Why the quality management system matters
Every other obligation on a provider of a high-risk AI system is something you must do once, or repeatedly, or continuously. Article 17 of the EU AI Act is different: it is the obligation to be an organisation capable of doing all of them. It requires a documented quality management system covering thirteen specified aspects, from regulatory strategy through data management to an accountability framework naming who inside the company is responsible for what. It turns compliance activities into a governed system.
It is also the provision most likely to decide whether a compliance programme survives contact with a supervisory authority. Risk management files and technical documentation can be produced retrospectively, at cost. A quality management system cannot, because its evidential value lies entirely in having operated over time. For Swedish providers this is the AI Act work with the longest lead time, even with the high-risk obligations now deferred to December 2027 and August 2028.
Who has to have one
Article 17 binds providers of high-risk AI systems. Article 16(c) puts it in the operative list of provider duties: providers shall “have a quality management system in place which complies with Article 17”. Deployers have no equivalent duty, though one that makes a substantial modification or changes a system’s intended purpose can become a provider under Article 25 and inherit it.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, made one change here, and it is narrower than most commentary suggests: paragraph 2 was replaced. Paragraph 1, with all thirteen lettered aspects, and paragraphs 3 and 4 stand as adopted in 2024. Anyone saying the Omnibus rewrote the quality management system regime has not compared the two texts.
What Article 17 actually requires
A documented system, not a set of intentions
Article 17(1) requires providers to “put a quality management system in place that ensures compliance with this Regulation”, and adds that the system “shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions”. The form is prescribed: culture, habit and institutional knowledge do not satisfy this. The chapeau then says the system “shall include at least the following aspects”, making the thirteen points a floor rather than a menu.
The thirteen aspects
Point (a) is a strategy for regulatory compliance, covering conformity assessment procedures and the management of modifications to the system. Points (b) and (c) cover the techniques, procedures and systematic actions used for design, design control and verification, then for development, quality control and quality assurance. Point (d) covers examination, test and validation procedures carried out before, during and after development, and how often they are performed. Point (e) covers the technical specifications and standards applied and, where harmonised standards are not applied in full or do not cover every requirement, the means used instead. Point (f) is data management in unusually broad terms, from acquisition, collection, analysis and labelling through storage, filtration, mining, aggregation and retention.
Points (g), (h) and (i) pull three other articles into the quality system: risk management under Article 9, the setting-up, implementation and maintenance of a post-market monitoring system under Article 72, and procedures for reporting serious incidents under Article 73. Point (j) covers communication with national competent authorities, notified bodies, other operators, customers and other interested parties. Point (k) covers record-keeping of all relevant documentation and information, and point (l) resource management, including security-of-supply related measures. Point (m) closes the list with an accountability framework “setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph”.
Point (m) is the one companies underestimate. An accountability framework is not an organisational chart: it allocates named responsibility for each of the preceding twelve aspects. That allocation is the first thing an authority asks to see, because it is the fastest way to find out whether the rest is real.
Proportionality, and what the Omnibus actually changed
Article 17(2) as amended now reads: “The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.”
The pre-Omnibus text was identical except that the first sentence stopped at “organisation”. The whole operative effect of the amendment is the insertion of the words naming SMEs, start-ups and small mid-cap enterprises. The Act defines an SME by reference to Recommendation 2003/361/EC and an SMC by reference to Recommendation (EU) 2025/1099. The second sentence matters most and was not touched: proportionality never reduces the required degree of rigour or level of protection. It governs how elaborately you document and run the system, not how well the system has to work.
Integrating with a quality system you already have
Article 17(3) provides that providers “subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law”. Note what it does not do: it names no sector and no specific legislation. Commentary attributing a list of medical device or machinery legislation to Article 17(3) is importing it from elsewhere.
This is the largest cost saving available to a regulated manufacturer, and the Omnibus drew attention to it. Recital (37) of Regulation (EU) 2026/1744 identifies Article 8(2), Article 9(10) and Article 17(3) as the mechanisms that “allow economic operators to integrate, when necessary and appropriate, an assessment of AI-specific risks into existing risk and quality management systems”, and requires the Commission to publish guidelines on their application by 1 August 2027 at the latest.
Financial institutions and the three-point carve-out
Article 17(4) provides that for providers that are financial institutions subject to internal governance requirements under Union financial services law, the obligation to put a quality management system in place “with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law”.
Read the exception carefully. Points (g), (h) and (i) are risk management under Article 9, post-market monitoring under Article 72 and serious incident reporting under Article 73, and those three apply in full. A Swedish bank or insurer cannot treat its existing governance framework as answering the whole of Article 17. It answers ten of thirteen aspects, and the three left out are the operationally demanding ones.
