SkarpSkarp

Chapter 14 of 25

Operators, Deployers and Fundamental-Rights Impact Assessments

Once a high-risk system moves through distribution and into use, responsibility shifts but does not disappear. Articles 22–27 allocate verification, contractual support, monitoring, worker notice and impact-assessment duties across the full chain.

27 min readen

The Responsibility Chain: Articles 22-27

Compliance continues after development

Articles 22-27 allocate duties after a high-risk AI system leaves the provider: representation, import, distribution, deployment, monitoring, and impact assessment.

A relay, not a hand-off

Visualise a relay race: each operator receives a compliance responsibility. Passing the system onward does not erase verification, information, or cooperation duties.

Four action types

Track whether an Article requires an actor to verify, withhold or suspend, inform, or cooperate. These are different duties with different triggers.

The deployment layer

Article 26 governs use in practice. Article 27 adds a pre-deployment fundamental-rights impact assessment for specified deployers and specified high-risk systems.

Article 22: Authorised Representatives

The mandatory appointment

Before making a high-risk system available in the Union, a third-country provider must appoint a Union-established authorised representative by written mandate.

What the mandate enables

The provider shall enable performance. The mandate empowers verification of conformity materials and procedure, plus contact with competent authorities.

Ten-year availability

For 10 years after placement or service, specified provider details, the declaration, technical documentation, and any notified-body certificate must be kept available.

Requests, cooperation, registration

On a reasoned request, the representative provides necessary conformity information, including provider-controlled logs, cooperates on risk action, and may handle registration.

A mandate can end

If the representative considers or has reason to consider the provider is acting contrary to its obligations, it shall terminate and immediately inform the authority and, where applicable, notified body.

Articles 23-24: Importer and Distributor Gateways

Importer: verify before placement

Article 23 requires checks of conformity assessment, technical documentation, CE marking, declaration, instructions, and the provider's authorised representative.

Importer: stop and inform

Sufficient reason to suspect non-conformity, falsification, or falsified documents means no market placement until conformity. Article 79(1) risk triggers notification.

Importer: identity and evidence

Importers identify themselves where applicable, protect compliance during storage or transport, retain listed materials for 10 years, and cooperate with authorities.

Distributor: verify before availability

Article 24 checks CE marking, declaration copy, instructions, and specified provider and importer obligations before making the system available on the market.

Distributor: corrective response

A distributor finding non-conformity after availability must take corrective action, withdraw or recall, or ensure another relevant operator does so. Risk notification is immediate.

Checkpoint: Who Must Stop the System?

Read the trigger carefully. This question tests the difference between an importer placing a system on the market and a distributor making it available.

A distributor has information giving it reason to consider a high-risk AI system is not in conformity with Section 2. What does Article 24(2) require?

  1. It may make the system available if it labels the issue for customers.
  2. It shall not make the system available on the market until it has been brought into conformity with those requirements.
  3. It must immediately terminate its relationship with the provider in every case.
  4. It need only retain a copy of the EU declaration for 10 years.
Show Answer

Answer: B) It shall not make the system available on the market until it has been brought into conformity with those requirements.

Article 24(2) imposes a withholding duty: the distributor shall not make the system available until conformity is restored. If the system presents an Article 79(1) risk, it must also inform the provider or importer, as applicable.

Article 25: When the Value Chain Creates a New Provider

Provider status can transfer

Article 25 treats a distributor, importer, deployer, or other third party as provider in specified rebranding, substantial-modification, and intended-purpose-change cases.

Three triggers

The triggers are: own name or trademark; substantial modification while remaining high-risk; or changing intended purpose so a previously non-high-risk system becomes high-risk.

The original provider's position

For that specific system, the original provider is no longer provider. It shall closely cooperate and supply necessary information, reasonably expected access, and assistance.

Written value-chain support

Integrated suppliers and the high-risk provider must specify information, capabilities, technical access, and other assistance in a written agreement based on the state of the art.

