Your mandated EU point of contact under Article 22 of the AI Act

Deployer obligations and the FRIA

Using a high-risk AI system brings its own obligations. Deployers must use it as instructed, keep humans in control and keep logs; some deployers must also assess the impact on fundamental rights before first use.

Article 26 AI Act Article 27 FRIA Logs kept at least 6 months Same dates as provider duties

Article 26 in practice

Who needs a FRIA (Article 27)

DeployerFRIA required
Bodies governed by public lawYes, for Annex III systems (except critical infrastructure)
Private entities providing public servicesYes, for Annex III systems (except critical infrastructure)
Deployers of credit scoring systems, or of risk assessment and pricing for life and health insuranceYes
Other private deployersNo, but Article 26 still applies

The assessment describes the process, the period and frequency of use, the categories of people affected, specific risks of harm, human oversight measures and the measures if risks materialise. The market surveillance authority is notified of the results.

When a deployer becomes a provider

A deployer that puts its name or trade mark on a high-risk system, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk, is considered a provider (Article 25) and takes on all provider obligations.

Frequently asked questions

How long must deployers keep logs?

At least six months, unless other Union or national law provides otherwise.

Do private companies need a fundamental rights impact assessment?

Only private entities providing public services, and deployers of credit scoring or life and health insurance risk and pricing systems. Other private deployers follow Article 26 without a FRIA.

Can a deployer become a provider?

Yes, by putting its name or trade mark on the system, making a substantial modification, or changing the intended purpose so the system becomes high-risk (Article 25).

Related

Note: This guide provides general information about Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), not legal advice. Last reviewed 5 October 2026.