Article 26 makes the deployer — the organisation that runs an AI agent — accountable for what it does. From 2 August 2026, you need human oversight, monitoring and provable records. VINCHY is the control layer that gives you all three.
Article 26 of the EU AI Act lists the obligations of deployers of high-risk AI systems. Here are the core duties, each mapped to a VINCHY capability.
VINCHY holds every risky action at a human-approval gate before it runs. Each agent has a named, accountable owner; trust levels decide how much runs automatically; irreversible actions — send, pay, delete — always wait for a person.
A policy engine encodes per-action rules and organisational guardrails. Actions outside policy are blocked or escalated to a human — so the agent is used the way it is meant to be.
A live dashboard shows every agent, its pending actions and an overturn-rate governance metric. Spot a problem and pause or disable any agent instantly.
Every action is written to a tamper-evident, cryptographically signed (Ed25519) hash-chained audit trail, retained for at least six months. If a record is altered, verification breaks — so the log is provable, not just present.
Because every action carries who proposed it, who approved it and when, you can reconstruct exactly what happened and report it to the provider or authorities without guesswork.
Per-action records — the action, its justification and the human decision behind it — give you the basis to inform people affected by an AI-assisted decision.
One click exports an EU AI Act gap report, a Trust report and a human-readable audit timeline as PDF — the evidence an authority or auditor asks for, ready to hand over.
VINCHY logs the model behind each action (Mistral, Claude, GPT-4o, Gemini, Llama, GLM…) and its hosting region — transparency information that feeds your data protection impact assessment.
Most AI compliance tools record what an agent did, after the fact — a flight recorder for the system's builder. Useful, but it cannot stop a wrong action.
VINCHY governs what an agent is allowed to do: a human approves risky actions before they run, and every decision is sealed in a tamper-evident record. Prevention, not just a recording.
Connect an agent, route its risky actions through VINCHY, and watch a clean audit trail build itself.
Article 26 sets out the obligations of deployers of high-risk AI systems. A deployer is any organisation that uses an AI system under its own authority. The duties include assigning competent human oversight, using the system according to the provider's instructions, monitoring its operation, keeping the automatically generated logs for at least six months, informing affected persons and workers, and cooperating with authorities.
A deployer is the person or company that uses an AI system in its business — as opposed to the provider, who builds it or places it on the market. If your company runs AI agents to get work done, you are the deployer, and Article 26 obligations can apply to you.
The EU AI Act entered into force in August 2024. The obligations for high-risk AI systems, including the Article 26 deployer duties, apply from 2 August 2026.
Article 12 is a provider duty — the builder must enable automatic event logging. Article 26 is a deployer duty — the user must provide human oversight, monitor the system, keep logs and stay accountable. Different parties, different responsibilities. VINCHY focuses on the deployer side.
Under Article 26(6), deployers must keep the logs automatically generated by a high-risk AI system, where those logs are under their control, for a period appropriate to the purpose and at least six months, unless other law says otherwise.
The Act's maximum penalties reach €35 million or 7% of worldwide annual turnover for prohibited practices. Breaches of deployer obligations are subject to fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
VINCHY is a control layer for AI agents. It holds risky actions for human approval before they run, records every action on a tamper-evident, signed audit trail kept for at least six months, lets you monitor and pause agents, and exports auditor-ready reports. It works with agents from Zapier, n8n, Make and custom tools — no code changes.
No. Article 26 applies to deployers of high-risk AI systems as defined by the Act. Whether a given agent is high-risk depends on its use case. VINCHY's control-and-evidence posture is useful either way — and it is exactly what you need if your use is high-risk.
See, approve and prove every action your AI agents take — and meet your Article 26 deployer obligations.
Create free account