AI Act role · Art. 3(4)

EU AI Act — Deployer

You use an AI system under your authority in a professional context — whether you built it or bought it from a provider.

Key obligations apply from

2 August 2026

3d left

Risk tier

high risk

Full AI Act applies by Aug 2027 for remaining Annex I scope

Scope notes: Deployers of high-risk AI must conduct fundamental rights impact assessments, ensure human oversight, monitor operation, and keep logs. Many obligations apply even when the provider holds primary conformity responsibility.

First steps before 2 August 2026

  1. 1Inventory AI systems used in professional operations
  2. 2Verify provider conformity documentation for high-risk systems
  3. 3Conduct fundamental rights impact assessments where required
  4. 4Establish human oversight and incident reporting procedures

Who supervises you?

Market surveillance authorities in each Member State enforce the AI Act. The European AI Office supports coordination, GPAI oversight, and cross-border cases.

AI Act implementation & AI Office

Priority mandates for you

5 instruments
GuidelinesIn developmentAML — financial3d leftArt. 27(5)

Fundamental rights impact assessment for deployers

Guidelines on conducting fundamental rights impact assessments before deploying high-risk AI — required for deployers of Annex III systems (except where exempt).

Why it matters: Deployer-side obligation distinct from provider conformity — critical for banks, insurers, and public bodies using third-party AI.

View on map
Administrative templateIn developmentAML overlap3d leftArt. 73(3)

Serious incident reporting template

Implementing act establishing the template for reporting serious incidents and malfunctioning of high-risk AI and GPAI models.

Why it matters: Providers and deployers must report within prescribed timelines — this template defines the required fields.

View on map
GuidelinesIn developmentAML overlap3d leftArt. 96

High-risk AI systems — requirements and conformity

Guidelines on the practical implementation of Chapter III requirements — risk management, data governance, transparency, human oversight, accuracy, and robustness (Art. 96(1)(a)).

Why it matters: Primary interpretive guide for Chapter III conformity once published — distinct from the Art. 6 classification consultation now open.

View on map
GuidelinesIn developmentAML — financial3d leftArt. 97

Application of requirements to Annex III use cases

Guidelines on how Chapter III requirements apply to each category of high-risk AI listed in Annex III.

Why it matters: Maps abstract obligations to concrete use cases — essential for deployers in HR, credit, insurance, and biometrics.

View on map
GuidelinesConsultation closed · drafting3d leftArt. 98

Transparency obligations for certain AI systems

Guidelines on transparency for AI interacting with natural persons, emotion recognition, biometric categorisation, and deepfakes (Art. 50).

Why it matters: Applies even when your AI is not high-risk — chatbots and synthetic content need disclosure from Aug 2026.

View on map
All rules for this roleAI Act on EUR-Lex

This page is an independent orientation guide — not legal advice. National implementation and sector-specific rules may apply. Always verify scope against the official AI Act text and your supervisor.