Compass
20 obligations for Deployer, High-risk under Annex III, 4 already in force and 16 still ahead.
Deployer (Art. 3 Nr. 4): You use an AI system under your own authority, outside a personal, non-professional activity. This role is particularly relevant to organisations using third-party AI systems in their workflows. Deployer obligations may include human oversight, checks on input data, retention of logs and informing workers. A fundamental rights impact assessment is required in certain cases. See each obligation for its conditions.
High-risk under Annex III (Art. 6 Abs. 2, Anhang III): Standalone AI systems in one of the eight areas listed in Annex III, such as employment, creditworthiness, education or critical infrastructure. Typical cases: Candidate screening, creditworthiness assessment, exam proctoring, risk assessment in life and health insurance.
2 February 2025 already applies 1 obligation
Chapters I and II: definitions, AI literacy and the prohibitions
Support the AI literacy of your staff
What the regulation requires: Providers and deployers take measures to support the development of AI literacy among their staff and other persons dealing with the operation of the systems on their behalf, taking into account prior knowledge, experience, training and the context of use.
Implementation guidance: Assess training needs based on the systems used, staff responsibilities and prior knowledge. Plan suitable training and regular refreshers. Document content and attendance, and review whether the measures adequately support the intended use.
Possible evidence: Training concept per role, attendance records, date of the most recent refresher.
Threats in the catalogue that this obligation touches:
- Overreliance Reliability and Responsible Use
- Shadow AI (Unsanctioned AI Service Use) Reliability and Responsible Use
Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 recast Art. 4. The duty to ensure AI literacy has become a duty to support its development. It is now expressly clarified that no one has to guarantee a particular level of competence for any individual. The obligation as such remains and has applied since 2 February 2025. The wording attaches to AI systems; a provider of a general-purpose AI model alone is covered in so far as they also provide or deploy systems.
i
Full text at EUR-Lex, opens in a new tab:
2 August 2026 already applies 3 obligations
General start of application: transparency obligations, conformity assessment, registration, post-market monitoring
Disclose emotion recognition and biometric categorisation
What the regulation requires: Deployers of an emotion recognition system or a biometric categorisation system must inform the persons exposed to it about its operation and process the personal data in accordance with data protection law.
Implementation guidance: Assess the permissibility of the intended use before deployment. Pay particular attention to the general prohibition on emotion recognition at work and in education, and the exceptions for medical and safety reasons.
Possible evidence: Information provided to those affected, data protection legal basis, assessment against Art. 5.
Label deepfakes and published AI texts
What the regulation requires: Deployers who generate or manipulate deepfakes with an AI system must disclose that the content has been artificially generated or manipulated. Those publishing text to inform the public on matters of public interest must also disclose this, unless the content has undergone human review with editorial responsibility.
Implementation guidance: Define how labelling is applied in each publication channel. Account for the specific rules for art and satire. For text, assess and document the conditions for an exception based on human review and editorial responsibility.
Possible evidence: Labelling rule per channel, arrangement for editorial responsibility.
Threats in the catalogue that this obligation touches:
- Disinformation Malicious Use for Attacks, Fraud and Disinformation
Explain decisions on request
What the regulation requires: Affected persons have a right to obtain a clear and meaningful explanation from the deployer where a decision is taken on the basis of the output of an Annex III system and produces legal effects or significantly and adversely affects their health, safety or fundamental rights. Systems under Annex III point 2 are excluded. The explanation must cover the role of the system in the decision-making procedure and the main elements of the decision.
Implementation guidance: Prepare understandable explanations for the relevant use cases. Use the provider’s information and define how requests for explanation are handled and adapted to the individual case.
Possible evidence: Explanation template, handling path and deadline for requests.
2 December 2027 still ahead 15 obligations
Requirements and obligations for high-risk systems under Annex III
Document the classification with reasons
What the regulation requires: Whether a system is high-risk is determined under Art. 6. Anyone relying on the exemption in Art. 6(3), because the system performs only a narrow, preparatory or supporting task, must document that assessment before the system is placed on the market or put into service.
Implementation guidance: For each system, document which Annex III areas you assessed and how you reached the classification. Record the date and responsible person. This reasoning provides the basis for identifying the applicable obligations.
Possible evidence: Classification record per system with legal reference, reasoning, date and responsible person.
Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 added paragraphs 1a to 1c to Art. 6. Systems used exclusively for non-safety-relevant aspects such as user assistance, performance optimisation or usability are not considered safety components. Conversely, a system remains a safety component where its failure or malfunction would endanger health and safety.
i
Full text at EUR-Lex, opens in a new tab:
Check whether you become a provider
What the regulation requires: Anyone who puts their name or trademark on a high-risk system already placed on the market, makes a substantial modification to it, or changes its intended purpose such that it becomes high-risk, is considered the provider of that system and bears the full provider obligations.
Implementation guidance: Before marketing a system under your own name, substantially modifying it or changing its intended purpose, assess whether your organisation assumes the provider role. Account for the resulting obligations during planning.
Possible evidence: Record for each modification: nature of the change, assessment under Art. 25(1), outcome.
Use the system in line with the instructions
What the regulation requires: Deployers take appropriate technical and organisational measures to ensure they use the systems in accordance with the instructions for use accompanying them.
Implementation guidance: Compare the instructions for use with the planned deployment before introduction. Where use differs from the intended purpose, assess whether the legal classification or your organisation’s role changes.
Possible evidence: Record comparing the intended purpose with the planned use, internal usage rule.
Assign human oversight to suitable people
What the regulation requires: Human oversight must be assigned to natural persons who have the necessary competence, training and authority, and who receive the necessary support.
Implementation guidance: Appoint the persons responsible for oversight and document their intervention powers. Ensure they have sufficient knowledge, support and authority to intervene effectively when needed.
Possible evidence: Designation of the persons exercising oversight, evidence of competence, written authority to intervene.
Ensure suitable input data
What the regulation requires: In so far as the deployer exercises control over the input data, they must ensure that it is relevant and sufficiently representative in view of the intended purpose of the system.
Implementation guidance: Assess the suitability and representativeness of input data under your control. Pay particular attention to potential bias in your own datasets, such as personnel records or earlier decisions.
Possible evidence: Description of the input data, assessment of suitability and representativeness.
Monitor operation and suspend on risk
What the regulation requires: Deployers monitor operation on the basis of the instructions for use. Where they identify a risk within the meaning of Art. 79(1), they must immediately inform the provider or distributor and the market surveillance authority and suspend use. In the event of a serious incident, they must inform the provider first, then the importer or distributor and the authority.
Implementation guidance: Define criteria for identifying risks and initiating action. Determine who decides to suspend operation and how the provider and competent authorities are informed.
Possible evidence: Monitoring rule with thresholds, escalation path, documented notifications.
Threats in the catalogue that this obligation touches:
- Adversarial Inputs Attacks on the Running Model and Service
- Model Denial of Service Attacks on the Running Model and Service
- Cost Harvesting / Repurposing Attacks on the Running Model and Service
- Application Denial of Service Attacks on the Running Model and Service
- Agentic AI / Autonomous Agents Agentic and Autonomous AI
- Model Drift & Degradation Reliability and Responsible Use
Keep the logs for at least six months
What the regulation requires: In so far as the automatically generated logs are under the control of the deployer, they must be kept for at least six months, unless other law provides otherwise.
Implementation guidance: Clarify with the provider who stores the logs and how you can access them. Align technical settings and contractual arrangements with the required retention period, particularly for cloud services.
Possible evidence: Contractual assurance of log access, documented retention period.
Inform workers and their representatives in advance
What the regulation requires: Employers putting a high-risk system into service at the workplace must inform workers representatives and the affected workers in advance that they will be subject to the use of the system.
Implementation guidance: Plan to inform affected workers and their representatives before putting the system into service. Also assess the applicable participation rights under national employment law.
Possible evidence: Information notice with date, evidence of involvement of the representative body.
Register in the EU database as a public authority
What the regulation requires: Deployers that are public authorities or Union institutions, bodies, offices or agencies must register in the EU database before putting into service or using an Annex III system and must register the system there; systems under Annex III point 2, that is safety components of critical infrastructure, are excluded. Union institutions and bodies must not use an unregistered system under Art. 26(8) and must inform the provider or distributor.
Implementation guidance: Check the required EU database entries before putting the system into service. Resolve missing or incomplete provider information during procurement and document the result.
Possible evidence: Registration entry, verification of the provider entry before going live.
