A high-risk AI system has to meet seven requirements, set out in Chapter III, Section 2 of the EU AI Act, Articles 9 to 15: a risk management system, data governance, technical documentation, automatic logging, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity. Article 8 says the system must comply with all of them, taking into account its intended purpose and the state of the art. Those requirements are properties of the system. The duties that prove them sit in Section 3: the provider runs a quality management system, keeps the file for 10 years, passes a conformity assessment, signs a declaration, affixes the CE marking and registers. The deployer uses the system as instructed, assigns human oversight, and keeps the logs.
Two things changed in 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the dates: Sections 1, 2 and 3 of Chapter III now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. It also amended several of the requirements themselves, which is where this guide differs from most of what is on page one. Whether a system is high risk at all is a separate question, answered in our guide to Article 6 and the Annex III list.
| Requirement | What the system must do | Article |
|---|---|---|
| Risk management | Run a documented, iterative risk process across the lifecycle, and test before release against predefined metrics. | Art. 9 |
| Data governance | Train, validate and test on data sets managed for relevance, representativeness, errors and bias. | Art. 10, Art. 4a |
| Technical documentation | Hold an Annex IV file, drawn up before release and kept up to date. | Art. 11 |
| Record keeping | Technically allow automatic logging of events over the system's lifetime. | Art. 12 |
| Transparency | Ship instructions for use that let deployers interpret and use the output. | Art. 13 |
| Human oversight | Be designed so natural persons can monitor, override and stop it. | Art. 14 |
| Accuracy, robustness, cybersecurity | Perform consistently, declare accuracy metrics, resist manipulation. | Art. 15 |
What does the risk management system require?
Article 9 requires a risk management system to be established, implemented, documented and maintained. It is a continuous iterative process planned and run throughout the entire lifecycle, with four steps: identify and analyse the known and reasonably foreseeable risks to health, safety or fundamental rights; estimate and evaluate the risks under intended use and reasonably foreseeable misuse; evaluate other risks from post-market monitoring data; and adopt targeted measures. Residual risk, per hazard and overall, has to be judged acceptable.
Testing is part of the article, not an extra. Article 9(8) requires testing at any appropriate point in development and in any event before the system is placed on the market or put into service, against prior defined metrics and probabilistic thresholds appropriate to the intended purpose. Article 9(9) asks you to consider whether the system is likely to affect people under 18 and other vulnerable groups. And Article 9(10) lets a provider already subject to internal risk management rules under other Union law, a bank for example, fold these steps into those procedures.
What are the data governance requirements, after the Omnibus?
Article 10 applies to systems trained on data. Training, validation and testing data sets must be subject to governance practices covering design choices, collection and origin, preparation, assumptions, availability and suitability, examination for biases, measures to detect, prevent and mitigate them, and data gaps. The sets must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose.
The Omnibus changed this article in three ways. Paragraph 5, which allowed special categories of personal data to be processed for bias detection, was deleted and replaced by a new Article 4a, with six conditions including that synthetic or anonymised data would not do, that the data is not accessed by other parties, and that it is deleted once the bias is corrected. Paragraph 1 now cross refers to Article 4a(1). And paragraph 6 now says that for systems not trained on data, the quality criteria apply only to the testing data sets.
What goes into the technical documentation and logs?
Article 11 requires technical documentation to be drawn up before the system is placed on the market or put into service, kept up to date, and to contain at a minimum the elements in Annex IV: a general description, a detailed description of the elements and the development process, monitoring and control, performance metrics, the risk management system, changes over the lifecycle, the standards applied, the EU declaration of conformity, and the post-market monitoring plan. For a product under Annex I Section A legislation, Article 11(2) requires a single set of documentation covering both regimes.
As amended, Article 11(1) extends the simplified route to small mid-cap enterprises. SMEs, including start-ups, and SMCs may provide the Annex IV elements in a simplified manner using a Commission form, and notified bodies must accept that form. Article 12 is the logging requirement: the system must technically allow for the automatic recording of events over its lifetime, sufficient to identify risk situations and substantial modifications, support post-market monitoring, and let deployers monitor operation.
What do transparency, oversight and robustness mean in practice?
