A line-by-line map, written as legal analysis rather than marketing. For each deployer obligation under Article 26 of Regulation (EU) 2024/1689, the specific ComplyEdge mechanism that enforces or evidences it, and an honest note where a duty is organisational and remains yours. Article 26 now applies from 2 December 2027 (status note below). What binds deployers from 2 August 2026 is Article 50 transparency, mapped in its own section.
| Art 26 | Deployer obligation (in substance) | ComplyEdge mechanism / evidence |
|---|---|---|
| 26(1) | Take appropriate technical and organisational measures to use the system per the provider's instructions for use. | Every decision records the versioned rule bundle (bundle_id) and jurisdiction in force — configuration-in-force evidence. Following the provider's instructions for use remains yours; the log does not prove instruction adherence. |
| 26(2) | Assign human oversight to competent, trained, resourced natural persons. | Where Layer 2 is used, ambiguous cases are advisory-only and can be surfaced for a human; the log can record that escalation. That is ComplyEdge's own review path — not Art. 26(2) assignment of oversight over your high-risk system. Appointing, training, and resourcing that person remains yours. |
| 26(3) | Paragraphs 1–2 are without prejudice to other obligations under Union or national law, and to your freedom to organise your own resources. | Interpretive provision — no technical mechanism. Listed for completeness. |
| 26(4) | Ensure input data is relevant and sufficiently representative, to the extent under deployer control. | Each input is recorded as a SHA-256 text_hash with agent identity and jurisdiction — an input-provenance trail without retaining raw content. The representativeness judgement remains yours. |
| 26(5) | Monitor operation per the instructions; inform the provider (Art 72) and market surveillance authority of risks; suspend use; report serious incidents (Art 73). | Runtime checks and optional drift monitoring produce a continuous, article-cited decision log that can support operational monitoring. ComplyEdge does not itself notify providers or market surveillance authorities under Art. 72/73, or suspend your system for you. |
| 26(6) | Keep the automatically generated logs, where under your control, for an appropriate period — at least six months unless other Union/national law applies. | Automatic, tamper-evident logging of each ComplyEdge check: timestamp, agent identity, action, text_hash, citation, and a hash-chain link. Retention configurable (default ≥180 days). This is the check/audit trail — not a substitute for every native log the high-risk system itself generates. |
| 26(7) | Employers: inform workers' representatives and affected workers before putting a high-risk system into use at the workplace. | Organisational duty (worker notice). Outside ComplyEdge's technical scope; listed for completeness. |
| 26(8) | Public-authority deployers: register the system in the EU database (Art 49); do not use it if unregistered. | Organisational / registration duty — outside ComplyEdge's technical scope; listed for completeness. |
| 26(9) | Where applicable, use the provider's Art 13 information to carry out the data protection impact assessment (DPIA) under GDPR Article 35. | ComplyEdge supplies the decision record, input provenance and article-cited rule basis the DPIA can draw on. The DPIA itself remains yours. Note: this paragraph concerns the DPIA — not the Article 27 fundamental-rights assessment (below). |
| 26(10) | For post-remote biometric identification in a criminal investigation, obtain prior judicial or administrative authorisation. | Organisational / judicial-authorisation duty — outside ComplyEdge's scope. (ComplyEdge separately enforces the Art 5 prohibitions on impermissible biometric practices.) |
| 26(11) | Where an Annex III system makes, or assists in making, decisions about natural persons, inform those persons they are subject to it. | Organisational disclosure duty specific to Annex III high-risk use — without prejudice to Article 50. Art. 50 chatbot / marking / deepfake rules are a separate transparency regime; they do not discharge 26(11). Informing persons they are subject to the high-risk system remains yours. |
| 26(12) | Cooperate with competent authorities on any action regarding the system. | The tamper-evident audit export is an artifact you can hand to an authority — a verifiable, article-cited record (Art 12 record-keeping feeding the Annex IV technical documentation required by Art 11, which the Art 43 conformity assessment draws on). |
text_hash, citation and a hash-chain link — retained for an appropriate period (ComplyEdge default ≥180 days; note that the six-month floor in Art 26(6) binds only where the deployment is itself high-risk, and from 2 December 2027, so for an Article 50 deployer this retention is a product guarantee rather than a statutory minimum) and exportable as a tamper-evident record (Art 12, feeding Annex IV technical documentation under Art 11). That is a practical, machine-generated substrate for the compliance documentation Measure 2.1 contemplates — produced as a by-product of operation rather than assembled after the fact.For the evidenceable substrate — configuration and jurisdiction on the record (26(1) support), escalation logging where Layer 2 runs (26(2) support), input provenance (26(4)), monitoring logs (26(5) support), check/audit log-keeping (26(6)), authority-facing export (26(12)), plus the Art 27 FRIA-gap phrase flag — you get a continuous, tamper-evident, article-cited record generated at runtime, not a periodic attestation. Organisational duties listed above stay yours. Confirm mappings with counsel before relying on them operationally.
Terms of Service · Privacy Policy · DPA · SaaS Agreement
ComplyEdge · EU AI Act Article 26 deployer one-pager · Article references follow Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (application dates). Timeline verified 2026-08-03 against primary sources. Article 26 contains twelve paragraphs; sub-paragraph numbering above was verified against the consolidated text (log-keeping 26(6); worker notice 26(7); registration 26(8); DPIA 26(9); person-notice 26(11); cooperation 26(12)). Confirm with your counsel before relying on it operationally. Evidence artifacts: audit export (Art 12 record-keeping — high-risk duties from Dec 2027) and Annex IV technical-documentation mapping (Art 11, used in the Art 43 conformity assessment) available on request.