Skip to content

The EU AI Act for deployers: what you actually have to do

4 min read by John Bagnall

Updated July 8, 2026

If you use AI rather than build and sell it, the Act calls you a deployer, and you have real duties, just lighter ones than a provider. Two of them are already in force, and the big ones land in August 2026. Here is what that actually means, in plain terms.

This is a readiness explainer, not legal advice. For your specific position, get advice, or check where you stand in ten minutes.

Are you a deployer?

A deployer is an organisation that uses an AI system under its own authority. Most businesses are deployers: you use an AI tool for hiring, support, analysis or content, but you did not develop it. A provider is the one who builds the system or puts it on the market under their own name.

The line matters because the obligations differ. And you can cross it without meaning to: rebrand someone else’s AI as your own, or significantly modify it, and you may pick up provider obligations too (Article 25). That is worth knowing before it surprises you.

What you already have to do

Two duties are live now, not in 2026:

  • AI literacy (Article 4). Since February 2025, you must ensure the people who use or are affected by your AI understand it well enough to use it responsibly. It applies whatever the risk level. It is the easiest duty to start on and the one most often forgotten. We cover it in full in AI literacy: the Article 4 duty in practice.
  • No prohibited practices (Article 5). Some uses are banned outright, including social scoring and emotion recognition in the workplace. Using one is the fastest route to the heaviest penalties. You need to know none of the AI you use, or that a vendor quietly adds, falls into this bucket.

What lands in August 2026

From 2 August 2026, if you deploy high-risk AI (think hiring, credit, education, essential services), the core deployer duties apply:

  • Use it responsibly (Article 26): follow the provider’s instructions, assign competent human oversight, monitor how it performs, and keep logs.
  • Assess the impact on people (Article 27): where required, run a Fundamental Rights Impact Assessment before first use, and connect it to your data-protection assessment.
  • Be transparent (Article 50): tell people when they are interacting with AI, and label AI-generated or deepfake content you publish.

One caveat worth stating plainly: the high-risk timing may still move under the EU’s Digital Omnibus package, which is not yet finally adopted. Plan for August 2026; watch for change.

Does it reach UK and non-EU companies?

Yes, often. The Act applies extraterritorially. If the outputs of the AI you use affect people in the EU, or you operate in the EU market, you can be in scope even with no EU office. “We’re not in the EU” is not the shield people assume it is.

What it costs to get this wrong

Penalties are tiered and reach up to €35M or 7% of global annual turnover for the most serious breaches. But the quieter cost arrives sooner: enterprise buyers increasingly ask vendors to prove their AI is governed. No evidence, no shortlist. The Act is becoming a procurement gate, not just a legal risk.

Where to start

You cannot manage what you have not mapped. The first moves are unglamorous and high-value: list the AI you use, classify each by risk, confirm none is prohibited, and start the literacy work. From there, the high-risk duties become a checklist rather than a scramble.

If you want an honest read on where you stand today, the free EU AI Act readiness assessment takes about ten minutes and gives you a score and your biggest gaps, no email required to see them. When you are ready to act on it, talk to us about putting real governance in place before the deadline does it for you.

For the full picture, see the EU AI Act guide.

Frequently asked questions

Does the EU AI Act apply to my company if we only use AI tools?

Yes. Using AI under your own authority makes you a deployer, and deployers have obligations under the Act. They are lighter than a provider's, but they are real, and some are already in force.

Does the EU AI Act apply to UK and other non-EU companies?

It can. The Act applies extraterritorially: if the outputs of the AI you use affect people in the EU, or you put AI on the EU market, you can be in scope regardless of where you are based.

When do the main deployer obligations start?

AI literacy (Article 4) and the ban on prohibited practices (Article 5) are already in force. The core high-risk deployer duties (Articles 26 and 27) and transparency duties (Article 50) apply from 2 August 2026, though that timing may still shift under the EU's Digital Omnibus, which is not yet finally adopted.

What are the penalties?

They are tiered by the type of breach and reach up to €35M or 7% of global annual turnover for the most serious, such as using a prohibited system.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert