For Chief Compliance Officers · EU AI Act

Article 26 Deployer Obligations — and how ComplyEdge evidences each

A line-by-line map, written as legal analysis rather than marketing. For each deployer obligation under Article 26 of Regulation (EU) 2024/1689, the specific ComplyEdge mechanism that enforces or evidences it, and an honest note where a duty is organisational and remains yours. Article 26 now applies from 2 December 2027 (status note below). What binds deployers from 2 August 2026 is Article 50 transparency, mapped in its own section.

Status: Article 26 applies from 2 December 2027, not 2 August 2026. Regulation (EU) 2026/1744 (Official Journal 24 July 2026, in force 27 July 2026) postponed the Annex III high-risk obligations, which include the Article 26 deployer duties mapped below and the Article 12 record-keeping duty, from 2 August 2026 to 2 December 2027. Annex I embedded systems move to 2 August 2028. Not postponed, and binding from 2 August 2026: Article 50 transparency, the Commission's fining powers over GPAI providers, and the investigate-and-sanction powers of national market-surveillance authorities across all 27 member states. The Article 5 prohibitions have applied since 2 February 2025. This map is published in full regardless, for two reasons: the substance of Article 26 is unchanged, and the mechanisms below are already running in production, so the deferral converts a scramble into a planning horizon. Treat any vendor or adviser still presenting Article 26 as already binding on deployers with appropriate caution.

