AI Act: obligations for AI deployers

AI literacy, prohibited practices, transparency, high risk: what the AI Act requires from an organisation that buys and uses AI systems, and what already applies in October 2026.

· 15 min read
Illustration: four glass blocks on a base, the third one taller and orange
AI literacy (Art. 4) Since February 2025
Transparency (Art. 50) Since August 2026
High risk (Art. 26 and 27) December 2027

AI Act deployer obligations apply to any organisation that uses, under its own authority, an artificial intelligence system designed by someone else. They depend on the system: train and raise awareness among staff for any AI (AI literacy, Article 4), give up prohibited uses (Article 5), inform people and flag generated content (Article 50) and, for high-risk systems, follow the instructions for use, ensure human oversight, keep logs and sometimes carry out a fundamental rights impact assessment (Articles 26 and 27). The first two have applied since February 2025 and transparency since August 2026; high risk will wait until December 2027. This article complements our guide to the EU AI Act.

01

Deployer or provider: what is your role under the AI Act?

Regulation (EU) 2024/1689, known as the AI Act, splits obligations between several actors. The provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. The deployer is the one using it “under its authority” in a professional context (Article 3(4)). Importers and distributors complete the chain.

Most organisations are therefore deployers: the bank scoring loan applications with a purchased tool, the hospital using emergency triage support, the local authority giving staff a generative AI assistant, the company screening applications with a module in its recruitment software. The role is not a formality: the vendor answers for the product's compliance, but only the user controls the context in which it is used, the people affected and the decisions that follow. That is what the regulation entrusts to it.

One organisation can hold several roles. If you build your own chatbot by calling a vendor's model, you become the provider of that system, since you put it into service under your name. And a deployer can switch to the provider role if it modifies the system (see section 8).

02

AI Act for user organisations: what applies as of 5 October 2026

The timeline changed in 2026. Proposed by the Commission on 19 November 2025, the “digital omnibus” on AI reached political agreement on 6 May 2026 and was adopted as Regulation (EU) 2026/1744 of 8 July 2026, published in the EU Official Journal on 24 July and in force since 27 July 2026. It replaces the Commission's conditional postponement with fixed dates. For a deployer, the situation is as follows.

Deployer obligations and application dates (as of 5 October 2026)
ObligationArticleApplication dateStatus
AI literacy of staffArt. 42 February 2025In force
Prohibited practicesArt. 52 February 2025In force
New prohibitions (non-consensual intimate content, child sexual abuse material)Art. 5, as amended by the omnibus2 December 2026Next deadline
Transparency: deepfakes, public-interest text, emotion and biometricsArt. 50(3) and (4)2 August 2026In force
Annex III high-risk systems: use, human oversight, logs, informationArt. 262 December 2027 (instead of 2 August 2026)Upcoming
Fundamental rights impact assessmentArt. 272 December 2027Upcoming
AI embedded in regulated products (Annex I: medical devices, machinery…)Art. 6(1)2 August 2028 (instead of 2 August 2027)Upcoming
Matrix of deployer obligations under the AI Act. Common baseline: staff AI literacy (Article 4), since February 2025. Prohibited practice, such as emotion recognition at work: do not use, since February 2025. Annex III high risk, such as recruitment or credit: instructions, human oversight, logs, information (Article 26) and FRIA (Article 27), from December 2027. Transparency, such as deepfakes: flag content and inform people, since August 2026. Minimal risk: nothing beyond the baseline. At the bottom: putting your name on the system, substantially modifying it or giving it a high-risk use turns the deployer into a provider (Article 25).
Deployer obligations by type of AI system, with their application dates (diagram in French).

Three points remain open at this date. First, France has not yet designated its supervisory authorities by law, although the deadline was 2 August 2025. The scheme presented by the Directorate-General for Enterprise in September 2025 gives coordination to the DGCCRF (consumer protection authority), most sensitive uses (biometrics, employment, education) to the CNIL (data protection authority), content transparency to Arcom (media regulator, with the DGCCRF), financial uses to the ACPR (banking and insurance supervisor), with technical support from ANSSI and PEReN. The relevant part of the bill adapting French law to EU law (DDADUE) was adopted by the Senate on 18 February 2026; it was still awaiting examination in the National Assembly when we last checked, in early October 2026.

