ARE YOU A DEPLOYER?
Establish whether the organization is using an AI system under its authority and whether another operator role also applies. The actual use context matters more than a generic company label.
A deployer does more than receive a provider's paperwork. The organization must govern the real use of the system: instructions, human oversight, local data, monitoring, logs, information duties, escalation and evidence that the operating controls actually existed.
Use the official Regulation as the controlling source. Article 26 governs deployers of high-risk AI systems, with related obligations such as Article 27 FRIA applying only where their conditions are met.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
Establish whether the organization is using an AI system under its authority and whether another operator role also applies. The actual use context matters more than a generic company label.
Article 26 contains important deployer duties for high-risk AI systems. Classification and intended purpose should be resolved before an organization assumes the full high-risk deployer pathway.
Instructions, assigned human oversight, relevant input data, operational monitoring, log retention and escalation should exist as evidence—not merely as policy statements.
Certain deployers and uses can trigger fundamental-rights impact assessment, worker information, affected-person information or other context-specific duties that must be evaluated separately.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
Record system identity, version, intended purpose, provider instructions, local configuration, affected context and the organization’s operator role.
Preserve who is responsible, what authority they hold, what they can monitor or override, and how escalation or suspension works in practice.
Retain relevant logs under deployer control, local input-data suitability evidence, monitoring findings, worker or affected-person notices where applicable, interventions and incidents.
A changed use, new configuration, material provider update, incident, performance departure or new legal fact can invalidate the prior operating position and require renewed review.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
START EVIDENCE PASSPORT →Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.
START COMPLIANCE WORKSPACE →Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.
START GOVERNANCE PRO →Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.
START INSTITUTION →Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
The Regulation defines a deployer as a person or entity using an AI system under its authority, except where the system is used in the course of a personal non-professional activity. Apply the current legal definition to the actual facts.
Article 26 addresses duties including following instructions for use, assigning competent human oversight, ensuring relevant input data where under deployer control, monitoring operation, keeping certain logs, and taking action when risk or serious incidents are indicated, subject to the precise facts and applicable provisions.
For high-risk systems, deployers must keep logs automatically generated by the system to the extent those logs are under their control, for the period required by the applicable provision and context.
Article 26 includes an information duty concerning workers and their representatives before certain workplace uses of high-risk AI. Other employment, data-protection or national-law duties may also apply.
Article 27 creates an FRIA obligation for specified deployers and high-risk uses. It is not a universal requirement for every deployer, so applicability should be determined from the organization and use case.
No. TA-14 structures role, applicability, evidence, gaps, provenance, changes and revalidation. It does not convert software access into legal advice, certification, regulatory approval or a notified-body function.
TA-14 Exchange Activity
Live cumulative activity recorded across the public Exchange surface.
···
Visitors
Recorded public visitors
···
Page Views
Recorded Exchange views