Law & Compliance · 2026-09-21 · 14 min read

AI Act Article 26: those who merely use high-risk AI carry duties — and the deadline moved to December 2027

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

Most of what has been written about the AI Act assumes a company that builds AI. The regulation's heavier surprise sits one level below: it binds the company that merely uses it. Whoever runs a high-risk system under their own responsibility is a deployer — and deployers carry their own duty stack, with fines of up to 15 million euros or 3 percent of worldwide turnover. And because the Digital Omnibus moved the application date while almost every guide still quotes the old one, this piece starts with the calendar.

The tour follows the statute, not the commentary: what shifted on 8 July 2026 with Regulation (EU) 2026/1744, who counts as a deployer under Article 3(4), which systems in a mid-sized company actually land in Annex III, the nine operational duties of Article 26, the trap of Article 25 that turns a user into a provider, and what already applies today — because parts of this regulation have been in force since February 2025.

The date almost everyone quotes wrongly

For a year the standard sentence was: the high-risk obligations apply from August 2026, the embedded ones from August 2027. Both are superseded. The Digital Omnibus — Regulation (EU) 2026/1744 of 8 July 2026, published on 24 July and in force three days later — rewrote Article 113(c). The reasons given are pragmatic: harmonised standards and national authorities were not ready in time, and applying the duties anyway would have produced divergent enforcement rather than compliance.

DateWhat startsAnchor
2 Feb 2025Prohibited practices + AI literacy — already in forceArt. 113(a), Art. 4, Art. 5
2 Aug 2025GPAI models, governance, penalty architectureArt. 113(b)
2 Aug 2026Transparency duties + right to an explanation — not deferredArt. 50, Art. 86
2 Dec 2026New prohibitions — intimate imagery and CSAM material enter Article 5Art. 5(1)(ba), (bb)
2 Dec 2027High-risk obligations for Annex III systems — including all deployer duties of Article 26Art. 113(c)(i)
2 Aug 2028High-risk embedded in regulated products (Annex I)Art. 113(c)(ii)

Two caveats belong to this table. The first is scope: the deferral covers Chapter III Sections 1 to 3 — the classification rules, the system requirements and the actor duties. It does not touch what sits outside: the prohibitions, AI literacy, transparency, the GPAI regime and the remedies chapter including the explanation right. The second is grandfathering: the Omnibus clarified in Article 111(2) that units of a system type lawfully placed on the market before the application date may continue to be placed on the market without the new obligations — the protection attaches to the type, not to your individual licence.

Who is a deployer — the definition that catches the mid-market

Article 3(4) defines the deployer in one line: a natural or legal person, authority or other body that uses an AI system under its own responsibility — unless the use is personal and non-professional. There is no development threshold, no size threshold and no sector threshold in this definition. The eighty-person company running an applicant tracking system whose vendor advertises AI-assisted pre-screening is a deployer of an Annex III system — whether or not anyone in the building has framed it that way.

The classification, not the intent, decides. Annex III point 4 covers employment, workers management and access to self-employment: systems intended for recruitment or selection — including targeted job advertisements, the sifting and filtering of applications and the evaluation of candidates — and systems intended for decisions affecting the terms of work relationships, promotions and terminations, for task allocation based on individual behaviour or personal traits, and for the monitoring and evaluation of performance and behaviour. Point 5 adds access to essential private and public services: creditworthiness assessment and credit scoring (fraud detection excepted) and risk assessment and pricing in life and health insurance. For most mid-sized companies, point 4 is the door: every CV-parsing, candidate-scoring, performance-monitoring tool sits inside it.

The nine duties of Article 26 — what the deployer owes

Article 26 has twelve paragraphs; nine of them carry operational duties for a private-sector deployer. They read like a management system specification, because that is what they are.

DutyWhat it means in practiceParagraph
Use per instructionsTechnical and organisational measures so the system is used in accordance with the provider's instructions of use and intended purposeArt. 26(1)
Human oversight by competent personsAssign oversight to natural persons with the necessary competence, training and authority — and give them supportArt. 26(2)
Input data under your controlWhere input data are under your control, ensure they correspond to the intended purpose and are sufficiently representativeArt. 26(4)
Monitor — and stopMonitor operation against the instructions; on reason to believe the system presents a risk, inform provider or distributor and the market surveillance authority without delay and suspend use; on a serious incident, inform the provider, then the importer or distributor and the authorities — if the provider cannot be reached, Article 73 applies correspondinglyArt. 26(5)
Keep the logsRetain automatically generated logs under your control for a period appropriate to the purpose, at least six months — unless other law provides otherwiseArt. 26(6)
Inform the workforce firstEmployers inform workers' representatives and affected employees before putting into service or using a high-risk system at the workplaceArt. 26(7)
Inform the persons decided overDeployers of Annex III systems that take or support decisions about natural persons inform those persons that they are subject to the system's use — applicants includedArt. 26(11)
Reuse the provider's information for the DPIAUse the Article 13 information, where applicable, to meet the data protection impact assessment duty of Article 35 GDPRArt. 26(9)
Cooperate with authoritiesCooperate with the competent authorities in all measures they take in relation to the systemArt. 26(12)

Three of these deserve a second reading. Paragraph 2 is not satisfied by a software subscription with an audit log: the oversight must sit with a person who carries competence, training and — the word that does the work — authority. An HR assistant who may flag but not override is not the oversight the article describes. Paragraph 5 turns the deployer into a sensor of the surveillance network: the company that merely uses the system is obliged to report a risk it detects and to suspend use. And paragraph 7 makes the information duty a pre-condition — the workforce is informed before the system runs, not after the first grievance.

