EU AI Act Article 26: What Deployers Must Actually Do
There is no shortage of content summarising the EU AI Act. There is a significant shortage of content explaining what a compliance team at a regulated firm actually needs to build, document, and be able to show a supervisor before August 2026.
This article is the second type. It is written for compliance professionals, DPOs, and heads of AI risk at FCA-regulated firms who need to understand not what Article 26 says, but what Article 26 requires you to produce.
Article 26 obligations fall on deployers (organisations that use AI systems) not just on the AI providers who build them. If your firm uses AI in any regulated context, you are almost certainly an Article 26 deployer.
Who Is a Deployer Under the EU AI Act?
The EU AI Act distinguishes between providers (organisations that develop or place AI systems on the market) and deployers (organisations that use AI systems under their own authority in a professional context). Most enterprise obligations in the Act fall on providers. Article 26 is the primary exception. It creates direct obligations for deployers.
A deployer is any organisation that:
- Uses an AI system in the course of its professional activities
- Does so under its own authority, meaning it has control over how the system is deployed and used
- Deploys the system in a context covered by the Act, which for high-risk systems includes areas such as credit assessment, insurance risk profiling, employment decisions, and access to critical services
In practice, this means that any regulated financial services firm using AI in credit decisioning, pricing, customer communications, claims handling, or risk classification is likely an Article 26 deployer. The fact that the AI system was built by a third-party provider does not change this. You deploy it. The obligations are yours.
What Article 26 Actually Requires: The Plain English Version
Article 26 imposes several categories of obligation on deployers of high-risk AI systems. The following is a plain English rendering of the substantive requirements: not a legal summary, but a compliance professional's reading of what needs to be built.
1. Human Oversight Measures
Deployers must assign human oversight of the AI system to persons with appropriate authority, competence, and resources. Those persons must be able to intervene in or interrupt the system's operation. This is not a policy statement. It requires documented role assignments, defined intervention procedures, and evidence that the oversight function is active, not nominal.
For most regulated firms, this means: a named individual or team responsible for each deployed AI system, with documented authority to halt the system, and a record of how that authority has been exercised over time.
2. Monitoring of AI System Operation
Deployers must monitor the operation of the AI system on the basis of instructions of use and report serious incidents or malfunctions to the provider and, where applicable, to competent authorities. This creates an obligation not just to have a system, but to actively monitor it, and to be able to demonstrate that monitoring occurred.
A supervisor will ask: how often do you review the system's operation? What do you look for? What do you do when something looks wrong? The answers need to be documented and evidenced, not described in a policy.
3. Technical and Organisational Measures
Deployers must implement appropriate technical and organisational measures to ensure the AI system is used in accordance with its intended purpose and the instructions provided by the provider. For regulated firms, this connects to existing obligations under FCA SYSC 8 and the ICO framework. The Article 26 requirements do not sit in isolation.
4. Record-Keeping and Documentation
Deployers must keep logs of the AI system's operation to the extent that this is within their control. This is the record-keeping obligation that turns monitoring into evidence. The phrase "to the extent within their control" is important. You do not need to log what the AI provider's system does internally, but you need to log what your deployment does, what outputs it produces, and what human oversight occurred.
The standard is not "we have logs." The standard is: could you reproduce, verify, and present to a supervisor what this AI system was doing on a specific date 18 months ago, in a form that has not been altered since generation? That is what Article 26 evidence looks like.
The Five Things You Need to Be Able to Show a Supervisor
Based on the obligations above, here is a practical checklist of what a compliance team needs to have produced before August 2026:
- An AI agent inventory. A documented, current list of every AI system deployed by the organisation in a high-risk context, including third-party tools and embedded AI features in SaaS products. The inventory needs to be maintained, not a one-time exercise.
- A risk classification rationale for each system. Documenting why each AI system is or is not classified as high-risk under Annex III of the Act, with the reasoning recorded and reviewable.
- Human-in-the-loop documentation. Records showing that human oversight roles are assigned, that those individuals have the authority and competence required, and that oversight activities are occurring in practice.
- Monitoring cadence evidence. Records showing how frequently the AI system's operation is reviewed, what the review covers, and what actions have been taken as a result. Monthly cadence aligned to risk committee cycles is a defensible minimum for most systems.
