9 min read

EU AI Act Article 26: the obligations you inherit by deploying

Buying a compliant AI product does not make you compliant. Article 26 binds the deployer, and most US firms do not know it already applies to them.

A common and expensive assumption: if the vendor says their AI product is compliant, the buyer is covered. The EU AI Act does not work that way. Article 26 places obligations on the deployer (the organization using the system under its own authority) that exist regardless of the provider conformity status.

You inherit obligations the moment you deploy

When you put a third-party high-risk AI system into use and its output affects people in the EU, you become a deployer. Provider obligations and deployer obligations are separate. A perfectly conformant provider does not discharge your duties under Article 26.

What Article 26 actually asks of a deployer

Use the system in line with the instructions for use. Assign human oversight to people with the competence and authority to exercise it. Ensure input data is relevant for the intended purpose where you control it. Keep the automatically generated logs. Monitor operation and notify the provider and the authorities when a risk or serious incident arises.

The exposure most US firms miss: you can buy a fully conformant high-risk system and still be non-compliant on the day you deploy it, because the deployer duties are yours to perform.

Why US companies are exposed without knowing it

The Act reaches deployers whose AI output is used in the EU, not only EU-incorporated entities. A US company selling into EU markets, or operating EU-facing hiring, credit, or insurance decisions through a third-party model, sits squarely inside Article 26, frequently without an inventory that even names the systems.

What to put on record

  • An inventory of third-party AI systems, classified against Annex III.
  • The human-oversight assignment per system.
  • The instructions for use you operate under.
  • Logs retained and a monitoring cadence.

AI governance is one of five capabilities at RAVENTRYX, and the one most clients arrive through. Article 26 readiness begins with the inventory above, before the deadlines land.

Common questions

Does Article 26 apply to a US company?

Yes, where the output of the AI system is used in the EU. A US company that deploys a third-party high-risk AI system whose results affect people in the EU takes on Article 26 deployer obligations, independent of where the company is incorporated and independent of the provider conformity status.

What is the difference between a provider and a deployer?

A provider develops or markets the AI system. A deployer uses it under their own authority. Article 26 places obligations on the deployer (human oversight, use according to instructions, input-data relevance, logging, and monitoring) that exist even when the provider has fully met its own conformity obligations.

What should a deployer document first?

An inventory of every third-party AI system in use, classified for whether it is high-risk under Annex III, plus the human-oversight assignment, the instructions-for-use you are operating under, and the monitoring you keep. This is step zero, and AI governance is one of five capabilities through which a deployer can build it.

Related capability →

Start a conversation.