Second, several Commission documents useful to deployers are announced but not yet published: the fundamental rights impact assessment template, guidelines on responsibilities along the value chain and on substantial modification (list kept by the Commission, updated 31 July 2026). Third, the guidelines on high-risk classification existed only as a draft, under consultation until 23 July 2026. Our article on high-risk AI systems covers that classification.

03

AI literacy (Article 4): the common baseline, already applicable

Article 4 covers all providers and deployers, whatever the risk level: a writing assistant is enough to be in scope. In its original version, it required organisations to ensure “to their best extent” a sufficient level of AI literacy among staff. The omnibus softened it: since 27 July 2026, organisations must take measures to support that literacy, without a specific level being required of each person. The Commission and Member States undertake to publish practical examples.

The Commission's Q&A sets the expected level:

  • no certificate or mandatory structure (AI officer, committee): an internal record of training and awareness actions is enough;
  • the scope covers employees, but also contractors and service providers using the systems on your behalf;
  • content is tailored to the role, the people's knowledge and the risk of the systems used;
  • supervision by national authorities starts in August 2026, with arrangements and penalties set by national law.

In practice, an AI literacy programme is built from the inventory of uses (section 11): a baseline for everyone (how it works, limits, plausible errors, data never to enter), then modules per population. People in charge of human oversight of a high-risk system will need genuine competence, training and authority (Article 26(2)): the softening of Article 4 does not apply to them.

04

Prohibited practices: what a deployer must not do

Since 2 February 2025, Article 5 has banned placing on the market but also using certain systems. Deployers are therefore directly concerned. Among the bans that can affect an ordinary organisation:

  • emotion recognition in the workplace and in education, except for medical or safety reasons (analysing call centre agents' tone, detecting pupils' fatigue);
  • social scoring leading to unfavourable treatment unrelated to the context in which the data was collected;
  • manipulative techniques or exploitation of vulnerabilities related to age, disability or social situation;
  • biometric categorisation to infer race, political opinions, trade union membership, beliefs or sexual orientation;
  • building facial recognition databases by untargeted scraping of images.

The Commission guidelines on prohibited practices, published in February 2025, detail these cases with examples. From 2 December 2026, the omnibus adds a ban on systems generating realistic intimate images of an identifiable person without consent or child sexual abuse material; for a deployer, it covers using the system for that purpose. These breaches carry the highest penalty ceiling: €35 million or 7% of worldwide turnover.

05

Article 50: deployer transparency obligations

Since 2 August 2026, Article 50 has required deployers to meet three information duties, clearly and at the latest at first exposure:

  • emotion recognition or biometric categorisation systems (where permitted): inform the people exposed that they are operating;
  • deepfakes (generated or manipulated images, audio or video resembling real people, places or events): disclose that the content is artificial, in an appropriate way for artistic or satirical works;
  • text published to inform the public on matters of public interest: disclose that it is AI-generated or manipulated, unless it has undergone human editorial control under a person's responsibility.

The Commission guidelines of 20 July 2026 clarify these rules. The provider's technical marking does not relieve the deployer of its own visible and understandable disclosure; the editorial control exception requires a documented review workflow, not a mere claim; content published before 2 August 2026 does not need retroactive labelling. For a communications department, this means a written rule on generated visuals and an approval workflow for texts.

The duty to tell users they are interacting with AI (Article 50(1)) falls on the provider. But if you assembled your website's chatbot yourself, that is you.

