Duties by role
Provider or deployer: how the role is determined, when it changes, and which duties follow.
The roles
| Role | Trigger |
|---|---|
| Provider | Develops a system or has it developed and places it on the market or puts it into service under their own name |
| Deployer | Uses a system under their own authority, outside personal activity |
| Importer | Places on the market a system from a third-country provider |
| Distributor | Makes a system available without being provider or importer |
When the role changes
- You put your name or trade mark on a high-risk system.
- You change a system's purpose such that it thereby becomes high risk.
- You make a substantial modification to a high-risk system.
The second is the most common in practice: deploying a general language model to pre-select job applications is a purpose determination that brings the use under Annex III.
Deployer duties at high risk
| Duty | Concretely |
|---|---|
| Follow the instructions for use | And document that this happens |
| Human oversight | A named person with authority, competence and time |
| Input data | Ensure it is suitable and representative for the purpose |
| Monitoring | Observe operation, inform the provider of anomalies |
| Logs | Retain, at least six months, so far as under your control |
| Information | Inform staff and those affected |
| Fundamental rights impact assessment | Public bodies and certain private deployers |
Human oversight, made concrete
Oversight is not a line in a policy. It requires five things at once:
- Authority. The person may reject the output and stop operation, without asking.
- Competence. They understand the system's limits and know its typical errors.
- Time. The review is planned into the process, not added to it.
- Basis. They can see what the result rests on, not only the result.
- Independence from automation bias. The tendency to follow a machine is known and damped by process design.
The last point is rarely implemented and is the most effective: oversight that can only confirm or reject a prior decision confirms it almost always in practice. Oversight that sees the case first, without the recommendation, decides differently.
What providers additionally owe
- A risk management system across the whole lifecycle.
- Data governance with requirements for training, validation and test data.
- Technical documentation under Annex IV.
- Automatic logging.
- Transparency and instructions for use for deployers.
- Accuracy, robustness and cybersecurity.
- Quality management system, conformity assessment, CE marking, registration.
Evidence for deployers
Five documents suffice at the core: the inventory with role and class, the classification reasoning, evidence of AI literacy, the designation of the people exercising oversight, and the logs. Anyone keeping those five can answer questions. See Preparing for audit.
Related courses and sources
EU AI Act, the official full text
Regulation (EU) 2024/1689 in full, in every official language. The primary source for any legal question.
Our governance articles summarise and contextualise. Where the exact wording matters, this text governs.