EU AI Act Deployer Obligations Checklist for Enterprises
Under Regulation (EU) 2024/1689, an enterprise that uses an AI system in a professional context without being its provider is classified as a deployer and carries a distinct set of legal obligations. Core duties under Article 26 include using high-risk systems according to the provider's instructions, assigning trained human oversight, monitoring operation, retaining system-generated logs for at least six months, and suspending use if a serious risk is identified. Most of these obligations become applicable on 2 August 2026.
Under Regulation (EU) 2024/1689, an enterprise that uses an AI system in a professional context without being its provider is classified as a deployer and carries a distinct set of legal obligations. Core duties under Article 26 include using high-risk systems according to the provider's instructions, assigning trained human oversight, monitoring operation, retaining system-generated logs for at least six months, and suspending use if a serious risk is identified. Most of these obligations become applicable on 2 August 2026.
Deployer obligation timeline
Enterprise deployers should plan controls against the Act's staged applicability dates. The milestones below organize literacy, core high-risk duties, and product-safety timelines.
-
2 Feb 2025
AI literacy obligations and prohibitions on unacceptable-risk practices apply to deployers.
-
2 Aug 2026
Core high-risk deployer obligations under Article 26 become applicable.
-
2 Aug 2027
High-risk AI as a safety component of regulated products (Annex I) becomes applicable.
Core deployer obligations under Article 26
Article 26 sets operational duties for enterprises that put high-risk AI systems into use. The checklist below is the practical baseline for governance, oversight, and incident response.
- Use the high-risk system in accordance with the provider's instructions for use
- Assign human oversight to personnel with the competence, training, and authority to intervene
- Monitor operation for indications of risk to health, safety, or fundamental rights
- Suspend use and notify the provider or market surveillance authority upon detecting a serious risk
- Retain automatically generated logs under the deployer's control for at least six months
- Inform affected workers and their representatives before putting a system into use in the workplace
Deployer vs. provider: why the distinction matters
A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its own authority in a professional context. Most enterprises adopting third-party AI tools are deployers, unless they substantially modify or rebrand the system.
Confirming the role per system is essential. Modification can shift obligations from deployer to provider, which changes documentation, conformity, and post-market duties. Inventory work should capture both the classification of each system and the legal role your organization holds for that system.
Fundamental rights impact assessments and transparency duties
Deployer obligations under the AI Act, including the Fundamental Rights Impact Assessment, are separate from GDPR obligations such as the Data Protection Impact Assessment. The two processes address related but distinct risks and should be coordinated rather than duplicated.
Most substantive deployer duties under Article 26 apply to high-risk systems. AI literacy obligations and prohibitions on unacceptable-risk practices, which became applicable in February 2025, apply to deployers more broadly regardless of risk tier. EU database registration requirements apply specifically to public-authority deployers of Annex III high-risk systems, not to private enterprise deployers generally.
Human oversight and logging controls
Two Article 26 controls often require early engineering and process design: human oversight and log retention. Oversight is not a nominal assignment. Personnel need competence, training, and real authority to intervene. Logging is not only storage: automatically generated logs under the deployer's control must be retained for at least six months and available when monitoring or incident review requires them.
Define a documented process for suspending system use and notifying the provider or market surveillance authority when a serious risk is identified. Pair that process with monitoring signals tied to health, safety, and fundamental rights outcomes.
Implementation priorities for enterprise deployers
Use the following sequence to move from inventory to operational readiness ahead of the August 2026 milestone for core high-risk duties.
- Inventory all AI systems in use and classify each against Annex I and Annex III criteria
- Confirm provider versus deployer role per system, noting that modification can shift obligations
- Build a compliance calendar aligned to the February 2025, August 2026, and August 2027 milestones
- Document human oversight assignments with training and authority records for each high-risk system
- Establish logging and retention infrastructure specific to high-risk AI system outputs
- Define a documented process for suspending system use and notifying providers or authorities
Penalties and compliance scope
Administrative fines can reach up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher, under the Act's tiered penalty structure. Exact tier-to-obligation mapping should be confirmed against the consolidated regulation text. AI Act compliance does not replace GDPR; the regimes should be run in coordination.
Frequently asked questions
What is the difference between a provider and a deployer under the EU AI Act?
A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its own authority in a professional context. Most enterprises adopting third-party AI tools are deployers, unless they substantially modify or rebrand the system.
Do deployer obligations apply to all AI systems or only high-risk ones?
Most substantive deployer duties under Article 26 apply to high-risk systems. AI literacy obligations and prohibitions on unacceptable-risk practices, which became applicable in February 2025, apply to deployers more broadly regardless of risk tier.
What penalties apply for non-compliance with deployer obligations?
Administrative fines can reach up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher, under the Act's tiered penalty structure. Exact tier-to-obligation mapping should be confirmed against the consolidated regulation text.
Does AI Act compliance replace GDPR obligations?
No. Deployer obligations under the AI Act, including the Fundamental Rights Impact Assessment, are separate from GDPR obligations such as the Data Protection Impact Assessment. The two processes address related but distinct risks and should be coordinated rather than duplicated.
Do all enterprise deployers need to register in the EU AI database?
No. EU database registration requirements apply specifically to public-authority deployers of Annex III high-risk systems, not to private enterprise deployers generally.
Prepare Runtime Controls Ahead of August 2026
Core high-risk deployer obligations, including human oversight and logging, become applicable on 2 August 2026. Building the underlying runtime governance infrastructure now reduces the risk of a compliance gap at that deadline.
Explore Runtime Governance