Regulation & governance9 min read
EU AI Act for Deployers: What Businesses Must Do
EU AI Act obligations for deployers: AI literacy, transparency duties, high-risk use rules, when a user becomes a provider, and a practical checklist.
Published
Under the EU AI Act, most businesses are deployers: they use AI systems built by someone else. For a deployer, obligations depend on how the system is used. Every deployer must take measures to ensure sufficient AI literacy among staff. Specific transparency duties apply when you publish deepfakes, AI-written public-interest texts, or use emotion recognition or biometric categorisation. The heavy obligations, such as human oversight, monitoring, log retention and informing workers, apply only when you use a high-risk AI system. And in certain cases, a deployer can become a provider and inherit the provider's much larger set of duties.
This article explains each layer in plain language. It is general information, not legal advice. The AI Act (Regulation (EU) 2024/1689) is detailed, guidance from the EU and national authorities continues to develop, and some application dates have been subject to proposed changes. For decisions with legal consequences, read the official text and consult qualified counsel.
Provider or deployer: which role are you?
The AI Act assigns obligations by role. The two roles that matter for most companies are:
| Role | Who it is | Typical example |
|---|---|---|
| Provider | Develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name | A software company selling an AI recruiting tool |
| Deployer | Uses an AI system under its own authority, except for purely personal, non-professional use | A retailer using that recruiting tool to screen applicants |
Importers, distributors and authorised representatives have their own duties, but most businesses using AI are deployers. A company can be both: a provider for a tool it builds and sells, and a deployer for tools it buys.
The role is assessed per AI system. Using a general chat assistant to draft emails makes you a deployer of that system. Building your own customer-facing chatbot on top of a model's API can make you the provider of that chatbot.
Layer 1: Obligations for every deployer
AI literacy
Article 4 requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other people who operate or use AI systems on their behalf. This has applied since 2 February 2025 and does not depend on risk level.
The law does not prescribe a course or certificate. What is sufficient depends on the staff's knowledge, the context of use and the people affected. A practical approach is role-based training on what the tools do, their limits, data rules and when to escalate. Our article on AI literacy under the EU AI Act covers this in detail.
No prohibited practices
The bans in Article 5 apply to everyone, including deployers. They cover, among others, harmful manipulation, exploiting vulnerabilities, social scoring, emotion recognition at the workplace or in education (except for medical or safety reasons), certain biometric categorisation and untargeted scraping of facial images. These have applied since 2 February 2025. Most normal business uses are nowhere near these practices, but HR and marketing teams in particular should know where the lines are. The article on EU AI Act risk categories explains each tier with examples.
Layer 2: Transparency duties in specific situations
Article 50 sets transparency obligations. Some fall on providers (for example, designing chatbots so people know they are talking to an AI, and marking synthetic content in a machine-readable way). Deployers have their own duties:
- Deepfakes: if you generate or manipulate image, audio or video content that resembles real people, objects, places or events and could falsely appear authentic, disclose that it was artificially created or manipulated. Lighter rules apply to evidently artistic, satirical or fictional work.
- AI-generated public-interest text: if you publish AI-generated or manipulated text to inform the public on matters of public interest, disclose this, unless the content has undergone human review or editorial control and someone holds editorial responsibility.
- Emotion recognition and biometric categorisation: if you use such a system (where it is not prohibited), inform the people exposed to it.
These duties were scheduled to apply from 2 August 2026. In practice, many businesses already label AI-generated media and chatbots because customers expect it.
Layer 3: Obligations when you use a high-risk AI system
High-risk systems are mainly those used for purposes listed in Annex III of the Act, such as recruitment and HR decisions, creditworthiness assessment, pricing and risk assessment in life and health insurance, access to education, and essential public services, plus AI that is a safety component of regulated products. If your use falls into one of these areas, Article 26 sets out the deployer obligations. In summary:
| Obligation | What it means in practice |
|---|---|
| Use according to instructions | Follow the provider's instructions for use, including limits on purpose and context |
| Human oversight | Assign oversight to people with the competence, training, authority and support to do it |
| Input data | Where you control the input data, make sure it is relevant and sufficiently representative for the intended purpose |
| Monitoring | Monitor the system's operation, and inform the provider and authorities about risks or serious incidents |
| Suspension | Stop using the system if you have reason to believe it presents a risk, and inform the relevant parties |
| Logs | Keep the logs the system generates automatically, to the extent they are under your control, for at least six months unless other law requires otherwise |
| Workers | Inform workers' representatives and affected workers before putting a high-risk system into use at the workplace |
| Affected persons | Inform people when a high-risk system is used to make or assist decisions about them |
| Data protection | Use the provider's information to carry out a data protection impact assessment where the GDPR requires one |
Some deployers must also carry out a fundamental rights impact assessment (Article 27) before first use. This applies to bodies governed by public law, private entities providing public services, and deployers of systems for creditworthiness assessment or life and health insurance risk and pricing.
