Blog / Getting started
Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.
You already know you use an AI system in a professional context — an LLM API inside support, a third-party ranking engine, or a model embedded in your workflow. This guide covers deployer obligations, not a full comparison of every AI Act role.
For role mapping across provider / deployer / GPAI provider, use the pillar article: Provider vs deployer vs GPAI provider.
A deployer uses an AI system under its own authority in the course of a professional activity. You do not need to have trained the model to be a deployer.
When the system is high-risk, deployers typically face duties under Article 26, including:
Standalone Annex III high-risk duties apply from 2 December 2027 (Digital Omnibus). Art. 50 transparency can still apply earlier (2 August 2026) when people interact with AI.
Calling OpenAI does not automatically make you “only a deployer” of everything users see.
| Layer | Typical role |
|---|---|
| Foundation model API | You may be a deployer of that model |
| Your branded product / feature placed on the market | You are often still a provider of that AI system |
Treat deployer checklists as necessary but not sufficient until counsel confirms you are not also a provider of the system you ship.
Templates: Human oversight SOP · AI system card
Not legal advice. Deployer duties are fact- and classification-specific.
Get a free readiness brief for your product — not a commodity risk label.
Get a free readiness brief for your product