What are deployer obligations under the EU AI Act?
AI regulation: the EU AI Act
Under the EU AI Act, a deployer is the person or organisation using an AI system under its authority. Deployers already have to support AI literacy and avoid prohibited uses. From 2 August 2026, deployers also face Article 50 transparency duties. If a system is high-risk, extra duties can apply around human oversight, input data, monitoring, logs, worker information and, for some deployers, a fundamental-rights impact assessment. As of 21 July 2026, a pending Omnibus could still move some high-risk dates, but not the general Article 50 deployer dates.
What this means
If your organisation uses AI rather than sells it, the EU AI Act can still apply to you. The Act calls you a deployer when you use an AI system under your authority. That usually means the legal person running the tool in business, public service or another organisational setting, not each individual employee acting on its behalf.
For most organisations, the starting point is simpler than many assume. The Act does not automatically dump the full high-risk regime on every team using a chatbot, drafting assistant or image tool. But it does already require AI literacy and it already bans certain uses. Then, from 2 August 2026, deployers also pick up transparency duties under Article 50, and some deployers will have further obligations if the system they use is high-risk.
The timing now needs careful handling. On 21 July 2026, the Digital Omnibus on AI had been adopted and signed, but the OEIL procedure file still showed it as awaiting publication in the Official Journal. That means the law formally in force remains the AI Act as it stands today until the amending regulation is published and enters into force. Once that happens, some high-risk dates move, but the general Article 50 deployer dates do not.
Why it matters
This matters because deployer risk is operational, not theoretical. The teams most exposed are often HR, customer operations, fraud, credit, insurance, public service delivery, communications and procurement, not just engineering. A deployer can create liability by using a lawful tool in the wrong context, by failing to tell people they are being subject to emotion recognition or biometric categorisation, by publishing unlabeled deepfakes, or by treating a high-risk system like an ordinary software purchase.
It also matters because everyday AI use creates blind spots. Staff using chat assistants, image generators or workflow tools without approval can put an organisation outside its own controls. The Act does not use the phrase "shadow AI", but untracked use can still break the logic of compliance: you cannot train people properly, classify tools, decide whether Article 50 applies, or prepare high-risk controls if you do not know what is being used.
Finally, the deployer question is also a boundary question. Many organisations assume they are "just users". Often that is right. But the more they commission, heavily customise, relabel or materially reshape a system, the closer they move toward provider status, with a much heavier compliance load.
How it works
Who counts as a deployer
A deployer is a natural or legal person, public authority, agency or other body using an AI system under its authority, except for personal non-professional use. In practice, that usually means the organisation, not each employee individually. The Commission's Article 50 Q and A is explicit that where a legal person uses a system through employees, contractors or freelancers acting on its behalf and under its control, the legal person remains the deployer.
That matters for ordinary business tools. If your staff use a third-party chat assistant for drafting or translation within the organisation, the organisation is still acting as a deployer. The Commission's AI literacy Q and A confirms that even this kind of use can trigger Article 4 literacy duties. So the deployer category is not reserved for public authorities or obvious high-risk use cases.
What already applies now
Two deployer duties already apply today. First, Article 4 on AI literacy has applied since 2 February 2025. Second, the Article 5 prohibitions have also applied since 2 February 2025. So a deployer cannot wait for the rest of the Act before acting.
For deployers, AI literacy is not a certification scheme or a one-size-fits-all training course. The Commission says organisations should tailor measures to the risk of the systems they use, the role of the organisation, the knowledge of staff and the context in which the tools are used. The same Q and A also makes two practical points that matter for deployers. Reading the provider's instructions alone is often not enough, and using a general tool such as ChatGPT for ordinary work can still trigger the literacy obligation.
Staying clear of prohibited practices is the second immediate duty. The Commission's prohibited-practices guidance is non-binding, but it is currently the main official explanation of how the prohibitions should be read. As of 21 July 2026, those prohibitions are the ones already in the AI Act in force. The pending Omnibus would add new Article 5 prohibitions on AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material, but those new prohibitions are not yet in force because the Omnibus had not yet been published in the Official Journal. If and when it does enter into force, those new prohibitions will apply from 2 December 2026.
Article 50 deployer transparency duties
Article 50 is where many ordinary deployers first get concrete operational duties. The Commission published transparency guidelines on 20 July 2026 and states that these obligations start to apply on 2 August 2026. The key deployer-facing duties are these.
First, deployers of emotion recognition systems and biometric categorisation systems must inform natural persons exposed to those systems of their operation. The Commission says this applies whether the system operates in real time or afterwards. This is a deployer duty, not just a provider duty.
