Platform
Solutions
Company
Who we are
About Careers
Follow along
Newsroom Contact
Get in touch Book a demo

What does the EU AI Act require of AI deployers?

JVJochem VerheulAug 2026 · Explainer

A deployer under the EU AI Act is any organisation that uses an AI system under its own authority in a professional context. If your company runs AI on real work, you are almost certainly a deployer. The Act gives deployers their own obligations, separate from the obligations of the vendors who build the systems, and they are the obligations most companies will actually have to live with.

What applies already

Three things are in force today. The prohibitions on unacceptable practices have applied since February 2025. The AI literacy duty has applied since the same date: your staff must have a sufficient level of AI literacy for the systems they work with, whatever the risk level. And since August 2026 the transparency rules of Article 50 apply, together with the enforcement machinery: people must be told when they are interacting with AI, generated content must be marked, and national authorities can now fine. Penalties run up to €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for most other violations.

What arrives in December 2027

The full deployer regime for high-risk systems, Article 26, was moved to December 2, 2027 by the Digital Omnibus. High-risk covers the areas where AI decisions carry consequence for people: hiring and employment, credit and essential services, education, critical infrastructure, law enforcement, migration, and justice. For those systems, deployers must:

  • Use the system according to the provider's instructions, and ensure the input data under their control is relevant and sufficiently representative.
  • Assign human oversight to named natural persons who have the competence, the training, and the authority to intervene. Oversight on paper does not qualify.
  • Monitor the system in operation, suspend it when it presents a risk, and report serious incidents to the provider and the authorities.
  • Keep the automatically generated logs, for at least six months and longer where other law requires it.
  • Inform workers before using high-risk AI on them at work, inform affected persons when the system takes or informs decisions about them, and be able to explain an individual decision when someone exercises their right to one.

The Omnibus deferred the dates. It did not soften the substance. Sixteen months is a runway for building the structure, not a reason to wait.

Read the list again, slowly

Every obligation on it is the same demand in different clothes: a person with a name who answers for the system, oversight that actually operates, a record that survives, and decisions that can be reconstructed when someone asks. The regulation does not ask whether your model is impressive. It asks who is accountable and what you can show.

Why this matches the Principal Firm

This is the part we find remarkable. The Principal Firm derives an organisational form from economics, with no reference to regulation: when agents do the volume, what remains of the firm is a small human part that specifies the work, decides at the gates, and answers for the outcome, above a record that proves what happened. Article 26 asks high-risk deployers for named oversight with real authority, working monitoring, durable logs, and reconstructable decisions. The law and the economics converge on the same anatomy.

The practical consequence: a firm that restructures around delegation gets most of its deployer duties as a by-product of how it already works. The named person at the gate is the oversight requirement. The append-only record is the logging requirement. The specification is what makes "used according to instructions" checkable. A firm that bolts AI onto its existing shape gets the opposite: a compliance project that runs beside the work and ages badly.

One line we hold ourselves to: no platform makes you compliant, and we will not claim ours does. What structure can do is produce the oversight and the evidence your obligations require, while the judgement, and the accountable persons, remain yours.

What to do with the sixteen months

Handle the duties that already apply: literacy and transparency. Then map where AI touches consequence in your organisation, because that map is roughly where high-risk classification will land. Then build the structure while it is cheap: see where you stand, put the oversight and the record in place, and let December 2027 arrive as a date instead of a deadline. If you operate in the public sector, start earlier; the bar is highest where the affected party is a citizen.

THIS ARTICLE IS ORIENTATION, NOT LEGAL ADVICE. REGULATION (EU) 2024/1689, AS AMENDED BY THE DIGITAL OMNIBUS.

See where you stand ← All posts