{
  "node_id": "eu-ai-act-deployer-obligations-high-risk",
  "title": "EU AI Act - Obligations of Deployers of High-Risk AI Systems (Article 26)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Article 26 establishes the obligations of deployers - the natural or legal persons who use a high-risk AI system under their authority - for high-risk AI systems listed in Annex III; Article 26 obligations are distinct from and complementary to provider obligations under Articles 16-27; key deployer obligations under Article 26 include: (1) Article 26(1) - assign human oversight to natural persons with the necessary competence, training, and authority; (2) Article 26(2) - ensure input data is relevant in view of the intended purpose of the high-risk AI system; (3) Article 26(3) - monitor the operation of the high-risk AI system and log relevant data to the extent under the deployer's control; (4) Article 26(4) - inform and obtain consent from individuals subject to real-time remote biometric identification systems where required; (5) Article 26(5) - notify the provider when the deployer detects risks or incidents involving the high-risk AI system; Article 27 - deployers who are public bodies or who use high-risk AI systems in the context of employment and workers management, access to essential services, or education must conduct a Fundamental Rights Impact Assessment (FRIA) before deploying high-risk AI systems; FRIA must include: a description of the processes where the high-risk AI will be used; the period of use; categories of natural persons and number of individuals affected; specific risks to fundamental rights identified; the measures taken to address those risks; the deployer must register the FRIA in the EU database under Article 49; the distinction between provider and deployer is critical - deployers are not providers unless they substantially modify the AI system or place it on the market under their own name, triggering the deployer-becomes-provider conditions in Article 25(4).",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-deployer-obligations-high-risk.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-3-definitions",
    "eu-ai-act-article-113-entry-into-force-application",
    "eu-ai-act-high-risk-employment-recruitment",
    "eu-ai-act-high-risk-biometric-systems",
    "eu-ai-act-post-market-surveillance-monitoring",
    "eu-ai-act-sme-startup-provisions"
  ],
  "primary_citations_count": 5
}