All questions

I deploy AI but did not build it — what must I do under the Act?

EU AI ActLegislation verified on Ook in het Nederlands

Short answer

If you deploy an AI system you did not build, you are a "deployer" under Regulation (EU) 2024/1689 (the EU AI Act). What you must do depends on the AI system you use:

  • For high-risk AI, you have the specific duties in Article 26, plus a fundamental-rights impact assessment if you are a public body or certain private deployers (Article 27).
  • For AI that interacts with people, recognises emotions, categorises biometrics, generates deepfakes, or produces synthetic text/audio/image, you owe transparency duties under Article 50.
  • You must never use prohibited AI (Article 5).
  • For general-purpose AI models (GPAI), the main obligations sit with the provider; as a downstream deployer you mostly benefit from the provider's documentation and have the Article 50 duties where the GPAI is used to produce content covered by it.

Who counts as a "deployer"

Article 3(4) of Regulation (EU) 2024/1689 defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority. This is distinct from the provider (Article 3(3)) — the developer that places the system on the market or puts it into service under its own name. Simply buying, integrating or operating someone else's AI makes you the deployer; you inherit a separate set of obligations even though you did not build it.

The typical case: high-risk AI you did not build (Article 26)

Most deployer obligations sit in Chapter III, Section 4. If the AI you use is listed in Annex III or is a safety component of a product covered by Union harmonisation law, Article 26 requires you to:

  1. Use the system as instructed — follow the provider's instructions for use (Article 26(1)).
  2. Assign competent human oversight to natural persons with the necessary training, authority and support (Article 26(2)).
  3. Ensure input data is relevant and sufficiently representative for the system's intended purpose, monitoring for the "garbage in, garbage out" risk (Article 26(4)).
  4. Monitor the system in operation and inform the provider and the competent national authority of any serious incident or any situation in which the AI presents a risk (Article 26(5)).
  5. Keep the automatically generated logs for at least six months, unless sectoral law says otherwise (Article 26(6)).
  6. Inform workers' representatives and affected workers before putting a high-risk AI system to work (Article 26(7)).
  7. Run a data-protection impact assessment under the GDPR (Regulation (EU) 2016/679) where the use is likely to be high-risk for personal data (Article 26(9)).
  8. Inform natural persons that they are subject to a high-risk AI system, except in narrow law-enforcement exemptions (Article 26(11)).
  9. Cooperate with national competent authorities exercising their powers under the Act (Article 26(12)).
  10. For public bodies and certain private deployers (e.g., providers of public services in banking, insurance, employment, education — see Article 27(1)), perform a fundamental-rights impact assessment (FRIA) before first use (Article 27(2)).

You do not need to re-do the provider's conformity assessment, but you must use the system within the conditions the provider declared, and you remain liable for misuse.

Transparency: AI that interacts with people (Article 50)

Article 50 applies to deployers in four main situations:

  • You interact with an AI system (e.g., a chatbot): inform the person that they are interacting with AI, unless obvious from context.
  • You use an emotion recognition or biometric categorisation system: inform the exposed persons.
  • You use a system that generates or manipulates deepfake image, audio or video: disclose the AI-generated/manipulated content.
  • You publish text generated by AI, or you publish synthetic audio, image, video or text generated by AI: label it as AI-generated in a machine-readable way, unless it is part of an artistic, creative, satirical or fictional work and the disclosure would conflict with the work's enjoyment.

These are deployer obligations, not optional — they apply even where you did not build the underlying model.

Rules you cannot contract out of

  • Article 5 — Prohibited AI practices. A deployer must not put prohibited AI into service (e.g., social scoring by public authorities, certain manipulative or exploitation techniques, untargeted scraping for facial recognition databases, real-time remote biometric identification in publicly accessible spaces for law enforcement, with limited exceptions). Even if a vendor offers you such a tool, deploying it is your direct violation.
  • Article 99 — Penalties. Competent authorities can fine deployers up to EUR 15 million or 3% of total worldwide annual turnover for breaches of the operator-side duties, whichever is higher (Article 99(4)), and the smaller tier of up to EUR 7.5 million / 1% for supplying incorrect information.

General-purpose AI models: where you stand as a downstream deployer

Under Chapter V (Articles 51–56), obligations for general-purpose AI (GPAI) models sit primarily with the provider (Article 53 — technical documentation, copyright-compliance policy, training-data summary; Article 55 — additional duties for "GPAI models with systemic risk"). As a deployer of an AI system built on a GPAI model that you did not build:

  • You do not carry the Chapter V obligations directly — but you must receive the upstream documentation from your provider chain (Article 25).
  • Where a GPAI system is used to generate content caught by Article 50 (chatbots, deepfakes, synthetic media, AI-generated text for public), the Article 50 transparency duties do apply to you as deployer.
  • The provider remains accountable for the model; you remain accountable for how you use it.

A practical checklist for a deployer who did not build the AI

  1. Ask the vendor: "What Annex III / product-safety category is this system in, and do you have a Declaration of Conformity?" — this determines whether Article 26 applies.
  2. Read and circulate the instructions for use; assign named humans with oversight.
  3. Set up logging, incident reporting to vendor and competent authority, and six-month log retention.
  4. Run the GDPR DPIA if personal data is involved; if you are a public body or listed private deployer, add the FRIA (Article 27).
  5. For any user-facing or content-generating AI, build the Article 50 disclosures into the UX.
  6. Train workers, inform worker representatives, and prepare a register of AI uses so that Article 26(11) notification obligations are easy to honour.
  7. Sanity-check the system against Article 5 prohibitions before deployment.

Sources

Disclaimer: This FAQ is general information about Regulation (EU) 2024/1689. The application dates depend on the risk category (provisions on prohibited AI apply from 2 February 2025; high-risk obligations apply from 2 August 2026; most other provisions from 2 August 2025). For your specific deployment, consult a qualified EU/EEA AI-law counsel.