Assign human oversight and use per instructions (deployer)
As a deployer of a high-risk system: use it in accordance with the instructions for use, assign human oversight to competent, trained and resourced natural persons, ensure input data is relevant and sufficiently representative, monitor operation, and keep the automatically-generated logs.
- Applies to
- Deployer
- Applies from
- 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply
- Derives from
- Article 26
- Primary source
- Art. 26 AIA
Evidence an auditor expects
- Deployer human-oversight record — Evidence the deployer assigned competent, trained human oversight, used the system per instructions, and checked input-data relevance.
- Automatically-generated logs — Retained operational logs the deployer must keep for high-risk systems within its control.
Audit red flags
Fails an audit
- Deployer does not retain the automatically-generated logs of the high-risk system within its control.
FAQ
What evidence do I need for Article 26?
Deployer human-oversight record, Automatically-generated logs. Each should be contemporaneous, versioned, and traceable to the system version.
When does “Assign human oversight and use per instructions (deployer)” apply?
From 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply. It applies to: Deployer.
What fails an audit here?
Deployer does not retain the automatically-generated logs of the high-risk system within its control.
Legal source
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.