External currency note

A July 8, 2026 signed-pending-publication Digital Omnibus includes Article 25 amendments, but is not in force. A December 16, 2025 medical-device proposal is also not in force.

Article 26(1)-(6): Using, Overseeing, Monitoring, and Logging

Use the system as instructed

Deployers shall take appropriate technical and organisational measures so use follows the accompanying instructions for use. Operational practice must connect back to those instructions.

Human oversight is assigned

Oversight goes to natural persons with necessary competence, training, authority, and support. The Article does not reduce other legal duties of deployers.

Input-data duty when control exists

To the extent a deployer controls input data, it shall ensure that data is relevant and sufficiently representative for the system's intended purpose.

Monitor, inform, suspend

If compliant use may present an Article 79(1) risk, the deployer shall inform specified parties without undue delay and suspend use. Serious incidents trigger immediate reporting.

Logs: a six-month floor

Automatically generated logs under deployer control must be kept for a purpose-appropriate period of at least six months, unless applicable Union or national law provides otherwise.

Article 26(7)-(12): Workplace, Registration, Biometrics, and Notice

Workplace notice comes first

Before workplace service or use, employer-deployers shall inform workers' representatives and affected workers that they will be subject to the high-risk AI system.

Registration and data protection

Public-sector deployers must not use an envisaged system missing from the EU database. Where applicable, Article 13 information supports required data-protection impact assessments.

Post-remote biometric identification

For the defined targeted criminal investigation, authorisation must be requested beforehand or without undue delay, and no later than 48 hours, subject to a narrow initial-identification exception.

Limits and records

Rejected authorisation means immediate stop and deletion. Untargeted use is barred in the stated circumstances, sole-output adverse decisions are barred, and uses are documented.

Inform affected people

Annex III deployers making or assisting decisions about natural persons shall inform them they are subject to the high-risk system. Deployers also shall cooperate with authorities.

Decision Drill: What Must a Deployer Do?

Decision Drill: Build the Response Sequence

A city authority plans to use an Annex III high-risk system to help make decisions about applicants for a public service. It controls the input data. During operation, staff conclude that using the system in accordance with its instructions may still create a risk within Article 79(1).

Work through the sequence before revealing your answer:

  1. Before use: What registration question must the authority ask? What Article 27 question may arise because this is a body governed by public law?
  2. Set-up: Who must receive human oversight, and what qualifications and support must they have?
  3. Inputs: What must the authority ensure, given that it controls the input data?
  4. Risk discovered: Who must be informed, how quickly, and what happens to use of the system?
  5. Records and communication: How long are controlled automatically generated logs kept at minimum? What must affected natural persons be told?

Suggested answer

Before use, a public-authority deployer must comply with Article 49 registration obligations. If the envisaged system is not registered in the Article 71 EU database, it shall not use it and shall inform the provider or distributor. Under Article 27, a body governed by public law deploying an Article 6(2) high-risk system, subject to the stated Annex III point 2 exception, shall perform the fundamental-rights impact assessment before deployment.

It shall assign human oversight to natural persons with necessary competence, training, authority, and support. Because it controls inputs, it shall ensure they are relevant and sufficiently representative for the intended purpose. When it has reason to consider an Article 79(1) risk may result despite instructed use, it shall, without undue delay, inform the provider or distributor and relevant market-surveillance authority, and shall suspend use. Logs under its control are retained for a purpose-appropriate period of at least six months unless applicable law provides otherwise. Because the system is an Annex III system making or assisting decisions about natural persons, it shall inform them that they are subject to its use.

Article 27: Fundamental Rights Impact Assessment

Who must assess?

Before deployment, Article 27 applies to specified public-law bodies, private public-service providers, and deployers of Annex III points 5(b) and 5(c), subject to the stated exception.

The six required elements

Describe processes, duration and frequency, affected people, specific harms, implementation of human oversight, and measures for materialised risks including governance and complaints.

