Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Who is accountable for each AI system?

Updated

Article 14 of Regulation (EU) 2024/1689 requires high-risk systems to be effectively overseen by natural persons; Article 26(2) requires deployers to assign that oversight to competent people. ISO/IEC 42001:2023 accountability is a standard. Not legal advice. Naming an owner is not Article 14 compliance.

AI ownership and accountability, last verified 10 September 2026 against Articles 3(56), 4, 14, 26 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not assign YOUR overseers.

This is Articles 4, 14 and 26, not YOUR org chart

Audience: an engineering manager, CISO, compliance lead, or product owner deciding who is answerable for each AI system the organisation builds or uses. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not assign overseers and does not file with the AI Office.

The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 4 is AI literacy, in force from 2 February 2025 under Article 113(a) because Article 4 sits in Chapter I. Article 14 is human oversight of high-risk AI systems, a design-and-development requirement on the provider. Article 26(2) is the deployer duty to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Those are not the same duty and they do not fall on the same party. Last verified 10 September 2026. Not legal advice.

  • Statute versus standard versus guidance versus product: Articles 3(56), 4, 14, 26 and 113 of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 accountability and top-management commitment are a management-system standard, not a legal substitute for the Act. NIST AI RMF 1.0 Govern function material is guidance, not law. The RACI below is a ShipReadyMetrics recommendation. This page labels which kind of text each claim rests on.
  • The EU AI Act overview on this site is the pillar page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
  • This page does not invent a 2 August 2026 start date for Article 4. Article 113(a) applies Chapters I and II from 2 February 2025. Article 14 and Article 26 sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027. This page does not invent a 2 August 2026 date for Annex I.

Article 14 is a legal duty; ISO 42001 accountability is practice

Do not collapse them. Article 14 tells a provider to design a high-risk system so that natural persons can effectively oversee it, and Article 26(2) tells a deployer to put competent, trained, empowered, supported people in that seat. ISO/IEC 42001:2023 asks an organisation to define roles, responsibilities and authorities as part of a management system — useful, and not the Act. Last verified 10 September 2026. Not legal advice.

Legal oversight duty versus standard accountability practice (not YOUR assignment; not a determination that YOUR system is high-risk; not legal advice)
SourceWhat the cited text isKind of textLast verified
Article 14 of 2024/1689 — human oversight by designAuthentic Article 14(1): High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use. Article 14(4) enumerates what the assigned person must be enabled to do, including understanding capacities and limitations, remaining aware of automation bias, correctly interpreting output, deciding not to use the system or to disregard, override or reverse its output, and intervening or interrupting through a stop button or similar procedure.Article 14 of 2024/1689. Legal requirement, only if it applies. It binds the design of the system, not an org chart. This page does not design YOUR interface.10 September 2026
Article 26(2) of 2024/1689 — the deployer assigns the humansAuthentic Article 26(2): Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Competence, training, authority and support are four separate words; an owner with the title but no authority does not satisfy the sentence.Article 26(2) of 2024/1689. Legal requirement, only if it applies. Distinct from the Article 14 design measures. This product does not assign YOUR overseers.10 September 2026
Article 4 and Article 3(56) of 2024/1689 — AI literacyAuthentic Article 4: Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. Article 3(56) defines AI literacy.Articles 3(56) and 4 of 2024/1689. Legal requirement, only if it applies. In force from 2 February 2025 under Article 113(a) — not 2 August 2026. This page does not run YOUR literacy programme.10 September 2026
ISO/IEC 42001:2023 — roles, responsibilities and authoritiesThe standard's leadership clause asks top management to demonstrate commitment and to assign responsibilities and authorities for relevant roles, and its Annex A control areas include internal organisation and policies related to AI. That is accountability practice. It is certifiable by an accredited certification body.ISO/IEC 42001:2023. Best practice / standard, not a legal substitute for the Act. An ISO 42001 certificate is not CE marking, is not an Article 43 conformity assessment, and does not discharge Article 14 or Article 26.10 September 2026
NIST AI RMF 1.0 Govern functionNIST AI 100-1, January 2023, describes accountability structures, roles and responsibilities as part of governing AI risk. Voluntary US agency guidance.Guidance, not law. Not Regulation (EU) 2024/1689 and not ISO/IEC 42001:2023.10 September 2026

A RACI example — an illustration, not YOUR allocation

The rows below are one worked example for a single high-risk AI system that an organisation deploys from an external provider. It is a ShipReadyMetrics recommendation offered as a starting point. It is not a determination that YOU are a deployer, that YOUR system is high-risk, or that these are the right roles for your organisation. Article 25 allows the value-chain allocation to be settled contractually; counsel reads that contract. Last verified 10 September 2026. Not legal advice.

