Why deployer obligations matter
Most of the public debate about the EU AI Act has focused on the companies that build artificial intelligence. Yet the majority of European businesses are not developers – they are users. If your company runs a CV-screening tool, a credit-scoring engine or an AI system that supports decisions about people, you are almost certainly a deployer, and the AI Act gives deployers their own set of legal duties.
These obligations, set out mainly in Article 26 for high-risk systems, begin to apply from 2 December 2027. That date was originally 2 August 2026, but the Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred the high-risk regime when it entered into force on 27 July 2026. Getting them wrong is not a technicality: deployers can face administrative fines and, just as importantly, liability towards the people affected by an AI decision. This article explains, in plain terms, what a deployer is and what you must actually do.
Who counts as a deployer
A deployer is any natural or legal person using an AI system under its own authority in the course of a professional activity. The key word is authority: you decide to put the system to work in your organisation. Purely personal, non-professional use falls outside the definition.
The distinction between provider and deployer is not always tidy. If you significantly modify a high-risk system, put your own name or trade mark on it, or change its intended purpose, you may become a provider and inherit the far heavier obligations that role carries. For most companies, though, the practical question is simpler: which high-risk AI systems are we using, and are we meeting our deployer duties for each one?
The core obligations under Article 26
Use the system according to its instructions
Deployers must use a high-risk AI system in line with the instructions for use supplied by the provider. This sounds obvious, but it has teeth: if you deploy a tool outside its documented purpose or operating conditions, you lose much of the legal protection the provider’s conformity work gave you and take on the risk yourself.
Ensure meaningful human oversight
You must assign human oversight to people who have the competence, training and authority to carry it out. Oversight is not a rubber stamp. The people responsible must be able to understand the system’s limitations, interpret its output, and override or stop it where necessary.
Monitor operation and keep logs
Deployers must monitor how the system performs in practice and act when it behaves in a way that could create a risk. Where you control the logs the system generates, you must keep them for an appropriate period – at least six months unless otherwise required – so that incidents can be reconstructed.
Make sure input data is relevant
To the extent you control the input data, you must ensure it is relevant and sufficiently representative for the system’s intended purpose. Feeding a hiring tool skewed or incomplete data is a fast route to discriminatory outcomes – and to liability.
Inform workers and affected people
Before putting a high-risk system to work in the workplace, deployers must inform workers’ representatives and the affected employees. Where a system makes or supports decisions about individuals, those people generally have the right to be told that an AI system is involved and, in relevant cases, to receive an explanation.
Fundamental rights impact assessment
Certain deployers – public bodies and private operators providing public services, plus deployers of specific high-risk systems such as creditworthiness and life or health insurance risk assessment – must carry out a fundamental rights impact assessment under Article 27 before first use. The assessment maps who could be affected, the risks to their rights, and the human-oversight and mitigation measures in place. It complements, rather than replaces, the data protection impact assessment you may already owe under the GDPR.
Praktiskt exempel
A Swedish retailer buys an AI tool that ranks job applicants. The vendor is the provider; the retailer is the deployer. To comply, the retailer names a trained recruiter to review every shortlist and reject the ranking where it looks off, informs candidates that AI supports the process, checks that the historical hiring data feeding the tool is not skewed against particular groups, keeps the system’s logs, and briefs the works council before go-live. None of this is exotic – but skipping any step turns an efficiency gain into a compliance gap.
Vanliga misstag som företag gör
The first is assuming that buying from a compliant provider is enough. It is not; deployer duties are separate and non-transferable. The second is treating human oversight as a formality, with a reviewer who lacks the time or authority to intervene. The third is silence – deploying people-facing AI without telling staff or affected individuals. The fourth is failing to keep an inventory of which AI systems are even in use, which makes every other obligation impossible to meet.
Rekommenderade åtgärder
Build a register of every AI system in the business and classify each one by risk. For each high-risk system, read the provider’s instructions and confirm you are operating within them. Assign named, trained people to oversight, define how they can override the system, and set a log-retention rule. Decide whether Article 27 applies to you and, if so, run the fundamental rights impact assessment before use. Finally, prepare clear notices for employees and affected individuals, and align them with your existing GDPR transparency wording.
Vanliga frågor
Are deployers fined the same as providers?
The AI Act sets tiered fines, with the highest reserved for prohibited practices. Breaches of deployer obligations sit in a lower but still serious band, and national authorities can act. Reputational and civil-liability exposure often matters more than the fine itself.
Do these duties apply to every AI tool we use?
The Article 26 obligations attach to high-risk systems. Lower-risk tools may only trigger transparency duties, and some limited uses fall outside the high-risk list. The first step is always to classify each system correctly.
When do the obligations start?
The main high-risk rules, including deployer obligations, apply from 2 December 2027 for the stand-alone systems listed in Annex III. Systems that are safety components of regulated products under Annex I follow from 2 August 2028. Do not wait for the deadline to build your governance.
Slutsats
The EU AI Act is not only a rulebook for AI developers. If your company uses high-risk AI, you are a deployer with concrete, enforceable duties around human oversight, monitoring, data quality and transparency. The good news is that these obligations are manageable with a clear inventory and sensible governance. Lawgent helps businesses map their AI systems, classify risk and put deployer compliance in place before the 2 December 2027 deadline – so you can use AI with confidence rather than exposure.