EU AI Act 2026-09-21 7 min
EU AI Act Compliance: The Obligations By Role, Article By Article
The EU AI Act splits obligations by role, not by industry. A provider that builds or badges a high-risk system carries Article 16's list; a deployer that merely runs one carries Article 26's, which is shorter.
Providers of high-risk AI systems shall: (a) ensure that their high-risk AI systems are compliant with the requirements set out in Section 2; ... (f) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service; (g) draw up an EU declaration of conformity in accordance with Article 47; (h) affix the CE marking to the high-risk AI system ... in accordance with Article 48.
Regulation (EU) 2026/1744, in force since 27 July 2026, moved the application date of the Act's high-risk obligations (Chapter III, Sections 1 to 3, which contain Articles 16 and 26) from 2 August 2026 to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems.
Most compliance questions about the EU AI Act ("Artificial Intelligence Act", Regulation (EU) 2024/1689) resolve to one question first: which role does the reader's organisation play. The Act defines four operator roles in Article 3, and the substantive duties attach to the role, not to the sector.
The four roles, as the Act defines them
"'provider' means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge" (Article 3(3))
"'deployer' means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity" (Article 3(4))
Two narrower roles sit either side of the supply chain: an importer (Article 3(6)) is established in the Union and places on the market a system carrying a third-country provider's name; a distributor (Article 3(7)) makes a system available on the Union market without being the provider or importer. Most organisations reading a compliance guide are providers or deployers, so those two carry the weight below.
Provider obligations: Article 16
Article 16 lists what a provider of a high-risk AI system must do before and after the system reaches the market. The chapeau is unconditional ("shall", not "should"):
"Providers of high-risk AI systems shall: (a) ensure that their high-risk AI systems are compliant with the requirements set out in Section 2; (b) indicate on the high-risk AI system ... their name, registered trade name or registered trade mark, the address at which they can be contacted; (c) have a quality management system in place which complies with Article 17; (d) keep the documentation referred to in Article 18; (e) when under their control, keep the logs automatically generated by their high-risk AI systems as referred to in Article 19; (f) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43 ...; (g) draw up an EU declaration of conformity in accordance with Article 47; (h) affix the CE marking ... in accordance with Article 48; (i) comply with the registration obligations referred to in Article 49(1); (j) take the necessary corrective actions and provide information as required in Article 20."
In plain terms: a provider owns the system's conformity from design through the market. That means a documented quality management system, retained technical documentation and logs, a real conformity assessment (not a self-declaration alone, for the systems Article 43 names), the CE mark, and entry in the EU database before the system goes live.
Deployer obligations: Article 26
A deployer (the organisation that runs a high-risk system it did not build) carries a shorter, use-time list:
"Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. ... Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support." (Article 26(1)-(2))
The same article adds a monitoring duty: a deployer that has reason to believe the system, used as instructed, presents a risk must suspend use and inform the provider or distributor and the market surveillance authority without undue delay (Article 26(5)). A deployer does not run the provider's conformity assessment, but it cannot use a high-risk system on autopilot either. Oversight has to be assigned to a named person with real authority to intervene.
When each duty applies, after the July 2026 amendment
The dates matter because the Act phases itself in rather than applying whole on one day, and the schedule changed in July 2026. Regulation (EU) 2026/1744 (the "Digital Omnibus on AI", signed on 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026) amended Article 113, which now sets these points: Chapters I and II (definitions and prohibited practices) apply from 2 February 2025, with narrow exceptions in Article 5 that apply from 2 December 2026; the general-purpose AI model, governance and penalties provisions apply from 2 August 2025; and Chapter III, Sections 1, 2 and 3, which contain Articles 16 and 26 above, apply from 2 December 2027 for high-risk systems classified under Article 6(2) and Annex III, and from 2 August 2028 for high-risk systems classified under Article 6(1) and Annex I.
"Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I" (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, Article 1(40))
That means Article 16 and Article 26 are not yet applicable law for the Annex III cases most compliance teams are asking about: the date is 2 December 2027, and 2 August 2028 for product-embedded systems. The text of Articles 16 and 26 quoted above was not changed by the amending regulation; only the application dates moved. Anything written before July 2026 that gives 2 August 2026 for these duties is out of date.
What Rekvira does with this
Rekvira's MCP tools return the article text with its pinpoint citation on request, so an agent working a compliance question quotes Article 16(f) or 26(2) directly rather than a paraphrase. That is the whole of what the tool does: sources, with the article and the date attached. Whether a given system is high-risk, and what a provider or deployer must therefore build, is a determination for the professional reading the text.
Rekvira puts this inside the AI you already use. Say “Read https://rekvira.com/start.md and follow the onboarding instructions” to Claude or ChatGPT and it connects itself. No form, no password, free during the Founding Beta.
See how it works