# EU AI Act Article 26 deployer runtime checklist

General information only. Confirm the role, system classification, applicable date, Member State
rules, sector rules, data-protection requirements, and deployment facts with qualified advisers.

- Version: v1.0
- Last updated: 2026-07-27
- Scope: deployers of high-risk AI systems under Article 26 of Regulation (EU) 2024/1689, with the
  application dates and transitions introduced by Regulation (EU) 2026/1744.

Primary sources:

- Regulation (EU) 2024/1689, Official Journal text: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Regulation (EU) 2026/1744: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- Article 26, Commission AI Act Service Desk: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
- Article 6, Commission AI Act Service Desk: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-6
- Article 99, Commission AI Act Service Desk: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99

Use an evidence link, owner, verdict, gap, and remediation date for every applicable line.

## 1. Role, classification, and date

- [ ] Record why the organisation is a deployer for this system under Article 3(4).
- [ ] Check whether any Article 25 action also makes the organisation a provider.
- [ ] Record the intended purpose and Article 6 high-risk classification.
- [ ] Record the Annex I or Annex III route and the evidence supporting it.
- [ ] For an Annex I route, record the applicable section and the amended Article 2 scope rules.
- [ ] Record any Article 6(3) assessment and approval.
- [ ] Record whether Article 26 applies and the applicable Chapter III date: 2 December 2027 or 2 August 2028.
- [ ] For an earlier system, assess Article 111(2), its design baseline, and significant changes.
- [ ] Identify any public-authority use and the 2 August 2030 transition endpoint.
- [ ] Determine whether a separate Article 27 fundamental-rights impact assessment applies.
- [ ] Map current Article 4, Article 50, data-protection, employment, and sector duties separately.

## 2. Instructions and operating boundaries — Article 26(1)

- [ ] Pin the provider instructions to the deployed system version.
- [ ] Record the intended purpose, supported inputs, limitations, accuracy conditions, and required oversight.
- [ ] Convert the operating boundaries into configuration, access, and release controls.
- [ ] Define review triggers for model, prompt, tool, data-source, vendor, and purpose changes.
- [ ] Keep each deviation, decision, owner, expiry, and corrective action.

## 3. Human oversight — Article 26(2) and (3)

- [ ] Name the natural persons assigned to oversight for each operating period.
- [ ] Record each person’s competence, training, authority, and support.
- [ ] Define approval, disregard, override, escalation, intervention, and suspension rights.
- [ ] Provide the system context and provider instructions needed for each decision.
- [ ] Define coverage, response targets, unavailable-reviewer handling, and escalation.
- [ ] Record how the chosen resource model implements the provider-defined oversight measures.
- [ ] Map the other Union and national obligations preserved by Article 26(3).
- [ ] Test representative decisions, overrides, stop actions, and recovery.
- [ ] Retain Decision Requests, decisions, role snapshots, rationale, timestamps, and drills.

## 4. Input data under deployer control — Article 26(4)

- [ ] Map each input source and the party that controls it.
- [ ] Define relevance and representativeness criteria for the intended purpose.
- [ ] Test allowed sources, required fields, freshness, provenance, format, and population coverage.
- [ ] Define reject, correction, narrowed-use, and suspension outcomes for failed checks.
- [ ] Keep validation results, exceptions, remediation, and the governed run or batch identifier.

## 5. Monitoring, risk, and incident routing — Article 26(5)

- [ ] Translate the instructions for use into monitored signals and thresholds.
- [ ] Assign the monitoring owner, review frequency, provider feedback path, and escalation contacts.
- [ ] Define provider notification under Article 72 where it is relevant.
- [ ] Define the Article 79(1) risk-assessment and suspension path.
- [ ] Define notification to the provider or distributor and market-surveillance authority without undue delay.
- [ ] Define the serious-incident sequence: provider first, followed by importer or distributor and the authority.
- [ ] Define the Article 73 route for a provider that cannot be reached.
- [ ] Run a provider-unreachable drill and retain contact attempts and reporting decisions.
- [ ] Record trigger facts, analysis, suspension scope, notices, timestamps, recovery authority, and corrective action.
- [ ] Financial institutions: map the relevant Union financial-services governance controls to Article 26(5).

## 6. Automatic logs and retention — Article 26(6)

- [ ] Identify every automatically generated log under the deployer’s control.
- [ ] Record gaps where the provider or another party controls required logs.
- [ ] Define an appropriate retention period of at least six months.
- [ ] Check Union, national, data-protection, employment, and sector rules that change the period.
- [ ] Record system and version, timestamps, governed references, outputs, policy decisions, human interventions, errors, and effects needed for reconstruction.
- [ ] Apply access control, integrity checks, privacy minimisation, deletion, legal holds, and export controls.
- [ ] Test retrieval for a defined run and reconcile the expected record population.
- [ ] Financial institutions: maintain the logs with the documentation required by relevant Union financial-services law.

## 7. Conditional duties — Article 26(7), (8), (9), (11), and (12)

- [ ] Workplace use: inform workers’ representatives and affected workers before use.
- [ ] Record the applicable Union and national information procedures and evidence of delivery.
- [ ] Article 49(3): for public authorities, Union institutions, bodies, offices or agencies, or persons acting on their behalf, register the deployer, select the Annex III system, and register its use in the Article 71 EU database.
- [ ] Do not use the system, and inform the provider or distributor, when the required Article 71 registration is missing.
- [ ] Use Article 13 provider information in any required GDPR or Law Enforcement Directive DPIA.
- [ ] Inform natural persons subject to Annex III high-risk AI-assisted decisions as Article 26(11) requires.
- [ ] Define an owner and evidence path for cooperation with competent authorities.
- [ ] Retain authority requests, responses, materials supplied, legal review, owner, and dates.

## 8. Post-remote biometric identification — Article 26(10)

- [ ] Confirm whether the specialist law-enforcement path applies.
- [ ] Document any initial-identification exception and its objective, verifiable facts.
- [ ] Request authorisation ex ante, or without undue delay and no later than 48 hours, from a judicial authority or an administrative authority whose decision is binding and subject to judicial review.
- [ ] Limit use to what is strictly necessary for the specific investigation.
- [ ] Stop use and delete linked personal data after rejected authorisation.
- [ ] Prevent an adverse legal decision based solely on the system output.
- [ ] Document each use in the police file and make it available to the stated authorities on request.
- [ ] Complete annual reporting and check stricter Member State law.

## 9. Runtime exercise and readiness verdict

- [ ] Run one representative case from input through final effect.
- [ ] Run an oversight intervention and a suspension.
- [ ] Run an invalid-input case and confirm the defined outcome.
- [ ] Run a potential-risk and serious-incident tabletop exercise.
- [ ] Retrieve the automatic logs and reconcile system, policy, decision, and effect identifiers.
- [ ] Export the scoped evidence and verify its integrity.
- [ ] Record every gap, owner, severity, remediation date, retest, and residual limitation.
- [ ] Have the accountable deployer owner approve the readiness verdict.