Example RACI for one deployed high-risk system (an illustration; not YOUR allocation; not legal advice)
ActivityResponsible / AccountableConsulted / InformedKind of text
Keeping the inventory row accurate — purpose, tier, provider posture, GPAI flagsResponsible: the named system owner. Accountable: the compliance owner who owns the register.Consulted: engineering lead, procurement. Informed: security, legal.ShipReadyMetrics recommendation. Mirrors Annex VIII field shapes; not an Article 49 registration.
Assigning the natural persons who exercise oversight, and confirming they have authority to stop the systemResponsible: the named system owner. Accountable: the executive who can actually authorise a stop.Consulted: counsel, HR for workplace effects. Informed: the oversight persons themselves.Mirrors Article 26(2) of 2024/1689 (legal requirement, only if it applies). Assigning a name is not compliance with it.
Holding the provider's instructions for use and conformity basis for a deployed systemResponsible: procurement or vendor management. Accountable: the compliance owner.Consulted: counsel. Informed: the system owner, security.Mirrors Article 26(1) of 2024/1689 (legal requirement, only if it applies). Holding a document is not a conformity determination.
AI literacy for the people who operate or are affected by the systemResponsible: the people manager for each affected team. Accountable: an executive sponsor.Consulted: legal, learning and development. Informed: works council or workers' representatives where relevant.Mirrors Articles 3(56) and 4 of 2024/1689 (legal requirement, only if it applies; in force 2 February 2025 under Article 113(a)).
Keeping automatically generated logs for as long as the applicable duty requiresResponsible: the engineering owner of the system. Accountable: the compliance owner.Consulted: data protection, security. Informed: the system owner.Mirrors Articles 12, 19 and 26(6) of 2024/1689 (legal requirements, only if they apply). The evidence-retention-checklist guide on this site is that page.
Deciding whether an event is a reportable serious incident, and reporting itResponsible: incident response. Accountable: counsel, with the executive who signs.Consulted: the system owner, the provider. Informed: security leadership.Mirrors Articles 3(49), 55(1)(c) and 73 of 2024/1689 (legal requirements, only if they apply). The AI-incident-reporting guide on this site is that page. No product starts a clock.
Deciding whether the Act applies at all, and in which roleResponsible: counsel. Accountable: counsel.Consulted: compliance, engineering, product. Informed: everyone above.Legal question on YOUR facts. No page, register, or product answers it. This page does not determine that YOU are a provider or a deployer.

Ownership checklist

This is a question list, not a determination that Article 14 or Article 26 binds YOU, and not a filing. Walk it with counsel. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page.

  • Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
  • For each system, is there one named natural person — not a team, not a mailbox — who is answerable for it? A register that stores a squad name has not answered the question.
  • Does that person have the competence, training, authority and support that Article 26(2) names, if that article applies? Authority means they can stop the system without asking anyone.
  • Is oversight actually possible in the product, or only on paper? Article 14(1) is about the system being designed so that it can be effectively overseen, and Article 14(4)(e) names a stop button or a similar procedure that brings the system to a halt in a safe state.
  • Has anyone written down what the overseer is expected to do when the output looks wrong, and what happens if they are overruled? Automation bias is named in Article 14(4)(b), only if that article applies.
  • Who owns AI literacy for the people who operate or are affected by each system? Article 4 has applied since 2 February 2025 under Article 113(a), not 2 August 2026.
  • Does assigning an owner in a product make YOU compliant with Article 14? No. It records a fact the organisation entered.
  • Does an ISO/IEC 42001:2023 accountability structure discharge Article 14 or Article 26? No. It is a standard, not a legal substitute for the Act.
  • Document the assessment, including a no-owner-yet and a not-in-scope decision. This page does not keep YOUR file.

