TL;DR: Article 13 imposes a two-level transparency obligation. Providers must give deployers detailed instructions for use that describe system capabilities, limitations, and output reliability conditions. Deployers must use the system within those instructions and must inform end users that they are subject to an AI system. Both obligations are enforceable from August 2027 for new high-risk systems.
Article 13 of the EU AI Act is the transparency provision for high-risk AI systems. It sits between the provider's technical obligations (the risk management system in Article 9, the data governance requirements in Article 10) and the deployer's operational obligations (human oversight in Article 14, accuracy monitoring in Article 15). Understanding Article 13 requires understanding both sides of the supply chain, because the obligation runs in sequence: provider to deployer, deployer to end user.
This guide explains both levels of the obligation, what the instructions for use document must contain, how transparency requirements interact with GDPR Article 22, and what adequate user notification looks like in practice.
Article 13 overview: two levels of transparency
Article 13 establishes a two-level transparency structure for high-risk AI systems.
At the first level, providers must design and develop their systems so that "their operation is sufficiently transparent to enable deployers to understand the system's functioning and implement it appropriately." This is a design obligation, not just a documentation one. A system that cannot produce usable transparency information is non-compliant with Article 13 regardless of what paperwork accompanies it.
At the second level, deployers must inform natural persons subject to the system's outputs that they are being assessed or processed by a high-risk AI system, in a clear and comprehensible way. The exception covers cases where EU or national law requires confidentiality, primarily law enforcement contexts.
The two levels are separately enforceable. A provider with deficient instructions violates Article 13 even if the deployer handles notification correctly. A deployer who fails to notify users violates Article 13 even if the provider's documentation is complete.
Provider obligations: the instructions for use
The instructions for use are the primary Article 13 deliverable for providers. Every high-risk AI system must be accompanied by instructions for use that meet the content requirements of Article 13(3).
Identity and contact details. The instructions must identify the provider by name and provide contact information for technical support and compliance inquiries. For systems distributed through intermediaries, the provider's identity must still be clearly stated.
System capabilities and limitations. The instructions must describe what the system is designed to do and what it is not. Limitations include: the population on which the system was validated, the data types it processes, the decision contexts for which it is appropriate, and contexts for which it has not been validated.
Input data requirements. The instructions must specify what input data the system requires, what format and quality standards apply, and what happens to output quality when inputs deviate from the required specification.
Accuracy, robustness, and fairness metrics. Article 13(3)(b)(iii) requires quantified performance metrics for the intended use case. Vague statements like "high accuracy" do not satisfy the requirement.
Human oversight measures. The instructions must describe what oversight the system requires and what indicators suggest a human should review or override an AI output.
Circumstances where outputs may be unreliable. If the system performs differently on certain demographic groups, in certain data environments, or under certain operational conditions, those circumstances must be disclosed. Failure to disclose known reliability limitations is one of the most likely sources of Article 13 enforcement action.
Expected lifetime and maintenance requirements. The instructions must cover how long the system is expected to remain accurate and what maintenance or retraining is required.
Deployer obligations: using the system and notifying users
Deployers have two distinct obligations under Article 13.
Obligation 1: Use the system within its intended purpose. Deployers cannot use a high-risk AI system outside its intended purpose without becoming the provider of a new or modified system, which would trigger the full provider obligations including Article 9, technical documentation, and conformity assessment. Review the instructions for use carefully before deployment.
Obligation 2: Notify end users that they are subject to a high-risk AI system. Article 13(2) requires deployers to ensure that natural persons the system interacts with are notified. The exception covers cases where national law expressly prohibits disclosure, primarily law enforcement and national security contexts.
The notification obligation is the most visible element of Article 13 for end users, and the most likely to generate complaints if missing.
The "meaningful information" standard
The Regulation requires that notification be given in "a clear and comprehensible form." Regulators and commentators have developed an informal standard around "meaningful information" that goes beyond a checkbox.
Meaningful notification tells the end user four things:
- That an AI system is involved in a decision or assessment that affects them.
- What the AI system is doing (screening their application, assessing their creditworthiness, analyzing their medical images).
- What the outputs of the AI system will be used for (whether the output will be the sole basis for a decision, or one input among several).
- Who to contact to ask questions about the AI system's role in the decision.
A privacy policy disclosure that mentions AI in general terms, buried on page 12 of a terms of service, does not satisfy this standard. The notification must be specific to the system, specific to the use case, and delivered at or before the point at which the AI system begins processing data about the individual.
Practical scenarios: what notice looks like in three high-risk contexts
AI hiring tool. An employer using an AI system to screen CVs must notify candidates before or at the time of application that their application will be assessed by an AI system. The notice should describe what the system evaluates, confirm that a human will review cases before any final decision, and provide contact information for questions. Under GDPR Article 22, if screening produces a legal effect such as rejection, the candidate is also entitled to a meaningful explanation of the logic used.
