Revised 1 October 2026. The Digital Omnibus on AI entered into force on 27 July 2026. The high-risk obligations described here now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for high-risk AI embedded in products under Annex I. The prohibitions, Article 50 transparency, the general purpose AI obligations and the revised Product Liability Directive kept their dates. The timeline at the end of this page has been rewritten to match.
The Act does not use the word operator in its enacting terms. It uses deployer, and it draws the line at whoever uses an AI system under their own authority in the course of a professional activity. On this site operator and deployer are the same figure, and the obligations below attach to that figure whether the underlying model was built in house, licensed from a provider or reached through an API.
Who is an operator
Article 3(4) defines a deployer as any natural or legal person, public authority, agency or other body using an AI system under its authority, except in a purely personal, non professional activity. Two consequences follow. A sole trader running an autonomous agent to qualify sales leads is an operator. A department inside a larger group that uses an agent procured centrally is an operator for its own use, even though the contract with the provider was signed elsewhere.
Article 25 draws a second line, between providers and deployers. Putting the deployer's own name on a high-risk system, modifying it substantially, or repurposing it beyond its intended use can turn the deployer into a provider with the full upstream obligations. In practice, prompt layer customisation, retrieval augmentation or fine tuning can quietly change who is on the hook.
Article 26 obligations
Article 26 is the operational core of the deployer regime for high-risk systems. The obligations run as follows.
- Use in accordance with instructions. Take appropriate technical and organisational measures to use the system within the parameters set by the provider's instructions for use (Art. 26(1)).
- Human oversight. Assign oversight to natural persons with the necessary competence, training, authority and support (Art. 26(2)).
- Input data. To the extent the deployer controls input data, ensure it is relevant and sufficiently representative for the system's intended purpose (Art. 26(4)).
- Monitoring and incidents. Monitor operation, report serious incidents to the provider and, where applicable, to the market surveillance authority, and suspend use where monitoring reveals a risk within the meaning of Article 79 (Art. 26(5)).
- Logs. Keep automatically generated logs for a period appropriate to the intended purpose, and at least six months unless Union or national law provides otherwise (Art. 26(6)).
- Workers. Where the system is used at work, inform worker representatives and affected workers before putting it into service (Art. 26(7)).
- Public sector registration. Deployers that are public authorities register their use in the EU database before or at the time of deployment, through Article 49 (Art. 26(8)).
None of these duties can be delegated through a contract. A provider's terms of service cannot remove them, and an indemnity cannot convert a compliance failure into a recoverable commercial loss. They are owed to the supervisor and, through the supervisor, to the persons affected by the system's outputs. They apply to Annex III systems from 2 December 2027.
Fundamental rights impact assessment
Article 27 adds an obligation for a narrower class of deployers. Public bodies, private operators providing public services, and deployers of the systems in Annex III point 5(b) and 5(c), creditworthiness assessment and life and health insurance pricing, must complete a fundamental rights impact assessment before first use. It covers the process in which the system is used, the period and frequency of use, the categories of persons likely to be affected, the specific risks of harm, the human oversight in place, and the measures to take if those risks materialise, including governance and complaints.
Unlike the provider's conformity assessment under Article 43, the FRIA is a living document. It must be updated whenever one of its elements changes, and its results are notified to the market surveillance authority. It falls due with the rest of Annex III on 2 December 2027. The FRIA generator drafts the structure.
Enforcement architecture
Enforcement sits with two sets of authorities. At Union level, the AI Office, the European Artificial Intelligence Board and the Commission coordinate on general purpose AI and on cross border matters; the AI Office holds the separate fining regime for general purpose AI model providers under Article 101. In each Member State, one or more designated authorities carry out market surveillance under Chapter IX of the Act.
Operators should expect the first questions to come from supervisors they already know. Article 74(6) makes the financial supervisor the market surveillance authority for high-risk AI used by regulated financial institutions, where the use is directly connected to the financial service. Article 74(8) makes data protection authorities the market surveillance authorities for Annex III point 1 systems used for law enforcement, border management, justice and democracy, and for Annex III points 6, 7 and 8. The Act does not displace the GDPR.
Penalties
Article 99 sets the ceilings, in each case the higher of a fixed amount and a share of total worldwide annual turnover. Breach of the Article 5 prohibitions carries the highest exposure, up to EUR 35 million or 7 per cent. Most operator failures fall in the second tier, up to EUR 15 million or 3 per cent, which covers the obligations of providers and deployers of high-risk AI, including the Article 26 duties above. Supplying incorrect, incomplete or misleading information to notified bodies and competent authorities sits in a third tier, up to EUR 7.5 million or 1 per cent. For SMEs and start-ups the applicable ceiling is the lower of the two figures.
Supervisors weigh the nature, gravity and duration of the infringement, the size and turnover of the operator, any penalties already imposed by other authorities for the same facts, and the degree of cooperation. The penalty regime has applied since 2 August 2026, and only to obligations that are themselves in application.
Timeline
The Act entered into force on 1 August 2024. The prohibitions in Article 5 and the AI literacy duty in Article 4 have applied since 2 February 2025. The rules on general purpose AI models and the first layer of governance have applied since 2 August 2025. Article 50 transparency and the enforcement of everything already in application began on 2 August 2026.
The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moved the operator regime for high-risk systems listed in Annex III, together with most of the provisions relevant to deployers, to 2 December 2027, and the obligations for high-risk AI embedded in products under Union harmonisation legislation to 2 August 2028. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking duty.
This site treats 2 December 2027 as the date by which everything described above must be in place for any Annex III system already in production, and from the first day for any system deployed afterwards. The Omnibus tracker holds the provision by provision record.
References
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L, 12.7.2024.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ L, 24.7.2026.
- Article 3, definitions. In particular Article 3(4), deployer.
- Article 14, human oversight. Read together with Annex IV and Annex VIII.
- Article 25, on the reclassification of deployers as providers through substantial modification or rebranding.
- Article 26, deployer obligations. The sub paragraphs discussed above.
- Article 27, fundamental rights impact assessment for deployers of certain high-risk AI systems.
- Article 74(6) and 74(8), market surveillance authorities for financial services and for the uses assigned to data protection authorities.
- Article 79, procedures at national level for dealing with AI systems presenting a risk.
- Article 99, penalties, including the three tiers and the treatment of SMEs.
- Recitals 53 to 65, the interpretive framework for high-risk classification and operator duties.