Regulation explainerArtificial Intelligence

EU AI Act obligations for deployers: what organizations using AI must do, and by when

Most organizations meet the EU AI Act as deployers: they use AI systems someone else built. Deployer duties are lighter than provider duties but real, and several already apply. This explainer covers who counts as a deployer, when you become a provider instead, what Articles 4, 5, 26, 27 and 50 require, and how the Digital Omnibus on AI moved the high-risk dates12.

Reviewed 8 min read

On this page
  1. Provider, deployer, importer, distributor: the roles that set your duties
  2. When a deployer becomes a provider under Article 25
  3. Deployer duties by article
  4. The timeline after the Digital Omnibus on AI
  5. How the fundamental rights impact assessment relates to a GDPR DPIA
  6. Deployer readiness checklist for the AI Act
  7. What this explainer is and is not
  8. Questions and answers
  9. Sources

Provider, deployer, importer, distributor: the roles that set your duties

Article 3 defines the operators in the AI value chain, and the same organization can hold different roles for different systems1.

Provider
Develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
Deployer
Uses an AI system under its authority, other than for personal, non-professional activity. A bank running a vendor's credit-scoring system is its deployer.
Importer
Is located or established in the EU and places on the market an AI system bearing the name or trademark of a person established outside the EU.
Distributor
Makes an AI system available on the EU market as part of the supply chain without being its provider or importer.

When a deployer becomes a provider under Article 25

Article 25 treats a deployer, distributor, importer or other third party as the provider of a high-risk AI system in three situations1.

  • If

    You put your name or trademark on a high-risk AI system already on the market.

    Then

    You are treated as its provider, whatever the contract says about who does the work.

    You can allocate tasks by contract, but the law follows the name the market sees.

  • If

    You make a substantial modification to a high-risk system and it stays high-risk.

    Then

    You take on provider duties for the modified system, including its conformity assessment.

    Unforeseen changes invalidate the original assessment.

  • If

    You change the intended purpose of a system, including a general-purpose one, so that it becomes high-risk.

    Then

    You become the provider of a new high-risk system, as when a general chat assistant is repurposed to rank job applicants.

    Risk class follows intended purpose.

  • If

    You configure and use the system within the provider's instructions for use.

    Then

    You remain a deployer, with the duties mapped below.

    That is the deployer role the Act describes.

Deployer duties by article

These duties apply to deployers in every sector; sector rules can add to them.

EU AI Act (Regulation (EU) 2024/1689), Article 4 and Article 5

European Union

Applies whenAny organization using AI systems in a professional capacity; these provisions have applied since 2 February 20251.

  • Take measures to support the AI literacy of staff; as amended by the Digital Omnibus, no particular level has to be guaranteed for any individual2.
  • Do not use prohibited practices, such as social scoring, harmful manipulation, untargeted scraping of facial images, or emotion recognition at work or in education outside medical or safety reasons1.
  • From 2 December 2026, also avoid AI systems that generate non-consensual intimate imagery or child sexual abuse material, which the Omnibus adds to the prohibitions2.

EU AI Act, Article 26

European Union

Applies whenDeployers of high-risk AI systems: from 2 December 2027 for Annex III systems and from 2 August 2028 for systems under the product legislation in Annex I2.

  • Use the system in line with the provider's instructions for use, backed by appropriate technical and organizational measures1.
  • Assign human oversight to people with the competence, training, authority and support to exercise it.
  • Where you control input data, make sure it is relevant and sufficiently representative for the intended purpose.
  • Monitor operation; if a risk appears, inform the provider and suspend use, and report serious incidents to the provider first and then the authorities.
  • Keep the logs under your control for at least six months, unless other law sets a different period1.
  • Inform workers' representatives and affected workers before workplace use, and tell people subject to Annex III decisions that a high-risk system is involved.

EU AI Act, Article 27

European Union

Applies whenBefore first use, for deployers that are public bodies or private entities providing public services, and for deployers of Annex III systems that assess creditworthiness or price life and health insurance1.

  • Carry out a fundamental rights impact assessment covering the process, period and frequency of use, affected groups, risks of harm, oversight measures and the response if risks materialize.
  • Notify the market surveillance authority of the results using the template the AI Office provides2.
  • Update the assessment when any of its elements changes.