AI credit scoring. A lender must notify applicants at the point of application that an AI system is used in the assessment process. The notice should explain that the AI system produces a risk score that is one input into the credit decision, identify the data types used (transaction history, declared income), and confirm that a human decision-maker reviews applications before a final decision. GDPR Article 22 rights apply independently.
AI medical diagnostic tool. A clinic using AI to analyze medical images must inform patients that their images will be processed by an AI diagnostic system and that a qualified clinician will review and confirm or modify the AI output before any clinical decision is made.
GDPR Article 22 and Article 13: additive obligations
GDPR Article 22 gives individuals the right not to be subject to solely automated decisions that produce legal or similarly significant effects, and entitles them to meaningful information about the logic of automated processing when such decisions do occur. EU AI Act Article 13 requires that individuals be notified that they are subject to a high-risk AI system.
These obligations stack. Where an AI system makes or significantly influences a decision with legal or similarly significant effects on an individual, the deployer must comply with both:
- The GDPR Article 22 right to explanation and the right to contest the decision.
- The Article 13 notification obligation before the AI system processes the individual's data.
The two obligations have different triggers and different content requirements. GDPR Article 22 requires explanation of the logic of a specific automated decision after it is made. Article 13 requires notification before or during the processing. Deployers in contexts involving automated decisions (credit, hiring, insurance, welfare benefit assessment) need processes that satisfy both.
GPAI models in high-risk deployment contexts
A growing deployment pattern involves organizations using a general-purpose AI model (a large language model or similar) in a context that constitutes a high-risk application. For example, a law firm using a GPAI model to assess evidence files in a legal context, or an HR department using a GPAI model to score candidate applications.
In these cases, the GPAI provider's instructions for use and transparency documentation will not cover the specific high-risk use case. The GPAI provider has documented the model's general capabilities, not the specific employment screening or legal assessment application.
The deployer in this situation effectively becomes the provider of a new high-risk AI application. This means the deployer must produce their own instructions for use that address the Article 13 content requirements for their specific use case, and must provide the required end-user notification based on those instructions.
This is one of the most frequent compliance gaps in current deployments. Organizations using GPAI models for applications that map to Annex III categories should seek explicit legal advice on whether they have taken on provider-equivalent obligations and how to meet the Article 13 requirements for their specific application.
Instructions for use template structure
A minimal Article 13 instructions for use document that satisfies audit review includes:
- Provider identity, address, and contact information for technical and compliance inquiries
- System name, version, and intended purpose statement
- Annex III category or categories under which the system is classified as high-risk
- Capabilities description: what the system does and the output types it produces
- Limitations and scope restrictions: what the system is not designed to do, contexts where it has not been validated
- Performance metrics: accuracy, robustness, and fairness metrics with methodology description
- Input data requirements: format, quality, and population specifications
- Circumstances of unreliability: known conditions where output quality decreases
- Human oversight requirements: what oversight is required, what indicators trigger human review
- User notification guidance: what deployers must communicate to end users and when
- Maintenance requirements: expected lifetime, retraining intervals, performance degradation indicators
- Cross-reference to Article 9 risk management record (available on request for conformity assessment)
What Article 13 compliance looks like in practice for deployers
For deployers, Article 13 compliance is primarily an operational question: do you have a process that ensures end users are notified before or at the start of each interaction with a high-risk AI system?
The notification process needs to be documented. When a regulator asks for evidence that you have met the Article 13 notification obligation, you need to show the notification itself (the text, the screen, the form field), evidence of when it is displayed in the user journey, and a record of how you determined that the notification meets the "clear and comprehensible" standard.
For teams working through the broader deployer compliance picture, the EU AI Act deployer evidence gaps guide covers the most common documentation shortfalls across the full deployer obligation set. For the full high-risk AI documentation stack, the EU AI Act Article 9 risk management system guide covers the upstream documentation that Article 13 transparency obligations depend on.
Related reading
- EU AI Act high-risk AI documentation templates
- EU AI Act Annex III high-risk AI systems 2026
- EU AI Act August 2026 compliance checklist
- GDPR Article 22 automated decisions and AI tools 2026
- EU AI Act deployer evidence gaps for SMEs
- One documentation set for EU AI Act, NIST AI RMF, and Texas TRAIGA
- EU AI Act Compliance for Small Teams: The Complete Guide (2026)
- EU AI Act Conformity Assessment: What It Is and Who Must Do It
- EU AI Act high-risk classification: what the May 2026 draft guidelines c
