Chapter 6 of 11
Obligations for Deployers: Using AI Systems Responsibly in Your Business
Most organizations do not build AI from scratch—they deploy it; learn what responsibilities fall on deployers, even when AI is purchased from vendors or embedded in SaaS tools.
1. Who Are Deployers Under the EU AI Act?
Who Is a Deployer?
In the EU AI Act, most organizations are deployers: they use AI systems in their own activities, often bought from vendors or embedded in SaaS tools, rather than building them from scratch.
Provider vs Deployer
Provider develops and places AI on the EU market. Deployer uses that AI in practice. A company can be both, but the obligations differ depending on the role.
Why the Distinction Matters
As a deployer of high-risk AI, you do not repeat the provider's conformity assessment. Instead, you must use the system as intended, ensure data quality, human oversight, logging, and transparency to users.
Mental Model
Think: Provider = “Is the system designed compliantly?” Deployer = “Is it used safely and fairly in my context?” This module focuses on the deployer side.
2. Mapping Your Role: Are You a Deployer, Provider, or Both?
Typical Deployer Scenarios
You are a deployer when you use AI in tools like recruitment SaaS, cloud credit scoring, AI medical image analysis, or customer service chatbots built by someone else.
When You Become a Provider Too
You may also be a provider if you significantly modify an AI system, or integrate AI components into a new product that you market under your own name.
Quick Role Checklist
Ask: Who built and marketed the system? Do we sell it under our brand? Have we substantially changed its purpose or performance? The answers show whether you are deployer only or also provider.
3. Thought Exercise: Spot the Deployer
Apply the concepts to a few scenarios. For each, decide if the organization is acting as a deployer, provider, or both.
- Scenario A: A supermarket chain buys an AI video analytics service that flags suspected shoplifting in real time. The service is branded and operated by an external vendor. The supermarket configures camera locations and decides when to intervene.
- Scenario B: A fintech startup develops its own credit scoring model and offers it as a paid API to other lenders across the EU, under its own brand.
- Scenario C: A hospital licenses an AI radiology tool but then builds a new interface and workflow, markets this combined solution under the hospital’s brand to other clinics, and charges them.
Your task
- Write down your classification for each scenario:
- A: ?
- B: ?
- C: ?
- Then check your reasoning against the model answers below.
Model answers (self-check)
- A: Deployer (they use a third-party high-risk AI system for security decisions).
- B: Provider (and deployer internally) (they build and place the AI on the market; if they also use it for their own lending decisions, they are also a deployer).
- C: Both provider and deployer (they modify and integrate the AI into a new marketed system, and also use it internally).
Reflect: In your own organization, where do you act only as a deployer, and where might you also be a provider?
4. Core Deployer Duties for High-Risk AI
High-Risk Deployer Duties
As a deployer of high-risk AI, your duties include: using the system as instructed, ensuring data quality, providing human oversight, keeping logs, informing users, and monitoring for incidents.
Use as Intended
You must follow the provider's instructions for use, including intended purpose, technical limits, and safe operating conditions. Using the system outside these can breach the AI Act.
Data, Oversight, and Logs
You are responsible for the quality of input data you supply, for ensuring qualified human oversight of the AI, and for keeping logs so decisions can be traced and audited.
Transparency and Monitoring
You must inform affected persons about the AI's role in decisions and monitor its performance in your context, reporting serious incidents to the provider and authorities when required.
5. Using High-Risk AI in HR: A Concrete Walkthrough
HR Screening Scenario
A company uses a vendor's SaaS to screen CVs and rank applicants. This employment-related AI is typically high-risk under the AI Act, so deployer obligations apply.
Use as Intended and Data Quality
Confirm that the tool's intended purpose covers your hiring use, and avoid repurposing it. Carefully choose input data, minimize protected attributes, and check for historical bias.
Human Oversight in HR
Train recruiters to understand and challenge AI scores, override recommendations when needed, and escalate anomalies such as systematic rejection of certain groups.
Logs, Transparency, Monitoring
Log system versions, inputs, outputs, and final decisions. Inform candidates about AI use in screening, and regularly monitor outcomes for bias or malfunction, pausing use if needed.
6. Quick Check: Deployer Duties in Practice
Test your understanding of deployer responsibilities for high-risk AI systems.
Your company uses a high-risk AI system from a vendor to decide on loan approvals. Which of the following is primarily YOUR responsibility as a deployer, not the vendor's?
- Designing the model architecture and training algorithm
- Ensuring that the customer data you input is accurate, relevant, and used within the system's intended purpose
- Drafting the EU declaration of conformity for the AI system
- Registering the AI system in the EU database as a high-risk AI provider
Show Answer
Answer: B) Ensuring that the customer data you input is accurate, relevant, and used within the system's intended purpose
As a deployer, you are responsible for data quality and using the system in line with its intended purpose. Designing the model, drafting the declaration of conformity, and registering the system are provider obligations.
7. Transparency and Article 50-Style Disclosure
Transparency Duties
Deployers must inform individuals when high-risk AI is used in decisions affecting them, and provide clear information about the AI's role, main factors, and human review.
