⏳ Article 50 transparency duties apply on 2 August 2026 — soon. What you need to prepare

AI Act Register Pilot

Deployer obligations: what the AI Act requires from whoever uses AI

Updated 10 July 2026 · Regulation (EU) 2024/1689, Articles 4, 25, 26, 27, 50 · 9 min read

Deployer: the exact definition

Article 3(4) of Regulation (EU) 2024/1689 defines the deployer as “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”.

Three elements matter. Using: you need not have paid, a free tool counts. Under its authority: you decide the purpose and the terms of use. Outside personal activity: professional use, even by a single employee, binds the organization.

The corollary is blunt: a company where three staff use a generative AI assistant that nobody authorised is the deployer of that system. The absence of a formal decision does not exempt you; it merely prevents you from knowing.

Shadow AI is a compliance risk, not an IT topic. Obligations arise from actual use. A map built from what teams declare systematically underestimates the estate. AI Act Register Pilot detects locally, by domain name, the AI tools actually opened — never reading page content.

Deployer vs provider: the three-question test

Ask these three questions for each system:

  1. Did I develop this system, or have it developed, to place it on the market under my name? If yes → provider.
  2. Did I put my name or trademark on a high-risk system already on the market? If yes → provider (Article 25(1)(a)).
  3. Did I substantially modify the system, or its intended purpose, to the point of changing what it is for? If yes → provider (Article 25(1)(b) and (c)).

Three “no” answers: you are a deployer. That covers the overwhelming majority of organizations. The regime is lighter, but not empty — and the financial exposure remains €15M or 3% of worldwide turnover.

Article 26 obligations, point by point

Article 26 applies to deployers of high-risk AI systems (Annexes I and III). These are the heaviest duties of the deployer regime.

§1 — Use in accordance with the instructions

Take appropriate technical and organisational measures to ensure the system is used in accordance with the instructions for use supplied by the provider. Plainly: read the instructions, and document that the intended conditions of use are respected.

§2 — Assign human oversight to competent people

Human oversight must be assigned to natural persons who have the necessary competence, training and authority, as well as the necessary support. Naming a “responsible person” without giving them the power to stop the system does not satisfy the obligation.

§3 — Control the input data

Where the deployer exercises control over the input data, it must ensure that data is relevant and sufficiently representative in view of the intended purpose. A scoring tool fed with biased history produces biased decisions, and the responsibility is no longer the provider's alone.

§4 — Monitor and alert

Monitor the operation of the system on the basis of the instructions and inform the provider, the distributor and the market surveillance authority where a risk within the meaning of Article 79 is identified. In the event of a serious incident, inform the provider first, then the importer or distributor and the competent authority.

§5 — Keep the logs

Keep the logs automatically generated by the system, to the extent they are under its control, for a period appropriate to the intended purpose of at least six months, unless Union or national law provides otherwise.

§7 — Inform workers' representatives

Before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers that they will be subject to its use. This duty stacks with national labour law.

§9 — Data protection impact assessment

Where relevant, deployers must use the information provided under Article 13 to carry out their data protection impact assessment (DPIA) under Article 35 GDPR. The two exercises feed each other: the AI system register should reference the matching DPIA.

§11 — Inform persons subject to a decision

Deployers of Annex III high-risk systems who make, or assist in making, decisions concerning natural persons must inform those persons that they are subject to the use of such a system. Combined with Article 86, the affected person may obtain a clear explanation of the role of the system in the decision.

When a deployer becomes a provider (Article 25)

The role shift is the main blind spot of compliance programmes. It occurs in three cases:

  • you put your name or trademark on a high-risk system already on the market;
  • you make a substantial modification to a high-risk system already on the market, which remains high-risk;
  • you change the intended purpose of a system, including a general-purpose one, such that it becomes high-risk.

The third case is the most insidious. Wiring a general-purpose model into a CV pre-screening process turns a “minimal” tool into an Annex III point 4 high-risk system — and makes you its provider. You then inherit Chapter III, Section 2: risk management, data governance, technical documentation, conformity assessment.

The register must therefore record, for every row, the real purpose and a role-shift indicator. That is exactly the alert AI Act Register Pilot raises when a declared purpose intersects Annex III.

Obligations that apply to every deployer

Even without a high-risk system, three obligations concern you.

Article 4 — AI literacy. Applicable since 2 February 2025. Deployers must take measures to ensure a sufficient level of AI literacy among their staff, taking into account technical knowledge, experience, training and the context of use. Generic training is not enough: it must be calibrated to the systems actually used — hence on the register.

Article 5 — prohibited practices. Applicable since 2 February 2025. No social scoring, no exploitation of vulnerabilities, no emotion recognition in the workplace or in education (outside medical or safety reasons), no untargeted scraping of facial images.

Article 50 — transparency. Applicable on 2 August 2026. Inform persons exposed to emotion recognition or biometric categorisation; disclose deepfakes and certain generated texts. See the Article 50 guide.

On top of that, certain deployers — bodies governed by public law, private entities providing public services, and operators assessing creditworthiness or pricing life and health insurance — must carry out the fundamental rights impact assessment of Article 27 before the first use of an Annex III high-risk system.

Penalties and timeline

BreachCap (Art. 99)
Prohibited practice (Art. 5)€35M or 7% of worldwide turnover
Deployer obligations (Art. 26), transparency (Art. 50), other obligations€15M or 3% of worldwide turnover
Incorrect or misleading information to authorities€7.5M or 1% of worldwide turnover

The higher of the fixed sum and the percentage applies; for SMEs and start-ups, the lower one does. Timeline: Articles 5 and 4 since 2 February 2025, GPAI since 2 August 2025, general regime and Article 50 on 2 August 2026, Annex I high-risk on 2 August 2027.

Actionable checklist

  1. Map the AI systems actually in use, including those no department ever approved.
  2. Qualify the role row by row with the three-question test; flag potential shifts to provider status.
  3. Isolate high-risk systems and apply Article 26: instructions, competent human oversight, logs kept at least six months, monitoring, informing workers.
  4. Check for prohibited practices (Article 5), especially emotion recognition at work.
  5. Prepare the transparency notices for 2 August 2026.
  6. Train teams on the systems they actually use (Article 4) and keep evidence of the training.
  7. Link each row to its GDPR DPIA where personal data is processed.
  8. Timestamp and archive each register review: it is the history, not the current file, that proves diligence.

What the extension does. Local domain-based detection of AI tools, register pre-fill, suggested role and risk level, deployer → provider shift alert, review reminders, timestamped history and up-to-date attestation. No data leaves your browser.

Get the register template

AI system register template (XLSX + CSV)

Columns for role, risk level, Annex III basis, obligations, review date.

Hosted in the European Union. No sharing, no reselling. Privacy policy

Keep reading

This content is provided for information only. It reflects Regulation (EU) 2024/1689 as at the update date and does not constitute legal advice.