I deploy AI but did not build it — what must I do under the Act?
Short answer
If you deploy an AI system you did not build, you are a "deployer" under Regulation (EU) 2024/1689 (the EU AI Act). What you must do depends on the AI system you use:
- For high-risk AI, you have the specific duties in Article 26, plus a fundamental-rights impact assessment if you are a public body or certain private deployers (Article 27).
- For AI that interacts with people, recognises emotions, categorises biometrics, generates deepfakes, or produces synthetic text/audio/image, you owe transparency duties under Article 50.
- You must never use prohibited AI (Article 5).
- For general-purpose AI models (GPAI), the main obligations sit with the provider; as a downstream deployer you mostly benefit from the provider's documentation and have the Article 50 duties where the GPAI is used to produce content covered by it.
Who counts as a "deployer"
Article 3(4) of Regulation (EU) 2024/1689 defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority. This is distinct from the provider (Article 3(3)) — the developer that places the system on the market or puts it into service under its own name. Simply buying, integrating or operating someone else's AI makes you the deployer; you inherit a separate set of obligations even though you did not build it.
The typical case: high-risk AI you did not build (Article 26)
Most deployer obligations sit in Chapter III, Section 4. If the AI you use is listed in Annex III or is a safety component of a product covered by Union harmonisation law, Article 26 requires you to:
- Use the system as instructed — follow the provider's instructions for use (Article 26(1)).
- Assign competent human oversight to natural persons with the necessary training, authority and support (Article 26(2)).
- Ensure input data is relevant and sufficiently representative for the system's intended purpose, monitoring for the "garbage in, garbage out" risk (Article 26(4)).
- Monitor the system in operation and inform the provider and the competent national authority of any serious incident or any situation in which the AI presents a risk (Article 26(5)).
- Keep the automatically generated logs for at least six months, unless sectoral law says otherwise (Article 26(6)).
- Inform workers' representatives and affected workers before putting a high-risk AI system to work (Article 26(7)).
- Run a data-protection impact assessment under the GDPR (Regulation (EU) 2016/679) where the use is likely to be high-risk for personal data (Article 26(9)).
- Inform natural persons that they are subject to a high-risk AI system, except in narrow law-enforcement exemptions (Article 26(11)).
- Cooperate with national competent authorities exercising their powers under the Act (Article 26(12)).
- For public bodies and certain private deployers (e.g., providers of public services in banking, insurance, employment, education — see Article 27(1)), perform a fundamental-rights impact assessment (FRIA) before first use (Article 27(2)).
You do not need to re-do the provider's conformity assessment, but you must use the system within the conditions the provider declared, and you remain liable for misuse.
Transparency: AI that interacts with people (Article 50)
Article 50 applies to deployers in four main situations:
- You interact with an AI system (e.g., a chatbot): inform the person that they are interacting with AI, unless obvious from context.
- You use an emotion recognition or biometric categorisation system: inform the exposed persons.
- You use a system that generates or manipulates deepfake image, audio or video: disclose the AI-generated/manipulated content.
- You publish text generated by AI, or you publish synthetic audio, image, video or text generated by AI: label it as AI-generated in a machine-readable way, unless it is part of an artistic, creative, satirical or fictional work and the disclosure would conflict with the work's enjoyment.
These are deployer obligations, not optional — they apply even where you did not build the underlying model.
Rules you cannot contract out of
- Article 5 — Prohibited AI practices. A deployer must not put prohibited AI into service (e.g., social scoring by public authorities, certain manipulative or exploitation techniques, untargeted scraping for facial recognition databases, real-time remote biometric identification in publicly accessible spaces for law enforcement, with limited exceptions). Even if a vendor offers you such a tool, deploying it is your direct violation.
- Article 99 — Penalties. Competent authorities can fine deployers up to EUR 15 million or 3% of total worldwide annual turnover for breaches of the operator-side duties, whichever is higher (Article 99(4)), and the smaller tier of up to EUR 7.5 million / 1% for supplying incorrect information.
General-purpose AI models: where you stand as a downstream deployer
Under Chapter V (Articles 51–56), obligations for general-purpose AI (GPAI) models sit primarily with the provider (Article 53 — technical documentation, copyright-compliance policy, training-data summary; Article 55 — additional duties for "GPAI models with systemic risk"). As a deployer of an AI system built on a GPAI model that you did not build:
- You do not carry the Chapter V obligations directly — but you must receive the upstream documentation from your provider chain (Article 25).
- Where a GPAI system is used to generate content caught by Article 50 (chatbots, deepfakes, synthetic media, AI-generated text for public), the Article 50 transparency duties do apply to you as deployer.
- The provider remains accountable for the model; you remain accountable for how you use it.
A practical checklist for a deployer who did not build the AI
- Ask the vendor: "What Annex III / product-safety category is this system in, and do you have a Declaration of Conformity?" — this determines whether Article 26 applies.
- Read and circulate the instructions for use; assign named humans with oversight.
- Set up logging, incident reporting to vendor and competent authority, and six-month log retention.
- Run the GDPR DPIA if personal data is involved; if you are a public body or listed private deployer, add the FRIA (Article 27).
- For any user-facing or content-generating AI, build the Article 50 disclosures into the UX.
- Train workers, inform worker representatives, and prepare a register of AI uses so that Article 26(11) notification obligations are easy to honour.
- Sanity-check the system against Article 5 prohibitions before deployment.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — full text on EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Article 3 (Definitions — "provider", "deployer"): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_3
- Article 5 (Prohibited AI practices): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_5
- Article 26 (Obligations of deployers of high-risk AI systems): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_26
- Article 27 (Fundamental rights impact assessment for high-risk AI systems): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_27
- Article 50 (Transparency obligations for providers and deployers of certain AI systems): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_50
- Chapter V — General-purpose AI models (Articles 51–56): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#cpt_5
- Article 99 (Penalties): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689#art_99
Disclaimer: This FAQ is general information about Regulation (EU) 2024/1689. The application dates depend on the risk category (provisions on prohibited AI apply from 2 February 2025; high-risk obligations apply from 2 August 2026; most other provisions from 2 August 2025). For your specific deployment, consult a qualified EU/EEA AI-law counsel.