EU AI Act, Article 50

European Union

Applies whenDeployers of emotion recognition or biometric categorization systems, of deepfakes, or of AI-generated text published to inform the public on matters of public interest; applicable since 2 August 20261.

  • Inform people exposed to an emotion recognition or biometric categorization system that it is operating.
  • Disclose that image, audio or video content forming a deepfake has been artificially generated or manipulated.
  • Disclose AI-generated text published on matters of public interest, unless it has had human review or editorial control under someone's editorial responsibility.

GDPR (Regulation (EU) 2016/679), Article 35

European Union

Applies whenA high-risk AI system processes personal data in a way likely to result in a high risk to people's rights3.

  • Carry out a data protection impact assessment, drawing on the information the provider must supply under Article 13 of the AI Act1.
  • Cross-reference or reuse relevant parts of that assessment in the fundamental rights impact assessment, as the Omnibus now expressly allows2.

The timeline after the Digital Omnibus on AI

The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force three days later2. For deployers, its main effect is to move the high-risk dates; it also softened the AI literacy wording and let impact assessments reuse DPIA work.

Obligations for high-risk systems listed in Annex III, which covers areas such as employment, education, access to essential services and law enforcement, now apply from 2 December 20272. High-risk systems that are safety components of products covered by Annex I legislation, such as medical devices, follow from 2 August 20282.

Some dates did not move. Prohibited practices and AI literacy have applied since 2 February 2025, and the Article 50 transparency duties since 2 August 2026; the only grace period, to 2 December 2026, covers providers' machine-readable marking for generative systems already on the market12. Use the extra high-risk time to build oversight and logging, not to postpone the work.

How the fundamental rights impact assessment relates to a GDPR DPIA

AspectFRIA under AI Act Article 27DPIA under GDPR Article 35
Who must do itPublic bodies, private entities providing public services, and deployers of credit-scoring or life and health insurance pricing systemsAny controller whose processing is likely to result in a high risk to individuals
TriggerFirst use of an in-scope high-risk AI systemPlanned processing of personal data that is likely to be high risk
FocusFundamental rights of affected people and groups, including non-discriminationRights and freedoms affected by processing personal data
Required contentProcess, period and frequency of use, affected groups, risks of harm, oversight and response measuresDescription of processing, necessity and proportionality, risks and safeguards
Who is toldThe market surveillance authority receives the resultsThe supervisory authority is consulted only if high residual risk remains

Many deployers will run both assessments on the same system; one owner for both avoids contradictory answers.

Deployer readiness checklist for the AI Act

0 of 10 checked

What this explainer is and is not

Questions and answers

Does the EU AI Act apply to organizations outside the EU?

It can. The Act covers deployers established or located in the EU, and also providers and deployers in third countries where the output produced by the AI system is used in the EU1. A company based elsewhere that uses AI to make decisions about people in the EU should check its duties rather than assume it is out of scope.

Is using a general-purpose AI assistant at work a high-risk use?

Usually not. Drafting emails or summarizing documents is not a high-risk purpose. Using the assistant for a purpose listed in Annex III, such as ranking job applicants or evaluating employees, can be high-risk, and repurposing it that way can make you the provider of a high-risk system under Article 25.

What should we do if a vendor's high-risk system does not meet the Act?

You rely on the provider for conformity, but you cannot ignore warning signs: if you have reason to think the system presents a risk, inform the provider and suspend use. Before buying, ask for the instructions for use, the conformity declaration and registration details, and write incident notification and cooperation duties into the contract.

Do we need a fundamental rights impact assessment for every high-risk system?

No. Article 27 applies to deployers that are public bodies or private entities providing public services, and to deployers of Annex III systems for creditworthiness assessment or life and health insurance pricing. Other deployers of high-risk systems still carry the Article 26 duties, and many will need a GDPR data protection impact assessment.

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  2. Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
  3. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  4. Artificial Intelligence capability: AI Governance and Safety offering — ColdAI

More in Artificial Intelligence

Back to Artificial Intelligence

Next step

Send us your AI inventory for a deployer-duty review

Share the AI systems you use and what each one decides or influences. We will reply with a first view of your role and risk class for each, and which duties to plan for before the high-risk dates arrive.

Review our AI Act duties