{
  "node_id": "eu-ai-act-provider-obligations-high-risk",
  "title": "EU AI Act - Obligations of Providers of High-Risk AI Systems (Articles 16-20)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Articles 16-20 establish the comprehensive obligations of providers - natural or legal persons who develop or have high-risk AI systems developed and place them on the market or put them into service under their own name or trademark - for high-risk AI systems listed in Annex III or covered by Annex I sector-specific legislation; core provider obligations under Articles 16-20 include: Article 16 - establish a quality management system under Article 17; draw up technical documentation under Article 11; ensure the high-risk AI system undergoes the applicable conformity assessment procedure under Articles 43-44; draw up the EU declaration of conformity under Article 47; affix CE marking under Article 48; register the system in the EU database under Article 49; Article 17 - implement a quality management system (QMS) covering: AI system development and testing; data governance; technical documentation procedures; post-market monitoring; risk management; conformity assessment; Article 18 - keep technical documentation for 10 years after placing on the market or putting into service (or for the period the system is in service where longer); Article 19 - cooperate with national competent authorities on all requests; Article 20 - implement automatic logging capabilities enabling re-tracing of AI system operation over a period appropriate to the AI system's purpose; the provider is responsible for compliance of the high-risk AI system throughout its lifecycle, including after sale - post-market monitoring obligations under Article 61 continue after the system has been placed on the market; where a high-risk AI system is embedded in a product covered by Union harmonisation legislation listed in Annex I (e.g., machinery, medical devices, automotive), providers must comply with both the EU AI Act and the applicable sectoral legislation.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-provider-obligations-high-risk.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-3-definitions",
    "eu-ai-act-article-113-entry-into-force-application",
    "eu-ai-act-conformity-assessment-procedure",
    "eu-ai-act-technical-documentation-requirements",
    "eu-ai-act-post-market-surveillance-monitoring",
    "eu-ai-act-deployer-obligations-high-risk"
  ],
  "primary_citations_count": 5
}