Module 2 of the AI Act Deployer certification: the twelve paragraphs of Art. 26 turned into an operating procedure, with the evidence each one produces and the deadlines that attach.

Article 26 is the deployer's article. Twelve paragraphs, and almost none of them are policy statements — they are things you do, on a schedule, that leave a trace. This module walks them in order and names the artefact each one produces, because an obligation that produces no artefact cannot be demonstrated.

A note on timing before we start. These obligations attach to high-risk systems, and the Chapter III regime for standalone Annex III systems applies from 2 December 2027 following the Digital Omnibus, and from 2 August 2028 for AI embedded in Annex I regulated products. That is not a reason to wait: the artefacts below take longer to build than the time remaining, and the Art. 4 literacy duty and the Art. 50 transparency duties already apply.

26(1) — Use it as the instructions say

Deployers shall take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions for use.

This is the hinge of the whole article. Everything downstream assumes it.

Two consequences. First, you need the instructions — Art. 13 obliges the provider to supply them, and a vendor who will not is selling you something you cannot lawfully deploy. Second, departing from the declared intended purpose is one of the three Art. 25 triggers that make you the provider. Module 5 is about that.

Artefact: the instructions for use, filed against the system, plus a written statement of how you are actually using it and a confirmation that the two match.

26(2) — Oversight by competent, trained people

Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

Four requirements, and organisations routinely satisfy two of them. Competence and training are usually addressed. Authority and support are usually not.

Authority means the overseer can act on what they see. An overseer who reviews every automated rejection but cannot overturn one has no authority, and the paragraph is not satisfied however diligent they are. Support means time, tooling and staffing: one person nominally overseeing 4,000 decisions a day is not being supported.

Note also that this paragraph is where Art. 4 AI literacy meets an enforceable duty. Art. 4 itself carries no fine band under Art. 99 — it appears in none of its paragraphs. Art. 26(2) does, through Art. 99(4).

Artefact: named individuals per system, their training record, a written delegation of authority stating what they may do, and evidence of the resourcing.

26(3) — Input data under your control

Where the deployer exercises control over input data, it shall ensure that data is relevant and sufficiently representative in view of the intended purpose.

The qualifier does real work. You owe this only for input data you control. A vendor's training data is not yours; the customer records you feed the system are.

Artefact: a description of the input feed, its provenance, and a periodic check that it still matches the population the system was built for. This is also where model drift becomes visible.

26(4) — Monitor operation

Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use.

Monitoring against the instructions, not against your own assumptions. If the instructions state accuracy metrics and operating conditions, those are what you monitor against.

Artefact: a monitoring plan naming the indicators, the thresholds, the frequency, and who reads the output.

26(5) — Suspend and notify

Where the deployer has reason to consider that use in accordance with the instructions may present a risk within the meaning of Art. 79(1), it shall without undue delay inform the provider or distributor and the relevant market surveillance authority, and suspend use of the system.

The order in the text is inform-and-suspend; the order in practice is suspend first. A system you believe is presenting a risk should not keep running while you draft a notification.

Note the trigger: risk arising from use in accordance with the instructions. If the risk arises because you were using it outside the instructions, you have an Art. 26(1) problem and probably an Art. 25 problem, not an Art. 26(5) notification.

Artefact: a suspension procedure that a duty manager can execute at 2 a.m., with the notification templates already written.

26(6) — Keep the logs, at least six months

Deployers shall keep the logs automatically generated by the high-risk AI system, to the extent those logs are under their control, for a period appropriate to the intended purpose, of at least six months, unless provided otherwise in applicable Union or national law.

Three qualifiers, all load-bearing: automatically generated (Art. 12 logs, not your application logs), under their control (a fully hosted SaaS may hold them, which is a contract question), and at least six months (a floor that sectoral retention rules frequently exceed).

Artefact: the retention schedule, the storage location, and the contractual clause that gets you the logs if the vendor holds them. That clause is the one to negotiate at procurement, because you will not get it afterwards.

26(7) — Tell the workers first

Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to its use.

Before, not after. This sits on top of national information and consultation law, and in several Member States the national requirement is heavier.

Artefact: the dated communication and, where representatives exist, the record of their information.

26(8) — Register, if you are a public body

Deployers that are public authorities or Union institutions must register in the EU database under Art. 49. Private deployers generally do not register; their providers do.

26(9) — Use the information for the DPIA

Where a data protection impact assessment is required under the GDPR, the deployer uses the information supplied under Art. 13 to fulfil it. The AI Act does not replace the DPIA, and the DPIA does not discharge the AI Act. They are two documents answering two questions, sharing one evidence base.

26(10) — Law enforcement authorisation

A narrow paragraph on post-remote biometric identification in criminal investigations, requiring prior judicial or administrative authorisation. It concerns law enforcement deployers; commercial organisations can note its existence and move on.

26(11) — Tell the person

Deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system.

Note "or assist in making". A human-in-the-loop arrangement does not remove this duty. And note that this is distinct from the Art. 50 transparency duties, which apply regardless of tier — Module 6 separates them.

Artefact: the notice, where it appears in the journey, and evidence it was shown.

26(12) — Cooperate

Deployers cooperate with the competent authorities on any action concerning the system. In practice this means being able to produce everything above within a reasonable period, which is an argument for keeping it in one file rather than across four teams.

The shape of the file

Read as a set, the twelve paragraphs produce a single deployer file per system: instructions for use, the classification determination, named overseers and their authority, the input data description, the monitoring plan, the suspension procedure, the log retention arrangement, the worker communication, the affected-person notice, and the DPIA link.

That file is what a supervisor asks for. Module 7 assembles it.

Check yourself

  1. Our overseer reviews every rejection but cannot overturn one. Art. 26(2) satisfied?No. The paragraph requires authority as well as competence and training.
  2. Our SaaS vendor holds the system logs. Are we still on the hook for Art. 26(6)?The duty is limited to logs under your control, which makes access a contractual question you must settle before signing.
  3. We informed staff the week after go-live.Too late. Art. 26(7) requires information before putting the system into service.
  4. A human approves each decision, so Art. 26(11) does not apply.It does. The paragraph covers systems that make decisions or assist in making them.

Previous: Module 1 — Are you a deployer, and of what? Next: Module 3 — Human oversight that survives a review →

Frequently Asked Questions

At least six months under Art. 26(6), unless Union or national law provides otherwise — and sectoral law frequently does provide otherwise, usually for longer. Six months is a floor, not a retention policy. The logs in question are the ones the system generates automatically under Art. 12, and only to the extent they are under the deployer's control.

Yes. Art. 26(7) requires deployers that are employers to inform workers' representatives and the affected workers before putting a high-risk system into service at the workplace. This is a duty owed before deployment, not after, and it sits alongside whatever national information and consultation law already requires.

Art. 26(5) requires the deployer to suspend use of the system and inform the provider or distributor and the relevant market surveillance authority without undue delay, where it has reason to consider that use in accordance with the instructions may present a risk within the meaning of Art. 79(1). Suspension comes first; the notification follows.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.