GovCompass

Art. 26(11) EU AI Act: informing individuals subject to high-risk AI decisions

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 26(11) requires deployers of high-risk AI to inform the people who are subject to the system's decisions that a high-risk AI system is being used. This applies even where there is no direct interaction, such as CV screening or credit scoring.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: transparency as a fundamental rights requirement

Art. 26(11) provides individuals affected by high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → with a right to know. DeployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → must "inform the natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry → on whom the high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → is intended to operate that they are subject to the use of the high-risk AI system." This obligation reflects the fundamental rights principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → that people should not be subject to significant AI-driven decisions without their knowledge.

Art. 26(11) is distinct from, but overlapping with, GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry → transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → requirements. Where GDPR requires transparency about data processing, Art. 26(11) requires transparency about AI decision-making. For high-risk AI systems that also process personal data, both frameworks apply.

When does the obligation apply?

Art. 26(11) applies when a natural person is "subject to" a high-risk AI system's operation. This includes:

  • Job applicants whose CVs are screened by AI
  • Customers whose credit applications are assessed by AI
  • Students whose academic performance is evaluated by AI
  • Benefit applicants whose eligibility is assessed by AI
  • Patients whose medical imaging is analyzed by AI

The obligation applies before or at the point of the AI interaction, not retroactively after a decision has been made.

What must be communicated?

The minimum required information:

  1. That an AI system is being used in the process that affects them
  2. The purpose of the AI system
  3. The deployer's contact details for further information or objection

Best practice (aligning with GDPR transparency standards) includes additionally:

  • The type of AI system (classification, recommendation, prediction)
  • The role of the AI in the overall decision (sole basis, supporting input, one factor among many)
  • The individual's rights, including the right to request human review under GDPR Art. 22 where applicable

Exception: security and sensitive contexts

Art. 26(11) provides a limited exception: where notifying the individual would compromise the purpose of the AI system. The clearest example is law enforcement contexts where advance notification would enable suspects to evade detection. However, this exception is narrow and must be proportionate, it cannot be used as a blanket exclusion for commercial contexts.

Notification template

Example for HR context (CV screening):

"[Organization name] uses an AI-assisted screening system to review applications. This system analyzes your application against the role requirements and produces a preliminary assessment. All AI assessments are reviewed by a human recruiter before any decision is made. For more information about how this system works or to raise a concern, contact [contact details]."

Compliance checklist

  1. Have you mapped every point in your processes where individuals are subject to high-risk AI?
  2. Is a notification in place for each such touchpoint?
  3. Is the notification provided before or at the point of the AI interaction?
  4. Does the notification cover at minimum: AI use, purpose, and contact details?
  5. Is the exception for sensitive contexts documented with a legal justification if you rely on it?
  6. Is the Art. 26(11) notification coordinated with your GDPR privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry → notice?
Legal referencesArt. 26
Share Share on LinkedIn

More on Transparency & explainability

Transparency templates for EU AI Act Art. 50: ready to use

Guide

Ready-to-use transparency templates help deployers meet the EU AI Act information duties: a chatbot disclosure, an AI-generated-content label, and an Art. 26(11) notice for individuals subject to a high-risk system. The disclosure must be active and comprehensible at the moment of interaction.

Art. 26.8 EU AI Act: registration in the EU database

Reference

Art. 26.8 requires deployers that are public authorities (or act on their behalf) to verify that a high-risk AI system is registered in the EU database before putting it into use, and to refrain from using it if it is not.

Art. 49 EU AI Act: registration in the EU database for providers

Reference

Art. 49 requires providers of high-risk AI systems to register the system in the EU database before placing it on the market. The database serves both market surveillance and public accountability, letting citizens see which high-risk systems are in use.

Art. 50 EU AI Act, transparency: inform users about AI interaction

Reference

Art. 50 of the EU AI Act sets four transparency duties: providers must ensure people know they are interacting with an AI system and must mark AI-generated content in a machine-readable way; deployers must inform people exposed to emotion recognition or biometric categorization and must disclose deep fakes and AI-generated text on matters of public interest. The obligations apply from 2 August 2026, with fines up to €15 million or 3% of global annual turnover, whichever is higher. One transition applies: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty.