Role · Deployer

You did not build it. You are still answerable for it.

A deployer uses an AI system under its own authority — the vendor chatbot, the bought scoring model, the tool inside your HR suite. Buying it does not move the duty. Article 26 puts oversight, input data, logging and worker notification on you, and Article 4 literacy applies whatever the risk class.

No card · EU-hosted · 5 minutes to a first classification
Veritome obligations register — EU AI Act and GDPR duties per system and for the organisation, with owners, dates and status
The reality

What deployers get wrong first.

What we hear

“Our vendor is CE-marked, so we are covered.”

What the product does

Provider conformity and deployer compliance are separate duties. The CE mark says the provider did their part. Article 26 oversight, input data, six months of logs and the worker notification remain yours.

What we hear

“We never received instructions for use, and nobody chased it.”

What the product does

Article 13 obliges the provider to supply them, and Article 26 obliges you to use the system in accordance with them. Without the IFU you cannot discharge your own duty — so its absence is your problem, not only theirs.

What we hear

“Nobody told the staff a model was scoring their work.”

What the product does

Article 26(7) requires you to inform workers and their representatives before a high-risk system goes into use at work. It is one of the few duties with a hard sequencing requirement: before, not after.

What you get

The deployer journey, not the provider one.

01

Only the duties that are yours

The engine derives obligations from your role and risk class. A deployer never sees the Annex IV technical file or the conformity assessment — those belong to whoever built the system.

02

Instructions for use, received and receipted

Log the IFU the provider supplied, record what it says about oversight and intended purpose, and hold a dated receipt. Where nothing arrived, the gap is visible instead of assumed.

03

Oversight with a named person

Article 26(2) wants oversight by people with competence and authority. The register holds who, not just that.

04

Six months of logs, on purpose

Article 26(6) sets the retention floor for automatically generated logs. The record says where they live and who can produce them.

05

Worker notification, before use

The Article 26(7) notice, dated, with the representatives informed — an artefact you can show, not a recollection.

06

Article 4 literacy for everyone

The literacy duty is not tied to risk class. Six role-based programmes with per-person completion, so the evidence exists before anyone asks.

In practice

From a list of tools to an auditable record.

Use case 01

An operations team running a bought CV-screening tool.

  • Annex III point 4 — employment. High-risk, so the full Art. 26 set applies.
  • Named human overseer recorded, with the authority to override an output.
  • Art. 26(7) worker notice issued and dated BEFORE the tool went live.
  • Automatically generated logs retained for the Art. 26(6) six-month floor.
Veritome obligations register — EU AI Act and GDPR duties per system and for the organisation, with owners, dates and status
Use case 02

A support team using a vendor chatbot on the public site.

  • Not high-risk — but Art. 50 still requires people to be told they are talking to an AI.
  • The disclosure notice is drafted from the record, not written from scratch.
  • Art. 4 literacy still applies to the team operating it.
  • No Annex IV, no conformity assessment: the engine never raises them.
Veritome guided classification — the register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
Use case 03

A council deploying a benefits-triage model.

  • A public body, so Art. 27 binds: a fundamental-rights assessment is required.
  • It pre-fills from the existing DPIA — Art. 27(4) permits that reuse explicitly.
  • Affected people are informed under Art. 26(11).
  • One record, filed against both the EU AI Act and GDPR duties it evidences.
Veritome evidence register — files with fingerprints, the clauses each satisfies, scope and status
Also included

The parts a deployer reaches for later.

Straight answers

Straight answers for deployers.

How do I know whether I am a deployer or a provider?

You are a deployer if you use an AI system under your own authority — a vendor's chatbot, a bought scoring model, a tool embedded in your HR software. You become a provider under Article 25 if you put your own name or trademark on a high-risk system, substantially modify one, or change its intended purpose so that it becomes high-risk. Most organisations are a deployer for the tools they buy and a provider only for what they build, and the register handles both at once.

What does Article 26 actually require of me?

Use the system according to the provider's instructions; assign human oversight to people with the competence and authority to exercise it; make sure input data is relevant and sufficiently representative for the intended purpose; monitor operation and suspend use if a risk emerges; keep the automatically generated logs for at least six months; inform workers and their representatives before putting a high-risk system into use at work; and tell affected people when a high-risk system is used in decisions about them.

Do the deployer duties apply if the system is not high-risk?

Some of them do. Article 4 AI literacy applies to every organisation using AI, regardless of risk class. Article 50 transparency applies where a person interacts with an AI system, or where content is generated — that is a duty tied to the situation, not the tier. The Article 26 obligations are the ones reserved for high-risk systems.

Do I need a fundamental rights impact assessment?

Article 27 binds deployers that are public bodies or private entities providing public services, and deployers of the creditworthiness and life-and-health-insurance-pricing systems in Annex III. Where it applies, the assessment can build on a data protection impact assessment you have already done — Article 27(4) says so explicitly, and Veritome pre-fills from the DPIA rather than asking twice.

The vendor says their product is compliant. Is that enough?

No. Provider conformity and deployer compliance are separate duties. A CE-marked system placed correctly on the market still leaves you the oversight, the input data, the logs, the worker notification and the literacy. What the provider owes you is the instructions for use under Article 13 — and if those have not arrived, that is the first thing to chase.