GovCompass

Art. 26.8 EU AI Act: registration in the EU database

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 26.8 requires deployers that are public authorities (or act on their behalf) to verify that a high-risk AI system is registered in the EU database before putting it into use, and to refrain from using it if it is not.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: the EU AI database

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → establishes a publicly accessible EU database for high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →. Art. 49 creates registration obligations for providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →. Art. 26.8 extends a more limited registration obligation to deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry →, specifically deployers operating high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → in areas of particular public interest: public authorities and bodies deploying AI in migration, asylum, and border controlcontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry →, and in biometric identification contexts.

Who must register under Art. 26.8?

Art. 26.8 creates deployer registration obligations for:

  1. Public authorities and EU institutions deploying a high-risk system listed in Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry →, with the exception of point 2 (critical infrastructure), under Art. 26(8) read with Art. 49(3). For Annex III points 1, 6 and 7 the entry is made in a secure, non-public section of the EU database (Art. 49(4))
  2. Any deployer using a high-risk AI system where the provider is established outside the EU, in this case the deployer takes on provider-equivalent registration obligations

For most private-sector Dutch organizations deploying AI in HR, credit, or healthcare contexts: Art. 26.8 registration is not directly required. However, the provider is required to register under Art. 49, and deployers should verify that their provider has done so.

What must be registered?

Deployer registrations must include:

  • The deployer's name, registered address, and contact details
  • The registration number of the AI system (assigned by the provider's registration)
  • The deployer's use case, how and in what context the system is deployed
  • The categories of individuals affected
  • Geographic scope of deployment within the EU

Verification obligations for all deployers

Even where Art. 26.8 does not directly require deployer registration, all deployers of high-risk AI should verify that their provider has fulfilled their registration obligations under Art. 49. Request the system's EU database registration number from your provider and cross-check it against the public database once it is operational.

Compliance checklist

  1. Are any of your high-risk AI deployments in Annex III points 1, 6, 7, or 8 contexts?
  2. Is your organization a public authority? If so, Art. 26.8 registration may apply directly.
  3. Are any of your AI providers established outside the EU? If so, verify registration obligations carefully.
  4. Have you requested and verified the EU database registration number from each of your high-risk AI providers?
Legal referencesArt. 26
Share Share on LinkedIn

More on Transparency & explainability

Transparency templates for EU AI Act Art. 50: ready to use

Guide

Ready-to-use transparency templates help deployers meet the EU AI Act information duties: a chatbot disclosure, an AI-generated-content label, and an Art. 26(11) notice for individuals subject to a high-risk system. The disclosure must be active and comprehensible at the moment of interaction.

Art. 26(11) EU AI Act: informing individuals subject to high-risk AI decisions

Reference

Art. 26(11) requires deployers of high-risk AI to inform the people who are subject to the system's decisions that a high-risk AI system is being used. This applies even where there is no direct interaction, such as CV screening or credit scoring.

Art. 49 EU AI Act: registration in the EU database for providers

Reference

Art. 49 requires providers of high-risk AI systems to register the system in the EU database before placing it on the market. The database serves both market surveillance and public accountability, letting citizens see which high-risk systems are in use.

Art. 50 EU AI Act, transparency: inform users about AI interaction

Reference

Art. 50 of the EU AI Act sets four transparency duties: providers must ensure people know they are interacting with an AI system and must mark AI-generated content in a machine-readable way; deployers must inform people exposed to emotion recognition or biometric categorization and must disclose deep fakes and AI-generated text on matters of public interest. The obligations apply from 2 August 2026, with fines up to €15 million or 3% of global annual turnover, whichever is higher. One transition applies: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty.