Chapter 5 of 11
Obligations for Providers: Building Compliant High-Risk AI
If your organization develops or places AI systems on the EU market, this module turns the dense list of provider obligations into a practical checklist for product, engineering, and compliance teams.
Orienting Yourself: Providers, High-Risk, and the AI Act
Zooming In: Provider Duties
This module focuses on what the EU AI Act requires from providers of high-risk AI systems. As of mid-2026, the core obligations are stable and define how you must design, document, and monitor these systems.
Who Counts as a Provider?
A provider is anyone who develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark. That includes startups, big tech, consultancies, and research labs.
Examples of Providers
You are likely a provider if you: build a credit-scoring model sold to EU banks, develop an AI-based medical device with a CE mark, or license a recruitment screening system to EU employers under your brand.
Your Compliance Goal
Assuming you have already classified a system as high-risk, your goal now is to turn the AI Act’s obligations into a practical provider checklist that fits into your AI product lifecycle.
The Big Obligation List
Key duties: risk management, data governance, technical documentation, logging, transparency and instructions for use, human oversight, accuracy and cybersecurity, conformity assessment and CE marking, post-market monitoring, and use of standards.
Step 1 – Build a Risk Management System Around the AI Lifecycle
Risk Management: The Core Requirement
Providers of high-risk AI must operate a continuous risk management system that covers the entire lifecycle. It is about identifying, analyzing, and reducing risks to health, safety, and fundamental rights.
1. Identify Risks
Map where the AI can cause harm: incorrect outputs, unfair or discriminatory outcomes, security failures, and misuse. Consider both intended use and reasonably foreseeable misuse, including impacts on fundamental rights.
2. Analyze and Prioritize
Estimate the severity and likelihood of each risk. Use this to prioritize your efforts, focusing on high-severity, plausible risk scenarios rather than minor or extremely unlikely issues.
3. Control and Reduce Risks
Apply technical controls (thresholds, robustness tests), organizational controls (dual review, user training), and design changes (clearer UI, restricted features) to bring risks down to an acceptable level.
4–5. Residual Risk and Updating
Check whether residual risk is acceptable; if not, iterate or narrow the system’s purpose. Keep the risk system updated when models, data, or deployment contexts change, using real-world feedback.
Key Artifacts
Maintain a Risk Management Plan, a Risk Register, and evidence of testing and validation. These documents later support your technical documentation and conformity assessment for CE marking.
Example – Risk Management for an AI Recruitment Screener
Scenario: AI Recruitment Screener
You provide a high-risk AI tool that pre-ranks job candidates for EU employers. This use case is close to real deployments and highlights discrimination, transparency, and human oversight risks.
Identifying Key Risks
Risks include discrimination against protected groups, opaque rejections without reasons, privacy issues from sensitive data, and recruiters over-relying on AI scores instead of exercising judgment.
Analyzing and Prioritizing
Discrimination has high severity and non-trivial likelihood, so it becomes a top priority. Over-reliance is also important, especially if the interface encourages users to treat scores as final.
Implementing Controls
You apply fairness-aware training, run bias tests, design the UI to show scores as recommendations, require human justifications for rejections, and provide guidance on lawful and non-discriminatory use.
Residual Risk and Monitoring
After controls, you document remaining risks, such as lingering bias from historical data, and mitigate them with quarterly fairness audits, complaint review, and risk reviews after retraining.
Step 2 – Data Governance and Data Quality Obligations
Data Governance: The Foundation
High-risk AI must be trained, validated, and tested on data that is relevant, representative where needed, and as free of errors as possible. This is central to both safety and fairness.
1. Plan Your Data Strategy
Clearly document which datasets you use for training, validation, and testing, and justify why they are appropriate for the system’s intended purpose and target population.
2. Check Quality and Integrity
Run systematic checks for missing values, noisy labels, and obvious errors. Use version control and data lineage tracking so you can always trace which data built which model.
3. Bias and Representativeness
Assess whether certain groups are under-represented or misrepresented. Where lawful and appropriate, use rebalancing or sampling strategies to reduce harmful bias in downstream model behavior.
4. Lawful Use and Privacy
Ensure compliance with GDPR and national rules. Minimize personal data, handle sensitive attributes carefully, and document your legal basis and safeguards for any personal data processing.
5. Document Everything
Record your data sources, preprocessing, and known limitations. These records are critical for conformity assessment, audits, and incident investigations involving your AI system.
Step 3 – Technical Documentation and Logging: Your Evidence Pack
Technical Documentation: Your Evidence Pack
Technical documentation is the structured evidence that your high-risk AI complies with the AI Act. You must have it ready before placing the system on the EU market or putting it into service.
What Goes In
Include: system description and architecture, risk management records, data governance details, model and training information, human oversight design, cybersecurity measures, and your post-market monitoring plan.