Standards will help, but not yet
At the end of July 2026, CEN and CENELEC published EN 18286:2026, “Artificial intelligence – Quality management system for EU AI Act regulatory purposes” — the first European standard developed in support of the AI Act, aimed squarely at Article 17.
It does not yet give you a presumption of conformity. That arrives only when the Commission cites the standard’s reference in the Official Journal, and no AI Act standard has been cited. CEN-CENELEC’s own newsletter, days after the standard appeared, says the Commission “is expected to publish the reference to the standard in the Official Journal of the European Union later in 2026” — future tense. Until then, applying EN 18286 is a strong evidential position and a sensible engineering decision, but not a legal shortcut. Nor is ISO/IEC 42001: the Commission says its goals and definitions are not aligned with the Article 17 quality management system.
Practical example
A medtech company outside Uppsala makes a diagnostic imaging device with an AI component. It has held ISO 13485 certification for a decade and runs a mature quality system under the Medical Device Regulation, with Läkemedelsverket as its Swedish authority. Its instinct is that Article 17 is already handled.
Partly right. Article 17(3) lets it fold the AI Act aspects into the quality system it already runs rather than build a parallel one. But folding in is work. Its existing system almost certainly has nothing on the AI-specific reach of point (f) — data labelling, filtration, mining and aggregation as governed processes — nothing on point (h) post-market monitoring in the Article 72 sense as distinct from MDR vigilance, and no accountability framework allocating the AI aspects to named people. There is a further reason to move. The Digital Omnibus replaced Article 43(3), and the replacement provides that for high-risk AI systems covered by Annex I Section A legislation, “assessment of the quality management system set out in Article 17 shall also be undertaken” as part of the sectoral conformity assessment. The same provision sets a deadline for notified bodies already notified under sectoral legislation to apply for designation under the AI Act, so assessment capacity is a scheduling risk worth planning around.
Common mistakes companies make
The first is starting with a document set instead of a system. A binder of policies written in a fortnight, with no evidence anyone followed them, is worse than useless in front of an authority: it demonstrates the gap between the written and the actual. The second is reading proportionality as dilution. Article 17(2) scales implementation to the size of the organisation and preserves the required rigour in the same breath.
The third is confusing the two reliefs available to smaller providers. The proportionality rule in Article 17(2) names SMEs, start-ups and SMCs; the separate simplified route in Article 63, which the Omnibus extends beyond microenterprises to SMEs including start-ups, is a different mechanism with a different beneficiary set. The fourth is assuming a published standard is a cited standard. The fifth, for financial institutions, is reading Article 17(4) as an exemption rather than a deeming provision with three articles carved out.
Recommended actions
Begin from the thirteen aspects and map each against what your organisation already does, honestly, naming the person who does it. Most established companies find six or seven substantially covered by existing practice, data management and post-market monitoring the real gaps, and the accountability framework absent in written form. If you already operate a quality system under sectoral Union law, plan the Article 17(3) integration route rather than a parallel build, and watch for the Commission guidelines due by 1 August 2027.
Then treat the system as something that has to run, not something that has to exist. Set review cycles, keep records showing the procedures were followed, and connect the quality system to the Article 9 risk management file and the Annex IV technical documentation so the three tell one story. If your system falls under Annex I Section A legislation, open the conversation with your notified body early: the designation deadline means assessment capacity is likely to tighten before the obligations apply.
Frequently asked questions
Is ISO/IEC 42001 certification enough to satisfy Article 17?
No. ISO/IEC 42001 is a useful framework and good evidence of maturity, but the Commission’s guidance states that its goals and definitions are not aligned with the Article 17 quality management system. It is not an AI Act harmonised standard and confers no presumption of conformity.
We are a small company. How much of Article 17 do we really have to do?
All thirteen aspects, implemented proportionately to the size of your organisation. Article 17(2) now names SMEs, start-ups and SMCs expressly. Proportionality reduces the elaboration of documentation and processes, not the degree of rigour or the level of protection required of the systems themselves.
When does the Article 17 obligation actually apply?
Following the Digital Omnibus, the high-risk obligations apply from 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those under Article 6(1) and Annex I. Because a quality management system has to have been operating to be worth anything, those dates are later than the date you should start.
Conclusion
Article 17 is the least glamorous provision in the AI Act’s high-risk regime and the one that takes longest to satisfy. The Digital Omnibus changed a single sentence of it. The thirteen aspects, the requirement for written policies, procedures and instructions, the integration route for regulated manufacturers and the narrow financial services carve-out all stand as they were. The companies that come out of December 2027 well will be those that started building the system, not the document set, in good time.
Lawgent helps businesses design and document AI Act quality management systems, and integrate them with existing sectoral quality frameworks.