Instructions for use, Article 13
The system must be transparent enough for deployers to interpret its output and use it appropriately, and it must come with instructions for use. Article 13(3) lists their minimum content: the provider's identity, the intended purpose, the tested level of accuracy, robustness and cybersecurity, known circumstances that could create risk, where relevant the performance on specific groups, any changes pre-determined at the initial conformity assessment, the human oversight measures, the computational resources and expected lifetime, and how to collect and interpret the logs.
Human oversight, Article 14
The system must be designed so natural persons can oversee it effectively while it is in use. The people assigned must be able to understand its capacities and limits, stay aware of automation bias, interpret the output, decide not to use it or override it, and interrupt it through a stop button or similar procedure that halts it in a safe state. For remote biometric identification under Annex III point 1(a), Article 14(5) requires separate verification by at least two competent people before acting on a match, with a law enforcement and border exception where Union or national law considers it disproportionate.
Accuracy, robustness and cybersecurity, Article 15
The system must achieve an appropriate level of all three and perform consistently throughout its lifecycle. Accuracy metrics go in the instructions for use. Systems that keep learning after release must be built to limit biased feedback loops. The cybersecurity measures must, where appropriate, address data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws.

What must the provider do beyond the requirements?
Article 16 lists twelve provider obligations, from (a) to (l). The ones that generate work are a quality management system under Article 17, conformity assessment under Article 43 before the system is placed on the market, an EU declaration of conformity under Article 47, the CE marking under Article 48, registration under Article 49(1), corrective action under Article 20, and accessibility under Directives (EU) 2016/2102 and (EU) 2019/882. Article 17 lists thirteen aspects the quality management system must cover. As amended, Article 17(2) says implementation is proportionate to the size of the organisation, naming SMEs and SMCs, while keeping the rigour needed for compliance.
Which conformity assessment applies depends on the system. For Annex III points 2 to 8, Article 43(2) prescribes internal control under Annex VI, with no notified body. For biometrics under point 1, a provider that applied harmonised standards or common specifications may choose internal control or a notified body; without them, Annex VII and a notified body. For Annex I Section A products, the replaced Article 43(3) sends you through the sectoral procedure, with the Section 2 requirements assessed as part of it. How that plays out for credit scoring and insurance pricing is in our guide to conformity assessment for high-risk financial AI.
| Duty | What the text fixes | Article |
|---|---|---|
| Keep the documentation | Technical file, QMS documents, notified body decisions and the declaration, for 10 years after release. | Art. 18, Art. 47(1) |
| Keep the logs | Logs under your control, for a period appropriate to the purpose and at least six months. | Art. 19; Art. 26(6) for deployers |
| Monitor after release | A post-market monitoring system based on a plan that forms part of the Annex IV file. | Art. 72 |
| Report serious incidents | No later than 15 days after becoming aware; 2 days for a widespread infringement or a critical infrastructure disruption; 10 days where a person dies. | Art. 73(2) to (4) |
Financial institutions get two concessions. Under Articles 18(3) and 19(2), providers subject to internal governance rules under Union financial services law keep the technical documentation and logs as part of the documentation those rules already require. On the post-market side, the Commission's guidance and template for the monitoring plan are now due by 2 September 2027, under Article 72(3) as replaced; the original text asked for an implementing act by February 2026.
What does a deployer owe?
Article 26 is shorter but not light. A deployer must use the system in accordance with the instructions for use, assign human oversight to people with the necessary competence, training, authority and support, make sure input data it controls is relevant and sufficiently representative, monitor operation, and suspend use and inform the provider and market surveillance authority where the system presents a risk. It keeps the logs under its control for at least six months. Employers must inform workers' representatives and affected workers before using a high-risk system at work. Under Article 26(11), deployers of Annex III systems that make or assist decisions about natural persons must tell those people, and Article 86 gives them a right to an explanation of the role the system played. Deployers that are financial institutions meet the monitoring duty by complying with their internal governance rules.
Some deployers also owe a fundamental rights impact assessment under Article 27, before first use: bodies governed by public law, private entities providing public services, and deployers of Annex III point 5(b) and (c) systems, which are credit scoring and life and health insurance risk assessment and pricing. The Omnibus lets that assessment cross refer to an existing data protection impact assessment, and requires the AI Office to provide a questionnaire template. If you are unsure which role you hold, our guide to provider versus deployer works through Articles 3 and 25.
When do these requirements apply?
