AI Act deployer obligations — what applies when you use AI rather than build it

“We only use AI, we do not build it” is the most common thing we hear — and it is usually right. It does not mean the AI Act leaves you alone. It means a different, lighter set of obligations applies, and it helps a great deal to know which.

First hour’s on us. No commitment.

Det här får du

  • Confirmation of your role for each system — deployer, provider, or both, with reasoning
  • The deployer duties that actually apply to you, rather than a generic compliance programme built for providers
  • Human oversight designed into the workflow, with named people who have the authority to override
  • Vendor contracts that oblige the provider to give you what you need to comply
  • A check on whether you have become a provider without meaning to

Hur det fungerar

  1. Intake, 45 minutes. What you use and how. Free.
  2. Assessment, one to two weeks. Roles, classifications, gaps.
  3. The plan. Short, prioritised, with the documents specified.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

What a deployer actually has to do

A deployer is anyone using an AI system under their own authority in a professional capacity. For high-risk systems, the duties are specific and finite:

  • Use the system according to the instructions for use. This sounds trivial and is not — using a tool outside its stated purpose can make you a provider.
  • Assign human oversight to natural persons who have the competence, training and authority to carry it out, and the support to do so.
  • Make sure input data is relevant and sufficiently representative for the intended purpose, to the extent you control it.
  • Monitor operation and inform the provider and the authorities where you identify a risk or a serious incident.
  • Keep the logs the system generates, for an appropriate period of at least six months where the logs are under your control.
  • Inform workers’ representatives and affected workers before putting a high-risk system into use in the workplace.
  • Inform the people subject to decisions, and give them an explanation of the role the system played where the decision affects them.

Some public bodies and certain private entities providing public services must also carry out a fundamental rights impact assessment before first use.

What a deployer does not have to do

This is worth stating plainly, because a lot of compliance effort gets spent in the wrong place.

You do not build the risk management system. You do not write the technical documentation. You do not run the conformity assessment or apply the CE marking. You do not do the data governance on training sets you never saw. Those are provider duties, and they belong to whoever placed the system on the market.

Your job is to use it correctly, oversee it properly, and be able to show both.

Three ways companies become providers by accident

Putting your name on it. Placing a high-risk AI system on the market under your own name or trademark makes you the provider, even if someone else built it. White-labelling is the usual route in.

Substantially modifying it. A modification that changes the intended purpose or affects compliance can shift the role. Fine-tuning a model on your own data sits close to this line, and where exactly it falls depends on what changed.

Changing the intended purpose. Using a system for something it was not designed and documented for — for example using a general text tool as a formal assessment step in hiring.

Each of these turns a light obligation set into a heavy one. All three are worth checking before a contract is signed, not after.

Get it into the contract

The single most useful thing a deployer can do is contractual. Your provider holds the information you need, and nothing in the regulation makes them hand it over on request unless you have agreed it.

Worth having in writing: a statement of the classification and the reasoning behind it; the instructions for use, kept current; access to the logs and confirmation of retention; notification duties for incidents and for changes that affect classification; support for your own oversight and information duties; and what happens if the provider’s classification turns out to be wrong.

What already applies, regardless of role

Two obligations do not wait for 2027 and do not depend on whether a system is high-risk.

Prohibited practices have applied since February 2025 — including emotion recognition in the workplace and in education, and certain biometric categorisation.

AI literacy (Article 4) has applied since February 2025 and falls on deployers as much as providers. Your people need a level of understanding appropriate to their role, and you need a record showing what you gave them.

Vanliga frågor

We use ChatGPT and similar tools internally. Does this apply?

General-purpose tools used for ordinary work are usually not high-risk. The picture changes if you build them into a decision process in an Annex III area — hiring, credit, access to services. AI literacy and the prohibitions apply either way.

How do we know if a system is high-risk?

Ask the provider for the classification and the reasoning. If it is high-risk it should be registered in the EU database and come with instructions for use. If they cannot answer, that is itself information.

What does “human oversight” mean in practice?

A named person who understands the system’s limits, can interpret its output, can decide not to use it, and can intervene or stop it. A reviewer who approves everything is not oversight.

Do we need to register anything?

Providers register high-risk systems. Certain deployers that are public authorities also register their use. Most private deployers do not.

How long does an assessment take?

For a deployer with a normal tool stack, usually one to two weeks. It is a much smaller exercise than a provider assessment.

Where to start

Bring a list of the AI you use, including the features inside tools you did not buy as AI. The first conversation is free, and it usually shortens the list rather than lengthening it.

Related