Use the information for the data protection impact assessment
What the regulation requires: Where applicable, deployers use the information received under Art. 13 to comply with their obligation to carry out a data protection impact assessment under Art. 35 GDPR or Art. 27 of Directive (EU) 2016/680.
Implementation guidance: Include the relevant provider information in the data protection impact assessment. Link the documents clearly, particularly information on performance limitations and known failure modes.
Possible evidence: Data protection impact assessment referencing the provider information.
Obtain authorisation for post-remote biometric identification
What the regulation requires: Anyone using a post-remote biometric identification system in the course of an investigation must request authorisation from a judicial or administrative authority in advance or without undue delay, and at the latest within 48 hours. If authorisation is refused, use must stop immediately and the data must be deleted. Every use is documented, and annual reports on use must be submitted to the market surveillance authority and the data protection authority.
Implementation guidance: Set up an authorisation process that accounts for the applicable deadlines outside regular working hours. For each use, document the specific link to the investigation, the request, the decision and subsequent procedural steps.
Possible evidence: Authorisation requests and decisions, entry in the case file, annual report to the market surveillance and data protection authorities.
Amendment by Reg. 2026/1744: Use without any link to a criminal offence, criminal proceedings, a genuine threat or the search for a missing person is excluded. An adverse decision based solely on the output of the system is not permitted.
Inform affected persons about the use
What the regulation requires: Deployers of an Annex III system that makes or assists in making decisions about natural persons must inform those persons that they are subject to the use of the system.
Implementation guidance: Place the notice where affected persons can see it in the relevant procedure, such as a job or credit application. Assess whether general privacy information is sufficient or targeted information is needed.
Possible evidence: Wording and placement of the notice per process.
Cooperate with the authorities
What the regulation requires: On a reasoned request from the competent authorities, all information and documentation necessary to demonstrate conformity must be provided, in one of the official languages of the Union.
Implementation guidance: Clarify which language the competent authority requires for the documents. Agree with suppliers on timely provision of the required information and translations.
Possible evidence: Named point of contact, complete documentation in the required language.
Carry out the fundamental rights impact assessment
What the regulation requires: Before putting the system into service, certain deployers must carry out a fundamental rights impact assessment: bodies governed by public law, private entities providing public services, and deployers of systems under Annex III point 5(b) and (c), that is creditworthiness assessment and risk assessment and pricing in life and health insurance. Systems under Annex III point 2 are excluded. It must describe the processes, the period and frequency of use, the categories of persons affected, the risks of harm, oversight measures and remedies.
Implementation guidance: First assess whether your organisation and the intended use fall within the obligation. Plan the assessment and the required notification to the competent market surveillance authority before putting the system into service.
Possible evidence: Completed fundamental rights impact assessment, notification to the market surveillance authority.
Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 reduced duplication: where a data protection impact assessment already covers the same points, its relevant sections may be incorporated by reference or as an extract. The AI Office is to develop a model questionnaire for this, including as an automated tool.
i
Full text at EUR-Lex, opens in a new tab:
Legacy systems are caught only on substantial change
What the regulation requires: For high-risk systems placed on the market or put into service before Chapter III becomes applicable, the regulation applies only if they are subsequently significantly changed in their design. The prohibitions in Art. 5 remain unaffected.
Implementation guidance: For each legacy system, document when it was placed on the market or put into service and its design at that time. Record subsequent changes so the applicability of the transition rule can be assessed.
Possible evidence: Inventory with a reference date per system and a change history.
Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 adjusted the reference point: what matters now is the start of application of Chapter III under Art. 113, that is 2 December 2027 for Annex III and 2 August 2028 for Annex I.
i
Full text at EUR-Lex, opens in a new tab:
2 August 2030 still ahead 1 obligation
Legacy high-risk systems used by public authorities
Bring public authority systems into line by 2030
What the regulation requires: Providers and deployers of high-risk systems intended to be used by public authorities must in any event take the necessary steps to comply with the requirements and obligations of the regulation by 2 August 2030.
Implementation guidance: Identify the affected legacy systems and prepare an implementation plan for 2 August 2030. Account for required changes, procurement procedures and coordination with providers.
Possible evidence: Implementation plan per legacy system with milestones up to 2030.
No separate obligations are recorded in the compass for this combination. Also assess general requirements, particularly AI literacy and prohibited practices, where applicable to your role.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.