Second, deployers must clearly label deepfakes. The Commission's Q and A explains that a deepfake is AI-generated or AI-manipulated image, audio or video that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Disclosure must happen by first exposure at the latest, in a clear and distinguishable way that people can perceive without special tools. A machine-readable mark embedded by the provider is not enough for the deployer to satisfy this duty on its own.
Third, deployers of generative AI systems must clearly label AI-generated or AI-manipulated text published for the purpose of informing the public on matters of public interest, unless the text has undergone human review or is subject to editorial control and editorial responsibility. The Commission gives a broad account of "matters of public interest", covering areas such as politics, public administration, justice, law enforcement, fundamental rights, public security, public health, environmental protection and developments that may become the subject of public debate. It also makes clear that superficial checks such as spelling correction do not amount to the kind of human review or editorial control that creates the exemption.
The timing needs careful treatment. Under the law in force on 21 July 2026, Article 50 applies from 2 August 2026. The pending Omnibus does not move those general Article 50 dates. What it would do, once in force, is create a limited grace period for providers of synthetic-content systems placed on the market before 2 August 2026, giving them until 2 December 2026 to comply with Article 50(2), the provider-side machine-readable marking duty. That is not a general deployer postponement. Deployer duties around emotion recognition, biometric categorisation, deepfake labelling and public-interest text remain on the 2 August 2026 track.
The transparency regime itself has its own page, AI transparency obligations; this page keeps to the deployer angle.
When a deployer becomes more like a provider
The easiest deployer case is straightforward use of a third-party system under someone else's name and intended purpose. But that boundary can shift.
The AI Act defines a provider as the person or organisation that develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. So if an organisation commissions a system and launches it under its own brand, it may be a provider from the outset, not merely a deployer.
The line tightens further for high-risk systems. Article 25 says a distributor, importer, deployer or other third party becomes the provider of a high-risk AI system if it puts its own name or trademark on a high-risk system already on the market, makes a substantial modification to it, or changes the intended purpose of a system, including a general-purpose AI system, in a way that makes it high-risk. That is the provision that turns "we only use it" into "we now carry provider obligations".
For general-purpose AI models, the Commission's guidance on GPAI providers follows a similar logic at model level: significant modifications matter, minor ones do not. Taken together, the practical message is clear. Normal configuration and internal use do not automatically make you a provider. But heavy customisation, relabelling and purpose-shifting can.
If the system is high-risk
High-risk deployer duties do not apply because a tool feels important or because AI is used in a sensitive conversation. They apply when the system is legally classed as high-risk. Under Article 6, that happens in two main ways.
One route is product safety under Article 6(1) and Annex I. The other route is the list of standalone use cases in Annex III, such as biometric categorisation and emotion recognition, parts of education, recruitment and worker management, credit scoring, life and health insurance pricing, parts of law enforcement, migration and border management, and some justice and democratic-process uses. The Commission's draft high-risk classification guidelines, published for consultation on 19 May 2026, are meant to help providers, deployers and authorities assess this.
If a deployer is using a high-risk AI system, Article 26 brings concrete duties. The deployer must use the system in line with the instructions for use. It must assign human oversight to sufficiently competent and supported people. To the extent it controls input data, it must ensure the data is relevant and sufficiently representative for the intended purpose. It must monitor the system's operation, inform the provider and authorities if use creates a risk, and suspend use where required. It must keep automatically generated logs under its control for an appropriate period of at least six months, unless another rule says otherwise. Employers must inform workers' representatives and affected workers before using a high-risk system at work. Public authorities and EU institutions using high-risk systems must also deal with registration obligations and must not use an Annex III high-risk system if it has not been registered in the EU database. Deployers of Annex III high-risk systems that make or assist decisions about natural persons must inform those persons that they are subject to the system's use.
The current timeline is split, and this is where many summaries go wrong. Under the AI Act currently in force, deployer duties tied to Annex III high-risk systems are due from 2 August 2026, while Article 6(1) product-safety high-risk systems and corresponding obligations are due from 2 August 2027. If the pending Omnibus is published and enters into force before those dates, it changes that timetable. Annex III standalone high-risk obligations move to 2 December 2027, as an outer limit, while Annex I product-safety high-risk obligations move to 2 August 2028. The Omnibus also leaves Article 6(5) in place and adds mechanisms for the Commission to specify affected high-risk systems and limits in certain Annex I contexts, but the practical deployer takeaway is simpler: the high-risk calendar may still shift very shortly, while Article 50 does not.
Fundamental-rights impact assessments for certain deployers
Article 27 is narrower than Article 26. It does not apply to every deployer of every high-risk system. It applies before deployment of certain high-risk systems referred to in Article 6(2), meaning Annex III systems, and covers two main groups.
