 26(12)
Deployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement this Regulation.
- GD-18 The pack: twelve items in a dated folder, generated rather than written
§02Art. 26
The rest of the article
Art. 26 has further duties on use in line with the instructions for use, informing workers, registration, data protection impact assessments and post-remote biometric identification. Whether and how each applies to a deployer is for its counsel.
§03Art. 12, Art. 13
What the provider must supply
Two provisions bind the provider here: Art. 12, and point (f) of the list of what Art. 13 says the instructions for use must contain.
High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.
Art. 12
(f) where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.
Art. 13
§04
What is not settled
Whether a system is high-risk, whether and to what extent the deployer controls the input data or the logs, and what log period other law sets, longer or shorter than six months, depend on the system and the deployer. The records above are evidence a deployer can produce. Whether they meet the Act, and each of those questions, is for its counsel.
§05
Sources
- Regulation (EU) 2024/1689, the AI Act, consolidated text of 27 July 2026, on EUR-Lex
https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
§06
Book a scoping call
Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.