Back to Publications
Regulatory Brief · AI Act

AI Act: You Are Probably a Deployer — And Owe Duties

29 July 2026By NexCyber Editorial AI Act

Most companies think the AI Act is for AI builders. If you use AI in hiring, credit or access to services, you are a deployer — and you owe obligations.

The short answer

Most organisations reading about the AI Act conclude it does not apply to them, because they do not build AI systems. That conclusion is usually wrong.

Regulation (EU) 2024/1689 assigns obligations by role, not by industry. The role that catches the most companies is deployer — an organisation using an AI system under its own authority. You do not have to write a line of model code to be one.

provider    you develop an AI system, or have one developed, and place it
            on the market or into service under your own name
deployer    you USE an AI system under your own authority

And a deployer can become a provider without meaning to. Put your own name or trademark on a high-risk system, make a substantial modification to it, or change its intended purpose so that it becomes high risk — and you take on the provider's obligations in full.

Two dates have already passed:

 2 February 2025   prohibited practices (Article 5) · AI literacy (Article 4)
 2 August   2025   general-purpose AI model obligations, governance, most penalties
 2 August   2026   general application, including Annex III high-risk systems
 2 August   2027   high-risk systems that are products or safety components

---

Where deployer duties actually bite

The AI Act does not care whether you consider your tool "an AI project". It cares what the system decides, and about whom.

Annex III lists the high-risk use cases, and three of them describe things ordinary companies do every week:

employment, worker management, access to self-employment
    -> screening or filtering applications, evaluating candidates,
       decisions on promotion, termination, task allocation, monitoring
access to essential private and public services
    -> creditworthiness evaluation, risk assessment and pricing
       in life and health insurance
biometrics
    -> identification, categorisation, emotion inference

If a bought tool ranks candidates, scores creditworthiness, or infers emotion in a workplace, you are operating a high-risk system — or a prohibited one. Nobody in your organisation necessarily called it an AI deployment. That does not change the classification.

---

What a deployer owes — Article 26

These obligations are yours, independent of anything the provider does:

  • Use the system in accordance with its instructions for use. Deviating from them can shift responsibility onto you.
  • Assign human oversight to people with the competence, training and authority to exercise it. A named reviewer with no power to overturn the output is not oversight; it is a signature.
  • Ensure input data is relevant and sufficiently representative in view of the intended purpose, to the extent you control that data.
  • Monitor operation and suspend use plus inform the provider where you identify a risk.
  • Keep the automatically generated logs for an appropriate period, at least six months unless other law says otherwise.
  • Inform workers' representatives and affected workers before putting a high-risk system into use in the workplace.
  • Inform people subject to decisions taken or assisted by a high-risk system in the Annex III cases.

And certain deployers must carry out a fundamental rights impact assessment before first use — including bodies governed by public law, private entities providing public services, and deployers of the creditworthiness and insurance-pricing use cases.

The FRIA is the obligation most likely to be discovered after deployment, and it is the one that cannot be produced retroactively with any credibility. It is an assessment *before* use; writing it afterwards documents what you already did.

---

The transparency duties that apply to almost everyone

Even outside high risk, Article 50 creates disclosure duties that reach ordinary commercial use from 2 August 2026:

  • people must be told they are interacting with an AI system, unless it is obvious;
  • synthetic audio, image, video and text must be marked in a machine-readable format;
  • deep fakes must be disclosed;
  • AI-generated text published to inform the public on matters of public interest must be disclosed, subject to defined exceptions.

The machine-readable marking requirement is a technical obligation on whoever generates the content, not a labelling policy on whoever publishes it. If your marketing team generates images or copy with AI, this is the clause that reaches them.

---

The prohibition that arrives by purchase

Article 5 has been enforceable since February 2025 and carries the regulation's highest penalty. Two of the eight bans describe features that arrive inside bought software:

emotion inference in the workplace and in education
    except for medical or safety reasons
biometric categorisation to infer sensitive attributes
    race, political opinions, trade union membership, religious beliefs,
    sexual orientation

An interview-analysis tool that scores candidate enthusiasm. A contact-centre feature that reports agent sentiment. A productivity monitor that flags disengagement. None of these arrive labelled as an AI project. All three describe emotion inference in a workplace.

A prohibited practice cannot be remediated by documentation. Every other tier is a matter of doing the work properly. This one is a matter of stopping.

---

What it costs to get the role wrong — Article 99

breach of the Article 5 prohibitions
    up to  EUR 35 000 000  or  7 %  of total worldwide annual turnover
breach of most other obligations, including deployer duties
    up to  EUR 15 000 000  or  3 %
incorrect, incomplete or misleading information to authorities
    up to  EUR  7 500 000  or  1 %

Amounts are the higher of the two. For SMEs and start-ups, the ceiling is the lower.

Seven per cent is the highest penalty ceiling in EU digital regulation — above the GDPR's four per cent — and it attaches to the tier that has been in force since February 2025.

---

And it reaches you from outside the Union

The regulation applies to providers placing systems on the Union market wherever they are established, and to providers and deployers established in third countries where the output produced by the system is used in the Union.

Output, not deployment, is the connecting factor. A model running entirely on US infrastructure, producing a decision used about a person in the EU, is inside scope.

---

Five determinations, in order

  1. 1Inventory AI systems you USE, not only those you build. Bought software is rarely inventoried as AI, and that is precisely why deployer duties are found late.
  2. 2Screen every line against Article 5 first. In force, highest penalty, no remediation path.
  3. 3Classify by use case, not by model. The same model is minimal risk summarising documents and high risk ranking candidates.
  4. 4Check whether you have become a provider by rebranding, modifying, or repurposing someone else's system.
  5. 5Record the minimal-risk conclusions too. An unrecorded decision is indistinguishable from no decision — and a market surveillance authority asks what you concluded, and why.

---

Test your position — free, no account, no sales call

Both tools are free and return a result immediately:

  • [Free applicability assessment](/assess) — determine your role, your risk tier, and which obligations follow. Covers the AI Act alongside CRA, NIS2, DORA and RED.
  • [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role, so the oversight duty lands on a named person rather than on a department.
  • [Penalty calculator](/resources/penalty-calculator) — exposure by regulation, on your own turnover.

No credit card. No call required to unlock the result.

---

Further reading

What is the EU AI ActAI Act risk tiers explainedArticle 5 prohibited practicesAI Act × CRA — overlap for AI products with digital elementsOne evidence set across five EU regulationsAI Act regulation overview

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. The AI Act applies in phases, and guidelines, harmonised standards and codes of practice supporting classification continue to be adopted — verify against the current text of Regulation (EU) 2024/1689 and the Official Journal. Consult your competent authority or a qualified adviser.*