SkarpSkarp

Chapter 5 of 11

Obligations for Providers: Building Compliant High-Risk AI

If your organization develops or places AI systems on the EU market, this module turns the dense list of provider obligations into a practical checklist for product, engineering, and compliance teams.

15 min readen

Orienting Yourself: Providers, High-Risk, and the AI Act

Zooming In: Provider Duties

This module focuses on what the EU AI Act requires from providers of high-risk AI systems. As of mid-2026, the core obligations are stable and define how you must design, document, and monitor these systems.

Who Counts as a Provider?

A provider is anyone who develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark. That includes startups, big tech, consultancies, and research labs.

Examples of Providers

You are likely a provider if you: build a credit-scoring model sold to EU banks, develop an AI-based medical device with a CE mark, or license a recruitment screening system to EU employers under your brand.

Your Compliance Goal

Assuming you have already classified a system as high-risk, your goal now is to turn the AI Act’s obligations into a practical provider checklist that fits into your AI product lifecycle.

The Big Obligation List

Key duties: risk management, data governance, technical documentation, logging, transparency and instructions for use, human oversight, accuracy and cybersecurity, conformity assessment and CE marking, post-market monitoring, and use of standards.

Step 1 – Build a Risk Management System Around the AI Lifecycle

Risk Management: The Core Requirement

Providers of high-risk AI must operate a continuous risk management system that covers the entire lifecycle. It is about identifying, analyzing, and reducing risks to health, safety, and fundamental rights.

1. Identify Risks

Map where the AI can cause harm: incorrect outputs, unfair or discriminatory outcomes, security failures, and misuse. Consider both intended use and reasonably foreseeable misuse, including impacts on fundamental rights.

2. Analyze and Prioritize

Estimate the severity and likelihood of each risk. Use this to prioritize your efforts, focusing on high-severity, plausible risk scenarios rather than minor or extremely unlikely issues.

3. Control and Reduce Risks

Apply technical controls (thresholds, robustness tests), organizational controls (dual review, user training), and design changes (clearer UI, restricted features) to bring risks down to an acceptable level.

4–5. Residual Risk and Updating

Check whether residual risk is acceptable; if not, iterate or narrow the system’s purpose. Keep the risk system updated when models, data, or deployment contexts change, using real-world feedback.

Key Artifacts

Maintain a Risk Management Plan, a Risk Register, and evidence of testing and validation. These documents later support your technical documentation and conformity assessment for CE marking.

Example – Risk Management for an AI Recruitment Screener

Scenario: AI Recruitment Screener

You provide a high-risk AI tool that pre-ranks job candidates for EU employers. This use case is close to real deployments and highlights discrimination, transparency, and human oversight risks.

Identifying Key Risks

Risks include discrimination against protected groups, opaque rejections without reasons, privacy issues from sensitive data, and recruiters over-relying on AI scores instead of exercising judgment.

Analyzing and Prioritizing

Discrimination has high severity and non-trivial likelihood, so it becomes a top priority. Over-reliance is also important, especially if the interface encourages users to treat scores as final.

Implementing Controls

You apply fairness-aware training, run bias tests, design the UI to show scores as recommendations, require human justifications for rejections, and provide guidance on lawful and non-discriminatory use.

Residual Risk and Monitoring

After controls, you document remaining risks, such as lingering bias from historical data, and mitigate them with quarterly fairness audits, complaint review, and risk reviews after retraining.

Step 2 – Data Governance and Data Quality Obligations

Data Governance: The Foundation

High-risk AI must be trained, validated, and tested on data that is relevant, representative where needed, and as free of errors as possible. This is central to both safety and fairness.

1. Plan Your Data Strategy

Clearly document which datasets you use for training, validation, and testing, and justify why they are appropriate for the system’s intended purpose and target population.

2. Check Quality and Integrity

Run systematic checks for missing values, noisy labels, and obvious errors. Use version control and data lineage tracking so you can always trace which data built which model.

3. Bias and Representativeness

Assess whether certain groups are under-represented or misrepresented. Where lawful and appropriate, use rebalancing or sampling strategies to reduce harmful bias in downstream model behavior.

4. Lawful Use and Privacy

Ensure compliance with GDPR and national rules. Minimize personal data, handle sensitive attributes carefully, and document your legal basis and safeguards for any personal data processing.

5. Document Everything

Record your data sources, preprocessing, and known limitations. These records are critical for conformity assessment, audits, and incident investigations involving your AI system.

Step 3 – Technical Documentation and Logging: Your Evidence Pack

Technical Documentation: Your Evidence Pack

Technical documentation is the structured evidence that your high-risk AI complies with the AI Act. You must have it ready before placing the system on the EU market or putting it into service.

What Goes In

Include: system description and architecture, risk management records, data governance details, model and training information, human oversight design, cybersecurity measures, and your post-market monitoring plan.

