Jump to

Deployer (EU AI Act)

What is a “deployer” under the EU AI Act?

A deployer is any natural or legal person, public authority or body using an AI system under its authority in the course of a professional activity; personal, non-professional use is excluded. The deployer is the AI Act’s use side: the company running a hiring tool, a scoring model or a chatbot in its own operations, as opposed to the provider, who develops the system and places it on the market. Most companies meet the Act in this role first — buying AI is far more common than building it.

Key deployer obligations

  • Use high-risk systems in accordance with the provider’s instructions;
  • Assign competent human oversight and control the quality of input data;
  • Monitor operation, keep the automatically generated logs, and report serious incidents;
  • Inform workers and their representatives before deploying high-risk AI in the workplace;
  • For credit scoring, life and health insurance pricing and public-service deployments, conduct a fundamental rights impact assessment;
  • Meet the Article 50 transparency duties towards affected persons where relevant.

Why the label matters

Deployers located outside the EU remain in scope where the system’s output is used in the EU — the clause that pulls companies into the Act without any EU establishment. Calling yourself “just a user” changes nothing: the duties attach to the function, not the label. And the boundary is not fixed — substantially modifying a system, or marketing it under your own name, converts a deployer into a provider, with the heavier obligations that follow.

Turkish context

The output clause is the route by which Turkey-based companies meet the AI Act: a Turkish firm whose scoring model, hiring tool or chatbot produces output used in the EU is a deployer in scope, no EU subsidiary required. Domestically there is no AI-specific statute in force; KVKK (Law No. 6698) governs the personal-data side, and labour and general liability rules do the rest. A feature-level classification memo — which features are AI systems, which are high-risk, which role you hold — is the sensible starting document.

Do: inventory every AI system in use, record the role you hold for each, and build oversight and logging before a regulator or customer asks. Don’t: modify or rebrand a bought-in system without checking whether you have just become its provider.

Related guides: The Classification Memo.

Sources. Regulation (EU) 2024/1689 (AI Act).