What deployers get wrong first.
The deployer journey, not the provider one.
From a list of tools to an auditable record.
An operations team running a bought CV-screening tool.
- Annex III point 4 — employment. High-risk, so the full Art. 26 set applies.
- Named human overseer recorded, with the authority to override an output.
- Art. 26(7) worker notice issued and dated BEFORE the tool went live.
- Automatically generated logs retained for the Art. 26(6) six-month floor.
A support team using a vendor chatbot on the public site.
- Not high-risk — but Art. 50 still requires people to be told they are talking to an AI.
- The disclosure notice is drafted from the record, not written from scratch.
- Art. 4 literacy still applies to the team operating it.
- No Annex IV, no conformity assessment: the engine never raises them.
A council deploying a benefits-triage model.
- A public body, so Art. 27 binds: a fundamental-rights assessment is required.
- It pre-fills from the existing DPIA — Art. 27(4) permits that reuse explicitly.
- Affected people are informed under Art. 26(11).
- One record, filed against both the EU AI Act and GDPR duties it evidences.
The parts a deployer reaches for later.
Straight answers for deployers.
How do I know whether I am a deployer or a provider?
You are a deployer if you use an AI system under your own authority — a vendor's chatbot, a bought scoring model, a tool embedded in your HR software. You become a provider under Article 25 if you put your own name or trademark on a high-risk system, substantially modify one, or change its intended purpose so that it becomes high-risk. Most organisations are a deployer for the tools they buy and a provider only for what they build, and the register handles both at once.
What does Article 26 actually require of me?
Use the system according to the provider's instructions; assign human oversight to people with the competence and authority to exercise it; make sure input data is relevant and sufficiently representative for the intended purpose; monitor operation and suspend use if a risk emerges; keep the automatically generated logs for at least six months; inform workers and their representatives before putting a high-risk system into use at work; and tell affected people when a high-risk system is used in decisions about them.
Do the deployer duties apply if the system is not high-risk?
Some of them do. Article 4 AI literacy applies to every organisation using AI, regardless of risk class. Article 50 transparency applies where a person interacts with an AI system, or where content is generated — that is a duty tied to the situation, not the tier. The Article 26 obligations are the ones reserved for high-risk systems.
Do I need a fundamental rights impact assessment?
Article 27 binds deployers that are public bodies or private entities providing public services, and deployers of the creditworthiness and life-and-health-insurance-pricing systems in Annex III. Where it applies, the assessment can build on a data protection impact assessment you have already done — Article 27(4) says so explicitly, and Veritome pre-fills from the DPIA rather than asking twice.
The vendor says their product is compliant. Is that enough?
No. Provider conformity and deployer compliance are separate duties. A CE-marked system placed correctly on the market still leaves you the oversight, the input data, the logs, the worker notification and the literacy. What the provider owes you is the instructions for use under Article 13 — and if those have not arrived, that is the first thing to chase.


