Methodology · Updated 17 August 2026

What evidence an EU AI Act deployer needs to hold in 2026

The AI Omnibus entered into force on 27 July 2026 and moved the Article 26 high-risk deployer obligations to 2 December 2027 for Annex III systems. The obligations were deferred, not withdrawn, and the evidence they call for is contemporaneous, which is why insurers and enterprise buyers already ask for it. This article sets out exactly what a deployer should have on file, distinguishes that baseline from certification, and explains why building one properly means the other is most of the way built already.

Key takeaways

  • The AI Omnibus entered into force on 27 July 2026. Article 26 deployer obligations now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems embedded in physical products. The Article 99 penalty exposure, up to EUR 15 million or 3 percent of worldwide turnover, attaches from those dates.
  • The legal minimum is the Article 26 operator file: a risk record, named human oversight, a logging practice, the provider's instructions for use, and an incident protocol. This is self-maintained and requires no third-party assessment.
  • Certification is a distinct, independently verified layer on top of that baseline, but the two draw on the same underlying evidence, so building the operator file properly is not wasted effort even for a deployer who never seeks certification.
  • What the Omnibus changed is the date, not the content of the requirement, which has been known since the Regulation's 2024 text. A deferred obligation still has to be met with evidence that can only be produced while the system runs.
  • A deployer facing an incident with no documentation in place faces compounded exposure across regulatory, civil liability and insurance dimensions at once. Civil liability and insurance scrutiny do not wait for 2 December 2027.

What the AI Omnibus changed, and what it did not

The substance of Article 26 has not changed since Regulation (EU) 2024/1689 was adopted in 2024. Every requirement described in this article has been publicly known for close to two years. What changed is the date. The AI Omnibus entered into force on 27 July 2026 and moved the high-risk obligations from 2 August 2026 to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems embedded in physical products. The Article 99 penalty regime, up to EUR 15 million or 3 percent of worldwide annual turnover, attaches from those dates rather than from August 2026. The Article 5 prohibitions, the Article 50 transparency obligations and the general purpose AI obligations under Articles 53 and 55 sit outside the Omnibus and run on their own timelines.

For deployers who had been treating the deferral as a working assumption, the assumption held. The more useful question is what a deferral is actually worth. Article 26 asks for a record of how a system was operated, which means the evidence has to be generated while the system runs. A deployer who starts building in November 2027 will be documenting a system that has been in production for eighteen months from memory. That is the practical reason the date moving does not move the work. The narrower question for this article is narrower and more useful than debating what should have happened: given that the obligation is now live, what evidence does a deployer actually need to hold, starting today.

The minimum: the Article 26 operator file

Article 26 of Regulation (EU) 2024/1689 sets out the obligations of deployers of high-risk AI systems. Stripped to its operational content, it requires five things that together form what this site and its network refer to as the operator file.

A current risk record. A description of what the AI system does, the population it affects, and its known limitations, kept current rather than written once at deployment and never revisited. This is the document a deployer produces first when a regulator or an insurer asks what the system is and what it was designed to do.

Named human oversight. Article 26 requires that natural persons assigned to oversee the system have the necessary competence, training, and authority, and are not simply nominal names attached to a role nobody actually performs. The oversight assignment needs to reflect a real operational practice, covered in depth in the human oversight certification evidence guide on this site.

A logging practice. The Regulation requires deployers to keep the logs the AI system automatically generates, to the extent those logs are under the deployer's control, for a period appropriate to the system's purpose. This is not a requirement to build new logging infrastructure from scratch in every case; it is a requirement to preserve and not discard what the system already produces.

The provider's instructions for use. A deployer must operate the system in accordance with the instructions for use accompanying it, and must retain those instructions as part of its own compliance record, since they define the scope of intended use against which any deviation is assessed.

An incident protocol. A documented process for identifying, assessing, and, where required under Article 73, reporting serious incidents. This overlaps closely with the evidence required for insurance claims notification, covered in how certification feeds insurance underwriting.

None of this requires a third party. A deployer can build and maintain the operator file entirely in-house, and Article 26 does not itself require certification or external audit. It is, however, the floor. A deployer without these five elements does not have a defensible position if a regulator, a claimant's counsel, or an insurer asks to see them.

Where certification sits above the floor

Certification under a structured methodology, including the seven-dimension framework this site publishes at methodology.html, is a distinct layer above the Article 26 minimum. The distinction that matters is verification. The operator file is a self-assessment: the deployer's own record of its own compliance, credible to the extent the deployer's own documentation practice is credible. A certification assessment introduces an independent party reviewing that evidence against a defined rubric and producing a score, published at one of the five levels described on the certification levels page, from Pre-Assessment through Elite.

The relationship between the two is not competitive. A deployer with a well-built operator file has already produced most of the evidence a certification assessment reviews: the seven dimensions map closely onto the operator file's five elements plus two additional evaluation angles, data governance and distribution control, that extend beyond what Article 26 strictly requires but that a mature governance programme addresses as a matter of course. This overlap is deliberate. The methodology was built to be legible against the AI Act's own structure, documented in full in the seven dimensions to EU AI Act obligations map on this site.

The practical consequence for a deployer deciding where to invest first is straightforward. Build the operator file to a genuinely defensible standard, not a minimal one, because that work is legally required today regardless of any certification decision. Whether to pursue independent certification on top of that foundation is a separate commercial decision, informed by whether an insurer, an enterprise counterparty, or a public procurement process is asking for third-party verification specifically, which the operator file alone does not provide.

The cost of having neither when something goes wrong

The reason this matters before the obligation bites is not abstract. Consider what happens to a deployer with no operator file and no certification when an AI agent incident occurs today. The incident itself still needs assessment: what happened, who was affected, whether it meets the Article 73 threshold for serious incident reporting. A deployer with no risk record, no oversight assignment, and no logging discipline in place is assessing this for the first time under pressure, with no prior documentation to establish what the system was supposed to do or what oversight was supposed to exist.

That absence compounds across three separate exposures simultaneously. On the regulatory side, the absence of an operator file is itself a distinct Article 26 violation, independent of whatever caused the underlying incident, meaning a single failure can generate two grounds for enforcement rather than one. On the civil liability side, courts assessing negligence claims look for evidence of reasonable oversight; an operator with no documentation has a materially harder case to make than one who can produce a contemporaneous record, a point explored at length in the liability decision tree published on insureyouragent.com. On the insurance side, a claim submitted by a policyholder who cannot produce the governance evidence their policy's underwriting assumed existed is far more likely to be scrutinised, delayed, or contested by the carrier.

Two of these three exposures are live today, before 2 December 2027. Civil liability under national law and the revised Product Liability Directive does not wait for the AI Act calendar, and neither does an insurer reading a claim. Only the Article 26 enforcement limb is deferred.

What to do this week

The practical starting point is not a certification engagement. It is an honest internal audit against the five elements of the operator file described above: does a current risk record exist, is there a named individual actually performing human oversight, are logs being preserved, are the provider's instructions for use on file, and does an incident protocol exist that someone could actually execute under pressure. Where any of these five is missing or stale, that is this week's work, independent of any decision about certification.

Once that foundation is credible, the Agent Certified intake process is the next conversation, structured to scope an assessment against the specific factors, agent count, governance maturity, and remediation needs, described in the certification cost guide on this site. The order matters: an assessment built on top of a genuine operator file produces a credible score quickly. An assessment attempted with no underlying documentation becomes, in practice, the process of building the operator file for the first time under a different name.

Frequently asked questions

What evidence does an EU AI Act deployer need to hold?

The minimum defensible position is the Article 26 operator file: a current risk record describing what the AI system does and its known limitations, a named individual with adequate competence assigned to human oversight, a logging practice consistent with what the system generates automatically, the instructions for use received from the provider, and a documented incident protocol. This is not a certification and does not require a third-party assessment, but it is the baseline documentation the Regulation requires a deployer to hold from the point of application, which the AI Omnibus moved to 2 December 2027 for Annex III high-risk systems. Insurers and enterprise procurement teams ask for the same five elements now, on their own schedule.

Is the EU AI Act operator file the same thing as certification?

No, but they draw on the same underlying evidence. The Article 26 operator file is a self-maintained compliance record with no independent verification requirement. Certification under a framework such as Agent Certified is a third-party assessment against a defined methodology that produces a score and a level. A deployer can hold a complete operator file without ever being certified. What makes the two connected in practice is that a well-built operator file already contains most of the evidence a certification assessment reviews, so building one is not wasted effort even for a deployer who never pursues certification.

Does the move to 2 December 2027 mean a deployer can wait?

No, for two reasons that have nothing to do with the regulatory calendar. First, the Article 26 obligations were deferred, not withdrawn, and the evidence they require is contemporaneous. A risk record and a logging practice cannot be reconstructed after the fact for a system that has already been running for a year. Second, insurance underwriters and enterprise procurement teams ask for the same governance evidence now, on their own schedule, and neither is bound by the AI Act timetable. From 2 December 2027, non-compliance with Article 26 carries Article 99 penalties of up to EUR 15 million or 3 percent of worldwide turnover for Annex III systems.

What happens if a deployer has no documentation when an incident occurs?

A deployer with no operator file at the time of an AI agent incident faces a compounded problem. First, the incident itself needs to be assessed and, where applicable, reported. Second, the absence of pre-existing documentation makes it harder to demonstrate that reasonable oversight was in place, which is directly relevant to both regulatory enforcement discretion and any negligence analysis in a related civil claim. Third, insurers responding to the claim are more likely to scrutinise or decline it where the policyholder cannot produce the governance evidence the policy's underwriting assumed existed. Building the file before an incident, not after one, is the entire point of the exercise.

References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). OJ L, 12 July 2024. Article 26 (deployer obligations), Article 73 (serious incident reporting), Article 99 (penalties), Article 113 (application dates).
  2. European Commission. AI Omnibus, entered into force 27 July 2026. Annex III high-risk obligations apply from 2 December 2027, Annex I from 2 August 2028. digital-strategy.ec.europa.eu, checked 17 August 2026.
  3. Agent Certified. Methodology specification, published at agentcertified.eu/methodology.
  4. Agent Certified. Certification levels, published at agentcertified.eu/certification-levels.
  5. EU AI Act Member State transposition and enforcement status tracker, published at agentliability.eu.
Related reading
Seven dimensions to EU AI Act map How the methodology aligns with Article 26 and beyond. Certification feeds underwriting Why the same evidence file serves compliance and coverage. Request an assessment Intake, scoping and the five step process.