Providers must meet the full set of provider duties for high-risk AI
Context fileUnder EU AI Act, Article 16
What does it require?
Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its documentation, a quality management system, retention of documentation and logs, conformity assessment, an EU declaration of conformity, CE marking, registration, corrective action when needed, cooperation with authorities on request, and accessibility in line with the EU accessibility directives.
Practical action
Map each Article 16 point to an owner and an evidence location in a compliance matrix for every high-risk system.
Who does it apply to?
Any provider placing a high-risk AI system on the EU market or putting it into service, wherever established.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesPolicyExecutive sponsor for AI · annualAI governance policy and accountability structure
Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes
Assigns each provider duty to a named owner with a reporting line.
-
supportsPolicyQuality lead · annualQuality management system for AI development and supply
Serves 3 recorded duties · evidence: AI quality management system manual, Internal audit of the AI management system, Management review minutes
The QMS is where most Article 16 duties are operated.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Provider compliance matrix | register | Article 16 points (a)–(l) mapped to owners, status and evidence for each high-risk system. |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 5.3; Annex A.3.2 | Original editorial mapping to roles, responsibilities and authorities. | medium |
| NIST AI RMF 1.0 | GOVERN 1.1, GOVERN 2.1 | Legal requirements identified and roles assigned. | medium |
Cite this record
AIPolicyTracker (2026). “Providers must meet the full set of provider duties for high-risk AI (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.