The high-risk obligation set, decoded: risk management, data governance, human oversight
If you've concluded a system is high-risk, the EU AI Act's Chapter III sets out the heavy obligations — and they read like engineering discipline, not paperwork. The good news for mid-market deployers is that your slice is much shorter than a provider's. Here's the whole set, plainly.
Risk management, running continuously
A high-risk system needs a risk-management system that operates across its life cycle — identifying and mitigating risks to health, safety and fundamental rights, and updating as the system and its use evolve. This is not a one-off assessment; it's an ongoing process, which is precisely where a well-run ISO 42001 risk register does double duty and saves you building two things.
Data governance and technical documentation
Providers must govern the data used to train, validate and test the system — relevance, representativeness, and attention to bias — and maintain technical documentation (Annex IV) detailed enough for authorities to assess conformity. Logging must be automatic, so the system's operation can be traced. These are provider-heavy duties; if you only deploy someone else's system, you rely on them for most of this, but you should confirm it exists.
Human oversight, accuracy, robustness, security
The system must be designed for effective human oversight, and must meet appropriate levels of accuracy, robustness and cybersecurity. For deployers, the operative duties are to use the system according to instructions, ensure competent human oversight actually happens, and monitor performance. This is the part of the Act that most rewards a company with real operating procedures already in place.
Conformity assessment, registration, and the deployer's shorter list
Before a high-risk system goes to market, it undergoes conformity assessment and (for many cases) registration in the EU database — provider duties. Deployers owe a lighter but real set: instructions-based use, human oversight, monitoring, keeping logs, and for certain uses a fundamental-rights impact assessment. Same system, very different homework — which is why settling your role first is not optional.
The mid-market reality
Most mid-sized companies are deployers of high-risk systems, not providers of them. That means your obligation list is genuinely manageable — provided you (a) confirm the provider did their part, (b) run oversight and monitoring properly, and (c) keep evidence. The trap is assuming "we just use it" removes all duties; it removes most, not all.
Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.