Regulation explainerArtificial Intelligence
EU AI Act obligations for deployers: what organizations using AI must do, and by when
Most organizations meet the EU AI Act as deployers: they use AI systems someone else built. Deployer duties are lighter than provider duties but real, and several already apply. This explainer covers who counts as a deployer, when you become a provider instead, what Articles 4, 5, 26, 27 and 50 require, and how the Digital Omnibus on AI moved the high-risk dates12.
On this page
- Provider, deployer, importer, distributor: the roles that set your duties
- When a deployer becomes a provider under Article 25
- Deployer duties by article
- The timeline after the Digital Omnibus on AI
- How the fundamental rights impact assessment relates to a GDPR DPIA
- Deployer readiness checklist for the AI Act
- What this explainer is and is not
- Questions and answers
- Sources
Provider, deployer, importer, distributor: the roles that set your duties
Article 3 defines the operators in the AI value chain, and the same organization can hold different roles for different systems1.
- Provider
- Develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
- Deployer
- Uses an AI system under its authority, other than for personal, non-professional activity. A bank running a vendor's credit-scoring system is its deployer.
- Importer
- Is located or established in the EU and places on the market an AI system bearing the name or trademark of a person established outside the EU.
- Distributor
- Makes an AI system available on the EU market as part of the supply chain without being its provider or importer.
When a deployer becomes a provider under Article 25
Article 25 treats a deployer, distributor, importer or other third party as the provider of a high-risk AI system in three situations1.
- If
You put your name or trademark on a high-risk AI system already on the market.
ThenYou are treated as its provider, whatever the contract says about who does the work.
You can allocate tasks by contract, but the law follows the name the market sees.
- If
You make a substantial modification to a high-risk system and it stays high-risk.
ThenYou take on provider duties for the modified system, including its conformity assessment.
Unforeseen changes invalidate the original assessment.
- If
You change the intended purpose of a system, including a general-purpose one, so that it becomes high-risk.
ThenYou become the provider of a new high-risk system, as when a general chat assistant is repurposed to rank job applicants.
Risk class follows intended purpose.
- If
You configure and use the system within the provider's instructions for use.
ThenYou remain a deployer, with the duties mapped below.
That is the deployer role the Act describes.
Deployer duties by article
These duties apply to deployers in every sector; sector rules can add to them.
EU AI Act (Regulation (EU) 2024/1689), Article 4 and Article 5
European UnionApplies whenAny organization using AI systems in a professional capacity; these provisions have applied since 2 February 20251.
- Take measures to support the AI literacy of staff; as amended by the Digital Omnibus, no particular level has to be guaranteed for any individual2.
- Do not use prohibited practices, such as social scoring, harmful manipulation, untargeted scraping of facial images, or emotion recognition at work or in education outside medical or safety reasons1.
- From 2 December 2026, also avoid AI systems that generate non-consensual intimate imagery or child sexual abuse material, which the Omnibus adds to the prohibitions2.
EU AI Act, Article 26
European UnionApplies whenDeployers of high-risk AI systems: from 2 December 2027 for Annex III systems and from 2 August 2028 for systems under the product legislation in Annex I2.
- Use the system in line with the provider's instructions for use, backed by appropriate technical and organizational measures1.
- Assign human oversight to people with the competence, training, authority and support to exercise it.
- Where you control input data, make sure it is relevant and sufficiently representative for the intended purpose.
- Monitor operation; if a risk appears, inform the provider and suspend use, and report serious incidents to the provider first and then the authorities.
- Keep the logs under your control for at least six months, unless other law sets a different period1.
- Inform workers' representatives and affected workers before workplace use, and tell people subject to Annex III decisions that a high-risk system is involved.
EU AI Act, Article 27
European UnionApplies whenBefore first use, for deployers that are public bodies or private entities providing public services, and for deployers of Annex III systems that assess creditworthiness or price life and health insurance1.
