Reglog

← Guides & analysis

EU AI Act deployer obligations: what you owe when you use a high-risk AI system

· 13 min read

Most of the EU AI Act's attention goes to the companies that build AI. But most companies will never build a high-risk AI system. They will buy one — a recruitment screener, a credit-scoring engine, an insurance pricing model — and use it. In the Act's vocabulary that makes them a deployer, and deployers have their own set of obligations.

They are lighter than a provider's. They are not optional, they carry fines, and one of them — the fundamental rights impact assessment — is easy to assume applies to far more companies than it does.

This is an information service to help you plan, not legal advice. For the obligations tied to your own AI use, see which apply to your company.

Are you a deployer?

Article 3(4) defines the role:

"'deployer' means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;"

Buying a tool and using it in your business is enough. You do not need to have built, trained or configured the underlying model.

The one thing to rule out first is that you have quietly become the provider. Under Article 25(1), a deployer is treated as the provider of a high-risk AI system — with the full provider obligations in Article 16 — if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system so that it becomes high-risk. White-labelling a vendor's screening tool, or repurposing a general-purpose assistant to rank job applicants, can move you across that line. Since the Digital Omnibus, breaches of Article 25(2) and (4) are also a separate fining ground under Article 99(4)(da). See the Article 25 trap for the detail. Fine-tuning a general-purpose AI model is a separate, model-level question, with its own compute-based test in the Commission's guidelines — see if you fine-tune an AI model, do you become its provider?

Everything below assumes you are a deployer and have stayed one.

The Article 26 checklist

Article 26 was not amended by the Digital Omnibus. Its duties, paragraph by paragraph (leaving out 26(10), which covers post-remote biometric identification in criminal investigations):

Duty Article What it means in practice
Use it as instructed 26(1) Technical and organisational measures to use the system in line with the provider's instructions for use
Real human oversight 26(2) Oversight assigned to people with "the necessary competence, training and authority, as well as the necessary support"
Input data quality 26(4) To the extent you control input data, it must be relevant and sufficiently representative for the intended purpose
Monitor, and act on risk 26(5) Monitor operation; if use may present a risk to health, safety or fundamental rights, inform the provider or distributor and the market surveillance authority and suspend use
Serious incidents 26(5) Immediately inform the provider first, then the importer or distributor and the market surveillance authorities
Keep the logs 26(6) Logs under your control kept for a period appropriate to the purpose, at least six months, unless other law provides otherwise
Tell your workforce 26(7) Employers inform workers' representatives and affected workers before putting the system into service at the workplace
Public-sector registration 26(8) Public-authority deployers register, and must not use a high-risk system that is not in the EU database
Feed your DPIA 26(9) Use the provider's Article 13 information when carrying out a GDPR data protection impact assessment
Tell affected people 26(11) Deployers of Annex III systems that make or assist decisions about natural persons must inform those persons
Cooperate 26(12) Cooperate with competent authorities acting in relation to the system

Two duties in that table need the most preparation.

The suspend duty in 26(5). Where you have reason to consider that using the system as instructed may result in it presenting a risk to health, safety or fundamental rights (a risk within the meaning of Article 79(1)), the text does not say "raise a ticket with the vendor". It says inform the provider or distributor and the market surveillance authority, and suspend use. That needs a named owner and a decision path before you need it, not after.

The workforce duty in 26(7). It falls on employers, it applies before the system goes live, and it covers both workers' representatives and the affected workers themselves. An HR tool switched on first and announced afterwards is the wrong order. And if the tool infers workers' emotions from their face, voice or the way they type, no notice makes it lawful — outside narrow medical or safety reasons that use is prohibited under Article 5(1)(f); see the emotion recognition ban at work.

If you are a financial institution, Article 26 contains two easements. Where you are subject to internal-governance requirements under Union financial services law, the monitoring duty in 26(5) is deemed fulfilled by complying with those rules, and the logs are kept as part of the documentation those rules already require (26(6)). The deeming clause refers to "the monitoring obligation"; it does not say whether it also covers the inform, suspend and serious-incident duties in the same subparagraph, so the cautious reading is that those still apply. The other Article 26 duties are unaffected.

