Skip to main content
Praxikon
All answers

Direct answer

When are you a deployer under the AI Act?

8 obligations under the AI Act bear on this, of which 7 apply today.

First step: Assess for every design change whether it is significant.

Whether you are a deployer is not a matter of what you call yourself but of what you do with the system. Across the 8 obligations there are 23 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: deployer.

The conclusion and your first steps

This applies now

Coming up

What decides whether this is about you

Article 111(2): legacy high-risk systems and the 2 August 2030 date
  • Applies when: The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed.
  • Applies when: The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them.
  • Applies when: Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date.
  • Applies when: The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union.
  • Applies when: Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged.
  • Unless: Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030.
Article 26: obligations of deployers of high-risk AI systems
  • Applies when: Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028.
  • Unless: Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law.
Article 4: AI literacy
  • Applies when: The organisation is a provider or deployer of an AI system within scope.
  • Unless: The provision does not require a specific individual level to be guaranteed.
Article 4a: legal basis for bias testing with special categories of personal data
  • Applies when: Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2.
  • Applies when: Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it.
  • Applies when: The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data.
  • Unless: Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all.
Article 5: prohibited practices
  • Applies when: Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
  • Unless: The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
Article 50: transparency
  • Applies when: An AI system is intended to interact directly with natural persons.
  • Applies when: The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario.
  • Unless: The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context.
  • Unless: Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026.
Article 85: right to lodge a complaint with the market surveillance authority
  • Applies when: Applies as soon as anyone has grounds to consider that the Regulation has been infringed. There is no standing threshold: the right belongs to any person, and the complaint goes to the market surveillance authority of the Member State concerned.
Article 86: right to an explanation of a decision
  • Applies when: Applies where a deployer takes a decision about a natural person on the basis of the output of a high-risk AI system listed in Annex III, with the exception of point 2 of that Annex, and that decision produces legal effects or similarly significantly affects that person in a way they consider to have an adverse impact on their health, safety or fundamental rights.
  • Unless: Paragraph 2 excludes the right for AI systems where exceptions from, or restrictions to, that obligation follow from Union or national law in compliance with Union law. Paragraph 3 further limits the right to cases where it is not otherwise provided for under Union law, which makes the boundary with Article 22 GDPR a case-by-case question.

These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.

Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

7 now · 1 later

Your situation

Whether you are a deployer is not a matter of what you call yourself but of what you do with the system. Across the 8 obligations there are 23 conditions and exceptions that decide it. Below they are listed per provision, with the official source.

Role

deployer

To record: Transition register of legacy high-risk systems · Deployment dossier: logs, worker information and information to affected persons · AI literacy measures record

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 26(1)-(12)
    • Article 5, Article 99(3) and Article 113(a)
    • Article 5(1)(a)-(h)
    • Article 5 read with Article 6 classification order
    • Article 50(1)-(5) and Article 113
    • Article 85
    • Article 86(1)-(3)
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended Article 111(2)
    • Amended Article 113 application dates
    • New Article 111(4)
    • Recital 39 of Regulation (EU) 2026/1744
    • Amendment of Article 4; entry into force 27 July 2026
    • Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)
    • Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)
    • Article 1, point 2(b), replacing Article 2(7)
    • Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)
    • Amendment to Article 5 and transition to 2 December 2026
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance
  • Guidelines on Article 50

    European Commission, version final-2026-07-20, checked on

    Locators in this source

    • Final guidelines, scope by Article 50 paragraph
    • Implementation guidance for providers and deployers

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Execution

Record role and classification for each AI system

The boundary is set out in the rules above. The outcome becomes demonstrable when the facts, role, classification, owner and reassessment are recorded for each system. Embed AI guides that inventory and sets up the AI register. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the AI register approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist