← Course outline
Aavistus Training · ai-act · AIA.06

Deployer obligations and fundamental-rights impact assessment

What you'll learn

What organisations USING high-risk AI must do: operate per instructions, assign competent human oversight, input-data relevance, monitoring and log retention, worker information, and the fundamental-rights impact assessment for public-body and Annex III 5(b)/(c) deployers.

Regulation — cited to the current EU text

Operating in accordance with instructions

Deployers must take appropriate technical and organisational measures to ensure the high-risk AI system is used in accordance with the instructions for use supplied by the provider 32024R1689 Article 26@2024-06-13. This is a structural obligation: the deployer must implement the provider's operational guidelines, not simply receive them. Freedom to organise internal resources remains, but that freedom cannot reduce the level of compliance with the instructions 32024R1689 Article 26@2024-06-13.

Assigning competent human oversight

Deployers are required to assign human oversight to natural persons who possess the necessary competence, training and authority, as well as the necessary support 32024R1689 Article 26@2024-06-13. The provision explicitly requires that oversight persons be equipped — structurally and technically — to fulfil the role. Appointing a formally designated overseer without the skills or means to intervene does not satisfy the obligation.

Input-data relevance

Where the deployer exercises control over the input data fed into the system, they must ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system 32024R1689 Article 26@2024-06-13. This obligation is conditional on control: it applies only to the extent that the deployer exercises control over the input data.

Monitoring and incident reporting

Deployers must monitor the operation of the high-risk AI system on the basis of the instructions for use 32024R1689 Article 26@2024-06-13. Two escalation duties flow from that monitoring:

  • Risk identification: If the deployer has reason to consider that use of the system in accordance with the instructions may nonetheless produce a risk within the meaning of Article 79(1), they must, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and suspend use 32024R1689 Article 26@2024-06-13.
  • Serious incidents: Where a serious incident is identified, the deployer must immediately inform the provider first, then the importer or distributor and the relevant market surveillance authorities 32024R1689 Article 26@2024-06-13.

Financial institutions subject to Union financial-services law on internal governance satisfy the monitoring obligation by complying with those sectoral rules 32024R1689 Article 26@2024-06-13. These monitoring and reporting obligations do not cover sensitive operational data of deployers of AI systems which are law enforcement authorities 32024R1689 Article 26@2024-06-13.

Log retention

Deployers must keep logs automatically generated by the high-risk AI system for a period appropriate to the intended purpose, with a floor of six months, unless applicable Union or national law — in particular data-protection law — requires otherwise 32024R1689 Article 26@2024-06-13. Retention applies to the extent that control exists. Financial institutions subject to Union financial-services governance rules retain logs as part of the documentation already required by that law 32024R1689 Article 26@2024-06-13.

Informing workers

Before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers that they will be subject to the use of that system 32024R1689 Article 26@2024-06-13. The obligation applies in advance of deployment and must follow any applicable Union or national procedural rules on worker information.

Fundamental-rights impact assessment (FRIA)

Article 27 introduces a pre-deployment assessment obligation for a defined subset of deployers. Prior to deploying a high-risk AI system falling under Article 6(2) — with the exclusion of systems intended to be used in the area listed in Annex III point 2 — the following deployers must perform a fundamental-rights impact assessment 32024R1689 Article 27@2024-06-13:

  • Bodies governed by public law
  • Private entities providing public services
  • Deployers of high-risk AI systems listed in Annex III points 5(b) and (c) (Annex III is not a provided source unit; its content is not reproduced here)

The assessment must address six mandatory elements 32024R1689 Article 27@2024-06-13:

(a) a description of the deployer's processes in which the system will be used for its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm to those persons or groups, taking into account the information given by the provider pursuant to Article 13; (e) a description of the human oversight measures to be implemented, in line with the instructions for use; (f) the measures to be taken if those risks materialise, including internal governance arrangements and complaint mechanisms.

The obligation applies to the first use of a given system. For similar subsequent deployments, a deployer may rely on a previously conducted FRIA or on existing impact assessments carried out by the provider. The deployer must update the assessment if the deployer considers that any of the elements listed has changed or is no longer up to date 32024R1689 Article 27@2024-06-13.

Upon completion, the deployer must notify the market surveillance authority by submitting the results using the template provided by the AI Office, unless exempt under Article 46(1) 32024R1689 Article 27@2024-06-13. Where the FRIA overlaps with a data-protection impact assessment under Article 35 of the GDPR or Article 27 of Directive 2016/680, the FRIA complements — it does not replace — that assessment 32024R1689 Article 27@2024-06-13.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The cases below are labeled illustrative context and are not regulatory sources. They show deployment environments where Article 26 and Article 27 obligations become practically relevant.

AI hiring growth in IT and staffing markets. The U.S. IT staffing market is forecast to reach USD 44.50 billion by 2031, driven in part by AI-assisted hiring and skills-based recruitment tools CASE-1. AI hiring in India's IT sector rose 16% year-on-year in June 2026 even as overall IT recruitment declined 3%, according to job-portal data CASE-3. Systems used to screen, rank or select candidates for employment fall under Annex III point 4(a) of the AI Act and are high-risk. Organisations deploying such tools at scale are therefore subject to the full Article 26 obligation set — including worker information requirements before deployment — and, if they are public bodies or private entities providing public services, to the Article 27 FRIA prior to going live.

Global Capability Centres and employment transformation. Global Capability Centres are reshaping employment and urban realty patterns across India, with AI-driven role allocation and workforce monitoring becoming central to their operating model CASE-2. Deployers of AI systems covered by Annex III points 5(b) and (c) (Annex III is not a provided source unit) must complete the FRIA and notify the market surveillance authority before first use, precisely because AI-based task allocation at scale carries structural risks of harm to identifiable worker groups.

Check your understanding

1. When a deployer identifies a serious incident involving a high-risk AI system, in what order must notifications be made?

2. What is the minimum period for which a deployer must retain logs automatically generated by a high-risk AI system?

3. A deployer has full control over the data it feeds into a high-risk AI system. What data-related obligation does this trigger?

4. Which of the following deployers is required to conduct a fundamental-rights impact assessment before deploying a high-risk AI system under Article 6(2)?

5. Where a fundamental-rights impact assessment and a GDPR Article 35 data-protection impact assessment are both required, what is the correct relationship between them?