A deployer under the EU AI Act is any organisation that uses an AI system under its own authority in a professional context. If your company runs AI on real work, you are almost certainly a deployer. The Act gives deployers their own obligations, separate from the obligations of the vendors who build the systems, and they are the obligations most companies will actually have to live with.
Three things are in force today. The prohibitions on unacceptable practices have applied since February 2025. The AI literacy duty has applied since the same date: your staff must have a sufficient level of AI literacy for the systems they work with, whatever the risk level. And since August 2026 the transparency rules of Article 50 apply, together with the enforcement machinery: people must be told when they are interacting with AI, generated content must be marked, and national authorities can now fine. Penalties run up to €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for most other violations.
The full deployer regime for high-risk systems, Article 26, was moved to December 2, 2027 by the Digital Omnibus. High-risk covers the areas where AI decisions carry consequence for people: hiring and employment, credit and essential services, education, critical infrastructure, law enforcement, migration, and justice. For those systems, deployers must:
The Omnibus deferred the dates. It did not soften the substance. Sixteen months is a runway for building the structure, not a reason to wait.
Every obligation on it is the same demand in different clothes: a person with a name who answers for the system, oversight that actually operates, a record that survives, and decisions that can be reconstructed when someone asks. The regulation does not ask whether your model is impressive. It asks who is accountable and what you can show.
This is the part we find remarkable. The Principal Firm derives an organisational form from economics, with no reference to regulation: when agents do the volume, what remains of the firm is a small human part that specifies the work, decides at the gates, and answers for the outcome, above a record that proves what happened. Article 26 asks high-risk deployers for named oversight with real authority, working monitoring, durable logs, and reconstructable decisions. The law and the economics converge on the same anatomy.
The practical consequence: a firm that restructures around delegation gets most of its deployer duties as a by-product of how it already works. The named person at the gate is the oversight requirement. The append-only record is the logging requirement. The specification is what makes "used according to instructions" checkable. A firm that bolts AI onto its existing shape gets the opposite: a compliance project that runs beside the work and ages badly.
One line we hold ourselves to: no platform makes you compliant, and we will not claim ours does. What structure can do is produce the oversight and the evidence your obligations require, while the judgement, and the accountable persons, remain yours.
Handle the duties that already apply: literacy and transparency. Then map where AI touches consequence in your organisation, because that map is roughly where high-risk classification will land. Then build the structure while it is cheap: see where you stand, put the oversight and the record in place, and let December 2027 arrive as a date instead of a deadline. If you operate in the public sector, start earlier; the bar is highest where the affected party is a citizen.
THIS ARTICLE IS ORIENTATION, NOT LEGAL ADVICE. REGULATION (EU) 2024/1689, AS AMENDED BY THE DIGITAL OMNIBUS.