Art. 13 AI Act: Instructions for High-Risk AI

What Art. 13 AI Act requires for instructions for use of high-risk AI systems – mandatory content, gaps and tips for providers and deployers.

What Article 13 requires

Art. 13 AI Act addresses a problem many organisations underestimate: a high-risk AI system can function flawlessly on a technical level and still be used unlawfully – simply because the deployer does not know how to interpret its output. Art. 13(1) AI Act therefore obliges providers to design systems so that their operation is “sufficiently transparent” to enable deployers to interpret and use the output appropriately.

Art. 13(2) AI Act turns this into a concrete documentation duty: high-risk AI systems must be accompanied by instructions for use in an appropriate digital format. The instructions must be concise, complete, correct and clear, in a form that is relevant, accessible and comprehensible to deployers. This is not a technical data sheet for developers, but a document that someone without an ML background can genuinely apply.

The mandatory content in detail

Art. 13(3) AI Act lists the minimum content required. In practice, this breaks down into four groups:

Identity and purpose: the name and contact details of the provider (and, where applicable, its authorised representative), plus the system’s intended purpose (points (a) and (b)(i)).

Performance and limitations: accuracy, robustness and cybersecurity as referred to in Art. 15 AI Act, including relevant metrics, along with known or foreseeable circumstances that may affect those levels – as well as reasonably foreseeable misuse that may lead to risks under Art. 9(2) AI Act (points (b)(ii)–(iii)). Where relevant: information to explain the output, performance regarding specific groups of persons, and specifications on training, validation and testing data sets (points (b)(iv)–(vi)).

Operation and oversight: predetermined changes to the system and its performance (point (c)), the human oversight measures under Art. 14 AI Act, including technical measures to facilitate the interpretation of outputs (point (d)), and the computational and hardware resources needed, the expected lifetime, and any necessary maintenance measures including the frequency of updates (point (e)).

Logging: a description of the mechanisms built into the system that allow deployers to collect, store and interpret logs in line with Art. 12 AI Act (point (f)).

Common gaps in practice

Many organisations already have some form of “user documentation” – but it rarely meets the requirements of Art. 13 AI Act. Three patterns come up repeatedly:

First, accuracy and robustness figures with concrete metrics are missing. Often there is only a generic statement such as “the system has been tested”, without deployers being able to establish under which conditions those tested values apply and when they might deteriorate.

Second, the interpretability of outputs is neglected. Art. 13(3)(b)(vii) AI Act expressly requires information enabling deployers to use the output appropriately. A bare result display without context – such as a score with no explanation of what it means or how stable it is – is not sufficient.

Third, the link to Art. 14 AI Act (human oversight) and Art. 12 AI Act (logging) is missing. Such instructions often treat the system in isolation, without describing what technical oversight measures exist or how the logging mechanisms actually work.

Who is responsible – and what does this mean for deployers?

The duty to draw up the instructions for use falls on the provider. Nevertheless, Art. 13 AI Act is relevant for deployers too: without instructions covering the minimum content set out above, you will struggle to properly evidence your own deployer obligations – for instance regarding human oversight or the evaluation of logs. If you operate a high-risk AI system and the provider’s instructions are incomplete, you should actively request the missing information before putting the system into productive use. Anyone acting as a provider themselves – for example by substantially modifying a third party’s system – takes on the full documentation duty under Art. 13 AI Act.

Conclusion

Art. 13 AI Act does not call for a marketing brochure, but for a technically robust operational document with concrete metrics, limitations and oversight mechanisms. Anyone relying solely on a generic user manual will quickly reveal gaps under scrutiny. Whether your system even qualifies as high-risk AI under the Regulation, and which obligations follow from that in concrete terms, can be clarified with our free risk check at /einstufung.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.