Who you are
Role decides your duty set, and it attaches to a system rather than to a company. Most organisations hold more than one.
Provider
Art. 3(3)Whoever develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. The heaviest role.
Deployer
Art. 3(4)Whoever uses an AI system under their own authority, other than in a personal non-professional activity. The role most organisations actually hold.
Importer
Art. 3(6)Someone in the Union placing on the market an AI system that bears the name or trademark of a provider established outside it.
Distributor
Art. 3(7)Anyone else in the supply chain who makes an AI system available on the market, other than the provider or the importer.
Operator
Art. 3(8)The collective term: provider, deployer, importer, distributor or authorised representative. Used where a duty falls on more than one role.
Authorised representative
Art. 3(5)A person in the Union appointed in writing by a provider outside it, to carry out the obligations the Regulation places on that provider.
What the thing is
Scope questions. Whether the Regulation applies at all, and in which class.
AI system
Art. 3(1)A machine-based system designed to operate with varying autonomy, that may adapt after deployment, and that infers from its input how to generate outputs — predictions, content, recommendations or decisions — which can influence its environment.
General-purpose AI model
Art. 3(63)A model showing significant generality, capable of performing a wide range of distinct tasks, that can be integrated into downstream systems. The obligations on these have applied since 2 August 2026.
High-risk
Art. 6, Annex IIIEither an AI system that is a safety component of a product covered by the Annex I legislation, or one used in an Annex III area — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.
Prohibited practice
Art. 5Uses banned outright, with no conformity route that makes them permissible — among them social scoring, untargeted facial-image scraping, and inferring emotions in the workplace or in education. In force since 2 February 2025.
Intended purpose
Art. 3(12)The use the provider intends, as stated in the instructions, the marketing material and the technical documentation. It governs what a deployer may lawfully do with the system.
Substantial modification
Art. 3(23)A change after placing on the market that is not foreseen in the provider's initial assessment and affects compliance or the intended purpose. It can make the modifier the provider.
What you have to produce
The artefacts. Most are the provider's; two are the deployer's.
Technical documentation
Art. 11, Annex IVThe file that shows a high-risk system meets the requirements — system description, development process, risk management, data, oversight design, accuracy and robustness evidence.
Instructions for use
Art. 13What the provider must give the deployer: capabilities, limitations, intended purpose, oversight measures, expected lifetime. Without them a deployer cannot discharge its own Art. 26 duty.
Declaration of conformity
Art. 47The provider's written statement that the system meets the requirements, kept for ten years and given to authorities on request.
CE marking
Art. 48The mark affixed by the provider claiming conformity. It is a claim by them, not a verification by anyone else — an importer still has to check what lies behind it.
FRIA
Art. 27The fundamental-rights impact assessment, required of public bodies and of deployers of the Annex III creditworthiness and insurance-pricing systems. It may build on a DPIA under Art. 27(4).
DPIA
GDPR Art. 35The data-protection impact assessment. Distinct from a FRIA and often required alongside it; the two overlap, and the Act says where the overlap counts.
Keeping it true
The duties that continue after go-live, which is where most programmes quietly stop.
Human oversight
Art. 14, Art. 26(2)Designed in by the provider, exercised by the deployer through a named person with the competence and the authority to override an output.
Post-market monitoring
Art. 72The provider's system for collecting and reviewing experience from systems in use, feeding back into risk management.
Serious incident
Art. 3(49), Art. 73An incident or malfunction leading, directly or indirectly, to death, serious harm to health, serious disruption of critical infrastructure, breach of fundamental-rights obligations, or serious harm to property or the environment. Reportable on a clock that starts when you knew.
AI literacy
Art. 4Skills, knowledge and understanding sufficient for staff to deploy AI informedly and be aware of its risks. It applies whatever the risk class — one of the few duties that is not tier-dependent.
Conformity assessment
Art. 43, Annex VIThe procedure demonstrating a high-risk system meets the requirements. Most Annex III systems take the internal-control route; some require a notified body.
Notified body
Art. 3(22)A conformity-assessment body designated under the Regulation. Involved only where the third-party route applies.