Back to blog

Blog / Getting started

AI Deployer Obligations under the EU AI Act: A SaaS Guide

Published 20 July 2026·Last updated 21 July 2026·7 min read
Author: ActBrief Editorial·Reviewer: Methodology pending external legal review

Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.

Changelog
Updated 21 July 2026: Refocused this page on deployer obligations (Art. 26) to avoid overlapping the provider vs deployer vs GPAI pillar article. Previous URL /blog/provider-vs-deployer-ai-act redirects here.

Who this page is for

You already know you use an AI system in a professional context — an LLM API inside support, a third-party ranking engine, or a model embedded in your workflow. This guide covers deployer obligations, not a full comparison of every AI Act role.

For role mapping across provider / deployer / GPAI provider, use the pillar article: Provider vs deployer vs GPAI provider.

Deployer in one sentence

A deployer uses an AI system under its own authority in the course of a professional activity. You do not need to have trained the model to be a deployer.

Core deployer duties (especially if high-risk)

When the system is high-risk, deployers typically face duties under Article 26, including:

  1. Use as intended — follow the provider’s instructions for use
  2. Human oversight — assign competent people who can understand and override outputs where required
  3. Input data — ensure data under your control is relevant and sufficiently representative for the intended purpose
  4. Monitoring & logs — monitor operation and keep automatically generated logs for the required period
  5. Incident reporting — inform the provider / authorities of serious incidents as required
  6. Worker / affected-person information — inform natural persons where the Act requires it

Standalone Annex III high-risk duties apply from 2 December 2027 (Digital Omnibus). Art. 50 transparency can still apply earlier (2 August 2026) when people interact with AI.

The SaaS trap: deployer of the model, provider of the product

Calling OpenAI does not automatically make you “only a deployer” of everything users see.

LayerTypical role
Foundation model APIYou may be a deployer of that model
Your branded product / feature placed on the marketYou are often still a provider of that AI system

Treat deployer checklists as necessary but not sufficient until counsel confirms you are not also a provider of the system you ship.

Deployer readiness checklist

Templates: Human oversight SOP · AI system card

What to do this week

  1. Inventory AI features you use vs AI features you place on the market.
  2. Draft the oversight SOP for any path that ranks, scores, or decides about people.
  3. Get a free readiness brief for your product — then send deployer vs provider open questions to counsel.

Related


Not legal advice. Deployer duties are fact- and classification-specific.

Official sources

Ready for legal review?

Get a free readiness brief for your product — not a commodity risk label.

Get a free readiness brief for your product