What organisations USING high-risk AI must do: operate per instructions, assign competent human oversight, input-data relevance, monitoring and log retention, worker information, and the fundamental-rights impact assessment for public-body and Annex III 5(b)/(c) deployers.
Deployers must take appropriate technical and organisational measures to ensure the high-risk AI system is used in accordance with the instructions for use supplied by the provider 32024R1689 Article 26@2024-06-13. This is a structural obligation: the deployer must implement the provider's operational guidelines, not simply receive them. Freedom to organise internal resources remains, but that freedom cannot reduce the level of compliance with the instructions 32024R1689 Article 26@2024-06-13.
Deployers are required to assign human oversight to natural persons who possess the necessary competence, training and authority, as well as the necessary support 32024R1689 Article 26@2024-06-13. The provision explicitly requires that oversight persons be equipped — structurally and technically — to fulfil the role. Appointing a formally designated overseer without the skills or means to intervene does not satisfy the obligation.
Where the deployer exercises control over the input data fed into the system, they must ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system 32024R1689 Article 26@2024-06-13. This obligation is conditional on control: it applies only to the extent that the deployer exercises control over the input data.
Deployers must monitor the operation of the high-risk AI system on the basis of the instructions for use 32024R1689 Article 26@2024-06-13. Two escalation duties flow from that monitoring:
Financial institutions subject to Union financial-services law on internal governance satisfy the monitoring obligation by complying with those sectoral rules 32024R1689 Article 26@2024-06-13. These monitoring and reporting obligations do not cover sensitive operational data of deployers of AI systems which are law enforcement authorities 32024R1689 Article 26@2024-06-13.
Deployers must keep logs automatically generated by the high-risk AI system for a period appropriate to the intended purpose, with a floor of six months, unless applicable Union or national law — in particular data-protection law — requires otherwise 32024R1689 Article 26@2024-06-13. Retention applies to the extent that control exists. Financial institutions subject to Union financial-services governance rules retain logs as part of the documentation already required by that law 32024R1689 Article 26@2024-06-13.
Before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers that they will be subject to the use of that system 32024R1689 Article 26@2024-06-13. The obligation applies in advance of deployment and must follow any applicable Union or national procedural rules on worker information.
Article 27 introduces a pre-deployment assessment obligation for a defined subset of deployers. Prior to deploying a high-risk AI system falling under Article 6(2) — with the exclusion of systems intended to be used in the area listed in Annex III point 2 — the following deployers must perform a fundamental-rights impact assessment 32024R1689 Article 27@2024-06-13:
The assessment must address six mandatory elements 32024R1689 Article 27@2024-06-13:
(a) a description of the deployer's processes in which the system will be used for its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm to those persons or groups, taking into account the information given by the provider pursuant to Article 13; (e) a description of the human oversight measures to be implemented, in line with the instructions for use; (f) the measures to be taken if those risks materialise, including internal governance arrangements and complaint mechanisms.
The obligation applies to the first use of a given system. For similar subsequent deployments, a deployer may rely on a previously conducted FRIA or on existing impact assessments carried out by the provider. The deployer must update the assessment if the deployer considers that any of the elements listed has changed or is no longer up to date 32024R1689 Article 27@2024-06-13.
Upon completion, the deployer must notify the market surveillance authority by submitting the results using the template provided by the AI Office, unless exempt under Article 46(1) 32024R1689 Article 27@2024-06-13. Where the FRIA overlaps with a data-protection impact assessment under Article 35 of the GDPR or Article 27 of Directive 2016/680, the FRIA complements — it does not replace — that assessment 32024R1689 Article 27@2024-06-13.
This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)
The cases below are labeled illustrative context and are not regulatory sources. They show deployment environments where Article 26 and Article 27 obligations become practically relevant.
AI hiring growth in IT and staffing markets. The U.S. IT staffing market is forecast to reach USD 44.50 billion by 2031, driven in part by AI-assisted hiring and skills-based recruitment tools CASE-1. AI hiring in India's IT sector rose 16% year-on-year in June 2026 even as overall IT recruitment declined 3%, according to job-portal data CASE-3. Systems used to screen, rank or select candidates for employment fall under Annex III point 4(a) of the AI Act and are high-risk. Organisations deploying such tools at scale are therefore subject to the full Article 26 obligation set — including worker information requirements before deployment — and, if they are public bodies or private entities providing public services, to the Article 27 FRIA prior to going live.
Global Capability Centres and employment transformation. Global Capability Centres are reshaping employment and urban realty patterns across India, with AI-driven role allocation and workforce monitoring becoming central to their operating model CASE-2. Deployers of AI systems covered by Annex III points 5(b) and (c) (Annex III is not a provided source unit) must complete the FRIA and notify the market surveillance authority before first use, precisely because AI-based task allocation at scale carries structural risks of harm to identifiable worker groups.
1. When a deployer identifies a serious incident involving a high-risk AI system, in what order must notifications be made?
The lesson specifies a strict sequence for serious incidents: the provider is informed immediately first, followed by the importer or distributor and market surveillance authorities. 32024R1689 Article 26@2024-06-13
2. What is the minimum period for which a deployer must retain logs automatically generated by a high-risk AI system?
The lesson sets a floor of six months for log retention, which may be overridden only by applicable Union or national law, including data-protection law. 32024R1689 Article 26@2024-06-13
3. A deployer has full control over the data it feeds into a high-risk AI system. What data-related obligation does this trigger?
Input-data relevance is a conditional obligation that arises only to the extent the deployer exercises control over the input data. 32024R1689 Article 26@2024-06-13
4. Which of the following deployers is required to conduct a fundamental-rights impact assessment before deploying a high-risk AI system under Article 6(2)?
The FRIA obligation applies to bodies governed by public law, private entities providing public services, and deployers of Annex III points 5(b) and (c) — and systems in the area listed in Annex III point 2 are explicitly excluded. 32024R1689 Article 27@2024-06-13
5. Where a fundamental-rights impact assessment and a GDPR Article 35 data-protection impact assessment are both required, what is the correct relationship between them?
The lesson states explicitly that where the assessments overlap, the FRIA complements — and does not replace — the data-protection impact assessment. 32024R1689 Article 27@2024-06-13