A deployer under the EU AI Act is a natural or legal person, public authority, agency, or other body that uses an AI system under its own authority — the organization that puts an AI tool to work in its operations. The one exception is where the system is used in the course of a personal, non-professional activity, which falls outside the definition. In practice, most organizations that adopt third-party AI tools are deployers: if your business runs an AI system to do its work, you are almost certainly a deployer under the Act.
This article is an educational explainer, not legal advice. It describes how the EU AI Act frames the deployer role so that teams can understand where they sit in the regulation. Whether a specific obligation applies to your organization is a question for qualified counsel.
The legal definition
The EU AI Act defines the roles it regulates in Article 3. Under Article 3(4), a deployer is:
a natural or legal person, public authority, agency, or other body using an AI system under its authority, except where the AI system is used in the course of a personal, non-professional activity.
Two parts of this definition do the work. The first is "using an AI system under its authority" — the deployer is the party that controls the use of the system and decides to run it for a given purpose. The second is the personal, non-professional exception — an individual experimenting with an AI chatbot at home is not a deployer, but the same person using that tool in the course of their job places their employer within scope.
The practical consequence is broad. When a company adopts a third-party assistant, a customer-service model, a recruitment-screening tool, or an AI feature embedded in software it has bought, it is deploying that system under its own authority. It becomes a deployer even though it did not build the underlying model.
Deployer vs provider
The deployer is one of several operators the Act defines, and it is most often confused with the provider. The distinction is fundamental to how responsibility is allocated.
A provider develops an AI system — or has one developed — and places it on the market or puts it into service under its own name or trademark. The provider builds the system and is responsible for how it is designed, documented, and conformity-assessed.
A deployer, by contrast, uses a system built by someone else. It does not create the model; it applies an existing one to its own operations. The typical relationship is a chain: a provider builds and offers the system, and a deployer adopts and runs it.
When a deployer becomes a provider
The line is not permanent. Under Article 25, a deployer can take on the obligations of a provider for a high-risk AI system in several situations — most notably where it puts its own name or trademark on a high-risk system already on the market, or where it makes a substantial modification to such a system so that it remains high-risk. In those cases the deployer has, in effect, taken ownership of the system's behavior and inherits the heavier provider duties that follow. Understanding this shift matters because a deployer that customizes or rebrands a high-risk system may quietly cross into provider territory.
The duties that attach to deployers
Deployer obligations are lighter than a provider's but real, and they concentrate around using a system responsibly rather than building it. For high-risk AI systems in particular, the duties that typically attach to deployers include:
Use the system as intended
Deployers must use a high-risk AI system in accordance with the instructions for use supplied by the provider. Operating a system outside its documented purpose is one of the ways a deployer can lose the protection of the provider's conformity assessment.
Ensure human oversight
Deployers must assign human oversight to people with the competence, authority, and support to perform it. The oversight the provider designs into a high-risk system only works if the deployer staffs and empowers it in practice.
Monitor operation and keep logs
Deployers must monitor the operation of the system against its instructions and act where use may present a risk. They must also keep the logs the system automatically generates, to the extent those logs are under their control — the record that makes later review and accountability possible.
Inform affected people
Where required, deployers must inform the individuals affected by a high-risk system that they are subject to its use, and — in relevant contexts such as the workplace — inform workers and their representatives before putting it into use.
The Article 50(4) transparency duty
The duty most relevant to anyone running a website is the Article 50 transparency obligation. Under Article 50(4), a deployer that uses an AI system to generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. A parallel duty applies to AI-generated or manipulated text published to inform the public on matters of public interest, which must likewise be disclosed as AI-generated.
For any organization publishing AI-assisted media or copy, this is a concrete labelling requirement. The practical answer is to disclose AI-generated content clearly and consistently at the point of publication, so the transparency duty is met by default rather than case by case. A deeper walk-through of the obligation lives in the Article 50 help guide.
How the deployer relates to the other operators
The Act regulates a supply chain of roles, not a single actor. Alongside the deployer and the provider sit importers, distributors, and product manufacturers — collectively the operators the regulation defines. Each carries obligations calibrated to how much control it has over the system.
The provider sits at the head of the chain, responsible for building a compliant system. The deployer sits at the point of use, responsible for running it as intended and being transparent about it. Because the deployer is closest to the people ultimately affected, its duties — oversight, monitoring, and disclosure — are the ones that shape the real-world experience of an AI system, even though the deployer never wrote a line of the model.
For a fuller picture of how these roles fit together and which risk tier applies, see the EU AI Act glossary entry and the practical EU AI Act guide.