Proportional Detail
The level of technical detail should be proportionate. You do not have to publish trade secrets, but you must provide enough information for regulators or notified bodies to assess compliance.
Logging by Design
High-risk AI must be designed to support automatic logging of relevant events during operation. This enables later analysis of how the system behaved in real-world use.
What to Log
Typical logs: key inputs and outputs, decision paths or scores, system errors, security events, and human overrides. Logs must be secure and respect data protection rules.
Why It Matters
Without solid documentation and logging, it is difficult to pass conformity assessment, investigate incidents, or demonstrate accountability to regulators, customers, and affected people.
Step 4 – Transparency, Instructions for Use, and Human Oversight
Transparency and Human Oversight
High-risk AI must be understandable and controllable by humans. The AI Act requires transparent instructions for use and system designs that enable effective human oversight.
Clear Instructions for Use
You must explain the intended purpose, limitations, accuracy and robustness levels, input data requirements, known risks, and prohibited uses in language that non-expert users can follow.
Designing Oversight Roles
Specify who oversees the AI in practice: for example, a doctor, HR manager, or risk officer. Clarify their responsibilities and what they should do when they disagree with the AI.
Control Mechanisms
Provide ways to override, pause, or stop the AI, and define escalation paths for uncertain or high-stakes cases. Oversight must be more than a theoretical possibility.
Understandable Outputs
Present outputs in interpretable formats, with confidence scores or explanations where feasible. This helps humans challenge or correct the AI when something looks wrong.
Training and Avoiding Over-Reliance
Inform deployers that oversight personnel need training. Good design and documentation should help humans detect anomalies and avoid blindly following AI recommendations.
Step 5 – Robustness, Accuracy, and Cybersecurity by Design
Accuracy, Robustness, Cybersecurity
High-risk AI must reach appropriate levels of accuracy, robustness, and cybersecurity. These qualities are not optional add-ons; they are core legal requirements under the AI Act.
Accuracy and Metrics
Define relevant performance metrics and minimum thresholds. Test on independent data and across relevant subgroups to ensure the system performs consistently where it is intended to be used.
Robustness to Real-World Conditions
Evaluate how the system handles noisy, incomplete, or slightly unusual inputs. Provide fallback or safe modes when the system is pushed outside its validated operating domain.
Cybersecurity Threats
Secure your data, models, and infrastructure against attacks like data poisoning, model tampering, and unauthorized access. These threats can directly undermine safety and compliance.
Connect Back to Risk Management
Document your accuracy, robustness, and cybersecurity measures in the risk management file and technical documentation, and monitor them over time in your post-market processes.
Step 6 – Conformity Assessment and CE Marking
Conformity Assessment and CE Marking
High-risk AI systems must undergo a conformity assessment before being placed on the EU market. If they comply, providers issue an EU declaration of conformity and affix the CE marking.
Assessment Routes
Depending on the system and sector, you may follow internal control (self-assessment) or involve a notified body, an independent organization that checks compliance for certain high-risk cases.
Preparing for Assessment
Gather your technical documentation and risk management file, align with harmonized standards or common specifications, and carry out the necessary tests and internal audits.
Declaration and CE Mark
If the system complies, you draw up an EU declaration of conformity and affix the CE marking to the product and its documentation, signalling compliance with EU rules, including the AI Act.
Link to Other EU Laws
If your AI is part of a regulated product (like a medical device), the AI Act requirements are integrated into that product’s overall conformity assessment, not handled entirely separately.
Step 7 – Post-Market Monitoring and Incident Reporting
After Launch: Monitoring and Reporting
For high-risk AI, compliance continues after deployment. Providers must monitor real-world performance and report serious incidents and malfunctions to authorities within set timeframes.
Post-Market Monitoring System
Create a plan to collect field data, review logs and complaints, and detect new risks or misuse. Define what you track, how often, and who is responsible for analysis and follow-up.
Triggers and Corrective Actions
Specify thresholds or events that trigger corrective actions such as retraining, configuration changes, user guidance updates, or temporarily suspending the system.
Serious Incident Reporting
Define serious incidents (e.g., serious harm to health or fundamental rights) for your system. Set internal procedures to detect, escalate, and report them to authorities and customers on time.
Closing the Loop
Insights from post-market monitoring should feed back into your risk management, documentation, and product design so that the system becomes safer and more compliant over time.
Step 8 – Using Harmonized Standards and Codes of Practice
Why Standards Matter
The AI Act sets high-level rules. Harmonized standards and codes of practice translate these into detailed, practical requirements that providers can actually implement and audit.
Harmonized Standards
Standards adopted by EU bodies and cited in the Official Journal give a presumption of conformity. Following them is a powerful way to show that your high-risk AI meets legal requirements.
Codes of Practice
Codes of practice are often sector-specific guidelines created by industry and regulators. They help you interpret the AI Act for particular domains like healthcare, finance, or employment.
