Deployer obligations under the EU AI Act for AI agents: Article 26 and the FRIA under Article 27
Most banks that run an AI agent did not build it. They licensed it, configured it and put it in front of customers. Under the EU AI Act, Regulation (EU) 2024/1689, that makes them deployers. The AI Act deployer obligations for high-risk systems sit in Article 26, and the fundamental rights impact assessment, the FRIA, in Article 27. Both apply to Annex III high-risk systems from 2 December 2027. This article reads them for an AI agent that answers, recommends or acts for a bank, often by calling tools. It is not legal advice.
Who is a deployer
Article 3 defines both roles.
(3) ‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge; (4) ‘deployer’ means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity; (Article 3(3) and (4))
The test is authority, not ownership. A bank that runs a vendor's agent on its own customers is the deployer. The vendor that placed the agent on the market is the provider. Under Article 111(2), a system put into service before 2 December 2027 falls under the Chapter III duties only if its design changes significantly afterwards.
Article 26 applies only to high-risk systems. A customer-service agent that explains products is not on the Annex III list. It becomes high-risk when it evaluates the creditworthiness of a natural person or sets a credit score (Annex III, point 5(b), fraud detection excepted). Article 50 applies either way, and has since 2 August 2026.
The Article 26 duties one by one
Paragraph 8 concerns public authorities and paragraph 10 law enforcement, so neither concerns a private bank. The rest apply, with two carve-outs for financial institutions.
Use the system as the instructions say (Article 26(1))
Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. (Article 26(1))
The instructions for use are the provider's Article 13 document: the intended purpose, the known limitations, the accuracy tested and the oversight measures you are expected to implement. Obtain them, then compare them with the agent as configured: which tools it can call, which data it can read, which customers it faces. Closing that gap is the duty.
Assign human oversight to named people (Article 26(2) and (3))
Oversight goes to natural persons with the necessary competence, training, authority and support. Under Article 14(4) they must be able to understand the system's limits, interpret its output, decide not to use it and stop it. For an agent, that means someone who can read its tool calls and switch it off.
Keep input data relevant and representative (Article 26(4))
To the extent you control the input data, it must be relevant and sufficiently representative for the intended purpose. For an agent with retrieval, the corpus it reads is input data you control.
Monitor, report and suspend (Article 26(5))
Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. ... For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law. (Article 26(5))
Where you have reason to consider that use in line with the instructions may present a risk within the meaning of Article 79(1), you must inform the provider or distributor and the market surveillance authority without undue delay, and suspend use. The deemed-fulfilled clause covers monitoring only: your internal-control rules can carry it, but the escalation path has to exist on its own.
Keep the logs for at least six months (Article 26(6))
Logs under your control must be kept for a period appropriate to the intended purpose, and for at least six months, unless other Union or national law provides otherwise. Financial institutions keep them with the documentation they already hold under financial services law. For an agent, the log that matters is the sequence of tool calls, with inputs and outputs, tied to a version of the agent. If the vendor holds it, the contract must say how you get it.
Inform workers and the people affected (Article 26(7) and (11))
Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. (Article 26(11))
This is separate from the Article 50 duty to say that someone is talking to an AI system. A customer whose loan application an agent scores must be told that a high-risk system is used on them. Under paragraph 7, an employer must inform workers' representatives and the affected workers before a high-risk system is put into service at the workplace.
Two shorter duties (Article 26(9) and (12))
Where a data protection impact assessment is required, the deployer carries it out using the Article 13 information from the provider (paragraph 9), so the DPO should hold the instructions for use. Deployers cooperate with the competent authorities in any action they take on the system (paragraph 12).
