# High-Risk AI Obligations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/high-risk-ai-provider-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

This specific topic is needed to comprehensively cover the distinct set of obligations imposed specifically on providers of high-risk AI systems under Articles 16-17 of the AI Act, which is the core subject of this content and goes beyond general provider obligations.

## Overview

## Legal Framework
The core obligations for providers of high-risk AI systems are established by Articles 16 and 17 of the AI Act. These articles impose specific, additional duties that go beyond the general provider obligations in Chapter III. Article 16 mandates that providers ensure their high-risk AI systems are accompanied by clear and comprehensive instructions for use. These instructions must contain specified information, including the identity of the provider, the system's characteristics and performance, any human oversight measures required, and the changes the system will undergo through automatic software updates. Article 17 requires providers to establish a post-market monitoring system. This system must actively and systematically collect, document, and analyze data from the system's performance after it is placed on the market or put into service, allowing the provider to evaluate its continuous compliance.

## Practical Application
As the AI Act is a directly applicable regulation, its provisions create uniform obligations across the EU, leaving limited scope for divergent national implementation in this field. The authoritative commentary notes that this direct effect is similar to the GDPR's structure. The obligations under Articles 16 and 17 are concrete and action-oriented for providers. Compliance with Article 16 requires creating technical documentation that is usable, not just a formal checklist, ensuring deployers can implement the system safely and as intended. For Article 17, the post-market monitoring system must be a proactive, integrated business process, not a reactive complaint-handling mechanism. It is designed to feed data back into risk management and facilitate immediate corrective action if systemic risks are identified. Recital 137 clarifies that meeting these transparency and instruction obligations does not, in itself, constitute a declaration that the system's use is lawful under other EU or national laws.

## Key Considerations
*   The instructions for use under Article 16 are a key compliance document and a primary tool for enabling safe deployment; they should be drafted for the end-user, not just for auditors.
*   The Article 17 post-market monitoring system must be planned before market launch and requires defined procedures for data collection, analysis timelines, and escalation pathways for identified risks or serious incidents.
*   Providers should note that these obligations are without prejudice to other sector-specific transparency or monitoring rules (e.g., in medical device or machinery regulations), which may apply cumulatively.

## Legislation (full text of key provisions)

### Recital 79 — provider responsibility for high-risk AI systems

*Source: AI Act, aiact-rec-79-en, 2024-06-12 — https://overview.legal/posts/93840*

It is appropriate that a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system, regardless of whether that natural or legal person is the person who designed or developed the system.

### Recital 125 — High-risk AI systems conformity assessment procedure

*Source: AI Act, aiact-rec-125-en, 2024-06-12 — https://overview.legal/posts/93932*

Given the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

## Related topics

- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Conformity Assessment Procedures and Methodologies** — https://overview.legal/topics/conformity-assessment-procedures-ai
  This new topic is needed to specifically address the procedural and methodological aspects of conformity assessment for AI systems, including step-by-step proce
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection

---
Generated by overview.legal · https://overview.legal/topics/high-risk-ai-provider-obligations · 2026-08-22