The first group is bodies governed by public law and private entities providing public services, except for high-risk AI systems intended to be used in the Annex III point 2 critical-infrastructure area. The second group is deployers of Annex III point 5(b) and 5(c) systems, namely systems used to evaluate creditworthiness or establish credit scores, and systems used for risk assessment and pricing in relation to natural persons in life and health insurance.
The assessment must describe the deployer's processes, the period and frequency of system use, the categories of people likely to be affected, the specific risks of harm, the human oversight measures, and the measures to be taken if those risks materialise, including governance and complaint arrangements. The duty applies before first use, but a deployer can rely in similar cases on previous assessments or existing assessments carried out by the provider and update them if circumstances change.
Article 27 also contains a useful bridge to data protection law. Where the same ground is already covered by a DPIA under Article 35 GDPR or the parallel law-enforcement DPIA route, the Article 27 fundamental-rights impact assessment should complement that DPIA rather than duplicate it. This is the most practical way to think about interaction between AI governance and privacy governance. The AI Office is also tasked with developing a questionnaire template and automated tool to simplify compliance, but as of 21 July 2026 this page should be read on the basis that the statutory duty exists even if the tooling is still developing.
The assessment itself has its own page, fundamental rights impact assessment; this page keeps to when the duty applies and to whom.
General-purpose tools and shadow AI in everyday operations
Most deployers will meet the Act first through general-purpose tools, not Annex III. A marketing team using a chatbot, an operations team using an internal assistant, or a policy team drafting briefings with a generative tool will not automatically be in high-risk territory. But those teams are still within deployer reality.
The Commission's AI literacy Q and A confirms that an organisation using a chatbot for ordinary tasks such as writing advertising text or translating text is still expected to comply with Article 4. If that same organisation publishes AI-generated text on matters of public interest without real human review or editorial control, Article 50 can also bite. If it publishes a synthetic spokesperson video that qualifies as a deepfake, the deepfake labelling duty can bite too.
This is why shadow AI is a governance problem. It is not a separate legal category in the Act. But if staff sign up to tools outside procurement and policy, an organisation can miss core deployer obligations: literacy, classification, transparency, worker information, logging, escalation routes and, in the right case, a fundamental-rights impact assessment. The practical risk is not only legal non-compliance. It is also the organisation's inability to prove that it knew what it was deploying, why it classified it the way it did, and what controls were in place.
Examples
A company uses AI to screen CVs, rank candidates and monitor worker performance. Annex III expressly lists recruitment, selection, task allocation and performance monitoring in employment as high-risk use cases. That means Article 26 matters if the system is legally high-risk. The employer must use the system in line with instructions, assign competent human oversight, monitor operation, retain logs under its control for at least six months, and inform workers' representatives and affected workers before workplace use. On the law in force as at 21 July 2026, those Annex III deployer duties are due from 2 August 2026, unless the pending Omnibus enters into force first and moves Annex III high-risk timing to 2 December 2027.
A lender or insurer deploys AI to assess a person's creditworthiness or set life or health insurance pricing. Annex III specifically lists those use cases. Here the deployer lens is stronger than in many other sectors because Article 27 also applies. The deployer must not only manage the Article 26 operational duties if the system is high-risk, but also perform a fundamental-rights impact assessment before first use, with scope for alignment with an existing DPIA where the coverage overlaps. As of 21 July 2026, the same timing caveat applies: current law points to 2 August 2026 for Annex III deployer duties, but the pending Omnibus would move that track to 2 December 2027 once in force.
A communications team publishes an AI-generated explainer on a contested public policy issue and also releases a synthetic video that makes a real person appear to say something they never said. Article 50 is engaged in two different ways. AI-generated or AI-manipulated text published to inform the public on matters of public interest must be clearly labelled unless it has undergone substantive human review or editorial control and responsibility. Deepfake content must be disclosed by first exposure at the latest, in a clear and distinguishable way. These deployer duties apply from 2 August 2026 under both the current law and the pending Omnibus track.
Common misunderstandings
"Only AI builders need to worry about the Act." No. Deployers already have duties around AI literacy and prohibited uses, and they gain additional transparency and sometimes high-risk duties even if they buy the system from someone else.
"The Omnibus has already changed the law." Not yet, as of 21 July 2026. The Digital Omnibus on AI had been adopted and signed, but the OEIL file still showed it as awaiting publication in the Official Journal. Until publication and entry into force, the current AI Act timetable formally stands.
"Article 50 has been postponed." No, not in general. The pending Omnibus leaves the general Article 50 timetable in place. The important distinction is that it would create a limited grace period until 2 December 2026 for legacy systems already on the market before 2 August 2026 to meet the provider-side Article 50(2) marking duty. That is not a blanket delay for deployer transparency obligations.