The Act also gives affected people a right to an explanation of individual decisions taken on the basis of certain high-risk systems' output that significantly affect them. Deployers need a way to answer such requests.
Human oversight is the obligation that most changes daily work. It means more than a person clicking "approve". The reviewer must understand the system's capabilities and limits, be able to interpret its output, be aware of the risk of over-relying on it, and be able to override or stop it. Our guide to human-in-the-loop AI describes how to design review steps that work in practice.
When a deployer becomes a provider
Article 25 is easy to overlook and can change everything. You take on provider obligations for a high-risk AI system if you:
- put your name or trademark on a high-risk system already on the market,
- make a substantial modification to a high-risk system so that it remains high-risk, or
- change the intended purpose of an AI system, including a general-purpose one, so that it becomes high-risk.
The third point matters for businesses building on general-purpose models. Using a general chat model to draft marketing copy is low risk. Building a workflow on the same model that ranks job applicants could make you the provider of a high-risk system, with obligations for risk management, technical documentation, conformity assessment and registration.
Timeline and why to check it
The Act entered into force on 1 August 2024 and applies in stages:
| Date | What was scheduled to apply |
|---|---|
| 2 February 2025 | Prohibited practices, AI literacy |
| 2 August 2025 | Rules for general-purpose AI models, governance, penalties framework |
| 2 August 2026 | Most remaining provisions, including Annex III high-risk rules and transparency duties |
| 2 August 2027 | High-risk rules for AI in products covered by EU product safety law (Annex I) |
The EU has proposed changes to some of these dates, in particular for high-risk obligations. Because such changes go through the legislative process, check the current consolidated text and official guidance before planning your compliance work around a specific date.
Penalties in brief
Fines are tiered by the type of infringement. The highest tier, for prohibited practices, reaches up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Most other infringements, including deployer obligations, can reach up to 15 million euros or 3%. For SMEs and start-ups, the lower of the two amounts applies. National authorities enforce the rules, and enforcement practice will develop over time.
A practical checklist for deployers
- List every AI system in use, including AI features inside existing software.
- For each, record the provider, the purpose, who uses it and what data goes in.
- Classify each use case. The free EU AI Act risk checker gives a first orientation.
- Confirm that no use touches a prohibited practice.
- Set up role-based AI literacy measures and keep a record of them.
- Identify transparency situations: deepfakes, public-interest text, emotion recognition.
- For high-risk uses: obtain the provider's instructions, assign trained human oversight, define monitoring, keep logs, inform workers and affected persons, and check whether a fundamental rights impact assessment is needed.
- Check whether any of your own modifications or integrations could make you a provider.
- Write or update your AI acceptable use policy so staff know the rules.
- Review the inventory regularly, because new tools and new uses appear constantly.
Common mistakes
- Assuming the vendor handles compliance. Providers carry most obligations for high-risk systems, but deployers have their own, which cannot be outsourced.
- Classifying tools instead of uses. The same tool can be minimal risk in one department and high-risk in another.
- Overlooking AI inside existing software. HR, CRM and finance tools increasingly include AI features that may fall into high-risk areas.
- Treating human oversight as a checkbox. Oversight by someone without time, training or authority does not meet the intent.
- Planning around outdated dates. Verify the current timeline.
- Forgetting other laws. The GDPR, employment law, consumer protection and sector rules continue to apply alongside the AI Act.
Next steps
Start with an inventory and a first classification using the EU AI Act risk checker. Then read EU AI Act risk categories explained to understand the borderline cases, and set up your training approach with AI literacy under the EU AI Act. For anything that looks high-risk, involve legal counsel early.
FAQ
What is a deployer under the EU AI Act?
A deployer is any person or organisation that uses an AI system under its own authority in a professional context. A company that uses an AI tool bought from a vendor is typically a deployer; the vendor is the provider.
What obligations apply to every deployer?
AI literacy measures for staff apply to all providers and deployers. Transparency duties apply in specific situations such as deepfakes or emotion recognition. Most other obligations apply only to high-risk uses.
Can a deployer become a provider?
Yes. If you put your name or trademark on a high-risk system, substantially modify it, or change its intended purpose so that it becomes high-risk, you take on provider obligations.
When do the deployer obligations apply?
AI literacy and the prohibitions have applied since 2 February 2025. Most high-risk and transparency rules were scheduled for 2 August 2026, but the EU has proposed changes to some dates, so check the current official timeline.
Related articles
Regulation & governance9 min read
EU AI Act Risk Categories Explained With Examples
The four EU AI Act risk categories explained with business examples: prohibited, high-risk, transparency and minimal risk, plus GPAI rules and borderline cases.
Regulation & governance7 min read
AI Literacy Under the EU AI Act: What Article 4 Means
What the AI literacy requirement in Article 4 of the EU AI Act means for companies, who it covers, what good training includes and how to document it.
Regulation & governance8 min read
How to Write an AI Acceptable Use Policy for Your Team
How to write an AI acceptable use policy: the sections to include, a copyable outline, a traffic-light data rule, rollout steps and mistakes to avoid.