06

High-risk systems: Article 26 obligations

Annex III high-risk systems cover eight areas: biometrics, critical infrastructure, education, employment and workforce management, access to essential services (public benefits, credit, life and health insurance, emergency call triage), law enforcement, migration, justice and democratic processes. When you use one, Article 26 will require you, from 2 December 2027, to:

  1. Use the system in accordance with its instructions, through appropriate technical and organisational measures.
  2. Assign human oversight to competent, trained people with the necessary authority and support.
  3. Ensure input data is relevant, where you control it, to the system's intended purpose.
  4. Monitor operation, inform the provider and the authority of risks, suspend use if needed, and report serious incidents.
  5. Keep the automatically generated logs under your control for at least six months.
  6. Inform workers' representatives and affected workers before putting such a system into service at the workplace.
  7. Inform people that they are subject to a decision made or assisted by the system; they may also request an explanation (Article 86).
  8. For public authorities: check that the system is registered in the EU database and register their use of it.

The sixteen-month postponement should not hide the workload: organised human oversight, log retention, informing workers and affected people all require procedures and often contract changes. For high-risk systems already on the market and intended for public authorities, Article 111 allows until 2 August 2030 to comply.

07

FRIA: the fundamental rights impact assessment (Article 27)

The fundamental rights impact assessment (FRIA) does not apply to all deployers. For Annex III systems other than critical infrastructure, Article 27 limits it to three categories:

  • bodies governed by public law: administrations, local authorities, public hospitals, universities;
  • private entities providing public services;
  • any deployer of a system for creditworthiness assessment or credit scoring of individuals, or for risk assessment and pricing in life and health insurance.

Carried out before first use, it describes the processes in which the system is used, its duration and frequency of use, the categories of people affected, the risks of harm to them, human oversight measures and what is planned if risks materialise (governance, complaints handling). The result is notified to the market surveillance authority. The AI Office must provide a questionnaire template, which the omnibus also provides for as an automated tool; as of 5 October 2026, it had not been published.

08

When a deployer becomes a provider (Article 25)

Article 25 turns a deployer, distributor or importer into a provider in three cases:

  • it puts its name or trademark on a high-risk system already on the market;
  • it makes a substantial modification and the system remains high-risk;
  • it changes the intended purpose of a system that was not high-risk, including a general-purpose AI system, so that it becomes high-risk.

The third case is the most common in practice: an HR team using a general-purpose assistant to rank applications gives it an Annex III purpose. The organisation then becomes the provider of a high-risk system, with risk management, technical documentation, conformity assessment and CE marking. The initial provider is then no longer considered the provider of that system, but must cooperate and hand over the necessary information and technical access (Article 25(2)). A clear use policy listing forbidden purposes for general-purpose tools is the best protection.

09

AI Act and GDPR: connecting the FRIA and the DPIA

Most AI systems process personal data: the AI Act adds to the GDPR without replacing it. There are two bridges. Article 26(9) requires deployers to use the information in the provider's instructions to carry out their data protection impact assessment (DPIA). Article 27(4) lets the FRIA build on the DPIA; the omnibus allows a simple cross-reference.

The CNIL considers a DPIA presumed necessary for AI Act high-risk systems that process personal data, and required in most cases for general-purpose systems. It lists the AI-specific risks to include: discriminatory bias, false content about real people, automation bias, poisoning or model inversion attacks. Its recommendations on deploying generative AI add a method: start from a specific need, set usage rules, favour secure deployments, train users, and involve the DPO, the CISO and business teams from the outset.

In healthcare, the French health authority (HAS) and the CNIL published in February 2026 a guide on the proper use of AI systems in care settings, aimed at deploying institutions: proportionate governance, an annual inventory of systems, information requirements towards providers, mandatory prior training and checking the system works in the local context.

