For Chief Compliance Officers · EU AI Act

Article 26 Deployer Obligations — and how ComplyEdge evidences each

A line-by-line map, written as legal analysis rather than marketing. For each deployer obligation under Article 26 of Regulation (EU) 2024/1689, the specific ComplyEdge mechanism that enforces or evidences it, and an honest note where a duty is organisational and remains yours. Article 26 now applies from 2 December 2027 (status note below). What binds deployers from 2 August 2026 is Article 50 transparency, mapped in its own section.

Status: Article 26 applies from 2 December 2027, not 2 August 2026. Regulation (EU) 2026/1744 (Official Journal 24 July 2026, in force 27 July 2026) postponed the Annex III high-risk obligations, which include the Article 26 deployer duties mapped below and the Article 12 record-keeping duty, from 2 August 2026 to 2 December 2027. Annex I embedded systems move to 2 August 2028. Not postponed, and binding from 2 August 2026: Article 50 transparency and the Commission's fining powers over GPAI providers (Art. 101). National market-surveillance penalty powers under Article 99 have applied since 2 August 2025 (Chapter XII early application, except Art. 101). The Article 5 prohibitions have applied since 2 February 2025. This map is published in full regardless, for two reasons: the substance of Article 26 is unchanged, and the mechanisms below are already running in production, so the deferral converts a scramble into a planning horizon. Treat any vendor or adviser still presenting Article 26 as already binding on deployers with appropriate caution.

