Law / European Union

AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring)

Regulation (EU) 2024/1689, Article 26(1) to (5)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

An AI risk obligations rule binding public and private bodies.

As of 24 September 2026.

What it requires

  • This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
  • If you are the deployer of a high-risk AI system, take appropriate technical and organisational measures to ensure you use it in accordance with the provider's instructions for use.
  • This duty, and your duty to assign human oversight, do not override any other deployer obligation under Union or national law, and do not limit your freedom to organise your own resources and activities when implementing the provider's human oversight measures.
  • If you are the deployer of a high-risk AI system, assign its human oversight to natural persons who have the necessary competence, training and authority, and give them the necessary support.
  • If you are the deployer of a high-risk AI system and you exercise control over its input data, ensure that input data is relevant and sufficiently representative in view of the system's intended purpose.
  • If you are the deployer of a high-risk AI system, monitor its operation on the basis of the provider's instructions for use, and inform the provider where relevant.
  • Where you have reason to consider that using the system per its instructions may present a risk to health, safety or fundamental rights, inform the provider or distributor and the relevant market surveillance authority without undue delay, and suspend use of the system.
  • Where you have identified a serious incident, immediately inform first the provider, then the importer or distributor and the relevant market surveillance authorities; if you cannot reach the provider, report the incident yourself as Article 73 requires of a provider.
  • This duty does not require disclosing your sensitive operational data if you are a law enforcement authority.
  • If you are a financial institution subject to internal-governance requirements under Union financial services law, you satisfy this monitoring duty by complying with those rules.

If you get it wrong

Private right of actionNo

Penalty structure

Article 99(4)(e): non-compliance with the obligations of deployers under Article 26 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.

Rule
Lower of for SME
As of
24 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
3

What it reaches

How the hook was established

express

What makes it apply

Operator establishment, Place of effect

Obligation class

Governance, Reporting

What it makes you log

Logging duty

Article 26(1) to (5) set use, oversight, input-data and monitoring duties; none of them requires the deployer to keep a log. The log-keeping duty is Article 26(6), its own row.

Kind
None
As of
24 September 2026

Who checks it

Audit expectation

none

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A deployer of a high-risk AI system must take appropriate technical and organisational measures to ensure it uses the system in accordance with the instructions for use accompanying it. That duty, and the deployer's duty to assign human oversight, are without prejudice to other deployer obligations under Union or national law and to the deployer's freedom to organise its own resources and activities for the purpose of implementing the human oversight measures the provider indicated.

A deployer of a high-risk AI system must assign human oversight of the system to natural persons who have the necessary competence, training and authority, as well as the necessary support. Without prejudice to a deployer's duties to use a high-risk AI system per its instructions and to assign human oversight, a deployer that exercises control over a high-risk AI system's input data must ensure that input data is relevant and sufficiently representative in view of the system's intended purpose.

A deployer of a high-risk AI system must monitor its operation on the basis of the instructions for use and, where relevant, inform the provider of that monitoring.

Where a deployer has reason to consider that using the system per its instructions may present a risk to health, safety or fundamental rights, it must, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and suspend use of the system; where it has identified a serious incident, it must immediately inform the provider and then the importer or distributor and the relevant market surveillance authorities.

The duty does not cover sensitive operational data of a law-enforcement deployer, and a deployer that is a financial institution subject to Union financial-services internal-governance rules satisfies it by complying with those rules.

Article 26 sits in Chapter III, Section 3, so like the other deployer duties in this article it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for one classified under Article 6(1) and Annex I.

When LexLint raises it

  • high_risk_decisions

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app