What documentation does a high-risk AI deployer need?
In short
Deployers of high-risk AI systems are not required to build the full technical file that providers must produce, but Article 26 still imposes a concrete documentation and record-keeping burden of its own. Companies that assume “we just use the tool, the vendor handles compliance” consistently underestimate what an auditor will expect to see.
1. The provider's instructions for use (Art. 13)
Providers must supply instructions for use covering the system’s intended purpose, level of accuracy, known limitations, and human oversight measures. Deployers must obtain, retain, and demonstrably follow these instructions under Article 26(1), simply having a vendor contract is not sufficient; the instructions themselves must be on file.
2. Technical documentation from the provider (Art. 11)
While providers author the technical documentation, deployers should retain a copy or evidence of access to it, since it underpins the human oversight and monitoring duties deployers themselves must satisfy. Its absence is a common gap flagged in gap analyses.
3. Automatically generated logs (Art. 12, Art. 26(6))
High-risk systems must be technically capable of automatically recording events (logs) over their lifetime. Article 26(6) requires deployers to retain the logs their system generates for at least six months, unless other applicable law (including national or EU data protection law) requires a longer period. Log retention policy should be written down, not assumed.
4. Human oversight assignment (Art. 14, Art. 26(2))
Deployers must assign human oversight to natural persons who have the necessary competence, training, and authority, and who are given the support needed to exercise it. This means documented evidence: who is assigned, what training they received, and what authority they hold to intervene in or halt the system’s output.
5. Input data quality (Art. 26(4))
Where a deployer controls the input data, it must ensure that data is relevant and sufficiently representative in view of the system’s intended purpose. This obligation is frequently missed because it sits with the deployer, not the provider, whenever the deployer supplies its own data into a third-party system.
6. Fundamental Rights Impact Assessment (Art. 27)
Certain categories of deployer (bodies governed by public law, private operators providing public services, and deployers of high-risk systems used for creditworthiness evaluation or life/health insurance risk assessment and pricing) must complete a fundamental rights impact assessment before first use. This is a standalone document describing the deployment context, affected persons, specific risks of harm, and the oversight and complaint-handling measures in place.
7. Worker information and consultation (Art. 26(7))
Where a high-risk AI system is used in the workplace, deployers who are employers must inform workers’ representatives and affected workers that they will be subject to its use, before the system is put into use, in line with national and EU information and consultation rules.
8. Registration and cooperation (Art. 26(8)–(9))
Deployers that are public authorities, or bodies acting on their behalf, must register the use of certain high-risk systems in the relevant section of the EU database before first use. All deployers must cooperate with market surveillance authorities and provide requested documentation on demand, which is only possible if the documentation above already exists.
Taken together, a deployer’s audit-ready file consists of: provider instructions, proof of human oversight assignment and training, a log retention record, an input-data quality note, worker notification records, and (where applicable) a fundamental rights impact assessment. Missing any one of these is the single most common finding in our gap-analysis reports.
Frequently asked questions
- Do deployers of high-risk AI need their own documentation?
- Yes. Deployers don't build the provider's technical file, but Article 26 imposes their own record-keeping: the provider's instructions for use, human-oversight assignment and training records, a log-retention record, an input-data quality note, worker-notification records, and (where applicable) a fundamental rights impact assessment.
- How long must deployers keep high-risk AI system logs?
- Article 26(6) requires deployers to retain the logs their high-risk system generates for at least six months, unless other applicable law (including national or EU data protection law) requires a longer period.
- Which deployers must complete a fundamental rights impact assessment?
- Bodies governed by public law, private operators providing public services, and deployers using high-risk systems for creditworthiness evaluation or life and health insurance risk assessment and pricing must complete a fundamental rights impact assessment under Article 27 before first use.
Related guides
Find your exact documentation gaps
Our full assessment produces an audit-ready gap analysis mapped to each obligation above.
Start the free check