Article 50-Style Information
Be ready to explain, in simple language, whether AI supports or automates decisions, what key parameters it uses, and how humans can review or override its outputs.
Example: Credit Decisions
A bank discloses AI use in its loan application interface and in decision letters explains key factors, human review, and how customers can challenge or request review.
Align With GDPR
When personal data is used, GDPR rights also apply, including the right to be informed and, in some cases, rights about automated decision-making and profiling.
8. Sector-Specific Considerations: Finance, Healthcare, Public Sector
Finance Deployers
In finance, focus on fairness and auditability: set escalation paths for contested credit or fraud decisions, test for discrimination, and keep detailed logs for regulators.
Healthcare Deployers
In healthcare, treat AI as decision support. Train clinicians, define when AI can be overruled, and log AI recommendations and final clinical choices for quality review.
Public Sector Deployers
In public services, emphasize due process: clear notices about AI, appeal and human review mechanisms, and impact assessments to understand societal effects.
Same Pattern, Different Contexts
Across sectors, identify likely harms, then adapt human oversight, logging, and transparency measures to manage those risks in your specific environment.
9. Shared Responsibility and Contracts With AI Vendors
Shared Responsibility
Compliance is shared: providers must supply compliant high-risk AI and documentation; deployers must use it responsibly. Contracts are where this cooperation becomes concrete.
What Providers Owe You
Expect instructions for use, performance and risk information, and logging capabilities or guidance from providers of high-risk AI systems.
Key Contract Clauses
Negotiate compliance warranties, rights to documentation, audit and cooperation clauses, and clear allocation of logging and data responsibilities.
Align Internally
Procurement of AI tools should involve legal, compliance, IT, and business teams, ensuring vendor terms fit your internal AI policies and risk appetite.
10. Design Your Deployer Action Plan
Use this activity to sketch a practical action plan for your (imaginary) organization as a deployer of high-risk AI.
- Pick a use case
- Example: AI for hiring, credit scoring, medical triage, or social benefit eligibility.
- List your deployer duties for this case
- Use in accordance with instructions.
- Data quality.
- Human oversight.
- Logging and records.
- Transparency to affected persons.
- Monitoring and incident reporting.
- For each duty, write one concrete action
- Example for HR screening:
- Use as instructed: “Check vendor documentation and confirm we only use the tool for roles and regions it supports.”
- Data quality: “Remove unnecessary sensitive fields from application forms.”
- Human oversight: “Train recruiters on how to interpret and override AI scores.”
- Logging: “Configure the system to export decision logs to our secure archive.”
- Transparency: “Update job ads and privacy notice to mention AI-assisted screening.”
- Monitoring: “Review hiring outcomes quarterly for bias indicators.”
- Identify who owns each action
- HR? IT? Compliance? Legal? Business unit?
Write down your plan in a table or bullet list. If you can, compare with a peer and discuss: Which actions are easiest? Which are hardest?
11. Key Terms Review
Flip these cards to review the most important concepts for deployers under the EU AI Act.
- Deployer (under the EU AI Act)
- An organization that uses an AI system in the course of its own activities (e.g., a company using an AI recruitment tool), regardless of who built the system.
- Provider (under the EU AI Act)
- An organization that develops an AI system or foundation model and places it on the EU market under its own name or trademark, or substantially modifies an existing system.
- High-risk AI system
- An AI system used in sensitive areas listed in the AI Act (such as employment, credit, healthcare, education, public services) where errors can significantly affect people's rights or safety.
- Human oversight (for deployers)
- Processes ensuring qualified humans can understand, supervise, and, when necessary, override or disregard AI outputs in real-world use.
- Data quality (for deployers)
- The obligation to ensure input data you supply to a high-risk AI system is relevant, accurate, and appropriate for your context, reducing bias and errors.
- Logging and record-keeping
- Maintaining logs of AI system operation (inputs, outputs, versions, decisions) so that decisions can be traced, audited, and investigated if problems arise.
- User-facing transparency
- Informing individuals when AI is used in decisions affecting them and providing understandable information about the AI’s role, main factors, and human review.
- Shared responsibility
- The idea that providers and deployers each have distinct but connected obligations under the AI Act, and must cooperate (often via contracts) to ensure overall compliance.
Key Terms
- Logging
- The recording of events, inputs, outputs, and system states during AI system operation to enable traceability and auditing.
- Deployer
- An organization that uses an AI system in the course of its own activities, regardless of who built the system.
- Provider
- An organization that develops an AI system or foundation model and places it on the EU market under its own name or trademark, or substantially modifies an existing system.
- Data quality
- The suitability of data for its intended use, including relevance, accuracy, representativeness where appropriate, and minimization of bias.
- Human oversight
- Measures and processes that ensure humans can effectively supervise an AI system, understand its outputs, and intervene or override when necessary.
- High-risk AI system
- An AI system used in sensitive areas listed in the EU AI Act (such as employment, credit, healthcare, education, public services) where errors can significantly affect people's rights or safety.
- Shared responsibility
- The distribution of compliance duties between providers and deployers, requiring cooperation to meet AI Act requirements.
- User-facing transparency
- Obligations to inform individuals when AI is used in decisions affecting them and to provide clear, understandable information about the AI’s role and logic.