Who actually needs a fundamental rights impact assessment

Start with who it covers, because the list is short. Article 27(1) does not apply to all deployers of high-risk AI. It applies, before deploying an Article 6(2) high-risk system, to:

Deployer FRIA required?
Bodies governed by public law Yes
Private entities providing public services Yes
Deployers of creditworthiness or credit-scoring systems (Annex III point 5(b)) Yes
Deployers of life and health insurance risk-assessment and pricing systems (Annex III point 5(c)) Yes
Any deployer, for systems used in critical infrastructure (Annex III point 2) No — expressly excluded
A private employer using a recruitment or worker-management tool (Annex III point 4) Not on the list, unless it is also a public-law body or a private entity providing public services

Where it applies, the assessment must describe the deployer's processes using the system; the period and frequency of use; the categories of people likely to be affected; the specific risks of harm to them, taking into account the provider's Article 13 information; the human oversight measures; and what happens if the risks materialise, including internal governance and complaint mechanisms (Article 27(1)(a)–(f)).

It is required for the first use. In similar cases you may rely on a previous assessment, or on one carried out by the provider, but you must update it if any element changes (27(2)). Once done, you notify the market surveillance authority of the results, submitting the filled-out template that the AI Office is to develop under 27(5) (27(3)). Deployers may be exempt from notifying in the Article 46(1) case, where a market surveillance authority has exceptionally authorised a system before its conformity assessment is complete.

For how this lands in specific sectors, see the AI Act for HR and recruitment software and the AI Act for credit scoring.

What the Digital Omnibus changed: the FRIA and your DPIA

Article 26 is untouched, but the Omnibus rewrote the relationship between the FRIA and the GDPR data protection impact assessment. Most deployers who need a FRIA will already need a DPIA for the same system, so this is the change with the most practical weight for them.

The original Article 27(4) read:

"…the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment."

The amended Article 27(4) reads:

"…the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment."

And Article 27(5), which tasks the AI Office with a template questionnaire "including through an automated tool", now adds that the template shall, where relevant, give deployers the possibility to include those cross-references or relevant parts of the DPIA.

In plain terms: the original text framed the FRIA as an addition layered on top of the DPIA. The amended text expressly lets you reuse DPIA work — by reference or by incorporation — for any FRIA element the DPIA already covers. The substantive list in 27(1)(a)–(f) did not change, so the FRIA still has to cover everything on it.

The right to an explanation

Article 86 gives people a right that deployers must be ready to answer. Any affected person subject to a decision taken by the deployer on the basis of the output of an Annex III high-risk system (other than point 2, critical infrastructure), which produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety or fundamental rights, has the right to obtain from the deployer "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken."

Two limits: it does not apply where Union or national law provides exceptions or restrictions (86(2)), and it applies only to the extent the right is not otherwise provided for under Union law (86(3)).

On timing, be careful. Article 86 sits in Chapter IX, outside the Chapter III provisions that Article 113 defers. But it turns on a system being "a high-risk AI system listed in Annex III", and the classification rules in Chapter III, Section 1 apply from 2 December 2027. We treat its practical start date as unsettled rather than assert one.

Separately, other law may already require some explanation today. One example is the GDPR: where a decision based solely on automated processing, including profiling, produces legal effects concerning a person or similarly significantly affects them (GDPR Article 22(1)), their right of access includes meaningful information about the logic involved and the significance and envisaged consequences of the processing (GDPR Article 15(1)(h)). That turns on the decision being based solely on automated processing, so a decision that a person actually takes, with the AI output as one input, may fall outside it. Check which rules apply to each decision rather than assuming the GDPR already covers you.

When all of this applies

Deployer duty Applies from
Not using a prohibited AI practice (Article 5) Already applies — Chapter II, since 2 February 2025 (the practices added by the Omnibus apply from 2 December 2026)
AI literacy (Article 4) Already applies — Chapter I, since 2 February 2025
Transparency duties that fall on deployers (Article 50) Already applies — since 2 August 2026
Articles 26 and 27, Annex III high-risk systems 2 December 2027
Article 26, Annex I high-risk systems (Article 27 covers only Article 6(2) systems, so it does not reach them) 2 August 2028

The deferral comes from Article 113, third paragraph, point (c), as amended: Chapter III, Sections 1, 2 and 3 — which includes Articles 26 and 27 — apply from those two dates.

There is also a transitional rule for high-risk systems already on the market or in service before then. Under Article 111(2), as amended, and without prejudice to Article 5, the Regulation applies to operators — deployers included — of high-risk AI systems placed on the market or put into service before "the date of application of Chapter III referred to in Article 113" only if, from that date, those systems "are subject to significant changes in their designs". Article 113 applies different parts of Chapter III from different dates, so the amended text does not say in terms which date it means; read naturally, and consistent with recital 39 of Regulation (EU) 2026/1744 (which ties the grace period to when "the relevant provisions" apply), it is the Sections 1–3 date for that system: 2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems. Components of the Annex X large-scale IT systems follow their own rule in Article 111(1). Providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030 in any case.

