EU AI Act · Art. 26
High-risk deployer duties (use per instructions, human oversight, monitoring, logs, worker notification)
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
By the Shieldra Compliance Team · Last updated 2026-07-29
What do you actually have to do?
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
Statutory basis: Art. 26 — https://artificialintelligenceact.eu/article/26/
When does it apply?
- 2028-08-02 — deferred to 2 August 2028 (Annex I, Digital Omnibus)
- 2027-12-02 — deferred to 2 December 2027 (Annex III, Digital Omnibus)
Does ISO 42001 or NIST AI RMF cover this duty?
Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.
| Mapped requirement | Strength | Why (and what’s missing) |
|---|
| ISO/IEC 42001 A.3 | Partial | Defined AI roles and life-cycle accountability support assigning human oversight, one element of the Art. 26 bundle. |
| ISO/IEC 42001 A.6 | Partial | Operation-and-monitoring stage processes contribute to the monitoring duty; log retention, worker notification, and input-data checks remain. |
| ISO/IEC 42001 A.9 | Partial | Responsible-use-per-intended-purpose processes directly support using the system per the provider's instructions, but the other Art. 26 duties remain. |
| NIST AI RMF GOVERN-3.2 | Partial | Defined human-AI oversight roles with override authority cover the oversight-assignment element of Art. 26. |
| NIST AI RMF MAP-3.5 | Partial | Documented, assessed oversight processes give the trained-human-oversight duty substance; log retention, input-data checks, and worker notification remain. |
| NIST AI RMF MEASURE-2.4 | Partial | Production monitoring of system behavior is the Art. 26 monitoring duty in RMF terms; log retention and notification duties are extra. |
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-07-29.
Frequently asked questions
What does "High-risk deployer duties (use per instructions, human oversight, monitoring, logs, worker notification)" require?
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
When does this obligation apply?
deferred to 2 August 2028 (Annex I, Digital Omnibus). deferred to 2 December 2027 (Annex III, Digital Omnibus)
Who does this obligation apply to?
The deployer role under the EU AI Act. Statutory basis: Art. 26.