- Signed, reproducible evidence packs. Governance artefacts that capture the state of the AI system's deployment, risk classification, findings, and oversight at a specific point in time, in a form that can be verified as unaltered under examination.
Why Audit Trails Are Not Enough
Most compliance teams, when they think about AI governance documentation, think about audit trails: log files, activity records, event streams. These are necessary but not sufficient for Article 26 compliance.
The problem with audit logs is threefold. First, they are mutable. Log files can be edited, overwritten, or deleted. A supervisor cannot rely on a log file as evidence of what the system was doing at a specific date unless it can be independently verified as unaltered. Second, they are platform-dependent. Log files from Google Workspace, Microsoft 365, and Salesforce Agentforce are not combined into a unified record of what AI agents were doing across your environment. Third, they are not reproducible in the sense Article 26 requires. Presenting a log file in a supervision visit is not the same as presenting a verifiable, signed record of system operation.
Governance evidence that satisfies Article 26 needs to be cryptographically signed at the point of generation, serialised in a canonical format, and stored in a way that allows the signature to be verified against the content at any future point. This is what distinguishes governance evidence from a nice-to-have audit trail.
The Enforcement Timeline and What to Prioritise
Article 26 obligations for high-risk AI systems come into force in August 2026.
For firms that have not yet started, the realistic priority order is:
In the next 30 days
- Identify which AI systems your organisation is deploying that may fall within Annex III scope
- Establish who is responsible for human oversight of each system. Even if the governance framework is not yet complete, assigning accountability is the first step
- Begin building your AI agent inventory. Enumerate what is actually running in your environment, including tools deployed without formal IT approval
In the next 60 days (post-enforcement)
- Produce your first evidence pack covering the inventory and risk classification
- Establish a monitoring cadence. Monthly review aligned to risk committee cycles is a defensible starting point
- Document your human oversight procedures and intervention protocols
Perfect compliance from day one is not achievable for most organisations in the time available. What is achievable, and what regulators will look for, is demonstrable effort: evidence that the organisation understood its obligations, took proportionate steps, and has a credible programme in place.
How AETHER Pulse Maps to Article 26
AETHER Pulse is built around the Article 26 evidence obligation. It provides:
- Cross-platform AI agent discovery. Enumerating agents across Google Workspace, Microsoft 365, OpenAI, Salesforce, Copilot Studio, LangSmith, and AWS Bedrock
- Five-dimensional risk classification. Assessing each agent on data access scope, external communication capability, human oversight status, regulatory touchpoints, and cross-platform patterns
- Eight toxic-combination detections. Identifying cross-platform patterns that no single admin surface can see
- HMAC-SHA256 signed evidence packs. Canonical JSON, per-tenant signing keys, reproducible and verifiable under examination 24 months after generation
- ICO Audit Readiness scorecard. Mapping findings to ICO AI Governance Framework controls
Published methodology: aetherpulse.app/methodology
Frequently Asked Questions
Does Article 26 apply if we use AI systems built by third parties?
Yes. The obligation falls on deployers (organisations that use AI systems) regardless of whether the system was built internally or procured from a third-party provider. If you deploy it in a high-risk context, Article 26 applies to you.
What counts as a high-risk AI system under Annex III?
Annex III lists specific categories including AI used in credit assessment, insurance risk profiling, employment and worker management decisions, access to essential private and public services, and certain law enforcement and border control contexts. Regulated financial services firms should assume that AI used in any customer-facing or credit-related context warrants careful assessment.
When does Article 26 come into force?
August 2026 for high-risk AI system obligations. For AI systems that are already on the market and in use, there are transitional provisions. Firms should seek specific legal advice on their position.
What happens if we are not compliant by August 2026?
The EU AI Act creates a supervisory and enforcement regime with national market surveillance authorities responsible for oversight. For UK firms, the FCA and ICO are the relevant authorities. Non-compliance can result in supervisory action, fines, and reputational consequences. The proportionate approach for most firms is to demonstrate active, good-faith compliance efforts.
Do we need external legal advice?
Yes, for specific legal questions about your organisation's classification and obligations. This article is a practical guide for compliance professionals, not legal advice.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation