We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Back to glossary
Glossary6 min read

Deployer (EU AI Act)

A deployer under the EU AI Act is any organization using an AI system under its own authority. Learn the deployer's duties, how it differs from a provider, and more.

Deployer (EU AI Act)

A deployer under the EU AI Act is a natural or legal person, public authority, agency, or other body that uses an AI system under its own authority — the organization that puts an AI tool to work in its operations. The one exception is where the system is used in the course of a personal, non-professional activity, which falls outside the definition. In practice, most organizations that adopt third-party AI tools are deployers: if your business runs an AI system to do its work, you are almost certainly a deployer under the Act.

This article is an educational explainer, not legal advice. It describes how the EU AI Act frames the deployer role so that teams can understand where they sit in the regulation. Whether a specific obligation applies to your organization is a question for qualified counsel.

The legal definition

The EU AI Act defines the roles it regulates in Article 3. Under Article 3(4), a deployer is:

a natural or legal person, public authority, agency, or other body using an AI system under its authority, except where the AI system is used in the course of a personal, non-professional activity.

Two parts of this definition do the work. The first is "using an AI system under its authority" — the deployer is the party that controls the use of the system and decides to run it for a given purpose. The second is the personal, non-professional exception — an individual experimenting with an AI chatbot at home is not a deployer, but the same person using that tool in the course of their job places their employer within scope.

The practical consequence is broad. When a company adopts a third-party assistant, a customer-service model, a recruitment-screening tool, or an AI feature embedded in software it has bought, it is deploying that system under its own authority. It becomes a deployer even though it did not build the underlying model.

Deployer vs provider

The deployer is one of several operators the Act defines, and it is most often confused with the provider. The distinction is fundamental to how responsibility is allocated.

A provider develops an AI system — or has one developed — and places it on the market or puts it into service under its own name or trademark. The provider builds the system and is responsible for how it is designed, documented, and conformity-assessed.

A deployer, by contrast, uses a system built by someone else. It does not create the model; it applies an existing one to its own operations. The typical relationship is a chain: a provider builds and offers the system, and a deployer adopts and runs it.

When a deployer becomes a provider

The line is not permanent. Under Article 25, a deployer can take on the obligations of a provider for a high-risk AI system in several situations — most notably where it puts its own name or trademark on a high-risk system already on the market, or where it makes a substantial modification to such a system so that it remains high-risk. In those cases the deployer has, in effect, taken ownership of the system's behavior and inherits the heavier provider duties that follow. Understanding this shift matters because a deployer that customizes or rebrands a high-risk system may quietly cross into provider territory.

The duties that attach to deployers

Deployer obligations are lighter than a provider's but real, and they concentrate around using a system responsibly rather than building it. For high-risk AI systems in particular, the duties that typically attach to deployers include:

Use the system as intended

Deployers must use a high-risk AI system in accordance with the instructions for use supplied by the provider. Operating a system outside its documented purpose is one of the ways a deployer can lose the protection of the provider's conformity assessment.

Ensure human oversight

Deployers must assign human oversight to people with the competence, authority, and support to perform it. The oversight the provider designs into a high-risk system only works if the deployer staffs and empowers it in practice.

Monitor operation and keep logs

Deployers must monitor the operation of the system against its instructions and act where use may present a risk. They must also keep the logs the system automatically generates, to the extent those logs are under their control — the record that makes later review and accountability possible.

Inform affected people

Where required, deployers must inform the individuals affected by a high-risk system that they are subject to its use, and — in relevant contexts such as the workplace — inform workers and their representatives before putting it into use.

The Article 50(4) transparency duty

The duty most relevant to anyone running a website is the Article 50 transparency obligation. Under Article 50(4), a deployer that uses an AI system to generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. A parallel duty applies to AI-generated or manipulated text published to inform the public on matters of public interest, which must likewise be disclosed as AI-generated.

For any organization publishing AI-assisted media or copy, this is a concrete labelling requirement. The practical answer is to disclose AI-generated content clearly and consistently at the point of publication, so the transparency duty is met by default rather than case by case. A deeper walk-through of the obligation lives in the Article 50 help guide.

How the deployer relates to the other operators

The Act regulates a supply chain of roles, not a single actor. Alongside the deployer and the provider sit importers, distributors, and product manufacturers — collectively the operators the regulation defines. Each carries obligations calibrated to how much control it has over the system.

The provider sits at the head of the chain, responsible for building a compliant system. The deployer sits at the point of use, responsible for running it as intended and being transparent about it. Because the deployer is closest to the people ultimately affected, its duties — oversight, monitoring, and disclosure — are the ones that shape the real-world experience of an AI system, even though the deployer never wrote a line of the model.

For a fuller picture of how these roles fit together and which risk tier applies, see the EU AI Act glossary entry and the practical EU AI Act guide.

On this page

  • The legal definition
  • Deployer vs provider
  • When a deployer becomes a provider
  • The duties that attach to deployers
  • Use the system as intended
  • Ensure human oversight
  • Monitor operation and keep logs
  • Inform affected people
  • The Article 50(4) transparency duty
  • How the deployer relates to the other operators

Share

Product and governance updates — see our privacy policy.

Frequently asked questions

Frequently asked questions

If your organization uses an AI system under its own authority to carry out its work — for example, adopting a third-party AI assistant, screening tool, or embedded AI feature — it is almost certainly a deployer. The only carve-out in Article 3(4) is for AI used in the course of a purely personal, non-professional activity, which does not cover business use.

A provider builds an AI system and places it on the market under its own name or trademark. A deployer uses a system built by someone else, under its own authority. The provider is responsible for how the system is designed and documented; the deployer is responsible for how it is used. Under Article 25, a deployer can become a provider if it rebrands a high-risk system or substantially modifies it.

For high-risk AI systems, deployers typically must use the system per the provider's instructions, ensure competent human oversight, monitor operation, keep the logs the system generates, and inform affected people where required. Separately, Article 50(4) requires deployers to disclose deepfake image, audio, or video content and AI-generated text published to inform the public.

Under Article 50(4), a deployer must disclose deepfake media it generates or manipulates, and must disclose AI-generated or manipulated text published to inform the public on matters of public interest. Labelling that content clearly at publication is how the duty is met. Qadar AI's Disclose widget automates that transparency, and the Article 50 help guide explains the obligation in detail.

Natali Craig
Olivia Rhye
Drew Cano

Still have questions?

Can’t find the answer you’re looking for? Talk to our team and we’ll help you get started.

Get in touch

Related terms

Provider (EU AI Act)Glossary

Provider (EU AI Act)

A Provider under the EU AI Act develops an AI system or GPAI model and places it on the market under its own name. Learn the definition, test, and duties.

Read more
Operator (EU AI Act)Glossary

Operator (EU AI Act)

An operator is the EU AI Act's umbrella term for any party in the AI value chain: provider, product manufacturer, deployer, authorised representative, importer, or distributor.

Read more
EU AI Act (Artificial Intelligence Act)Glossary

EU AI Act (Artificial Intelligence Act)

The EU AI Act is the EU's risk-based law for artificial intelligence. A plain-language summary of what it regulates, when it applies, and who must comply.

Read more

See how Qadar AI implements these concepts at runtime

A product specialist will reply within one business day

Book a demo

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·