Instructions for use: the Art. 13 package
What a provider's instructions for use must contain under Art. 13(3), how the package is built and handed to deployers, how a deployer receives it, and where it feeds the deployer's own duties.
A high-risk system must be designed and developed so that its operation is sufficiently transparent for deployers to interpret its output and use it appropriately, and it must come with instructions for use in an appropriate digital or other format (Art. 13(1)–(2)). The instructions are the hinge between the provider's duties and the deployer's: everything a deployer does under Art. 26 starts from them.
What Art. 13(3) requires
Concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers, covering:
- (a) the provider's identity and contact details, and its authorised representative's where there is one;
- (b) the system's characteristics, capabilities and limitations of performance — its intended purpose, the accuracy, robustness and cybersecurity levels it was tested against, known or foreseeable circumstances that may lead to risks, its technical capabilities to explain output where relevant, its performance for the specific persons or groups it is intended for, input-data specifications, and information for deployers to interpret the output;
- (c) any changes to the system pre-determined by the provider at the initial conformity assessment;
- (d) the human oversight measures (Art. 14), including the technical measures that help deployers interpret output;
- (e) the computational and hardware resources needed, the expected lifetime, and the maintenance and care measures, including software updates;
- (f) where relevant, a description of the mechanisms that let deployers collect, store and interpret the logs (Art. 12).
In Veritome — the provider's side
The instructions for use is a per-system structured document in Documents, opened in its own editor. Its checklist follows the Art. 13(3) points, and a readiness gauge on the system's supply-chain tab shows how complete the package is. When it is ready, the printable IFU package renders it as an A4 document, and a share link hands it to the deployer. The Art. 13 obligation sits in the Implement phase and, for Annex III systems, applies from 2 December 2027.
In Veritome — the deployer's side
A deployer records receipt of the provider's instructions on its own system record: what was received, from whom, and when. That receipt is where the deployer's duties begin — using the system in accordance with the instructions (Art. 26(1)), assigning oversight on the basis of the measures the instructions describe (Art. 26(2)), monitoring on their basis (Art. 26(5)), and using the information in them to carry out a DPIA under GDPR Art. 35 (Art. 26(9)). That last one is one of the Act's own reuse routes: Veritome shows it on the DPIA obligation and lets you record reliance without changing the status — see DPIA overlap.
Importers and distributors see the supply-chain list instead: the checks they owe under Art. 23 and Art. 24, including that the instructions accompany the system.
Where it feeds
The instructions for use are one of the Annex VIII fields the EU-database registration asks for, a component of the Annex IV technical file, and the document an importer must keep for ten years (Art. 23(5)). Producing it once in the editor feeds all three.