Provider obligations
The other side of the relationship.
Your mandated EU point of contact under Article 22 of the AI Act
Using a high-risk AI system brings its own obligations. Deployers must use it as instructed, keep humans in control and keep logs; some deployers must also assess the impact on fundamental rights before first use.
| Deployer | FRIA required |
|---|---|
| Bodies governed by public law | Yes, for Annex III systems (except critical infrastructure) |
| Private entities providing public services | Yes, for Annex III systems (except critical infrastructure) |
| Deployers of credit scoring systems, or of risk assessment and pricing for life and health insurance | Yes |
| Other private deployers | No, but Article 26 still applies |
The assessment describes the process, the period and frequency of use, the categories of people affected, specific risks of harm, human oversight measures and the measures if risks materialise. The market surveillance authority is notified of the results.
A deployer that puts its name or trade mark on a high-risk system, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk, is considered a provider (Article 25) and takes on all provider obligations.
At least six months, unless other Union or national law provides otherwise.
Only private entities providing public services, and deployers of credit scoring or life and health insurance risk and pricing systems. Other private deployers follow Article 26 without a FRIA.
Yes, by putting its name or trade mark on the system, making a substantial modification, or changing the intended purpose so the system becomes high-risk (Article 25).
The other side of the relationship.
Annex III categories.
Roles along the value chain.
Note: This guide provides general information about Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), not legal advice. Last reviewed 5 October 2026.