The remaining paragraphs sort the edge cases: paragraph 8 assigns registration duties to deployers that are public authorities or Union bodies, and obliges them to refrain from using a system that is not in the EU database and to inform the provider or distributor. Paragraph 10 is the biometric remote identification regime — reserved to law enforcement. And the fundamental rights impact assessment of Article 27 binds deployers that are public bodies or private entities providing public services, plus deployers of the credit and insurance systems of points 5(b) and 5(c) — not the typical private employer using a point-4 system.

The provider trap — Article 25

The single most expensive sentence in this part of the regulation is Article 25(1). A distributor, importer, deployer or other third party counts as the provider — and inherits the provider obligations of Article 16, with conformity assessment, technical documentation, quality management and registration — in three cases: when they put their name or trademark on a high-risk system already placed on the market or put into service, contractual arrangements notwithstanding; when they make a substantial modification that was not foreseen in the original conformity assessment while the system remains high-risk; or when they change the intended purpose.

The mid-market translation is concrete. Rebranding a white-label screening tool under your own name: provider. Taking a general-purpose assistant and wiring it into your promotion pipeline as the scoring layer: a change of intended purpose that lands you in Article 16. The contractual clause that allocates duties differently between you and the vendor does not rescue the first case — the text expressly holds regardless of it. Before a system goes live under your branding or with your modifications, the deployer-versus-provider question is the one question to answer in writing.

What already applies — the regulation did not wait for 2027

The deferral is partial, and the part that was not deferred is the part most companies have not mapped. Since 2 February 2025, Article 4 obliges providers and deployers to take measures ensuring a sufficient level of AI literacy of staff and other persons dealing with the operation and use of AI systems on their behalf — a duty calibrated to technical knowledge, context and the persons affected. Since 2 August 2026, the transparency duties of Article 50 run — and with them the explanation right of Article 86: a person subject to a deployer's decision based on an Annex III system's output, where that decision produces legal or similarly significant effects, may demand a clear and meaningful explanation of the system's role in the decision and its main elements. That right sits in Chapter IX — outside the deferred sections — and it already binds.

One more date lands before the deployer stack does: on 2 December 2026 the new prohibitions enter Article 5 — letters (ba) and (bb) ban systems that generate or manipulate realistic imagery showing identifiable persons in intimate contexts without their consent, and material within the meaning of Directive 2011/93/EU. For a company this is mostly a procurement and policy question: what your staff may not run on your infrastructure is now statute, not guideline.

What non-compliance costs — and the SME clause most commentary misses

Article 99(4)(e) places breaches of the Article 26 deployer duties in the middle tier: up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The prohibitions tier sits at 35 million or 7 percent; misleading answers to authorities cost up to 7.5 million or 1 percent.

Paragraph 6 is the line that matters for the mid-market: for SMEs — including start-ups — each fine resolves to the lower of the percentage and the fixed sum. That inverts the usual reading of an either-or clause and it is a deliberate choice: the regulation prices small companies by the cap, not by the turnover. Paragraph 6a, added by the Omnibus, extends the same lower-of rule for the paragraphs 4 and 5 fines to small mid-caps. It is a mitigant, not an exemption — fifteen million euros remains the ceiling, and the enforcement culture is being built by the member states right now, under an Article 99(1) instruction that sanctions must be effective, proportionate and dissuasive while accounting for SME survival.

What the board should decide this quarter

The December 2027 date is a preparation window, not a reason to wait — because three of the five decisions have lead times that do not compress well.

  • Inventory against Annex III, not against headlines. List every AI-supported system that touches people decisions — recruiting, performance, scheduling, credit checks on customers. The classification question is a document exercise: does the vendor position the system inside a point of Annex III, and does it claim the Article 6(3) carve-out? The answer decides whether Article 26 is yours.
  • Contracts: instructions of use or walk away. Article 26(1) makes compliance with the provider's instructions of use your duty. A vendor that cannot produce instructions of use for a high-risk system sells you an unclosable gap. The audit trail for logs under paragraph 6 belongs in the contract too — the six-month retention only covers what is under your control.
  • Name the oversight before the system runs. Competence, training, authority, support — paragraph 2 is a job description. Assign it, empower it, write it down. The same line answers the Art. 86 letter that arrives from the first rejected applicant.
  • Prepare the workforce information. Paragraph 7 has a sequence: workers' representatives and affected employees before the system runs. In works-council jurisdictions this is a process with its own calendar — start it with the purchase decision, not with the go-live.
  • Run the Article 25 test on every customisation. Own branding, own scoring layer, repurposed assistant — each is a candidate for provider status. The cheapest time for that assessment is before the modification, not after the authority letter.