Proportional Detail

The level of technical detail should be proportionate. You do not have to publish trade secrets, but you must provide enough information for regulators or notified bodies to assess compliance.

Logging by Design

High-risk AI must be designed to support automatic logging of relevant events during operation. This enables later analysis of how the system behaved in real-world use.

What to Log

Typical logs: key inputs and outputs, decision paths or scores, system errors, security events, and human overrides. Logs must be secure and respect data protection rules.

Why It Matters

Without solid documentation and logging, it is difficult to pass conformity assessment, investigate incidents, or demonstrate accountability to regulators, customers, and affected people.

Step 4 – Transparency, Instructions for Use, and Human Oversight

Transparency and Human Oversight

High-risk AI must be understandable and controllable by humans. The AI Act requires transparent instructions for use and system designs that enable effective human oversight.

Clear Instructions for Use

You must explain the intended purpose, limitations, accuracy and robustness levels, input data requirements, known risks, and prohibited uses in language that non-expert users can follow.

Designing Oversight Roles

Specify who oversees the AI in practice: for example, a doctor, HR manager, or risk officer. Clarify their responsibilities and what they should do when they disagree with the AI.

Control Mechanisms

Provide ways to override, pause, or stop the AI, and define escalation paths for uncertain or high-stakes cases. Oversight must be more than a theoretical possibility.

Understandable Outputs

Present outputs in interpretable formats, with confidence scores or explanations where feasible. This helps humans challenge or correct the AI when something looks wrong.

Training and Avoiding Over-Reliance

Inform deployers that oversight personnel need training. Good design and documentation should help humans detect anomalies and avoid blindly following AI recommendations.

Step 5 – Robustness, Accuracy, and Cybersecurity by Design

Accuracy, Robustness, Cybersecurity

High-risk AI must reach appropriate levels of accuracy, robustness, and cybersecurity. These qualities are not optional add-ons; they are core legal requirements under the AI Act.

Accuracy and Metrics

Define relevant performance metrics and minimum thresholds. Test on independent data and across relevant subgroups to ensure the system performs consistently where it is intended to be used.

Robustness to Real-World Conditions

Evaluate how the system handles noisy, incomplete, or slightly unusual inputs. Provide fallback or safe modes when the system is pushed outside its validated operating domain.

Cybersecurity Threats

Secure your data, models, and infrastructure against attacks like data poisoning, model tampering, and unauthorized access. These threats can directly undermine safety and compliance.

Connect Back to Risk Management

Document your accuracy, robustness, and cybersecurity measures in the risk management file and technical documentation, and monitor them over time in your post-market processes.

Step 6 – Conformity Assessment and CE Marking

Conformity Assessment and CE Marking

High-risk AI systems must undergo a conformity assessment before being placed on the EU market. If they comply, providers issue an EU declaration of conformity and affix the CE marking.

Assessment Routes

Depending on the system and sector, you may follow internal control (self-assessment) or involve a notified body, an independent organization that checks compliance for certain high-risk cases.

Preparing for Assessment

Gather your technical documentation and risk management file, align with harmonized standards or common specifications, and carry out the necessary tests and internal audits.

Declaration and CE Mark

If the system complies, you draw up an EU declaration of conformity and affix the CE marking to the product and its documentation, signalling compliance with EU rules, including the AI Act.

Link to Other EU Laws

If your AI is part of a regulated product (like a medical device), the AI Act requirements are integrated into that product’s overall conformity assessment, not handled entirely separately.

Step 7 – Post-Market Monitoring and Incident Reporting

After Launch: Monitoring and Reporting

For high-risk AI, compliance continues after deployment. Providers must monitor real-world performance and report serious incidents and malfunctions to authorities within set timeframes.

Post-Market Monitoring System

Create a plan to collect field data, review logs and complaints, and detect new risks or misuse. Define what you track, how often, and who is responsible for analysis and follow-up.

Triggers and Corrective Actions

Specify thresholds or events that trigger corrective actions such as retraining, configuration changes, user guidance updates, or temporarily suspending the system.

Serious Incident Reporting

Define serious incidents (e.g., serious harm to health or fundamental rights) for your system. Set internal procedures to detect, escalate, and report them to authorities and customers on time.

Closing the Loop

Insights from post-market monitoring should feed back into your risk management, documentation, and product design so that the system becomes safer and more compliant over time.

Step 8 – Using Harmonized Standards and Codes of Practice

Why Standards Matter

The AI Act sets high-level rules. Harmonized standards and codes of practice translate these into detailed, practical requirements that providers can actually implement and audit.

Harmonized Standards

Standards adopted by EU bodies and cited in the Official Journal give a presumption of conformity. Following them is a powerful way to show that your high-risk AI meets legal requirements.

Codes of Practice

Codes of practice are often sector-specific guidelines created by industry and regulators. They help you interpret the AI Act for particular domains like healthcare, finance, or employment.

