EU AI ActChapter III

The high-risk obligation set, decoded: risk management, data governance, human oversight

If you've concluded a system is high-risk, the EU AI Act's Chapter III sets out the heavy obligations — and they read like engineering discipline, not paperwork. The good news for mid-market deployers is that your slice is much shorter than a provider's. Here's the whole set, plainly.

Risk management, running continuously

A high-risk system needs a risk-management system that operates across its life cycle — identifying and mitigating risks to health, safety and fundamental rights, and updating as the system and its use evolve. This is not a one-off assessment; it's an ongoing process, which is precisely where a well-run ISO 42001 risk register does double duty and saves you building two things.

Data governance and technical documentation

Providers must govern the data used to train, validate and test the system — relevance, representativeness, and attention to bias — and maintain technical documentation (Annex IV) detailed enough for authorities to assess conformity. Logging must be automatic, so the system's operation can be traced. These are provider-heavy duties; if you only deploy someone else's system, you rely on them for most of this, but you should confirm it exists.

Human oversight, accuracy, robustness, security

The system must be designed for effective human oversight, and must meet appropriate levels of accuracy, robustness and cybersecurity. For deployers, the operative duties are to use the system according to instructions, ensure competent human oversight actually happens, and monitor performance. This is the part of the Act that most rewards a company with real operating procedures already in place.

Conformity assessment, registration, and the deployer's shorter list

Before a high-risk system goes to market, it undergoes conformity assessment and (for many cases) registration in the EU database — provider duties. Deployers owe a lighter but real set: instructions-based use, human oversight, monitoring, keeping logs, and for certain uses a fundamental-rights impact assessment. Same system, very different homework — which is why settling your role first is not optional.

The mid-market reality

Most mid-sized companies are deployers of high-risk systems, not providers of them. That means your obligation list is genuinely manageable — provided you (a) confirm the provider did their part, (b) run oversight and monitoring properly, and (c) keep evidence. The trap is assuming "we just use it" removes all duties; it removes most, not all.

The framing. High-risk obligations look daunting as a wall of articles, but they resolve into a provider list (build it right, document it, assess it) and a deployer list (use it right, oversee it, evidence it). Know which is yours, and the wall becomes a checklist.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.