The honest remainder

Three qualifications keep this honest. First, December 2027 is the application date, not a grace period for systems bought later: a point-4 system first placed on the market after the date carries the duties from day one, and Article 111's grandfathering protects types placed on the market earlier — read the contract's delivery date accordingly. Second, the classification question will produce disputes: vendors have an incentive to frame systems outside Annex III, and the Article 6(3) carve-out with its registration duty is exactly the ground on which those arguments will run — where the vendor's position is thin, your own assessment is the fallback, not their brochure. Third, the deployer stack is not the whole map: GDPR obligations run in parallel — paragraph 9 expressly ties the Article 13 information to the impact assessment — and German labour law adds its own co-determination layer on top of paragraph 7.

Whoever takes one sentence from this piece: you do not need to build AI for the AI Act to reach you — using it on people is enough. The reprieve the Omnibus granted is fourteen months; the duties themselves are unchanged. The companies that use the window to write down who oversees what, and on which data the system is allowed to run, are the ones for whom December 2027 is a date and not a project crisis.

Related service

Turning obligations into systems

This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.

IT strategy consulting

Frequently asked questions about AI Act deployer duties

Are we a ‘deployer’ if we only use AI software?

Yes. Under Article 3(4) a deployer is any entity that uses an AI system ‘under its own responsibility’ — regardless of who developed it. A company that buys an applicant tracking system with AI pre-screening and runs it in its own hiring process is a deployer. Development is not the threshold; use is.

Which mid-market systems typically fall under high-risk?

Mainly two blocks of Annex III: point 4 covers AI in employment and workforce management — recruitment and selection of candidates, decisions affecting working conditions, promotions and terminations, and the monitoring and evaluation of performance and behaviour. Point 5 covers access to essential services — including creditworthiness assessment and risk pricing in life and health insurance. A standard ATS with AI-assisted sorting falls under point 4(a).

From when do the Article 26 deployer duties apply?

The Digital Omnibus (Regulation (EU) 2026/1744) moved the dates: for high-risk systems under Annex III the duties apply from 2 December 2027, for Annex I systems from 2 August 2028. The original dates of August 2026 and 2027 are superseded — anyone still quoting ‘August 2026’ for deployer obligations is reading the pre-Omnibus text.

Do we have to inform employees about AI use?

Yes, in advance. Article 26(7) obliges deployers that are employers to inform workers’ representatives and affected employees, before putting into service or using a high-risk system at the workplace, that they will be subject to its use. Paragraph 11 additionally requires informing natural persons about whom the system takes or supports decisions — which includes job applicants.

What happens if we white-label or rebuild a purchased system?

You become the provider — with the far heavier obligations of Article 16. Article 25(1) places distributors, importers, deployers and other third parties in the provider position when they put their name or trademark on the system, make a substantial modification, or change its intended purpose. Rebuilding a general chatbot into an automated candidate ranker is the classic case.

What fines do deployers face?

Breaches of the Article 26 deployer duties sit in Article 99(4)(e): up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. For SMEs, paragraph 6 applies the lower of the two figures — a genuine SME carve-out. False or misleading information to authorities costs up to 7.5 million or 1 percent. For comparison: breaches of the Article 5 prohibitions carry 35 million or 7 percent.

Which duties already apply today, before December 2027?

Three. First, AI literacy under Article 4 — since 2 February 2025 providers and deployers must ensure a sufficient level of AI literacy of their staff. Second, the Article 50 transparency duties and the Article 86 right to an explanation — both have applied since 2 August 2026 and were not deferred. Third, on 2 December 2026 the new prohibited practices of Article 5 enter into force, including the ban on generating realistic intimate imagery of identifiable persons without their consent.

Sources, status and note: All provisions were checked verbatim against the consolidated text, retrieved on 21 September 2026: Article 26 for the nine deployer duties — instructions of use, human oversight, input data, monitoring and suspension, six-month log retention, workforce information, information of affected persons, DPIA reuse and cooperation; Article 25 for the provider trap; Annex III for the employment and essential-services use cases; Article 113 for the amended application dates; Article 86 for the explanation right; Article 5 for the new prohibitions from December 2026; and Article 99 for the fine brackets and the SME lower-of rule. Primary texts on EUR-Lex: Regulation (EU) 2024/1689 and the amending Regulation (EU) 2026/1744 (Digital Omnibus on AI), whose recital 40 sets the 2 December 2027 and 2 August 2028 dates. This is a professional assessment, not individual legal advice; where a choice matters, take counsel.