Evaluating ERM or GRC software? Get free Excel and Word RFP templates — 250+ requirements

Get the templates

Article 26(5)

UpcomingConditional timing

Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents

Applies to Deployer; High-Risk AI.

Actors
Deployer
AI class
High-Risk AI
Themes
Monitoring, Reporting & ImprovementGovernance & Accountability

Tracker Networks Guidance

Monitor the high-risk AI system in accordance with the provider's instructions. If use may cause an Article 79(1) risk, suspend use and notify the required parties without undue delay. If a serious incident is identified, immediately follow the Article 26(5) notification sequence and use Article 73 mutatis mutandis if the provider cannot be reached.

Official text

Article 26(5)Official source
5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities. For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.

Timing depends on the system

  • 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
  • 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
  • 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
  • 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
  • 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities

Suggested controls

Related risks

  • Failure to Correct or Report Non-Conforming High-Risk AI

    Non-conformity or material risk may not trigger timely containment, investigation, corrective action and notifications.

  • Improper High-Risk AI Deployment

    A deployer may operate high-risk AI contrary to provider instructions, without qualified oversight, suitable inputs or required monitoring.

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 26(5), first subparagraph

    Upcoming

    Monitor High-Risk AI Operation Against Provider Instructions

    Tracker Networks Guidance

    Monitor operation of the high-risk AI system based on the instructions for use and, where relevant, provide the provider with information needed for Article 72 post-market monitoring.

    Official text

    Article 26(5), first subparagraphOfficial source
    5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.

    Suggested controls

    Related risks

    • Improper High-Risk AI Deployment

      A deployer may operate high-risk AI contrary to provider instructions, without qualified oversight, suitable inputs or required monitoring.

  2. Article 26(5), first subparagraph

    Upcoming

    Suspend High-Risk AI Use and Notify Required Parties When a Relevant Risk Is Identified

    Tracker Networks Guidance

    If there is reason to consider that use of the high-risk AI system in accordance with the instructions may cause the system to present an Article 79(1) risk, suspend use and, without undue delay, inform the provider or distributor and the relevant market-surveillance authority.

    Official text

    Article 26(5), first subparagraphOfficial source
    5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.

    Suggested controls

    Related risks

    • Failure to Correct or Report Non-Conforming High-Risk AI

      Non-conformity or material risk may not trigger timely containment, investigation, corrective action and notifications.

    • Improper High-Risk AI Deployment

      A deployer may operate high-risk AI contrary to provider instructions, without qualified oversight, suitable inputs or required monitoring.

  3. Article 26(5), first subparagraph

    Upcoming

    Immediately Report Identified Serious Incidents Involving High-Risk AI

    Tracker Networks Guidance

    If your organization identifies a serious incident involving the high-risk AI system, immediately inform the provider first, then the importer or distributor and the relevant market-surveillance authorities. If the provider cannot be reached, apply Article 73 mutatis mutandis. Law-enforcement deployers do not need to disclose sensitive operational data.

    Official text

    Article 26(5), first subparagraphOfficial source
    5. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.

    Suggested controls

    Related risks

    • Failure to Correct or Report Non-Conforming High-Risk AI

      Non-conformity or material risk may not trigger timely containment, investigation, corrective action and notifications.

    • Improper High-Risk AI Deployment

      A deployer may operate high-risk AI contrary to provider instructions, without qualified oversight, suitable inputs or required monitoring.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 26(5): Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents | Tracker Networks