A line-by-line map, written as legal analysis rather than marketing. For each deployer obligation under Article 26 of Regulation (EU) 2024/1689, the specific ComplyEdge mechanism that enforces or evidences it, and an honest note where a duty is organisational and remains yours. Article 26 now applies from 2 December 2027 (status note below). What binds deployers from 2 August 2026 is Article 50 transparency, mapped in its own section.
| Art 26 | Deployer obligation (in substance) | ComplyEdge mechanism / evidence |
|---|---|---|
| 26(1) | Take appropriate technical and organisational measures to use the system per the provider's instructions for use. | Every decision records the versioned rule bundle (bundle_id) and jurisdiction in force — a record of the configuration the system was operated under. |
| 26(2) | Assign human oversight to competent, trained, resourced natural persons. | The interpretive layer is advisory-only: ambiguous cases are surfaced for a human and never auto-decided; the log records where human review was triggered. Appointing and training that person remains yours. |
| 26(3) | Paragraphs 1–2 are without prejudice to other obligations under Union or national law, and to your freedom to organise your own resources. | Interpretive provision — no technical mechanism. Listed for completeness. |
| 26(4) | Ensure input data is relevant and sufficiently representative, to the extent under deployer control. | Each input is recorded as a SHA-256 text_hash with agent identity and jurisdiction — an input-provenance trail without retaining raw content. The representativeness judgement remains yours. |
| 26(5) | Monitor operation per the instructions; inform the provider (Art 72) and market surveillance authority of risks; suspend use; report serious incidents (Art 73). | Continuous runtime monitoring + drift detection; every blocked decision is a logged, article-cited event forming the monitoring record and the factual basis for an Art 72/73 notification. |
| 26(6) | Keep the automatically generated logs, where under your control, for an appropriate period — at least six months unless other Union/national law applies. | Automatic, tamper-evident logging: timestamp, agent identity, action, text_hash, citation, and a hash-chain link per event. Retention configurable (default ≥180 days). |
| 26(7) | Employers: inform workers' representatives and affected workers before putting a high-risk system into use at the workplace. | Organisational duty (worker notice). ComplyEdge documents the deployment's rule scope and purpose, giving the factual basis for the notice. |
| 26(8) | Public-authority deployers: register the system in the EU database (Art 49); do not use it if unregistered. | Organisational / registration duty — outside ComplyEdge's technical scope; listed for completeness. |
| 26(9) | Where applicable, use the provider's Art 13 information to carry out the data protection impact assessment (DPIA) under GDPR Article 35. | ComplyEdge supplies the decision record, input provenance and article-cited rule basis the DPIA draws on. The DPIA itself remains yours. Note: this paragraph concerns the DPIA — not the Article 27 fundamental-rights assessment (below). |
| 26(10) | For post-remote biometric identification in a criminal investigation, obtain prior judicial or administrative authorisation. | Organisational / judicial-authorisation duty — outside ComplyEdge's scope. (ComplyEdge separately enforces the Art 5 prohibitions on impermissible biometric practices.) |
| 26(11) | Where an Annex III system makes, or assists in making, decisions about natural persons, inform those persons they are subject to it. | Article 50 transparency rules (chatbot / synthetic-content / emotion-notice) enforce and evidence the disclosure at the point of interaction. |
| 26(12) | Cooperate with competent authorities on any action regarding the system. | The tamper-evident audit export is the artifact handed to an authority — a verifiable, article-cited record (Art 12 record-keeping feeding the Annex IV technical documentation required by Art 11, which the Art 43 conformity assessment draws on). |
text_hash, citation and a hash-chain link — retained for an appropriate period (ComplyEdge default ≥180 days; note that the six-month floor in Art 26(6) binds only where the deployment is itself high-risk, and from 2 December 2027, so for an Article 50 deployer this retention is a product guarantee rather than a statutory minimum) and exportable as a tamper-evident record (Art 12, feeding Annex IV technical documentation under Art 11). That is the deployer-side evidence record the Code asks you to keep, generated as a by-product of operation rather than assembled after the fact.For the technically-evidenceable obligations — instructions-in-force (26(1)), human oversight (26(2)), input provenance (26(4)), monitoring and incident basis (26(5)), log-keeping (26(6)), person-notice (26(11)) and authority cooperation (26(12)), plus the Art 27 FRIA-gap flag — you get a continuous, tamper-evident, article-cited record generated at runtime, not a periodic attestation. Every claim above is demonstrable from a live deployment and reproducible from our public materials.
Terms of Service · Privacy Policy · DPA · SaaS Agreement
ComplyEdge · EU AI Act Article 26 deployer one-pager · Article references follow Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (application dates). Timeline verified against primary sources 26 July 2026. Article 26 contains twelve paragraphs; sub-paragraph numbering above was verified against the consolidated text (log-keeping 26(6); worker notice 26(7); registration 26(8); DPIA 26(9); person-notice 26(11); cooperation 26(12)). Confirm with your counsel before relying on it operationally. Evidence artifacts: audit export (Art 12) and Annex IV technical-documentation mapping (Art 11, used in the Art 43 conformity assessment) available on request.