Deployer
Article 3, point 4, of Regulation (EU) 2024/1689:
a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.
Whoever uses an artificial intelligence system under its own authority within a professional activity. It is the figure Regulation (EU) 2024/1689 calls the “deployer”; the Spanish text of the Regulation calls it “responsable del despliegue”.
It is the role of almost any company that buys software with AI in it rather than developing it.
Which obligations it carries
It is not an obligation: it is a role, and different obligations depend on it according to the system concerned. Those of Article 26 are a legal obligation of the deployer applicable from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I. Those of Article 50(3) and (4) — emotion recognition, biometric categorisation and deep fakes — are a legal obligation of the deployer applicable from 2 August 2026. And Article 4 is a legal obligation of providers and deployers from 2 February 2025, as a measures-based obligation: it does not require guaranteeing a specific level of AI literacy of any individual.
What it is not
It is not “provider”. The obligations of Articles 17, 18, 72, 73 and Annex IV belong exclusively to the provider, and attributing them to the deployer is the sector’s most common allocation error. Nor is it a company-wide role: it is assigned per system. The same organisation can be the deployer of twelve tools and the provider of one.
The nuance almost nobody captures
The role can change with respect to a specific system, but only for high risk: putting one’s own brand on a high-risk system already on the market, substantially modifying a high-risk system so that it remains high-risk, or changing the intended purpose of a system that was not high-risk so that it becomes so (Article 25(1), points (a), (b) and (c)). On a minimal-risk system, none of the three operates.
Related terms
To find out more
- AI agents: what to log, and why Article 22 GDPR almost never applies
- An agent with broad permissions can drift outside its intended purpose without anyone deciding it should
- When an agent chains actions, who's responsible? Article 26(2) answers with three words
- When you stop being the deployer and become the provider: the three scenarios under Article 25
- Post-market monitoring: the system belongs to the provider, the information is yours
- You change what a system is for: what stops being true in everything you had already documented?
- The AI Act doesn't require you to keep an inventory. It's the precondition for almost everything that does
- What an authority can ask you: the article that usually gets cited belongs to the provider, not you