"Any use of a chatbot is high-risk." No. Many common chat assistant uses trigger Article 4 literacy and may create Article 50 issues depending on how outputs are published, but they are not automatically high-risk under Article 6 and Annex III.
"If the provider embeds a machine-readable mark, the deployer is done." Not for deepfakes. The Commission says deployers cannot rely only on the provider's machine-readable marking to satisfy their own disclosure duty. People must get a clear, perceivable label by first exposure at the latest.
Risks and boundaries
This page is about the deployer lens, not the whole AI Act. It should not be read as a substitute for the main EU AI Act page or the pages on who the Act applies to, AI literacy, transparency obligations and fundamental rights impact assessments. Those topics sit around this one, but the practical legal question here is narrower: what must the organisation using AI actually do?
The biggest boundary issue is classification. Article 26 and Article 27 do not apply just because a use case feels sensitive. They apply if the system is legally high-risk. That can require a close reading of Article 6, Annex I, Annex III, the provider's intended purpose and, where relevant, the Commission's guidance. As of 21 July 2026, the Commission's high-risk classification guidelines were still in draft, with consultation open until 23 July 2026.
The second boundary issue is timing. Current law still governs until the Omnibus is published and enters into force. On that basis, Article 50 starts on 2 August 2026, Annex III high-risk deployer obligations are also due from 2 August 2026, and Article 6(1) product-safety high-risk obligations are due from 2 August 2027. If the Omnibus enters into force before those dates, Annex III high-risk obligations move to 2 December 2027 and Annex I product-safety obligations move to 2 August 2028. So the deployer answer is time-sensitive right now.
The third boundary issue is overlap with other law. Article 27 expressly complements rather than replaces a DPIA. Employment law, anti-discrimination law, sector-specific regulation, consumer law and data protection law can all still apply independently. Compliance with the AI Act does not displace those frameworks.
Finally, "shadow AI" is not a term from the Regulation. It is a practical governance label for unapproved or untracked tool use. It matters because it can undermine deployer compliance, but it should not be confused with a formal statutory category.
What to do next
Start with an inventory, not a policy slogan. You need to know which AI systems are actually being used under the organisation's authority, including ordinary chat assistants, embedded vendor features and locally improvised workflows. Without that map, the rest of the Act is difficult to apply.
Then sort those systems into three buckets. First, systems that already require action now because Article 4 literacy applies or because the system could be used in a prohibited way. Second, systems likely to trigger Article 50 from 2 August 2026, especially emotion recognition, biometric categorisation, deepfakes and AI-generated text published on matters of public interest. Third, systems that might be high-risk under Article 6 and Annex III, especially in HR, credit, insurance, public services and law enforcement-adjacent contexts.
For each likely Article 50 use case, decide now who owns the label, when the disclosure appears, and how human review or editorial control will be evidenced. For each potentially high-risk use case, build a simple internal decision record covering classification, provider instructions, human oversight, logging, incident escalation, worker information and whether an Article 27 assessment is needed.
Also review the provider boundary. If you are rebranding, heavily customising or materially changing a system's intended purpose, ask whether you are still only a deployer. The answer can change. Finally, set a short-term legal and governance review around the Omnibus publication event, because the high-risk timeline may still move on only a few days' notice.
FAQs
Are we a deployer if staff use an external AI chatbot at work?
Usually yes. If the organisation is using the system under its authority, the organisation is the deployer. Individual employees acting under that authority are not treated as separate deployers.
Do deployers already have obligations before 2 August 2026?
Yes. Article 4 AI literacy and the Article 5 prohibitions have applied since 2 February 2025.
Do Article 50 deployer duties move under the pending Omnibus?
No, not in general. The deployer-facing Article 50 duties still sit on 2 August 2026. The pending Omnibus only creates a limited grace period until 2 December 2026 for certain provider-side Article 50(2) obligations on legacy synthetic-content systems.
Do we need to label every AI-generated article or blog post?
No. The specific Article 50 text duty is for AI-generated or AI-manipulated text published with the purpose of informing the public on matters of public interest, unless it has undergone substantive human review or editorial control and editorial responsibility.
When does a deployer become a provider?
Potentially when it develops or commissions a system and puts it into service under its own name or trademark, or, for a high-risk system already on the market, when it rebrands it, substantially modifies it, or changes its intended purpose so that it becomes high-risk.
Who has to do an Article 27 fundamental-rights impact assessment?
Not every deployer. The duty is targeted at certain deployers of Annex III high-risk systems, especially public bodies, private entities providing public services, and deployers of credit scoring or life and health insurance risk assessment and pricing systems.
Is "shadow AI" itself regulated by the AI Act?
Not as a defined legal category. It is a practical governance problem: if teams use AI tools outside approved channels, the organisation may fail literacy, transparency or high-risk control duties because it cannot govern what it cannot see.
