EU AI Act

What must a deployer of AI do under the EU AI Act?

Deployer duties under the EU AI Act in three layers. Every AI system: AI literacy (Article 4, since 2 Feb 2025) and the Article 5 bans. Some systems: Article 50 disclosures for emotion recognition, deepfakes and AI text (from 2 Aug 2026). High-risk systems: Article 26 duties and, for some deployers, a fundamental rights impact assessment (from 2 Dec 2027).

Most organizations will meet the EU AI Act as deployers: they use AI systems that someone else built. A deployer's duties come in three layers. Two apply to every AI system and already apply. Some systems trigger the Article 50 disclosure duties from 2 August 2026. High-risk systems bring the Article 26 duties, and for some deployers an impact assessment, from 2 December 2027.

3Layers of duty
2 Feb 2025Literacy and bans
2 Aug 2026Article 50
2 Dec 2027Annex III high-risk

Quotations are from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026 on 2 October 2026. This is not legal advice.

Are you a deployer?

Article 3(4) defines a deployer as "a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity". If your staff use AI at work, your organization is almost certainly a deployer of each of those systems. If you also build or rebrand a system, you may be its provider too; our guide to provider and deployer roles covers the tests.

What applies to every deployer now?

Two duties, both applying since 2 February 2025. Article 4 requires providers and deployers to "take measures to support the development of AI literacy" of their staff and others using AI on their behalf; our Article 4 guide covers what that means after the July 2026 rewrite. Article 5 prohibits certain uses outright, including emotion inference in the workplace and in education; our Article 5 guide lists them.

Which disclosures fall on deployers?

From 2 August 2026, Article 50 gives deployers two duties. Under Article 50(3), deployers of emotion recognition or biometric categorization systems must inform the people exposed to them. Under Article 50(4), deployers must disclose deepfakes, and AI-generated text "published with the purpose of informing the public on matters of public interest" unless it has had human review and someone holds editorial responsibility. Our Article 50 guide covers both, with the exceptions.

What must a deployer of a high-risk system do?

Article 26Duty
(1)Take technical and organizational measures to use the system in line with its instructions for use
(2)Assign human oversight to people with "the necessary competence, training and authority, as well as the necessary support"
(4)Where it controls the input data, ensure the data is relevant and sufficiently representative for the intended purpose
(5)Monitor operation, inform the provider, and report risks to the provider or distributor and the market surveillance authority
(6)Keep the automatically generated logs under its control for at least six months
(7)Employers: inform workers' representatives and affected workers before use at the workplace
(8)Public bodies: register their use and do not use a system that is not in the EU database
(9)Use the provider's Article 13 information for the GDPR data protection impact assessment
(11)For Annex III systems that make or assist decisions about people, tell those people they are subject to it
(12)Cooperate with the competent authorities

Under the amended Article 113, these apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 86 also gives people affected by decisions based on an Annex III system's output a right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken".

AI Act deployer checklist (Articles 26 and 27)

High-risk AI system,Annex III area,Provider (vendor),Use per instructions (26(1)),Human overseers named and trained (26(2)),Input data relevant and representative where we control it (26(4)),Monitoring and risk reporting route (26(5)),Logs kept at least six months (26(6)),Workers informed before use (26(7)),Public body: registered in EU database (26(8)),DPIA uses provider's Article 13 information (26(9)),People told they are subject to it (26(11)),FRIA needed? (27: public bodies and services; credit; life and health insurance),FRIA done and notified,Owner,Review date
,,,,,,,,,,,,,,,
,,,,,,,,,,,,,,,
"EU AI Act Articles 26 and 27 apply to Annex III high-risk systems from 2 December 2027 and to Annex I systems from 2 August 2028, as amended by Regulation (EU) 2026/1744. Template from credentialpress.com/guides/eu-ai-act-deployer-obligations. Not legal advice.",,,,,,,,,,,,,,,

Which deployers need a fundamental rights impact assessment?

Not all. Article 27(1) requires one, before deploying an Annex III high-risk system other than critical infrastructure, from deployers "that are bodies governed by public law, or are private entities providing public services", and from deployers of the credit scoring and life and health insurance pricing systems in Annex III, point 5(b) and (c). It covers the processes, the period and frequency of use, the people affected, the risks, human oversight and the response to risks, and the results are notified to the market surveillance authority. Since July 2026, it can cross-refer to the DPIA. Our guides to AI impact assessments and to the AI Act for banks and insurers go further.

When does a deployer become a provider?

Article 25(1) makes a deployer, or any distributor, importer or other third party, a provider of a high-risk system if it puts its name or trademark on it, makes a substantial modification, or modifies the intended purpose of a system so that it becomes high-risk. Then the provider obligations apply, and since July 2026, Article 25(2) requires the original provider to hand over documentation, known limitations and failure modes, and technical access.

What should a deployer do this quarter?

List the AI systems in use and mark which are high-risk under Annex III. For those, use the checklist above to plan each Article 26 duty for December 2027, and decide whether Article 27 applies to you. For every system, record your Article 4 literacy measures now. Our guide for HR teams covers the most common high-risk use. Credential Press is independent of the EU institutions.

Frequently asked questions

Who is a deployer under the EU AI Act?

Article 3(4) defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Most organizations that use AI at work are deployers.

What must every deployer do?

Take measures to support the AI literacy of staff and others using AI on its behalf (Article 4), and not use AI for any practice Article 5 prohibits. Both have applied since 2 February 2025.

What must a deployer of a high-risk AI system do?

Under Article 26: use it per the instructions, assign trained human oversight, keep input data relevant where it controls it, monitor and report risks, keep logs for at least six months, inform workers before workplace use, use the provider's information for its DPIA, and tell people when the system makes or assists decisions about them.

When do the deployer duties for high-risk AI apply?

From 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, after Regulation (EU) 2026/1744 moved the dates in July 2026.

Which deployers need a fundamental rights impact assessment?

Under Article 27(1): bodies governed by public law, private entities providing public services, and deployers of credit scoring and life and health insurance pricing systems, before deploying an Annex III high-risk system other than critical infrastructure.

Can a deployer become a provider?

Yes. Under Article 25, a deployer that puts its name or trademark on a high-risk system, makes a substantial modification, or changes the intended purpose so that a system becomes high-risk takes on the provider's obligations.

EU AI Act: test yourself in five minutes

Which books go deeper on the EU AI Act?

Cover of AI Governance Framework

AI Governance Framework

Building one that survives the EU AI Act. 22 chapters, 384 pages.

Cover of AI Governance Worked Scenarios

AI Governance Worked Scenarios

24 worked situations under the EU AI Act, decided against the Articles. 81 pages.

Sources

Every quotation above was read on 2 October 2026 through the EU Publications Office.

Credential Press is independent of the European Commission. This is not legal advice.