Article 26(5)
UpcomingConditional timingMonitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Applies to Deployer; High-Risk AI.
- Actors
- Deployer
- AI class
- High-Risk AI
- Themes
- Monitoring, Reporting & ImprovementGovernance & Accountability
Tracker Guidance
Monitor the high-risk AI system in accordance with the provider's instructions. If use may cause an Article 79(1) risk, suspend use and notify the required parties without undue delay. If a serious incident is identified, immediately follow the Article 26(5) notification sequence and use Article 73 mutatis mutandis if the provider cannot be reached.
Official text
5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities. For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.
Timing depends on the system
- 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
- 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
- 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
- 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
- 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities
Sub-obligations
These are independently assessable parts of the parent requirement.
Article 26(5), first subparagraph
UpcomingMonitor High-Risk AI Operation Against Provider Instructions
Tracker Guidance
Monitor operation of the high-risk AI system based on the instructions for use and, where relevant, provide the provider with information needed for Article 72 post-market monitoring.
Official text
Article 26(5), first subparagraphOfficial source 5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.
Article 26(5), first subparagraph
UpcomingSuspend High-Risk AI Use and Notify Required Parties When a Relevant Risk Is Identified
Tracker Guidance
If there is reason to consider that use of the high-risk AI system in accordance with the instructions may cause the system to present an Article 79(1) risk, suspend use and, without undue delay, inform the provider or distributor and the relevant market-surveillance authority.
Official text
Article 26(5), first subparagraphOfficial source 5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.
Article 26(5), first subparagraph
UpcomingImmediately Report Identified Serious Incidents Involving High-Risk AI
Tracker Guidance
If your organization identifies a serious incident involving the high-risk AI system, immediately inform the provider first, then the importer or distributor and the relevant market-surveillance authorities. If the provider cannot be reached, apply Article 73 mutatis mutandis. Law-enforcement deployers do not need to disclose sensitive operational data.
Official text
Article 26(5), first subparagraphOfficial source 5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.