Deployer
The EU AI Act role of an organisation that uses a high-risk AI system, as opposed to building one. A deployer has duties of its own, and a vendor handling compliance does not remove them.
What it means in practice
The ownership article says a deployer of a high-risk system must monitor it for anomalies, dysfunctions and unexpected performance, keep its logs for at least six months, assign competent people to oversee it, and inform the provider and the authorities of a serious incident. The governance article adds that the heaviest obligations generally sit with the vendor developing the system, and that the compliance deadline for stand-alone high-risk systems moved to 2 December 2027.
How we use it
The audit article says an audit maps the processes in scope against the Act’s own risk scale, and the ownership article says the deployer duties presume a named person to carry them out. See what happens when nobody owns the AI you have rolled out and risk classification.
FAQ
Questions about Deployer
What is a deployer?
A deployer is an organisation that uses a high-risk AI system, as opposed to building one. The ownership article says it has duties of its own under the EU AI Act.
What must a deployer do?
The ownership article lists four duties: monitor the system, keep its logs for at least six months, assign competent people to oversee it, and inform the provider and authorities of a serious incident.
What it means for a business
The duties presume someone is doing the work: monitoring needs someone monitoring and oversight needs someone assigned. A business that has not decided who that is will find the deadline arriving without an answer.
Ready to put this to work?
Tell us where your team is with AI and we will tell you honestly what would make the biggest difference.
