Answers
What does Article 26 of the EU AI Act require of teams on human oversight?
Article 26 sets the duties of whoever uses a high-risk AI system in their own work — the deployer, as opposed to the vendor who built it. Two of those duties are about people and records: oversight has to be assigned to named people with the competence, training and authority to exercise it, and the logs the system generates have to be kept, as far as they are under your control, for at least six months. It is not due yet. The high-risk obligations were postponed to 2 December 2027 for the systems listed in Annex III — hiring, credit, education, access to essential services and the like — and to 2 August 2028 for AI built into products already covered by EU safety law; only the transparency duties have applied since 2 August 2026. So this is preparation, with more than a year of room. A human-oversight record should show who holds oversight and with what authority, which rules the AI worked under and since when, what changed and who changed it, and what each AI read before it acted. Arroway keeps that human side of the record; it does not replace the system's own logs, and it is not a compliance report.
Last updated September 28, 2026
Most AI use at work is not in scope — check before you prepare
Article 26 applies to high-risk systems, and high-risk is a defined list, not a feeling. An assistant drafting code, summarising meetings or answering customers is usually not on it. A system that screens job applicants, scores creditworthiness, grades students or decides access to public services usually is. The first step is therefore to list where your team uses AI and mark which uses fall in those categories. For the ones that do, the questions that follow are concrete: who is the person watching it, what are they allowed to stop, and where is it written down.
What a human-oversight record has to show
Four things, each tied to a date. Who holds the oversight role for each use, and what they are allowed to decide — a name and a scope, not a department. The rules the AI operates under: thresholds, when a human must review, what it must never do on its own. Every change to those rules, with who approved it and what it replaced, so the rule in force on any past day can be reconstructed. And what the AI was given before it acted, so that "it followed the rule" can be checked rather than assumed. A folder of meeting notes holds some of this; what it cannot show is which version was in force when, and who made it so.
What Arroway holds, and what it does not
Arroway holds the rules and decisions a team gives its AIs: each one with the person who approved it and the date, the condition that ends it, and the one it replaced, while what an assistant proposed stays visibly a proposal until a person approves it. Nothing is overwritten: a retired rule leaves the AI's read and stays in the history, with who retired it and why. Arroway also records what each read delivered to an AI — kept for 90 days, which is shorter than the six months Article 26 asks for the system's logs, so it is not a substitute for them. Those logs come from the high-risk system and its provider; Arroway does not see that system. There is no ready-made oversight report to export today. Where the data lives and who processes it is on the trust page.
What it looks like in practice
A company uses an AI tool to shortlist job applicants — an Annex III use. The head of recruiting is named as the person with oversight. In February she decides that any applicant the tool ranks below the cut-off gets a human review before rejection. In May she lowers the cut-off after complaints that good candidates were being dropped. In 2028 an authority asks what rule applied to an applicant rejected in April, and who had the power to change it. With the decision in a chat thread and the change in a spreadsheet, the answer is a reconstruction. In Arroway, February's rule carries her name and date; May's rule is recorded as replacing it, with her name again; the assistants the team uses to prepare shortlists read only the rule in force. The April answer is the February rule, with the history showing when it ended and who ended it. The tool's own screening logs are a separate record, kept by its provider.
Questions people ask about this
- Does using Arroway make us compliant with Article 26?
- No. Compliance is a set of duties your organisation carries — competent people, following the provider's instructions, monitoring, incident reporting, keeping the system's logs, informing workers — and no tool discharges them for you. Arroway keeps the part of the record that is about people deciding: who decided, with what authority, what was in force and what was retired. This page is not legal advice; your counsel decides what applies to you.
- When do we actually need this?
- The Annex III obligations apply from 2 December 2027, and those for AI embedded in regulated products from 2 August 2028. The transparency duties apply from 2 August 2026. A record of who decided what only helps if it starts before the question is asked, which is the argument for starting it early; it is not a deadline that has arrived.
- Who audits Arroway itself?
- The trust page on this site says where the data lives, how it is protected, which providers touch it, how long each part is kept and how it is deleted — each line taken from what the system does today. Arroway does not claim a certification it does not hold.
Where this is verifiable
Regulation (EU) 2024/1689 (the AI Act), Article 26 on the obligations of deployers of high-risk AI systems and Annex III on high-risk uses; Regulation (EU) 2026/1744, which postponed the high-risk dates; the trust page on this site, including the 90-day retention of read records; and the sanction, supersession and expiry-condition rules in the sanctioned product spec. This page summarises the regulation for preparation and is not legal advice. Everything described here about Arroway is behaviour the tools apply today, not roadmap.
https://www.arroway.app/en/answers/eu-ai-act-article-26-human-oversight-record