Skip to content

Regulatory reference

AI Act deployer obligations

Most AI Act coverage is written for providers. Article 26 binds deployers — the organisations that simply use a high-risk system — and that is a far larger population. Any EU employer using AI in recruitment. Any lender scoring creditworthiness. Any insurer pricing risk. These obligations apply from 2 December 2027, and one of them has a longer lead time than the others.

Who counts as a deployer

A provider develops or places an AI system on the market. A deployer uses one under its own authority. You can be a deployer without writing a line of code, without an AI team, and without thinking of yourself as an AI company at all.

The Annex III categories that catch ordinary businesses:

CategoryWhat it looks like in practice
Employment and HRCV screening, candidate ranking, promotion or task-allocation decisions, performance monitoring
Essential private servicesCreditworthiness assessment, insurance risk pricing for life and health
EducationAdmissions, assessment, proctoring, progression decisions
Critical infrastructureSafety management of utilities, traffic, digital infrastructure
BiometricsIdentification and categorisation systems

Buying a recruitment tool that ranks candidates makes you a deployer of a high-risk AI system. The vendor's compliance does not discharge your Article 26 obligations, and no contract can assign them away.

What Article 26 requires

Twelve paragraphs. Described rather than quoted — check the consolidated text before relying on exact wording.

Obligation
1Technical and organisational measures to use the system according to the provider's instructions for use
2Assign human oversight to natural persons with the necessary competence, training, authority and support
4Where you control input data, ensure it is relevant and sufficiently representative for the intended purpose
5Monitor operation; inform the provider of risks; suspend use and notify the provider and market surveillance authority; report serious incidents
6Retain automatically generated logs for at least six months, unless other law provides otherwise
7Employers must inform workers and their representatives before putting a high-risk system into service in the workplace
8Public authorities must verify EU database registration before use
9Use the provider's Article 13 information to fulfil GDPR DPIA obligations
10Post-remote biometric identification: prior authorisation, no untargeted use, no sole-basis adverse decisions, annual reporting
11Inform affected individuals when a high-risk system is used in decisions concerning them
12Cooperate with competent authorities

And separately, Article 27 requires a fundamental rights impact assessment from public bodies, organisations providing public services, and anyone deploying credit-scoring or insurance-pricing systems. If you are a lender or an insurer, Article 26 is not the whole of your obligation.

Log retention is the one with a procurement cycle in front of it

Of the twelve, four are policies, six are processes, and one is infrastructure. Paragraph 6 is the infrastructure one, and it is routinely underestimated.

Six months minimum, automatically generated. Three questions decide how much work that is, and most organisations cannot answer them today:

Does the system generate logs at all? Many SaaS tools expose an activity feed rather than the automatically generated logs the Article contemplates. That is a vendor conversation, and the answer may be no.

Do you have them, or does the vendor? An obligation to retain logs you cannot export is not satisfiable. This needs to be in the contract, and renewal is when you have leverage.

What is your current retention? Thirty or ninety days is common. Extending to six months across a fleet of AI-touching systems is a storage and pipeline change, and it must be in place before December 2027 — logs you did not keep cannot be recovered afterwards.

That last point is why this one moves first. Every other Article 26 obligation can, in principle, be stood up in the weeks before the date. Retention cannot: the six-month clock means the system has to be running properly by roughly mid-2027 for you to have a compliant record on day one.

A reasonable sequence from here

Now — inventory. Which systems touch Annex III decisions? Most organisations discover AI in procurement tools, HR platforms and customer systems that nobody catalogued as AI. You cannot scope obligations against a population you have not established.

Now — the log question, per system. Ask every vendor the three questions above. The answers determine your engineering work and your contract renewals, both of which have long lead times.

2027 H1 — oversight and notification. Name the people, give them authority, and start the worker-information process. Where a works council is involved, treat it as consultation rather than notice.

2027 H1 — retention live. Ahead of the date, not on it, for the reason above.

Watch for: the Commission's Article 6 classification guidelines are due by 2 August 2027 — four months before obligations bite. Useful, but too late to be the start of your scoping.

Common questions about AI Act deployer obligations

Can we push these obligations onto the AI vendor?

No. Article 26 binds the deployer, and a contract cannot reassign a statutory obligation. What contracts can do is secure what you need to meet it — log export, documentation, the Article 13 information that feeds your DPIA. Those are worth negotiating at renewal.

Does Article 26 apply if we only use AI internally?

Yes. The test is whether the system falls in Annex III and whether you deploy it under your own authority, not whether it faces customers. Internal HR screening is among the clearest examples of a high-risk deployment.

What does "human oversight" actually require?

Assigning it to natural persons with the necessary competence, training, authority and support. The authority element is the one organisations trip on: a reviewer who cannot in practice overturn the system's output is not exercising oversight, whatever the policy says.

Do we have to tell people an AI was involved in a decision about them?

Paragraph 11 requires deployers to inform affected individuals when a high-risk system is used in decisions concerning them. It supports the right to an explanation of individual decision-making elsewhere in the Act. Plan for the notification path as well as the notification.

Six months of logs of what, exactly?

The automatically generated logs the system produces, to the extent they are under your control. Scope varies by system, which is why the per-vendor conversation matters more than a blanket retention policy — and why starting it now rather than in 2027 is the practical advice.

Dates on this page were verified on 23 September 2026 against the Council of the EU's press release of 29 June 2026 and the European Commission's regulatory framework page. Article-level detail is drawn from published compilations of the amended text and is described rather than quoted, because the consolidated text was not retrievable in full at the time of writing. This is a reference, not legal advice.

Last reviewed 2026-09-23. Published by Agent Trust Cloud, a Globixera company — globixera.com.