Obligation → mechanism

Art 26Deployer obligation (in substance)ComplyEdge mechanism / evidence
26(1)Take appropriate technical and organisational measures to use the system per the provider's instructions for use.Every decision records the versioned rule bundle (bundle_id) and jurisdiction in force — configuration-in-force evidence. Following the provider's instructions for use remains yours; the log does not prove instruction adherence.
26(2)Assign human oversight to competent, trained, resourced natural persons.Where Layer 2 is used, ambiguous cases are advisory-only and can be surfaced for a human; the log can record that escalation. That is ComplyEdge's own review path — not Art. 26(2) assignment of oversight over your high-risk system. Appointing, training, and resourcing that person remains yours.
26(3)Paragraphs 1–2 are without prejudice to other obligations under Union or national law, and to your freedom to organise your own resources.Interpretive provision — no technical mechanism. Listed for completeness.
26(4)Ensure input data is relevant and sufficiently representative, to the extent under deployer control.Each input is recorded as a SHA-256 text_hash with agent identity and jurisdiction — an input-provenance trail without retaining raw content. The representativeness judgement remains yours.
26(5)Monitor operation per the instructions; inform the provider (Art 72) and market surveillance authority of risks; suspend use; report serious incidents (Art 73).Runtime checks and optional drift monitoring produce a continuous, article-cited decision log that can support operational monitoring. ComplyEdge does not itself notify providers or market surveillance authorities under Art. 72/73, or suspend your system for you.
26(6)Keep the automatically generated logs, where under your control, for an appropriate period — at least six months unless other Union/national law applies.Automatic, tamper-evident logging of each ComplyEdge check: timestamp, agent identity, action, text_hash, citation, and a hash-chain link. Retention configurable (default ≥180 days). This is the check/audit trail — not a substitute for every native log the high-risk system itself generates.
26(7)Employers: inform workers' representatives and affected workers before putting a high-risk system into use at the workplace.Organisational duty (worker notice). Outside ComplyEdge's technical scope; listed for completeness.
26(8)Public-authority deployers: register the system in the EU database (Art 49); do not use it if unregistered.Organisational / registration duty — outside ComplyEdge's technical scope; listed for completeness.
26(9)Where applicable, use the provider's Art 13 information to carry out the data protection impact assessment (DPIA) under GDPR Article 35.ComplyEdge supplies the decision record, input provenance and article-cited rule basis the DPIA can draw on. The DPIA itself remains yours. Note: this paragraph concerns the DPIA — not the Article 27 fundamental-rights assessment (below).
26(10)For post-remote biometric identification in a criminal investigation, obtain prior judicial or administrative authorisation.Organisational / judicial-authorisation duty — outside ComplyEdge's scope. (ComplyEdge separately enforces the Art 5 prohibitions on impermissible biometric practices.)
26(11)Where an Annex III system makes, or assists in making, decisions about natural persons, inform those persons they are subject to it.Organisational disclosure duty specific to Annex III high-risk use — without prejudice to Article 50. Art. 50 chatbot / marking / deepfake rules are a separate transparency regime; they do not discharge 26(11). Informing persons they are subject to the high-risk system remains yours.
26(12)Cooperate with competent authorities on any action regarding the system.The tamper-evident audit export is an artifact you can hand to an authority — a verifiable, article-cited record (Art 12 record-keeping feeding the Annex IV technical documentation required by Art 11, which the Art 43 conformity assessment draws on).
Article 27 (FRIA) is a separate obligation. The fundamental-rights impact assessment is Article 27, not an Article 26 paragraph, and it is not the same as the GDPR Art 35 DPIA referenced in Art 26(9). ComplyEdge's Art 27 rule can flag prompt text that claims to skip a FRIA, and the article-cited corpus supplies the legal citation — it is not a FRIA workflow, and the assessment itself remains yours to produce.
Article 50 (transparency) binds from 2 August 2026 — separate from Article 26. It splits by role: 50(1) direct AI-interaction disclosure and 50(2) machine-readable marking of synthetic content are provider duties (a company building its chatbot or content generator on a general-purpose AI model is the provider of that system); 50(3) emotion-recognition notice and 50(4) deepfake / AI-generated-text disclosure are deployer duties. All bind from 2 August 2026. (Omnibus Art. 111(4) in Regulation (EU) 2026/1744: systems placed on the market before that date have until 2 December 2026 for the 50(2) marking only.) Agents acting for a person. The Commission's final transparency guidelines (20 July 2026, C(2026) 5054) read 50(1) to cover AI agents: where an agent can make bookings, manage correspondence, negotiate or conclude contracts, or execute purchases, it should disclose both its artificial nature and the person on whose behalf it acts, so that delegated authority and accountability for the resulting action are visible. Pure machine-to-machine traffic stays outside 50(1); the duty bites when the agent reaches a person. ComplyEdge's Article 50 rules enforce and evidence these Art. 50 disclosures at the point of interaction — they do not replace Art. 26(11).
The Article 50 Code of Practice asks for compliance documentation of your disclosures — it does not produce the runtime record. The Commission published the Article 50 Code of Practice on 10 June 2026. It is voluntary implementation support, not a new or binding obligation: Article 50 of Regulation (EU) 2024/1689 remains the legal baseline. For deployer signatories, Measure 2.1 commits them to internal compliance processes and documentation of how disclosure obligations are implemented (icons or equivalent labels, placement, review). The Code does not supply machinery that writes that documentation when an AI system acts — the tools built around it are browser-side checklists and marking validators that, in their own words, "do not make a legal or compliance determination." That runtime machinery is what ComplyEdge is. Each 50(3)/50(4) deployer disclosure is enforced at runtime and written as a logged, article-cited event — event ID, timestamp, text_hash, citation and a hash-chain link — retained for an appropriate period (ComplyEdge default ≥180 days; note that the six-month floor in Art 26(6) binds only where the deployment is itself high-risk, and from 2 December 2027, so for an Article 50 deployer this retention is a product guarantee rather than a statutory minimum) and exportable as a tamper-evident record (Art 12, feeding Annex IV technical documentation under Art 11). That is a practical, machine-generated substrate for the compliance documentation Measure 2.1 contemplates — produced as a by-product of operation rather than assembled after the fact.
Honest scope. ComplyEdge does not perform your organisational duties — worker notice (26(7)), registration (26(8)), competent-person assignment (26(2)), Annex III person-notice (26(11)), biometric authorisation (26(10)), or writing the DPIA/FRIA themselves. It enforces runtime obligations it actually covers (prohibited-practice blocking, Art. 50 disclosures where configured) and produces tamper-evident, article-cited evidence that can support the rest — it does not discharge them.

Why this is different from a policy PDF

For the evidenceable substrate — configuration and jurisdiction on the record (26(1) support), escalation logging where Layer 2 runs (26(2) support), input provenance (26(4)), monitoring logs (26(5) support), check/audit log-keeping (26(6)), authority-facing export (26(12)), plus the Art 27 FRIA-gap phrase flag — you get a continuous, tamper-evident, article-cited record generated at runtime, not a periodic attestation. Organisational duties listed above stay yours. Confirm mappings with counsel before relying on them operationally.

Terms of Service · Privacy Policy · DPA · SaaS Agreement

ComplyEdge · EU AI Act Article 26 deployer one-pager · Article references follow Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (application dates). Timeline verified 2026-08-03 against primary sources. Article 26 contains twelve paragraphs; sub-paragraph numbering above was verified against the consolidated text (log-keeping 26(6); worker notice 26(7); registration 26(8); DPIA 26(9); person-notice 26(11); cooperation 26(12)). Confirm with your counsel before relying on it operationally. Evidence artifacts: audit export (Art 12 record-keeping — high-risk duties from Dec 2027) and Annex IV technical-documentation mapping (Art 11, used in the Art 43 conformity assessment) available on request.