EU AI Act
What must a provider of a high-risk AI system do under the EU AI Act?

The provider carries most of the EU AI Act's weight for a high-risk system. It must build the system to the requirements in Section 2 of Chapter III, run a quality management system, take the system through conformity assessment, sign a declaration, affix the CE marking, register it, and keep watching it once it is on the market. After the July 2026 amendment, these duties apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
Quotations are from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026 on 2 October 2026. This is not legal advice.
What must the system itself meet?
Section 2 of Chapter III sets the requirements every high-risk system must meet, and Article 16(a) makes the provider responsible for meeting them:
| Article | Requirement |
|---|---|
| 9 | A risk management system, run as a continuous process across the lifecycle |
| 10 | Data governance for training, validation and testing data |
| 11 | Technical documentation, with at least the Annex IV elements, drawn up before the system goes on the market |
| 12 | Automatic recording of events over the system's lifetime |
| 13 | Transparency, including instructions for use for deployers |
| 14 | Human oversight designed into the system |
| 15 | Accuracy, robustness and cybersecurity |
Our guides to AI risk assessment under Article 9 and technical documentation under Article 11 go deeper on the two that take the most work.
What are the 12 Article 16 obligations?
Article 16 says providers of high-risk AI systems "shall":
- ensure the system complies with Section 2;
- show their name, registered trade name or trade mark, and contact address on the system, its packaging or its documentation;
- have a quality management system that complies with Article 17;
- keep the documentation in Article 18;
- keep the logs under their control, as in Article 19;
- ensure the system undergoes the conformity assessment in Article 43 "prior to its being placed on the market or put into service";
- draw up an EU declaration of conformity under Article 47;
- affix the CE marking under Article 48;
- register under Article 49(1);
- take corrective action and provide information under Article 20;
- demonstrate conformity on a reasoned request from a national competent authority; and
- meet the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882.
AI Act provider checklist
Provision,What it requires (summary),Status,Owner,Evidence (document or record),Notes Article 9,Risk management system across the lifecycle,,,, Article 10,"Data governance for training, validation and testing data",,,, Article 11 and Annex IV,Technical documentation before placing on the market (simplified form for SMEs and SMCs),,,, Article 12,Automatic recording of events (logging),,,, Article 13,Transparency and instructions for use for deployers,,,, Article 14,Human oversight designed in,,,, Article 15,"Accuracy, robustness and cybersecurity",,,, Article 16(b),"Name, trade name or trade mark and contact address on the system, packaging or documentation",,,, Article 16(c) and 17,Quality management system,,,, Article 16(d) and 18,Keep the documentation,,,, Article 16(e) and 19,Keep logs under your control,,,, Article 16(f) and 43,Conformity assessment before placing on the market,,,, Article 16(g) and 47,EU declaration of conformity,,,, Article 16(h) and 48,CE marking,,,, Article 16(i) and 49(1),Registration in the EU database,,,, Article 16(j) and 20,Corrective actions and information,,,, Article 16(k),Demonstrate conformity on request of a national competent authority,,,, Article 16(l),Accessibility requirements (Directives (EU) 2016/2102 and 2019/882),,,, Article 72,Post-market monitoring system and plan,,,, Article 73,Serious incident reporting,,,, "EU AI Act, as amended by Regulation (EU) 2026/1744: Chapter III Sections 1 to 3 apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Template from credentialpress.com/guides/eu-ai-act-provider-obligations. Not legal advice.",,,,,
Which conformity assessment route applies?
Article 43 sets three routes. For Annex III, points 2 to 8, which include employment, education, essential services and law enforcement, providers "shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body". For biometric systems in Annex III, point 1, the provider may choose internal control only if it has applied harmonised standards or common specifications in full; otherwise a notified body assesses the quality management system and technical documentation under Annex VII. For products under Section A of Annex I, the provider follows the conformity assessment in that product law, with the AI Act's requirements assessed as part of it.
What continues after the system is on the market?
Post-market monitoring under Article 72, based on a plan that is part of the technical documentation; since July 2026, the Commission must adopt guidance and a template for that plan by 2 September 2027. Serious incident reporting under Article 73, which our incident reporting guide covers. And cooperation with the original or new provider in the value chain under Article 25, which the July 2026 amendment spelled out.
What relief exists for smaller providers?
Under Article 11(1), SMEs, including start-ups, and small mid-cap enterprises may provide the Annex IV technical documentation in a simplified form the Commission will establish, and notified bodies must accept it. Under Article 63(1), SMEs without partner or linked enterprises may meet certain quality management system elements in a simplified manner. The fine caps for SMEs and SMCs are the lower of the amount and the percentage. Our guide to the July 2026 changes has the detail.
Can ISO/IEC 42001 help a provider?
In our reading it overlaps with the Act's quality management and risk management duties, but the AI Act's own requirements still have to be met and evidenced. Our ISO/IEC 42001 explainer covers what certification does and does not give you under Article 40.
What should a provider do this quarter?
Confirm which of your systems are high-risk and under which route, then use the checklist to assign an owner and a document to each requirement and obligation, with December 2027 or August 2028 as the deadline. For the people who will run the program, the AI Governance Framework handbook traces each obligation to its Article, written to the 2024 text, and the ISO/IEC 42001 Lead Implementer book covers the management system. Credential Press is independent of the EU institutions.
Frequently asked questions
Who is a provider under the EU AI Act?
Article 3(3) makes a provider the person or body that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Under Article 25, a deployer or other party that rebrands, substantially modifies or repurposes a high-risk system becomes its provider.
What are the requirements for a high-risk AI system?
Section 2 of Chapter III, Articles 8 to 15: a risk management system, data governance, technical documentation, record-keeping, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity.
Does a high-risk AI system need a notified body?
Usually not for Annex III. Article 43(2) puts Annex III points 2 to 8 on internal control under Annex VI, without a notified body. Biometric systems in point 1 need a notified body unless harmonised standards or common specifications were fully applied, and Annex I products follow their sector law's procedure.
When do the provider obligations apply?
From 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, after Regulation (EU) 2026/1744 moved the dates in July 2026.
Do small companies get any relief?
Some. SMEs and small mid-cap enterprises can use a simplified technical documentation form under Article 11(1), and SMEs without partner or linked enterprises can meet parts of the quality management system in a simplified way under Article 63(1).
What is the fine for breaching provider obligations?
Article 99(4)(a) puts the Article 16 obligations in the middle tier: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, with lower caps for SMEs and small mid-caps.
EU AI Act: test yourself in five minutes
Which books help providers build the system?

Building one that survives the EU AI Act. 22 chapters, 384 pages.

ISO 42001 Lead Implementer Exam Guide
PECB Certified ISO/IEC 42001 Lead Implementer. 12 chapters, 387 pages.
Sources
Every quotation above was read on 2 October 2026 through the EU Publications Office.
- Regulation (EU) 2024/1689 (AI Act), Articles 3, 9 to 20, 25, 43, 47 to 49, 63, 72, 73 and 99
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Regulation (EU) 2024/1689, consolidated text dated 27 July 2026 (no legal effect)
Credential Press is independent of the European Commission, ISO and IEC. This is not legal advice.