Context is decisive

The assessment is about the actual deployment: intended purpose, people or groups affected, likely harms, and the deployer's response arrangements in that use context.

First use, reuse, update

The duty applies to first use. Similar cases may rely on previous assessments, but changed or outdated listed elements require necessary steps to update information.

Notify and complement

After assessment, the deployer shall notify the authority using the template, subject to the Article 46(1) exemption. It complements, rather than replaces, a relevant DPIA.

Flashcards: Numbers, Triggers, and Roles

Flip each card, answer from memory, then use the back to check exact Article language and thresholds.

Third-country provider: Article 22 entry condition?
Before making a high-risk system available on the Union market, it shall appoint, by written mandate, an authorised representative established in the Union.
How long must Article 22 materials be kept available?
For 10 years after the high-risk AI system has been placed on the market or put into service.
Importer: four Article 23 verification areas?
Conformity assessment; technical documentation; CE marking, declaration and instructions; and appointment of an authorised representative.
Distributor: response to suspected Section 2 non-conformity?
It shall not make the system available on the market until the system has been brought into conformity with those requirements.
Article 25: three ways another actor can become provider?
Putting its name or trademark on the system; substantial modification while it remains high-risk; or changing intended purpose so it becomes high-risk.
Deployer log-retention minimum?
A period appropriate to intended purpose, of at least six months, unless applicable Union or national law provides otherwise.
Post-remote biometric identification: authorisation deadline?
Ex ante, or without undue delay and no later than 48 hours, subject to the specified initial-identification exception.
Article 27: what does a fundamental-rights assessment do?
It assesses the impact on fundamental rights that use may produce through six elements: process, time and frequency, affected groups, harms, oversight, and risk-response measures.

Final Check: Article 27 and Existing DPIAs

Choose the statement that most accurately reflects Article 27(4).

A deployer has already conducted a data protection impact assessment under GDPR Article 35, and that assessment meets one of Article 27's obligations. What does the source text require?

  1. The deployer is automatically exempt from Article 27.
  2. The fundamental-rights impact assessment shall complement the data protection impact assessment.
  3. The provider must replace the deployer's assessment with technical documentation.
  4. The deployer only needs to notify the national data protection authority, not the market-surveillance authority.
Show Answer

Answer: B) The fundamental-rights impact assessment shall complement the data protection impact assessment.

Article 27(4) says that where an Article 27 obligation is already met through the stated data protection impact assessment, the Article 27 fundamental-rights impact assessment shall complement that DPIA. The text does not say the DPIA eliminates Article 27.

Key Terms

deployer
The actor using a high-risk AI system in an operational setting and subject to Article 26 duties.
importer
An operator addressed by Article 23 that verifies specified conformity materials and conditions before placing a high-risk AI system on the market.
provider
The actor subject to Article 16 provider obligations; Article 25 can cause a distributor, importer, deployer, or other third party to be considered a provider.
distributor
An operator addressed by Article 24 that performs specified checks before making a high-risk AI system available on the market and takes corrective action when required.
human oversight
Oversight assigned by deployers to natural persons with necessary competence, training, authority, and support.
substantial modification
A modification to an already marketed or deployed high-risk system that, under Article 25(1)(b), can make the modifying actor a provider where the system remains high-risk under Article 6.
authorised representative
A representative established in the Union whom a third-country provider appoints by written mandate before making its high-risk AI system available on the Union market.
data protection impact assessment
An assessment under GDPR Article 35 or Directive (EU) 2016/680 Article 27 that Article 27(4) says a fundamental-rights impact assessment shall complement where relevant.
fundamental rights impact assessment
The Article 27 assessment of the impact that use of specified high-risk systems may produce on fundamental rights.
post-remote biometric identification
A high-risk AI system category addressed by Article 26(10), subject to targeted-investigation, authorisation, necessity, documentation, and reporting conditions.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself