Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
Context fileUnder EU AI Act, Article 26(5)
What does it require?
Deployers must monitor a high-risk AI system's operation against the provider's instructions and feed observations to the provider under Article 72. If they have reason to think the system as used may present a risk to health, safety or fundamental rights, they must inform the provider or distributor and the market surveillance authority without undue delay and suspend use. On a serious incident, they must immediately inform the provider, then the importer or distributor and the authorities. Financial institutions meet this through their internal governance rules.
Practical action
Give each high-risk system an operational owner with a kill-switch authority and a written escalation route to the provider and the authority.
Who does it apply to?
Deployers of high-risk AI systems; the incident-reporting leg is aligned with Article 73.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessIncident coordinator · continuousAI incident management and regulatory reporting
Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority
Suspension decision and notifications to provider and authority.
-
satisfiesTechnical measureAI system owner · continuousPost-deployment monitoring and drift detection
Serves 10 recorded duties · evidence: Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision
Deployer-side monitoring with feedback to the provider.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Operational monitoring log | record | |
| Suspension and escalation procedure | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 9.1; Annex A.6.2.6, A.8.4 | Operation and monitoring; communication of incidents. | high |
| NIST AI RMF 1.0 | MANAGE 2.4, MANAGE 4.1, MANAGE 4.3 | Deactivation mechanisms, post-deployment monitoring and incident response. | high |
Cite this record
AIPolicyTracker (2026). “Deployers must monitor high-risk AI, suspend use on risk and report serious incidents (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Operate a post-market monitoring system — EU AI Act, European Union
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.