AI Assurance Institute Logo AI Assurance Institute

Four Core Deployer Obligations Under the EU AI Act - and How to Meet Them in Practice

AI Quality Management Systems Series

Most organisations operating in or selling into the European Union are primarily deployers of AI systems rather than providers. They consume AI embedded in enterprise platforms, SaaS tools, and increasingly autonomous agents. Under the EU AI Act (Regulation (EU) 2024/1689), as amended by the Digital Omnibus on AI, this status carries specific operational obligations that cannot be met by dashboards or a single governance platform alone.

Provider duties (including the Article 17 quality management system and the EN 18286 framework for high-risk systems) sit with those who develop and place systems on the market. Deployer duties are different: they attach to how systems are put into use, overseen, explained to people, and supported by competent staff - and they remain the organisation's responsibility even when the underlying model or platform is supplied by a third party.

Four obligations sit at the centre of the deployer responsibility:

1. Transparency (Article 50)

People must know when they are interacting with an AI system or when content has been artificially generated or manipulated. This requires clear disclosure mechanisms, machine-readable marking where applicable, and consistent application across the systems in use. Article 50 is a horizontal transparency strand: it is not the same package as the high-risk quality-management obligations, and it needs its own operational controls - notices, labels, watermark/detection workflows where relevant, and records that the organisation can produce if challenged.

2. Accountability and human oversight (Article 26)

For high-risk uses - such as recruiting, credit scoring, or other decisions with significant impact on individuals - there must be named owners, real (not nominal) human oversight, and retained evidence of how oversight was exercised. Accountability cannot sit only in a policy document; it must be operational and demonstrable.

Under the Digital Omnibus timeline, the bulk of high-risk Chapter III obligations for Annex III systems apply from 2 December 2027 (and later for certain Annex I product-embedded systems). That deferral creates planning time; it does not change the substance of what Article 26 will require once in force: use in accordance with instructions, effective human oversight, attention to input data and operation, logging, and the ability to show who decided what, when, and on what basis.

3. AI literacy (Article 4)

Providers and deployers must take measures to support the development of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience, education and the context in which the systems are used. Following the Digital Omnibus, the obligation is framed around organisational measures rather than a guarantee of a fixed literacy level for every individual. It remains an ongoing responsibility, not a one-off training event - and for high-risk systems, competence expectations in quality and operational practice (including under EN 18286 for providers, and role-specific oversight capability for deployers) continue to make "paper-only" literacy programmes a weak answer.

4. Third-party assurance

Where AI is consumed from vendors, the data boundaries, training-data and model practices (where disclosed), instructions for use, and contractual allocation of provider versus deployer responsibilities must be clearly established. Assumptions are insufficient. Deployers need evidence that vendor obligations are pinned down and monitored - including change notification, incident support, logging access, and residual risks the deployer still owns when putting the system into service in a specific workplace or customer context.

These four areas are not solved by model-evaluation dashboards. They are met through ownership, identity and access boundaries, defined oversight processes, documented evidence, and contractual discipline - the core elements of an operating model.

How the AI Assurance Institute addresses each obligation

AI Assurance Institute provides dedicated solutions that address each of these obligations directly:

These individual solutions can be implemented on their own where a specific gap exists. They also form part of a broader, integrated approach when organisations require systematic coverage across the full set of deployer obligations - alongside provider-side QMS work under Article 17 and EN 18286 where the organisation is also a provider of high-risk systems.

The leadership test

The practical question for leadership is straightforward: if asked today which high-risk AI uses exist in the organisation, who is accountable for them, how transparency is maintained, and what evidence of oversight and vendor assurance is available, could the organisation answer clearly and quickly? Where the answer is incomplete, these four obligations provide a concrete starting point for closing the gap.