AI Compass
Compass

Duties by role

Provider or deployer: how the role is determined, when it changes, and which duties follow.

·2 min read·By Fachbereich Governance
DETAIL
2 sections

The roles

RoleTrigger
ProviderDevelops a system or has it developed and places it on the market or puts it into service under their own name
DeployerUses a system under their own authority, outside personal activity
ImporterPlaces on the market a system from a third-country provider
DistributorMakes a system available without being provider or importer

When the role changes

  • You put your name or trade mark on a high-risk system.
  • You change a system's purpose such that it thereby becomes high risk.
  • You make a substantial modification to a high-risk system.

The second is the most common in practice: deploying a general language model to pre-select job applications is a purpose determination that brings the use under Annex III.

Deployer duties at high risk

DutyConcretely
Follow the instructions for useAnd document that this happens
Human oversightA named person with authority, competence and time
Input dataEnsure it is suitable and representative for the purpose
MonitoringObserve operation, inform the provider of anomalies
LogsRetain, at least six months, so far as under your control
InformationInform staff and those affected
Fundamental rights impact assessmentPublic bodies and certain private deployers

Human oversight, made concrete

Oversight is not a line in a policy. It requires five things at once:

  • Authority. The person may reject the output and stop operation, without asking.
  • Competence. They understand the system's limits and know its typical errors.
  • Time. The review is planned into the process, not added to it.
  • Basis. They can see what the result rests on, not only the result.
  • Independence from automation bias. The tendency to follow a machine is known and damped by process design.

The last point is rarely implemented and is the most effective: oversight that can only confirm or reject a prior decision confirms it almost always in practice. Oversight that sees the case first, without the recommendation, decides differently.

What providers additionally owe

  • A risk management system across the whole lifecycle.
  • Data governance with requirements for training, validation and test data.
  • Technical documentation under Annex IV.
  • Automatic logging.
  • Transparency and instructions for use for deployers.
  • Accuracy, robustness and cybersecurity.
  • Quality management system, conformity assessment, CE marking, registration.

Evidence for deployers

Five documents suffice at the core: the inventory with role and class, the classification reasoning, evidence of AI literacy, the designation of the people exercising oversight, and the logs. Anyone keeping those five can answer questions. See Preparing for audit.

Related courses and sources

PaperFreeDE · EN

EU AI Act, the official full text

Regulation (EU) 2024/1689 in full, in every official language. The primary source for any legal question.

Our governance articles summarise and contextualise. Where the exact wording matters, this text governs.

Europäische KommissionGo to offer
Was this page helpful?
Duties by role