The duties that already apply are the ones most deployers are already exposed to today. See the prohibited AI practices under Article 5, AI literacy under Article 4, the Article 50 transparency rules and the full AI Act timeline.

The fines are real. Non-compliance with the deployer obligations in Article 26 is subject to administrative fines of up to EUR 15 000 000 or 3% of total worldwide annual turnover, whichever is higher (Article 99(4)(e)). For SMEs and start-ups it is whichever is lower (99(6)), and the Omnibus extended the "lower of" rule to small mid-caps for this tier (99(6a)). See how AI Act fines work.

A caution about the sources you are reading

As of 30 September 2026, the Commission's AI Act Service Desk still displays pre-Omnibus text, under its own "not yet updated" notice, on several provisions — including Article 25, the article that decides whether a deployer has become a provider, and Article 27, where it still shows the original "shall complement" wording rather than the amended cross-reference rule. The same notice also appears on provisions the Omnibus did not amend, including Article 26 itself, so the notice alone does not tell you whether a provision changed. Where a decision turns on the current wording, read the consolidated text and look for the amendment markers.

What to do now

  1. List every AI system you use, and mark the high-risk ones. Deployer duties attach per system. Start with whether each one is high-risk. If a vendor tells you its Annex III tool is not high-risk, ask which Article 6(3) condition it relies on.
  2. Check you have not become the provider. Rebranding, substantial modification or a changed intended purpose can each move you under Article 25(1), on the conditions set out above.
  3. Work out whether you are on the Article 27(1) list — public-law body, private entity providing public services, credit scoring, or life and health insurance pricing. If not, do not build a FRIA process you are not required to have.
  4. If you are on it, start from your DPIA. The amended Article 27(4) lets you cross-reference or incorporate it.
  5. Name an owner for the 26(5) suspend decision and the 26(7) workforce notice before any system goes live — they are two duties no vendor can do for you.

To see which obligations and which dates apply to your own systems, answer a few questions about your AI use. If you would rather not track changes like the FRIA template or the Service Desk update yourself, join the waitlist for the weekly email of verified AI Act changes we are building.

The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.

Frequently asked questions

What is a deployer under the EU AI Act?

Article 3(4) defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. A company that buys a third-party recruitment, credit-scoring or insurance-pricing tool and uses it in its business is a deployer of that system.

What does a deployer of a high-risk AI system have to do?

Article 26 requires deployers to use the system in line with the provider's instructions, assign human oversight to people with the necessary competence, training, authority and support, ensure input data under their control is relevant and sufficiently representative, monitor operation and inform the provider and market surveillance authority of risks and serious incidents, keep automatically generated logs under their control for at least six months, inform workers' representatives and affected workers before workplace use, inform natural persons subject to Annex III decisions, and cooperate with competent authorities. Public-authority deployers also have registration duties.

Does every deployer need a fundamental rights impact assessment?

No. Article 27(1) requires it before deploying an Article 6(2) high-risk system only from deployers that are bodies governed by public law or private entities providing public services, and from deployers of systems for creditworthiness and credit scoring (Annex III point 5(b)) or for risk assessment and pricing in life and health insurance (point 5(c)). Systems used in critical infrastructure (Annex III point 2) are excluded. A private employer using a recruitment tool is not on the list unless it is also a body governed by public law or a private entity providing public services.

When do the deployer obligations apply?

Articles 26 and 27 sit in Chapter III, Section 3. Under Article 113 as amended by the Digital Omnibus, that Section applies from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I systems. Some rules already reach deployers: the Article 5 ban on using a prohibited AI practice (Chapter II, applicable since 2 February 2025, except the practices added by the Omnibus, which apply from 2 December 2026), the Article 4 AI literacy duty (Chapter I, applicable since 2 February 2025) and the Article 50 transparency duties (applicable since 2 August 2026). Under Article 111(2), high-risk systems placed on the market or put into service before the date of application of Chapter III are covered only if their design changes significantly after that date (the amended text does not name the date; read naturally, it is 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems), but providers and deployers of those intended to be used by public authorities must comply by 2 August 2030 in any case.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.