How to Use Them
Identify relevant standards and codes, map your current practices against them, fill any gaps, and document which ones you follow in your technical documentation and compliance files.
Step 9 – Build Your Provider Compliance Checklist
Now turn the obligations into a practical checklist you could integrate into an AI product development lifecycle.
Thought exercise:
- Pick a system
- Choose one AI system you know (from a course, internship, or news story). Assume it has been classified as high-risk.
- Map the lifecycle stages
- Requirements and design.
- Data collection and preparation.
- Model development and testing.
- Deployment and integration.
- Operation and maintenance.
- For each stage, write 1–2 provider tasks that reflect AI Act obligations. For example:
- Design: "Define intended purpose, user groups, and foreseeable misuse; start a risk register."
- Data: "Document data sources and run bias checks on the training dataset."
- Development: "Log all experiments and performance metrics; test robustness to noisy inputs."
- Deployment: "Provide instructions for use and configure logging with the deployer."
- Operation: "Monitor field performance and set up incident reporting channels."
- Check coverage
- Does your checklist touch on: risk management, data governance, documentation, logging, transparency, human oversight, robustness/cybersecurity, conformity assessment, post-market monitoring, and standards?
- Refine
- If any area is missing, add at least one concrete task for that area.
If you are working in a group, compare checklists. Where do you see different interpretations of the same obligation? How might that affect real-world compliance?
Quick Check – Provider Obligations
Test your understanding of key obligations for providers of high-risk AI systems under the EU AI Act.
Which of the following best describes the provider’s responsibility for post-market monitoring of a high-risk AI system?
- Once the system is CE marked and sold, monitoring is optional and handled entirely by deployers.
- Providers must operate a documented post-market monitoring system, analyze real-world performance, and report serious incidents to authorities.
- Providers only need to update the model if customers complain about accuracy.
- Post-market monitoring applies only to AI systems used in healthcare.
Show Answer
Answer: B) Providers must operate a documented post-market monitoring system, analyze real-world performance, and report serious incidents to authorities.
The AI Act requires providers of high-risk AI to run a post-market monitoring system, collect and analyze real-world performance data, and report serious incidents and malfunctions to competent authorities. This duty applies across all high-risk sectors, not just healthcare.
Key Terms Review
Flip through these flashcards to reinforce core concepts from this module.
- Provider (under the AI Act)
- A natural or legal person that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark.
- High-risk AI system
- An AI system listed in the AI Act’s high-risk categories (for example, certain systems in employment, credit scoring, education, critical infrastructure, law enforcement, or healthcare) that must meet strict requirements.
- Risk management system
- A continuous process to identify, analyze, evaluate, and control risks to health, safety, and fundamental rights throughout the AI system’s lifecycle, with documented plans and evidence.
- Technical documentation
- The structured set of documents that describe the AI system, its purpose, design, data, risk controls, performance, and post-market monitoring plan, used to demonstrate compliance in conformity assessment.
- Conformity assessment
- The procedure used to show that a high-risk AI system meets AI Act requirements, sometimes involving a notified body, and leading to an EU declaration of conformity and CE marking.
- Harmonized standard
- A European standard developed by recognized bodies and cited in the EU Official Journal; following it gives a presumption of conformity with the legal requirements it covers.
- Post-market monitoring
- The provider’s ongoing process to collect and analyze data on the AI system’s real-world performance, detect new or increased risks, and feed this back into risk management and improvements.
Key Terms
- Logging
- Automatic recording of relevant events during the AI system’s operation (such as inputs, outputs, errors, and overrides) to enable traceability and incident investigation.
- Provider
- A natural or legal person that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark.
- CE marking
- A symbol affixed to products, including qualifying high-risk AI systems, indicating that they conform to applicable EU legislation.
- Human oversight
- Design and procedural measures that ensure humans can understand, supervise, and, where necessary, override or stop the AI system to prevent or minimize harm.
- Harmonized standard
- A technical standard adopted by European standardization bodies and cited in the Official Journal of the EU, providing a presumption of conformity when followed.
- High-risk AI system
- An AI system in one of the AI Act’s high-risk categories (for example, certain systems in employment, credit scoring, education, or healthcare) that must meet enhanced requirements.
- Conformity assessment
- The process of demonstrating that a high-risk AI system meets the AI Act’s requirements, which may involve internal checks or independent notified bodies.
- Post-market monitoring
- Ongoing activities by the provider to track and analyze the AI system’s real-world performance and risks after it has been placed on the market.
- Risk management system
- A structured, continuous process for identifying, analyzing, evaluating, and controlling risks to health, safety, and fundamental rights throughout the AI lifecycle.
- Technical documentation
- Documentation prepared by the provider that describes the AI system, its purpose, design, data, risk controls, performance, and monitoring, used to prove compliance.