10

Procurement: questions to ask your AI suppliers

Deployers depend on their provider for much of their compliance: without instructions, no compliant use; without exportable logs, no retention; without information on data, no serious DPIA. Buying an AI system therefore falls within your third-party risk management (TPRM). Questions to add to your supplier security questionnaire:

  • What is the system's intended purpose, and does the provider classify it as high-risk? On what basis?
  • Can you provide the instructions for use, the declared accuracy levels and known limitations?
  • What human oversight measures does the system provide, and which logs can be exported, in what format?
  • Is our data (prompts, documents, outputs) used to train or improve the model? Where is it hosted and processed?
  • Which third-party models are integrated, and how does the provider track their changes?
  • How is the system protected against AI-specific attacks (prompt injection, poisoning)?
  • How will we be informed of serious incidents and substantial modifications?
  • Does generated content carry marking compliant with Article 50(2)?

The answers feed the system's classification, the DPIA and the contract clauses. They should be reassessed with each major new version.

11

Inventory of uses and shadow AI: where to start

You cannot classify what you do not know. Yet many uses escape IT departments: according to Microsoft and LinkedIn's 2024 Work Trend Index, 78% of employees who use AI at work bring their own tools. This “shadow AI”, the AI equivalent of shadow IT, exposes you to data leaks, but also to prohibited or high-risk uses unknown to management. A six-step approach:

  1. List AI systems: purchased tools, AI features built into existing software, online services used by teams (survey, analysis of network flows and purchases).
  2. Determine your role for each: deployer, or provider if you built, modified or repurposed it.
  3. Classify each use: prohibited, high-risk, transparency, minimal risk. Prohibited uses stop immediately.
  4. Connect the inventory to the record of processing and DPIAs, and include the systems in your risk map and risk analysis.
  5. Govern: AI use policy, list of approved tools, AI literacy programme, approval workflow for new tools.
  6. Prepare for 2027 for high-risk systems: human oversight, logs, informing workers and affected people, FRIA where required.

This inventory is also a chance to consider AI's place in your own compliance processes, which we cover in our article on AI and GRC. To structure the assessment of your AI suppliers with questionnaires and a dedicated portal, see our vendor risk management module.

Summary

01

You are almost always a deployer

As soon as your organisation uses an AI system it bought or subscribed to under its own authority, the AI Act gives you obligations of your own, separate from the vendor's.

02

Part of it already applies

AI literacy and prohibitions since February 2025, transparency since August 2026. Obligations for Annex III high-risk systems are postponed to 2 December 2027 by the omnibus regulation.

03

Start with the inventory

List the uses, including shadow AI, classify each system, question suppliers and connect it all to your DPIAs: that is the foundation for everything else.

Frequently asked questions

What is a deployer under the AI Act?

Any natural or legal person, public authority, agency or other body using an AI system under its authority, except for personal non-professional use (Article 3(4)). A company using a CV screening tool or a generative AI assistant bought from a vendor is a deployer; the vendor is the provider.

Which AI Act obligations already apply to user organisations?

As of 5 October 2026: the AI literacy obligation (Article 4) and the ban on Article 5 practices, since 2 February 2025, then the Article 50 transparency obligations since 2 August 2026. Obligations specific to Annex III high-risk systems (Articles 26 and 27) will apply from 2 December 2027.

Is a certificate needed to meet the AI literacy obligation (Article 4)?

No. The European Commission states that no certificate is required and that an internal record of training and awareness actions is enough. Since the omnibus regulation, Article 4 asks organisations to support their staff's AI literacy, without setting a level each person must reach.

Who must carry out a fundamental rights impact assessment (FRIA)?

Article 27 limits it to certain deployers of Annex III high-risk systems: bodies governed by public law, private entities providing public services, and deployers of creditworthiness assessment or life and health insurance pricing systems. It is done before first use.

When does a deployer become a provider?

Under Article 25, when it puts its name or trademark on a high-risk system already on the market, makes a substantial modification to it, or changes the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk. It then takes on the provider's obligations.

What penalties does a deployer face for breaching the AI Act?

Up to €35 million or 7% of worldwide turnover for a prohibited practice, and up to €15 million or 3% for breaching deployer obligations (Article 26) or transparency obligations (Article 50), whichever is higher. For SMEs, the lower of the two applies. In France, the authorities that will impose them have not yet been designated by law.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.