Chapter III Sections 1, 2 and 3, which hold the classification rules, the requirements and the provider and deployer obligations, apply from 2 December 2027 for systems classified under Article 6(2) and Annex III, and from 2 August 2028 for systems under Article 6(1) and Annex I. These are flat dates in Article 113 as amended by Regulation (EU) 2026/1744, adopted on 8 July 2026 and in force since 27 July 2026. Systems already on the market before those dates are caught only on a significant change in design, under Article 111(2), except that providers and deployers of systems intended for public authorities must comply by 2 August 2030. Every date is set out in our guide to EU AI Act deadlines.
Non-compliance with the Article 16 provider obligations or the Article 26 deployer obligations carries fines of up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher, under Article 99(4). For SMEs, and since the Omnibus for SMCs, the lower of the two applies. The detail is in EU AI Act penalties and fines.
What the other results get wrong
Two of the page one results we read for this query were written before the Omnibus existed. A vendor guide dated 25 August 2025 gives 2 August 2026 as the date all high-risk systems must comply with Articles 9 to 49, and 2 August 2027 for systems embedded in regulated products. A law firm guide from February 2024 predates even the published Act. Neither is wrong about the requirements as they then stood, but both are wrong about the calendar you now face.
The second gap is the text itself. Summaries written from the 2024 text still describe Article 10(5) as the legal basis for processing sensitive data to detect bias. That paragraph no longer exists; Article 4a replaced it with tighter conditions. The simplified documentation route and the proportionality clause in the quality management system now reach small mid-caps, not only SMEs. If your programme was scoped from a 2024 checklist, re-read Articles 4a, 10, 11, 17 and 27 before you build on it.
Where does each system stand?
Fill this in per high-risk system, not per company. A blank cell is the next piece of work.
| Question | Your answer | Why it matters |
|---|---|---|
| Are you the provider, the deployer, or both for this system? | Section 3 splits the duties by role, and Article 25 can move you between them. | |
| Which Annex III point or Annex I act makes it high risk? | Decides the date, 2 December 2027 or 2 August 2028, and the conformity route. | |
| Where is the risk register, with residual risk judged per hazard? | Article 9(5) requires residual risk to be acceptable. | |
| Do you process special category data to detect bias, and on which Article 4a condition? | Article 10(5) no longer exists; Article 4a sets the conditions now. | |
| Which Annex IV sections are drafted, and who keeps them for 10 years? | Articles 11 and 18. | |
| Who can override or stop the system, and are they trained to? | Article 14(4) for the design, Article 26(2) for the deployer. | |
| How long are logs kept, and who controls them? | At least six months under Articles 19 and 26(6). | |
| Who reports a serious incident, and can they do it within two days? | Article 73 sets 15, 10 and 2 day limits. |
If most of the column is empty, start with the inventory: our guide to EU AI Act policies and documentation lists what each role has to hold. The free compliance check gives you a baseline, and the EU AI Act framework page shows how systems, classification, technical documentation and post-market monitoring are tracked.

Frequently asked questions
What are the requirements for high-risk AI systems?
Articles 9 to 15: risk management, data governance, technical documentation, record keeping, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity. Article 8 makes compliance with all of them mandatory.
Do the requirements apply from 2 August 2026?
No. Since Regulation (EU) 2026/1744 they apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems.
Does every high-risk system need a notified body?
No. Annex III points 2 to 8 use internal control under Annex VI. Biometrics under point 1 can use internal control only where harmonised standards or common specifications were applied. Annex I products follow their sectoral procedure.
How long must logs be kept?
For a period appropriate to the intended purpose and at least six months, unless other Union or national law, in particular data protection law, provides otherwise. That applies to providers under Article 19 and deployers under Article 26(6).
Are the requirements lighter for small companies?
The requirements are the same; the paperwork is lighter. SMEs and SMCs may use a simplified technical documentation form, the quality management system is proportionate to organisation size, and fines are capped at the lower of the two amounts.
Primary sources
Requirements and obligations above are taken from Articles 8 to 20, 26, 27, 43, 47 to 49, 72, 73, 86, 99, 111 and 113 and Annex IV of Regulation (EU) 2024/1689, read with the amendments to Articles 4a, 10, 11, 17, 27, 43(3), 72(3), 99, 111 and 113 made by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026. Consolidated texts are documentation tools; the Official Journal versions are authentic. Confirm the current text before relying on a specific provision.




