IN BRIEF

A role-focused guide for organisations using AI systems under their authority.

01 / DEPLOY

Know what you are using

Keep a working inventory of systems, purposes, providers, users and affected people. Read the provider’s instructions and confirm the real deployment context.

02 / DEPLOY

High-risk deployment

Where high-risk rules apply, deployer responsibilities include use in accordance with instructions, human oversight and monitoring, with further obligations in certain circumstances. Consult the applicable legal provisions for the specific use.

Review high-risk systems ↗
03 / DEPLOY

People and processes

Build appropriate AI literacy, escalation and review practices. Include legal, security and operational owners before deploying consequential uses.

04 / DEPLOY

Where does the deployer role begin?

A deployer uses an AI system under its authority, other than for personal non-professional activity. Buying from a vendor does not remove the need to identify the organisation’s own use, affected people and operational owner. A company can be a deployer of one system and a provider of another. Changes to a high-risk system or its intended purpose may also alter the role analysis under Article 25.

Compare provider responsibilities ↗
05 / DEPLOY

What does Article 26 require for high-risk use?

Among other duties, deployers must use high-risk systems according to instructions, assign human oversight to competent people and monitor operation on the basis of those instructions. They must address input data under their control where relevant and retain automatically generated logs for an appropriate period, subject to the provision’s conditions. Certain uses carry additional information, registration or impact-assessment requirements. Work from the exact paragraph relevant to the deployment.

Read Article 26 ↗
06 / DEPLOY

Questions to ask a supplier

Request the intended purpose and use limits, instructions, human oversight design, performance and known limitations, logging capability, update policy and incident channel. Ask how a significant change will be communicated. For a high-risk candidate, verify the applicable conformity information rather than treating a marketing claim as sufficient. Procurement records should make the operational assumptions visible to the people who will use the system.

  • What use was the system designed for?
  • What oversight and monitoring are expected?
  • Which changes require reassessment?
07 / DEPLOY

Deployment and affected people

Review transparency duties separately from high-risk deployer requirements. Consider workplace information and consultation rules, data protection obligations and fundamental-rights impact assessment where the Act requires it for specific deployers and uses. These questions depend on context and should be reviewed with the responsible legal and operational teams, especially when a system influences consequential decisions about individuals.

Check the transparency guide ↗
Verify the source

This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.

Read the AI Act ↗European Commission overview ↗