- Carry out a fundamental rights impact assessment covering the process, period and frequency of use, affected groups, risks of harm, oversight measures and the response if risks materialize.
- Notify the market surveillance authority of the results using the template the AI Office provides2.
- Update the assessment when any of its elements changes.
EU AI Act, Article 50
European UnionApplies whenDeployers of emotion recognition or biometric categorization systems, of deepfakes, or of AI-generated text published to inform the public on matters of public interest; applicable since 2 August 20261.
- Inform people exposed to an emotion recognition or biometric categorization system that it is operating.
- Disclose that image, audio or video content forming a deepfake has been artificially generated or manipulated.
- Disclose AI-generated text published on matters of public interest, unless it has had human review or editorial control under someone's editorial responsibility.
GDPR (Regulation (EU) 2016/679), Article 35
European UnionApplies whenA high-risk AI system processes personal data in a way likely to result in a high risk to people's rights3.
The timeline after the Digital Omnibus on AI
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force three days later2. For deployers, its main effect is to move the high-risk dates; it also softened the AI literacy wording and let impact assessments reuse DPIA work.
Obligations for high-risk systems listed in Annex III, which covers areas such as employment, education, access to essential services and law enforcement, now apply from 2 December 20272. High-risk systems that are safety components of products covered by Annex I legislation, such as medical devices, follow from 2 August 20282.
Some dates did not move. Prohibited practices and AI literacy have applied since 2 February 2025, and the Article 50 transparency duties since 2 August 2026; the only grace period, to 2 December 2026, covers providers' machine-readable marking for generative systems already on the market12. Use the extra high-risk time to build oversight and logging, not to postpone the work.
How the fundamental rights impact assessment relates to a GDPR DPIA
| Aspect | FRIA under AI Act Article 27 | DPIA under GDPR Article 35 |
|---|---|---|
| Who must do it | Public bodies, private entities providing public services, and deployers of credit-scoring or life and health insurance pricing systems | Any controller whose processing is likely to result in a high risk to individuals |
| Trigger | First use of an in-scope high-risk AI system | Planned processing of personal data that is likely to be high risk |
| Focus | Fundamental rights of affected people and groups, including non-discrimination | Rights and freedoms affected by processing personal data |
| Required content | Process, period and frequency of use, affected groups, risks of harm, oversight and response measures | Description of processing, necessity and proportionality, risks and safeguards |
| Who is told | The market surveillance authority receives the results | The supervisory authority is consulted only if high residual risk remains |
Many deployers will run both assessments on the same system; one owner for both avoids contradictory answers.
Deployer readiness checklist for the AI Act
What this explainer is and is not
Questions and answers
Does the EU AI Act apply to organizations outside the EU?
It can. The Act covers deployers established or located in the EU, and also providers and deployers in third countries where the output produced by the AI system is used in the EU1. A company based elsewhere that uses AI to make decisions about people in the EU should check its duties rather than assume it is out of scope.
Is using a general-purpose AI assistant at work a high-risk use?
Usually not. Drafting emails or summarizing documents is not a high-risk purpose. Using the assistant for a purpose listed in Annex III, such as ranking job applicants or evaluating employees, can be high-risk, and repurposing it that way can make you the provider of a high-risk system under Article 25.
What should we do if a vendor's high-risk system does not meet the Act?
You rely on the provider for conformity, but you cannot ignore warning signs: if you have reason to think the system presents a risk, inform the provider and suspend use. Before buying, ask for the instructions for use, the conformity declaration and registration details, and write incident notification and cooperation duties into the contract.
Do we need a fundamental rights impact assessment for every high-risk system?
No. Article 27 applies to deployers that are public bodies or private entities providing public services, and to deployers of Annex III systems for creditworthiness assessment or life and health insurance pricing. Other deployers of high-risk systems still carry the Article 26 duties, and many will need a GDPR data protection impact assessment.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Artificial Intelligence capability: AI Governance and Safety offering — ColdAI