EU AI Act — the deployer is accountable for what an AI agent does. VINCHY gives you the oversight + records to prove it.
How it works Features Roadmap EU AI Act Sign in Create free account
EU AI Act · Article 26 · Deployer obligations

EU AI Act Article 26 compliance for AI deployers

Article 26 makes the deployer — the organisation that runs an AI agent — accountable for what it does. From 2 August 2026, you need human oversight, monitoring and provable records. VINCHY is the control layer that gives you all three.

EU-hosted · tamper-evident audit · works with Zapier, n8n, Make & custom agents
€35M / 7%
EU AI Act maximum penalties (deployer breaches: up to €15M / 3%)
6 months
minimum log retention for deployers — Article 26(6)
Aug 2026
when high-risk deployer obligations apply
/// The Article 26 checklist

What Article 26 asks of you — and how VINCHY answers

Article 26 of the EU AI Act lists the obligations of deployers of high-risk AI systems. Here are the core duties, each mapped to a VINCHY capability.

Article 26(2) · Human oversight

Assign competent humans to oversee the AI

VINCHY holds every risky action at a human-approval gate before it runs. Each agent has a named, accountable owner; trust levels decide how much runs automatically; irreversible actions — send, pay, delete — always wait for a person.

Article 26(1) · Use per instructions

Take technical & organisational measures for proper use

A policy engine encodes per-action rules and organisational guardrails. Actions outside policy are blocked or escalated to a human — so the agent is used the way it is meant to be.

Article 26(5) · Monitoring

Monitor operation and act on risks

A live dashboard shows every agent, its pending actions and an overturn-rate governance metric. Spot a problem and pause or disable any agent instantly.

Article 26(6) · Logging & retention

Keep the automatically generated logs for ≥ 6 months

Every action is written to a tamper-evident, cryptographically signed (Ed25519) hash-chained audit trail, retained for at least six months. If a record is altered, verification breaks — so the log is provable, not just present.

Article 26(5) · Incident readiness

Reconstruct and report serious incidents

Because every action carries who proposed it, who approved it and when, you can reconstruct exactly what happened and report it to the provider or authorities without guesswork.

Article 26(11) · Inform affected persons

Show what the agent did and who decided

Per-action records — the action, its justification and the human decision behind it — give you the basis to inform people affected by an AI-assisted decision.

Article 26(12) · Cooperate with authorities

Hand over audit-ready evidence on request

One click exports an EU AI Act gap report, a Trust report and a human-readable audit timeline as PDF — the evidence an authority or auditor asks for, ready to hand over.

Article 26(8) · DPIA input · with Art. 13

Record which model ran, and where

VINCHY logs the model behind each action (Mistral, Claude, GPT-4o, Gemini, Llama, GLM…) and its hosting region — transparency information that feeds your data protection impact assessment.

They log what happened.
VINCHY controls what happens.

Provider logging — Article 12

Most AI compliance tools record what an agent did, after the fact — a flight recorder for the system's builder. Useful, but it cannot stop a wrong action.

Deployer governance — Article 26

VINCHY governs what an agent is allowed to do: a human approves risky actions before they run, and every decision is sealed in a tamper-evident record. Prevention, not just a recording.

/// Start in minutes

Free to start. No credit card.

Connect an agent, route its risky actions through VINCHY, and watch a clean audit trail build itself.

Home
Free
For individuals running personal AI agents. Human-approval gate + audit trail.
Business
Pilot
For companies that are EU AI Act deployers. Article 26 framing, compliance reports, team approvals.
Start free
/// FAQ

EU AI Act Article 26 — frequently asked questions

What is Article 26 of the EU AI Act?

Article 26 sets out the obligations of deployers of high-risk AI systems. A deployer is any organisation that uses an AI system under its own authority. The duties include assigning competent human oversight, using the system according to the provider's instructions, monitoring its operation, keeping the automatically generated logs for at least six months, informing affected persons and workers, and cooperating with authorities.

Who is a "deployer" under the EU AI Act?

A deployer is the person or company that uses an AI system in its business — as opposed to the provider, who builds it or places it on the market. If your company runs AI agents to get work done, you are the deployer, and Article 26 obligations can apply to you.

When do Article 26 obligations apply?

The EU AI Act entered into force in August 2024. The obligations for high-risk AI systems, including the Article 26 deployer duties, apply from 2 August 2026.

What's the difference between Article 12 and Article 26?

Article 12 is a provider duty — the builder must enable automatic event logging. Article 26 is a deployer duty — the user must provide human oversight, monitor the system, keep logs and stay accountable. Different parties, different responsibilities. VINCHY focuses on the deployer side.

How long must deployers keep AI logs?

Under Article 26(6), deployers must keep the logs automatically generated by a high-risk AI system, where those logs are under their control, for a period appropriate to the purpose and at least six months, unless other law says otherwise.

What are the penalties for non-compliance?

The Act's maximum penalties reach €35 million or 7% of worldwide annual turnover for prohibited practices. Breaches of deployer obligations are subject to fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

How does VINCHY help with Article 26?

VINCHY is a control layer for AI agents. It holds risky actions for human approval before they run, records every action on a tamper-evident, signed audit trail kept for at least six months, lets you monitor and pause agents, and exports auditor-ready reports. It works with agents from Zapier, n8n, Make and custom tools — no code changes.

Do all AI agents fall under Article 26?

No. Article 26 applies to deployers of high-risk AI systems as defined by the Act. Whether a given agent is high-risk depends on its use case. VINCHY's control-and-evidence posture is useful either way — and it is exactly what you need if your use is high-risk.

Govern your AI agents before August 2026

See, approve and prove every action your AI agents take — and meet your Article 26 deployer obligations.

Create free account