Art 26 deployer duties and the Art 27 FRIA
Lesson 5 of 5 in The Value Chain: Providers, Deployers, Importers, Distributors.
The deployer is where the Act meets actual people — patients, applicants, employees, suspects. Art 26 hands deployers of high-risk systems a duty set built around one idea: you control the context of use, so you answer for it.
The core duties: take appropriate technical and organisational measures to use the system in accordance with its instructions for use (26(1)); assign human oversight to natural persons who have the competence, training and authority — and the necessary support (26(2)); to the extent you control input data, ensure it is relevant and sufficiently representative for the intended purpose (26(4)); monitor operation per the instructions and, on any Art 79(1) risk, suspend use without undue delay and inform the provider or distributor and the market surveillance authority (26(5)); keep the automatically generated logs under your control for at least six months (26(6)).
Art 26(7) — tell your workers first
Before putting a high-risk system into service at the workplace, employer-deployers must inform workers’ representatives and the affected workers that they will be subject to it. This runs alongside — not instead of — national labour law and works-council rights. Deploying an employee-monitoring or task-allocation system quietly and disclosing it after rollout is a standalone breach, whatever the system’s accuracy.
Art 26(8)–(9) — public bodies and the GDPR bridge
Public authorities and EU bodies must verify that the system is registered in the EU database before use — and must not use an unregistered one. And deployers must use the provider’s Art 13 transparency information to discharge their GDPR Art 35 DPIA duty where one applies: the instructions for use are drafted, in part, to be your DPIA input.
Art 26(10) — post-RBI needs a judge within 48 hours
A deployer using post-remote biometric identification in a criminal investigation must request judicial or independent administrative authorisation within 48 hours of use (prior authorisation is the default; the 48-hour window covers justified urgency), use it only for a targeted search connected to a specific offence, and stop — deleting the results — if authorisation is refused. Untargeted trawling is excluded outright.
Art 26(11) + Art 86 — tell the person, then explain
Deployers taking or assisting decisions about natural persons with Annex III systems must inform those persons that a high-risk AI system is being used on them. Downstream sits Art 86: a person subject to a decision producing legal or similarly significant adverse effects, taken on the basis of output from an Annex III system (excluding point 2 critical infrastructure), may demand a clear and meaningful explanation of the role the system played and the main elements of the decision. Provider transparency (Art 13) exists so the deployer can actually answer.
Then comes the Act’s most distinctive deployer instrument: the fundamental rights impact assessment, or FRIA (Art 27). Not every deployer owes one — the Act targets deployments where power asymmetry is worst:
- bodies governed by public law, and private entities providing public services (education, healthcare, housing, social services);
- deployers of two specific Annex III systems regardless of sector: creditworthiness / credit scoring (5(b)) and risk assessment and pricing for life and health insurance (5(c)).
The FRIA is completed before first use, and updated when any element it covers changes. Its required content is a checklist worth knowing cold: (a) the deployer’s processes in which the system will be used, in line with its intended purpose; (b) the period and frequency of intended use; (c) the categories of natural persons and groups likely to be affected; (d) the specific risks of harm to those categories; (e) the human oversight measures per the instructions for use; (f) the measures to be taken if the risks materialise — internal governance, complaint mechanisms. The deployer then notifies the market surveillance authority (questionnaire-based, via an AI Office template), and where a DPIA already covers part of the ground, the FRIA complements it rather than repeating it.
When it goes wrong: who does what, and how fast
- Deployer detects a risk or serious incident
Art 26(5): monitoring per the instructions for use surfaces an Art 79(1) risk or a serious incident.
- Suspend use
Without undue delay — continuing to run a system you have reason to believe presents a risk is a breach in itself.
- Inform provider / distributor + market surveillance authority
Art 26(5): the deployer’s report flows both up the chain and sideways to the authority. Serious incidents: immediately, then per Art 73 clocks.
- Provider investigates + takes corrective action
Art 20: bring into conformity, withdraw, disable or recall — and inform every downstream operator. Art 73 reporting clocks run: 15 days general, 10 days death, 2 days widespread infringement or critical-infrastructure disruption.
- Authority evaluates
Art 79: compliance check, possibly demanding documentation, logs — conditionally even source code (Art 74).
- Corrective action verified, use resumes
Non-conformity ended; records of the whole episode feed post-market monitoring (Art 72).
- Restriction, withdrawal or recall ordered
Art 79(2): measures imposed; other Member States and the Commission informed; safeguard procedure available (Art 81).
Key terms: fundamental rights impact assessment, data protection impact assessment, human oversight, serious incident, market surveillance
Tool: AI Incident Tabletop — Run the escalation yourself: a deployer spots a failure, the clocks start, and you play every role in the chain.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.