High-Risk AI Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ legal information, not advice.This specific topic is needed to comprehensively cover the distinct set of obligations imposed specifically on providers of high-risk AI systems under Articles 16-17 of the AI Act, which is the core subject of this content and goes beyond general provider obligations.
Overview
Legal Framework
The core obligations for providers of high-risk AI systems are established by Articles 16 and 17 of the AI Act. These articles impose specific, additional duties that go beyond the general provider obligations in Chapter III. Article 16 mandates that providers ensure their high-risk AI systems are accompanied by clear and comprehensive instructions for use. These instructions must contain specified information, including the identity of the provider, the system's characteristics and performance, any human oversight measures required, and the changes the system will undergo through automatic software updates. Article 17 requires providers to establish a post-market monitoring system. This system must actively and systematically collect, document, and analyze data from the system's performance after it is placed on the market or put into service, allowing the provider to evaluate its continuous compliance.
Practical Application
As the AI Act is a directly applicable regulation, its provisions create uniform obligations across the EU, leaving limited scope for divergent national implementation in this field. The authoritative commentary notes that this direct effect is similar to the GDPR's structure. The obligations under Articles 16 and 17 are concrete and action-oriented for providers. Compliance with Article 16 requires creating technical documentation that is usable, not just a formal checklist, ensuring deployers can implement the system safely and as intended. For Article 17, the post-market monitoring system must be a proactive, integrated business process, not a reactive complaint-handling mechanism. It is designed to feed data back into risk management and facilitate immediate corrective action if systemic risks are identified. Recital 137 clarifies that meeting these transparency and instruction obligations does not, in itself, constitute a declaration that the system's use is lawful under other EU or national laws.
Key Considerations
- The instructions for use under Article 16 are a key compliance document and a primary tool for enabling safe deployment; they should be drafted for the end-user, not just for auditors.
- The Article 17 post-market monitoring system must be planned before market launch and requires defined procedures for data collection, analysis timelines, and escalation pathways for identified risks or serious incidents.
- Providers should note that these obligations are without prejudice to other sector-specific transparency or monitoring rules (e.g., in medical device or machinery regulations), which may apply cumulatively.