EU AI Act · Art. 26
High-risk deployer duties (use per instructions, human oversight, monitoring, logs, worker notification)
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
What do you actually have to do?
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
Statutory basis: Art. 26 — https://artificialintelligenceact.eu/article/26/
Who does this apply to?
- Deployer
When does it apply?
- 2028-08-02 — 2 August 2028 (Annex I, deferred by the Digital Omnibus)
- 2027-12-02 — 2 December 2027 (Annex III, deferred by the Digital Omnibus)
Does ISO 42001 or NIST AI RMF cover this duty?
Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.
| Mapped requirement | Strength | Why (and what’s missing) |
|---|---|---|
| ISO/IEC 42001 A.3 | Partial | Defined AI roles and life-cycle accountability support assigning human oversight, one element of the Art. 26 bundle. |
| ISO/IEC 42001 A.6 | Partial | Operation-and-monitoring stage processes contribute to the monitoring duty; log retention, worker notification, and input-data checks remain. |
| ISO/IEC 42001 A.9 | Partial | Responsible-use-per-intended-purpose processes directly support using the system per the provider's instructions, but the other Art. 26 duties remain. |
| NIST AI RMF GOVERN-3.2 | Partial | Defined human-AI oversight roles with override authority cover the oversight-assignment element of Art. 26. |
| NIST AI RMF MAP-3.5 | Partial | Documented, assessed oversight processes give the trained-human-oversight duty substance; log retention, input-data checks, and worker notification remain. |
| NIST AI RMF MEASURE-2.4 | Partial | Production monitoring of system behavior is the Art. 26 monitoring duty in RMF terms; log retention and notification duties are extra. |
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-09-16.
Frequently asked questions
What does "High-risk deployer duties (use per instructions, human oversight, monitoring, logs, worker notification)" require?
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
When does this obligation apply?
2 August 2028 (Annex I, deferred by the Digital Omnibus). 2 December 2027 (Annex III, deferred by the Digital Omnibus)
Who does this obligation apply to?
The deployer role under the EU AI Act. Statutory basis: Art. 26.