Obligation → mechanism

Art 26Deployer obligation (in substance)ComplyEdge mechanism / evidence
26(1)Take appropriate technical and organisational measures to use the system per the provider's instructions for use.Every decision records the versioned rule bundle (bundle_id) and jurisdiction in force — a record of the configuration the system was operated under.
26(2)Assign human oversight to competent, trained, resourced natural persons.The interpretive layer is advisory-only: ambiguous cases are surfaced for a human and never auto-decided; the log records where human review was triggered. Appointing and training that person remains yours.
26(3)Paragraphs 1–2 are without prejudice to other obligations under Union or national law, and to your freedom to organise your own resources.Interpretive provision — no technical mechanism. Listed for completeness.
26(4)Ensure input data is relevant and sufficiently representative, to the extent under deployer control.Each input is recorded as a SHA-256 text_hash with agent identity and jurisdiction — an input-provenance trail without retaining raw content. The representativeness judgement remains yours.
26(5)Monitor operation per the instructions; inform the provider (Art 72) and market surveillance authority of risks; suspend use; report serious incidents (Art 73).Continuous runtime monitoring + drift detection; every blocked decision is a logged, article-cited event forming the monitoring record and the factual basis for an Art 72/73 notification.
26(6)Keep the automatically generated logs, where under your control, for an appropriate period — at least six months unless other Union/national law applies.Automatic, tamper-evident logging: timestamp, agent identity, action, text_hash, citation, and a hash-chain link per event. Retention configurable (default ≥180 days).
26(7)Employers: inform workers' representatives and affected workers before putting a high-risk system into use at the workplace.Organisational duty (worker notice). ComplyEdge documents the deployment's rule scope and purpose, giving the factual basis for the notice.
26(8)Public-authority deployers: register the system in the EU database (Art 49); do not use it if unregistered.Organisational / registration duty — outside ComplyEdge's technical scope; listed for completeness.
26(9)Where applicable, use the provider's Art 13 information to carry out the data protection impact assessment (DPIA) under GDPR Article 35.ComplyEdge supplies the decision record, input provenance and article-cited rule basis the DPIA draws on. The DPIA itself remains yours. Note: this paragraph concerns the DPIA — not the Article 27 fundamental-rights assessment (below).
26(10)For post-remote biometric identification in a criminal investigation, obtain prior judicial or administrative authorisation.Organisational / judicial-authorisation duty — outside ComplyEdge's scope. (ComplyEdge separately enforces the Art 5 prohibitions on impermissible biometric practices.)
26(11)Where an Annex III system makes, or assists in making, decisions about natural persons, inform those persons they are subject to it.Article 50 transparency rules (chatbot / synthetic-content / emotion-notice) enforce and evidence the disclosure at the point of interaction.
26(12)Cooperate with competent authorities on any action regarding the system.The tamper-evident audit export is the artifact handed to an authority — a verifiable, article-cited record (Art 12 record-keeping feeding the Annex IV technical documentation required by Art 11, which the Art 43 conformity assessment draws on).
Article 27 (FRIA) is a separate obligation. The fundamental-rights impact assessment is Article 27, not an Article 26 paragraph, and it is not the same as the GDPR Art 35 DPIA referenced in Art 26(9). ComplyEdge's Art 27 rule flags deployments lacking a FRIA and the article-cited corpus supplies the legal basis for it — the assessment itself remains yours to produce.
Article 50 (transparency) binds from 2 August 2026 — separate from Article 26. It splits by role: 50(1) chatbot disclosure and 50(2) machine-readable marking of synthetic content are provider duties (a company building its chatbot or content generator on a general-purpose AI model is the provider of that system); 50(3) emotion-recognition notice and 50(4) deepfake / AI-generated-text disclosure are deployer duties. All bind from 2 August 2026. (Omnibus grace, adopted 29 Jun 2026: systems placed on the market before that date have until 2 December 2026 for the 50(2) marking only.) Agents acting for a person. The Commission's draft transparency guidelines (May 2026) read 50(1) to cover AI agents: where an agent can make bookings, manage correspondence, negotiate or conclude contracts, or execute purchases, it should disclose both its artificial nature and the person on whose behalf it acts, so that delegated authority and accountability for the resulting action are visible. Pure machine-to-machine traffic stays outside 50(1); the duty bites when the agent reaches a person. ComplyEdge's Article 50 rules enforce and evidence these disclosures at the point of interaction.
The Article 50 Code of Practice asks you to keep an evidence record — it does not produce one. The Commission published the Article 50 Code of Practice on 10 June 2026. It is voluntary implementation support, not a new or binding obligation: it points deployers back to Regulation (EU) 2024/1689 for the legal baseline and to keeping evidence records of the transparency measures they apply. The regulation asks for records; the Code assumes you can produce them but supplies no machinery to do so — the tools built around it are browser-side checklists and marking validators that, in their own words, "do not make a legal or compliance determination." That machinery is what ComplyEdge is. Each 50(3)/50(4) deployer disclosure is enforced at runtime and written as a logged, article-cited event — event ID, timestamp, text_hash, citation and a hash-chain link — retained for an appropriate period (ComplyEdge default ≥180 days; note that the six-month floor in Art 26(6) binds only where the deployment is itself high-risk, and from 2 December 2027, so for an Article 50 deployer this retention is a product guarantee rather than a statutory minimum) and exportable as a tamper-evident record (Art 12, feeding Annex IV technical documentation under Art 11). That is the deployer-side evidence record the Code asks you to keep, generated as a by-product of operation rather than assembled after the fact.
Honest scope. ComplyEdge does not perform your organisational duties — worker notice (26(7)), registration (26(8)), competent-person assignment (26(2)), biometric authorisation (26(10)), or writing the DPIA/FRIA themselves. It enforces the runtime obligations (disclosure, prohibited-practice blocking) and produces the tamper-evident, article-cited evidence for the rest, so those duties become auditable rather than self-attested.

Why this is different from a policy PDF

For the technically-evidenceable obligations — instructions-in-force (26(1)), human oversight (26(2)), input provenance (26(4)), monitoring and incident basis (26(5)), log-keeping (26(6)), person-notice (26(11)) and authority cooperation (26(12)), plus the Art 27 FRIA-gap flag — you get a continuous, tamper-evident, article-cited record generated at runtime, not a periodic attestation. Every claim above is demonstrable from a live deployment and reproducible from our public materials.

Terms of Service · Privacy Policy · DPA · SaaS Agreement

ComplyEdge · EU AI Act Article 26 deployer one-pager · Article references follow Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (application dates). Timeline verified against primary sources 26 July 2026. Article 26 contains twelve paragraphs; sub-paragraph numbering above was verified against the consolidated text (log-keeping 26(6); worker notice 26(7); registration 26(8); DPIA 26(9); person-notice 26(11); cooperation 26(12)). Confirm with your counsel before relying on it operationally. Evidence artifacts: audit export (Art 12) and Annex IV technical-documentation mapping (Art 11, used in the Art 43 conformity assessment) available on request.