Legal requirement versus guidance versus ShipReady recommendation

The table below labels each text. Do not treat a role assignment as an oversight measure, do not treat a standard as the article, and do not treat a product surface as a determination. Last verified 10 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 10 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689 Articles 14 and 26(2)Legal requirement — human oversight by design, and the deployer's assignment of competent, trained, authorised, supported natural persons, only if they apply.Does not determine that YOUR system is high-risk, does not assign YOUR overseers, and does not treat an owner field as compliance.
Regulation (EU) 2024/1689 Articles 3(56) and 4Legal requirement — AI literacy measures by providers and deployers, only if it applies. In force from 2 February 2025 under Article 113(a).Does not run YOUR literacy programme and does not date Article 4 from 2 August 2026.
Regulation (EU) 2024/1689 Articles 25 and 113Legal requirements — value-chain responsibility allocation, and the application dates. Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027.Does not write YOUR Article 25 agreement and does not invent a 2 August 2026 date for Annex I.
ISO/IEC 42001:2023Best practice / standard. Leadership, roles, responsibilities and authorities within an AI management system. Not a legal substitute for the Act.Does not treat an ISO 42001 accountability model, or a certificate, as discharging Article 14 or Article 26.
NIST AI RMF 1.0 (NIST AI 100-1, January 2023)Guidance, not law. Voluntary US agency framework with a Govern function covering accountability structures.Does not treat a Govern-function activity as an AI Act duty.
European Commission AI Act pages and AI Office materialsCommission materials. Guidance, not the regulation.Does not treat a Commission page as rewriting Article 4, Article 14, or Article 26.
This product's owner assignment on the AI inventoryShipReady recommendation: an ownerUserId recorded against a registered system, so an unowned system is a visible gap rather than a silence. Not a legal determination.Assigning ownerUserId is not Article 14 compliance, is not an Article 26(2) assignment, and is not a finding that oversight is effective. A named human still owns the assessment.

What to do now

As of last verification on 10 September 2026, Article 4 AI literacy has applied since 2 February 2025 under Article 113(a). Article 14 and Article 26 sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation. It is not a determination that those articles bind YOU. Walk it with counsel.

  • Give every row in the inventory a named human before you add another field to the schema. An unowned system is the finding, and it should be visible as one.
  • Separate the two questions an org chart usually blurs: who is answerable for the system existing, and who is in the seat when it produces an output that looks wrong. Article 26(2), if it applies, is about the second.
  • Check that the person named can actually stop the system. If they cannot, the authority element of Article 26(2) is missing, whatever the title says.
  • Ask counsel whether YOU are a provider or a deployer for each system, and whether Article 14 or Article 26 applies. This page does not run that test. Marking eu_ai_act in an obligation map is not that determination.
  • The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The how-shipreadymetrics-builds-ai-inventory guide on this site is the product page for the register. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register. An administrator can assign an owner to each registered system, and a system with no owner reads as an accountability gap rather than a pass. That assignment is a fact the organisation recorded. It is not an Article 26(2) assignment of human oversight, it is not Article 14 compliance, and it is not a determination that YOUR system is high-risk. Marking in-scope is not applicability. A named human still owns the assessment.

The register also records whether a human-oversight artefact exists for each high-risk system. Recording that artefact is not a finding that oversight is effective, that the overseers are competent, or that they have authority. This product does not assign overseers, does not run an Article 4 literacy programme, does not file with the AI Office, does not register in the EU database, does not issue certifications, and does not affix CE marks. The obligation map lists frameworks the organisation has marked in-scope. The cyber risk register lives under Security and is a different register.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 10 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 3(56), 4, 14, 25, 26 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated map of AI ownership and oversight distilled from Regulation (EU) 2024/1689 Articles 4, 14 and 26, with ISO/IEC 42001:2023 labelled as a standard and NIST AI RMF labelled as guidance, not the regulation. Whether those articles apply to YOU, and who has to be in the oversight seat, are legal questions for counsel on your facts. This page does not start a clock.

Does assigning an owner make us compliant with Article 14?

No. Article 14 of Regulation (EU) 2024/1689 is a design-and-development requirement: a high-risk AI system must be built so that natural persons can effectively oversee it, with the enabling measures Article 14(4) lists. An owner field in a register — including ownerUserId in this product — records a fact the organisation entered. It is not an oversight measure, it is not an Article 26(2) assignment, and it is not a finding that oversight is effective.

Is Article 14 the same duty as Article 26(2)?

No. Article 14 falls on the design of a high-risk AI system and is addressed to the provider building it. Article 26(2) falls on the deployer using it, and requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. A deployer that names a person cannot cure a system that was never designed to be overseen, and a provider's design does not choose the deployer's people. Last verified 10 September 2026.

Does ISO 42001 accountability discharge the EU AI Act?

No. ISO/IEC 42001:2023 is a voluntary management-system standard whose leadership clause asks top management to assign responsibilities and authorities. The AI Act is Regulation (EU) 2024/1689. Holding an ISO 42001 certificate is not CE marking, is not an Article 43 conformity assessment, and does not discharge Article 4, Article 14, or Article 26. Last verified 10 September 2026.

Did Article 4 AI literacy start on 2 August 2026?

No. Article 113(a) of Regulation (EU) 2024/1689 applies Chapters I and II from 2 February 2025, and Article 4 sits in Chapter I. Article 14 and Article 26 sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. Those dates are not one number. Last verified 10 September 2026.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.