When a deployer becomes a provider (Article 25)
Under Article 25(1) a deployer becomes the provider of a high-risk system, with the Article 16 duties, in three cases: putting its own name or trademark on a high-risk system already on the market; making a substantial modification to one; and modifying the intended purpose of a system that was not high-risk, including a general-purpose AI system, so that it becomes high-risk under Article 6. The third catches AI agents. Giving a general-purpose assistant a tool that reads a credit file and asking it to recommend a decision changes the intended purpose. The bank is now the provider of an Annex III, point 5(b) system, and owes the Section 2 requirements and a conformity assessment before the system is put into service. Article 17(4) deems a financial institution's quality management system fulfilled by the governance rules of financial services law, except for risk management, post-market monitoring and serious incident reporting.
Article 25(2) gives the new provider something in return. The initial provider must cooperate closely, make available the necessary information, including the technical documentation and the known limitations and failure modes, and give reasonable technical access, unless it has clearly specified that its system is not to be changed into a high-risk one. Read the vendor's terms for that clause before you change what the agent does.
The fundamental rights impact assessment
Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of: (a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13; (e) a description of the implementation of human oversight measures, according to the instructions for use; (f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms. (Article 27(1))
Three groups must carry out a FRIA: public bodies, private entities providing public services, and deployers of Annex III, point 5(b) and 5(c) systems. Point 5(b) covers creditworthiness evaluation and credit scoring of natural persons, except fraud detection. Point 5(c) covers risk assessment and pricing for natural persons in life and health insurance. A retail bank that scores consumer credit with an agent is in. A bank using an agent to allocate tasks to staff, which may be high-risk under point 4, is not, unless it provides a public service.
The duty attaches to the first use. You may rely on earlier FRIAs or on the provider's impact assessments in similar cases, and must update the assessment when any element changes (Article 27(2)). You notify the market surveillance authority of the results (Article 27(3)) and may cross-reference the DPIA (Article 27(4)).
What to document before December 2027
Article 26 asks for measures, people, monitoring and logs, not for a report. A supervisor will still ask you to show what you did.
- A register of AI systems with, for each one, your role, the Annex III point that applies and the reasoning.
- The instructions for use, dated and versioned, mapped to the internal controls that implement them (Article 26(1)).
- The people assigned to oversight, their training and authority, and the procedure to stop the agent (Article 26(2)).
- The monitoring procedure, the governance rule it relies on, and the escalation path with the suspension criteria (Article 26(5)).
- The log retention design: what is captured, including tool calls, who holds it and for how long (Article 26(6)).
- The customer and worker notices, the DPIA and, for point 5(b) and 5(c) systems, the FRIA and its notification (Articles 26(7), (9), (11) and 27).
- Test results showing that the agent behaves as the instructions for use say, on the version you run.
The last item is the one most teams lack. A separate article covers what an evidence pack should contain.
A checklist for a bank
- Classify each agent. If it evaluates creditworthiness or sets a credit score for natural persons, it is Annex III, point 5(b).
- Decide your role: deployer only, or provider under Article 25(1).
- Obtain the instructions for use. If you cannot, record that as a finding.
- Assign oversight to named people with the authority to stop the agent, and record their training.
- Map Article 26(5) monitoring onto the governance rules you already follow, and write down the escalation and suspension path.
- Confirm log retention of at least six months, including tool calls.
- Draft the customer notice under Article 26(11) alongside the Article 50 disclosure that already applies.
- For a point 5(b) system, carry out the FRIA before first use, notify the authority and cross-reference the DPIA.
- Test the agent against each duty on the version you run, and repeat when the model, the prompt, the tools or the corpus change.
DORA, Regulation (EU) 2022/2554, has applied to financial entities since 17 January 2025 and reaches the same agent through its rules on ICT risk, incidents and third-party providers.
Vidimus turns each applicable article into tests, runs them against the live agent, records its tool calls, grades every answer with a separate grading model, has a human reviewer confirm the result and issues a versioned, signed evidence pack. It does not certify compliance and gives no legal advice. The free EU AI Act risk classifier gives an indicative risk class and the AI Act deployer obligations that follow from it.