How to Use Them

Identify relevant standards and codes, map your current practices against them, fill any gaps, and document which ones you follow in your technical documentation and compliance files.

Step 9 – Build Your Provider Compliance Checklist

Now turn the obligations into a practical checklist you could integrate into an AI product development lifecycle.

Thought exercise:

  1. Pick a system
  • Choose one AI system you know (from a course, internship, or news story). Assume it has been classified as high-risk.
  1. Map the lifecycle stages
  • Requirements and design.
  • Data collection and preparation.
  • Model development and testing.
  • Deployment and integration.
  • Operation and maintenance.
  1. For each stage, write 1–2 provider tasks that reflect AI Act obligations. For example:
  • Design: "Define intended purpose, user groups, and foreseeable misuse; start a risk register."
  • Data: "Document data sources and run bias checks on the training dataset."
  • Development: "Log all experiments and performance metrics; test robustness to noisy inputs."
  • Deployment: "Provide instructions for use and configure logging with the deployer."
  • Operation: "Monitor field performance and set up incident reporting channels."
  1. Check coverage
  • Does your checklist touch on: risk management, data governance, documentation, logging, transparency, human oversight, robustness/cybersecurity, conformity assessment, post-market monitoring, and standards?
  1. Refine
  • If any area is missing, add at least one concrete task for that area.

If you are working in a group, compare checklists. Where do you see different interpretations of the same obligation? How might that affect real-world compliance?

Quick Check – Provider Obligations

Test your understanding of key obligations for providers of high-risk AI systems under the EU AI Act.

Which of the following best describes the provider’s responsibility for post-market monitoring of a high-risk AI system?

  1. Once the system is CE marked and sold, monitoring is optional and handled entirely by deployers.
  2. Providers must operate a documented post-market monitoring system, analyze real-world performance, and report serious incidents to authorities.
  3. Providers only need to update the model if customers complain about accuracy.
  4. Post-market monitoring applies only to AI systems used in healthcare.
Show Answer

Answer: B) Providers must operate a documented post-market monitoring system, analyze real-world performance, and report serious incidents to authorities.

The AI Act requires providers of high-risk AI to run a post-market monitoring system, collect and analyze real-world performance data, and report serious incidents and malfunctions to competent authorities. This duty applies across all high-risk sectors, not just healthcare.

Key Terms Review

Flip through these flashcards to reinforce core concepts from this module.

Provider (under the AI Act)
A natural or legal person that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark.
High-risk AI system
An AI system listed in the AI Act’s high-risk categories (for example, certain systems in employment, credit scoring, education, critical infrastructure, law enforcement, or healthcare) that must meet strict requirements.
Risk management system
A continuous process to identify, analyze, evaluate, and control risks to health, safety, and fundamental rights throughout the AI system’s lifecycle, with documented plans and evidence.
Technical documentation
The structured set of documents that describe the AI system, its purpose, design, data, risk controls, performance, and post-market monitoring plan, used to demonstrate compliance in conformity assessment.
Conformity assessment
The procedure used to show that a high-risk AI system meets AI Act requirements, sometimes involving a notified body, and leading to an EU declaration of conformity and CE marking.
Harmonized standard
A European standard developed by recognized bodies and cited in the EU Official Journal; following it gives a presumption of conformity with the legal requirements it covers.
Post-market monitoring
The provider’s ongoing process to collect and analyze data on the AI system’s real-world performance, detect new or increased risks, and feed this back into risk management and improvements.

Key Terms

Logging
Automatic recording of relevant events during the AI system’s operation (such as inputs, outputs, errors, and overrides) to enable traceability and incident investigation.
Provider
A natural or legal person that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark.
CE marking
A symbol affixed to products, including qualifying high-risk AI systems, indicating that they conform to applicable EU legislation.
Human oversight
Design and procedural measures that ensure humans can understand, supervise, and, where necessary, override or stop the AI system to prevent or minimize harm.
Harmonized standard
A technical standard adopted by European standardization bodies and cited in the Official Journal of the EU, providing a presumption of conformity when followed.
High-risk AI system
An AI system in one of the AI Act’s high-risk categories (for example, certain systems in employment, credit scoring, education, or healthcare) that must meet enhanced requirements.
Conformity assessment
The process of demonstrating that a high-risk AI system meets the AI Act’s requirements, which may involve internal checks or independent notified bodies.
Post-market monitoring
Ongoing activities by the provider to track and analyze the AI system’s real-world performance and risks after it has been placed on the market.
Risk management system
A structured, continuous process for identifying, analyzing, evaluating, and controlling risks to health, safety, and fundamental rights throughout the AI lifecycle.
Technical documentation
Documentation prepared by the provider that describes the AI system, its purpose, design, data, risk controls, performance, and monitoring, used to prove compliance.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself