Much of the discussion about the EU AI Act focuses on the companies that develop AI models. Yet most organisations will never build a model. They buy software with AI features, roll out assistants to staff, and use AI tools in recruitment, customer service or finance. Under the Act, that makes them deployers, and deployers have obligations of their own.
For most everyday uses, those obligations are modest. But a few common uses, particularly in HR and credit decisions, fall into the high-risk category, where the requirements are substantial. Knowing which of your AI uses sit where is the first job. What follows is general guidance, not legal advice.
Provider or deployer: why the role matters
The Act distinguishes between providers, who develop an AI system and place it on the market or put it into service under their own name, and deployers, who use an AI system under their authority in a professional context. Most of the heavy obligations for high-risk systems, such as conformity assessment and technical documentation, fall on providers.
The roles are not fixed, though. A deployer becomes the provider of a high-risk system if it puts its own name or trademark on it, makes a substantial modification to it, or changes the intended purpose of a system so that it becomes high-risk. An organisation that builds its own customer chatbot on a general-purpose model may well be the provider of that chatbot. Be clear about your role for each system.
The risk categories in brief
- Prohibited practices: a short list of uses banned outright, including social scoring, manipulative or deceptive techniques that cause significant harm, untargeted scraping of facial images, and emotion recognition in the workplace and in education, except for medical or safety reasons. These prohibitions have applied since February 2025.
- High-risk uses: uses listed in the Act where AI can significantly affect people’s lives, rights or safety. For most companies, the relevant ones are employment, such as screening applications, evaluating candidates, decisions on promotion or termination, and monitoring performance, and access to essential services, such as assessing creditworthiness or pricing life and health insurance. AI used to detect financial fraud is excluded from the credit category.
- Transparency obligations: systems that interact with people or generate content, such as chatbots, deepfakes and AI-generated text, where people have a right to know what they are dealing with.
- Minimal risk: most everyday uses, such as spam filters, writing aids or internal search, which carry no specific obligations under the Act beyond AI literacy.
What deployers of high-risk systems must do
If you use a high-risk system, the Act requires you among other things to:
- use the system in line with the provider’s instructions for use;
- assign human oversight to people with the necessary competence, training and authority;
- make sure input data you control is relevant and sufficiently representative for the intended purpose;
- monitor operation, inform the provider and authorities about serious incidents or risks, and suspend use where needed;
- keep automatically generated logs for at least six months, unless other law requires otherwise;
- inform workers and their representatives before using a high-risk system in the workplace, and inform people when such a system is used to make or assist decisions about them.
Public bodies, private organisations providing public services, and deployers using AI for credit scoring or for life and health insurance pricing must also carry out a fundamental rights impact assessment before first use. Following the Digital Omnibus on AI, the obligations for these stand-alone high-risk uses apply from 2 December 2027. That leaves time to prepare, but the groundwork, especially with suppliers, takes longer than most expect.
Transparency and AI literacy
Transparency obligations reach further than the high-risk rules. Providers must ensure people know when they are interacting with an AI system, such as a chatbot, and that synthetic content is marked in a machine-readable way. Deployers must disclose deepfakes, disclose AI-generated text published to inform the public on matters of public interest unless it has been through human editorial review, and inform people exposed to emotion recognition or biometric categorisation. If you build your own customer-facing assistant, assume the disclosure is your responsibility.
Every provider and deployer must also take measures to support AI literacy among staff and others who operate or use AI systems on its behalf. The Digital Omnibus softened the original wording, and the European Commission has said no certificate is needed. Deployers of high-risk systems must still make sure the people overseeing those systems are properly trained. A documented, role-based training approach covers both.
A practical plan
- Build an AI inventory. List the AI systems in use, including AI features inside software you already buy, tools staff use on their own initiative, and anything built in-house. Note the purpose, owner, supplier and data involved.
- Classify each use. Check it against the prohibited practices, the high-risk list and the transparency rules. Record your role, provider or deployer, and the reasoning behind the classification.
- Set up governance. Agree who approves new AI uses, give staff an acceptable-use policy, and fit AI risk into your existing GDPR and information security processes. Data protection impact assessments overlap with the Act’s requirements, so run them together.
- Question your suppliers. For purchased software, much of the evidence you need sits with the provider.
- Train people. Start with those who select, oversee or rely on AI in decisions about people.
Useful questions for suppliers include:
- Is the system, or any feature of it, classified as high-risk, and on what basis?
- What instructions for use, documentation and information on limitations will you provide?
- How does the system support human oversight and logging?
- Where is our data processed, and is it used to train or improve your models?
- How will you tell us about incidents, significant changes and updates affecting compliance?
How Altechy can help
The AI Value Assessment within our AI Strategy & Governance service is a fixed-scope engagement that identifies where AI pays off and scores each use case on EU AI Act risk along the way. For organisations that already use AI widely, we inventory your systems, classify them by risk category and give you a practical plan to close the gaps, aligned with your GDPR work. If you are building assistants or chatbots, our Generative & Agentic AI team designs transparency and human oversight in from the start.
We bring in specialists in AI regulation from our partner network where needed and remain your single point of contact. To discuss where you stand, book a free 60-minute idea session.
