Regulation (EU) 2026/1744 pulled two obligations apart. Article 4 AI literacy was rewritten as a duty to support development rather than to ensure it, and the new text says plainly that no provider or deployer has to guarantee any individual's level.
Article 14 human oversight was not reopened: a natural person, with competence, training and the authority to stop a running system. One of those can be discharged with a course catalogue. The other needs somebody who can take revenue offline on a Thursday and keep their job.
A duty with no role attached is a paragraph in a policy, and a role with no evidence attached is an assertion. Each of these three names the person who carries it and the artefact a supervisory authority or a customer's auditor would be shown.
Article 14 asks for a named natural person per system, not a committee and not a rota with gaps. The artefact is an appointment record carrying the individual, the date, the specific mechanism they may invoke alone - disable the endpoint, revoke the key, route to the fallback - and a dated exercise in which they used it.
Article 4 now sits on the organisation rather than on the learner, so the manager who funds and schedules the measures holds it. Record what was offered, who was in scope and when. The rewritten text does not ask you to guarantee anyone's level, which means a register of sessions and attendance is the whole evidence requirement.
Whoever applies the release threshold should not depend on the release for their objectives. One person may build; a different person, outside the delivery reporting line, must be able to refuse on evaluation evidence and have the refusal stand. The artefact is an approval record naming the reviewer and the thresholds, and an approval log with no rejections in it evidences a rubber stamp.
One individual, a date, and the specific mechanism: disable the endpoint, revoke the key, route to the fallback. If the answer is that they would raise it with someone, the appointment is not real yet.
A rehearsed intervention against a live system in a controlled window proves competence, training and authority in one artefact. An authority nobody has ever used is indistinguishable from one that was never granted.
Fine-tuning, substantial adaptation and rebranding move a system across the provider boundary. List them, require a named approver in the pipeline, and record the classification per system so it is a decision rather than a discovery.
Predecessor, successor, effective date and a briefing on the system's failure modes, produced before the structure change lands. Systems outlive the teams that build them, and this obligation is the one that fails silently.
No. Regulation (EU) 2026/1744 rewrote Article 4 rather than repealing it, so the duty to take measures supporting AI literacy still binds. What changed is the standard of proof. You evidence it with a programme and an attendance record instead of with an assessment of any individual's level.
Article 14 asks for natural persons with competence, training and the authority to intervene and to stop. A committee meets monthly and cannot be paged. Name an individual per system with a named deputy, and record the mechanism each of them may invoke without asking anybody else first.
Annex III stand-alone obligations apply from 2 December 2027 and Annex I from 2 August 2028, but naming a role is the slow part. Granting somebody the authority to take revenue offline is a decision an executive has to make, and an unexercised authority proves nothing until it has been drilled.
For most operator duties the Article 99 ceiling is whichever is larger, EUR 15M or 3% of annual worldwide turnover, and the test inverts to whichever is smaller for SMEs, start-ups and small mid-caps.
Prohibited practices run to EUR 35M or 7%. The likelier cost is a system nobody can halt.
This report asks which duty lands on which person and what proves they carry it. Engineering Team Design for AI: An Engineering Reference is the catalogue underneath it, numbering the organisational structures family by family with the artefact each one produces. Read this for who answers, that one for what to build.
VPs of engineering and heads of risk who own the answer when somebody asks which named person can stop a system. It assumes you already have AI in production and an org chart that was drawn for delivery rather than for accountability.
Drop your details and we'll send Engineering Team Design for AI Under Regulation straight to your inbox - no spam, unsubscribe anytime.
Point a two-week sprint at one system you already run and find out who could halt it today, what they would need to be granted first, and who signs a release they did not build. SECTION 7 - FAQ - 5 to 8 questions
Book an accountability review