Under the EU AI Act, whoever uses an AI system under its own authority, other than in a purely personal, non-professional activity 1. For high-risk systems it follows the instructions for use, staffs oversight, monitors, keeps logs, informs affected people and, in listed cases, performs the FRIA. The label names a task, not a kind of organisation.
- Developed in
- ch. 18, The EU operator roles
ch. 18, Deployer duties (Article 26) - Chapters
- ch. 15, Deployment · ch. 18, EU AI Act
- Contrast with
- Provider
- Source
- 1 numbered reference, listed below
Commonly confused
Provider versus Deployer
- Provider
- Under the EU AI Act, whoever develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for…
- Deployer
- Under the EU AI Act, whoever uses an AI system under its own authority, other than in a purely personal, non-professional activity.
The differenceDevelops the system and places it on the market under its own name, against uses it under its own authority.
Why it mattersDifferent duties and different evidence; a substantial modification can turn a deployer into the provider.
Where it is used
16 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 04 · The Stack Third-party and procured AI 1 mention
- 06 · The Role What employers get wrong in the job description 1 mention
- 08 · Regulatory Map EU AI Act, post-Omnibus 52 mentions
- 10 · Reading List EU guidance, codes and adjacent law 1 mention
- 12 · Governance Program The stakeholder map 9 mentions
- 13 · Risk Management The loop: identify, assess, treat, monitor 11 mentions
- 14 · Development The build as a chain of gates 12 mentions
- 15 · Deployment Opening 33 mentions
- 16 · Fairness & XAI Protected characteristics, proxies and the data you need to test 14 mentions
- 17 · Incidents The response lifecycle 19 mentions
- 18 · EU AI Act Scope and reach 41 mentions
- 19 · Privacy & AI Controller duties across the AI supply chain 9 mentions
- 20 · Existing Law Non-discrimination 4 mentions
- 21 · AI Laws Worldwide South Korea: the AI Basic Act 8 mentions
- 22 · Principles & Standards The ISO/IEC family 1 mention
- 23 · AI Agents What makes an agent a governance object 12 mentions
Patterns that use this term
20 pattern pages use the term; the 10 that use it most:
- Incident Pipeline 9 mentions
- FRIA-as-Code 6 mentions
- Vendor / Model Due-Diligence Gate 4 mentions
- Staged Rollout with Rollback Criteria 4 mentions
- Drift & Fairness Monitor 4 mentions
- Explanation Artefact 3 mentions
- Disclosure & Notification Pipeline 3 mentions
- Deactivation, Localisation & Retirement Runbook 3 mentions
- Rights Requests Against Models 2 mentions
- Downstream Use Register 2 mentions
Related terms
Sources
- [1] Regulation (EU) 2024/1689 (AI Act), consolidated text as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 Jul 2026; definitions in Art. 3, incl. 3(1), 3(3) to 3(14), 3(14b), 3(20), 3(22), 3(23), 3(29) to 3(32), 3(49), 3(55) to 3(57), 3(60), 3(61), 3(63), 3(68); Arts. 4, 5, 6 (incl. 6(3) third subparagraph, profiling), 9, 10, 11, 13, 14, 15, 17, 22 to 27 (incl. 26(11)), 40, 41, 43, 47, 48, 50, 53 (incl. 53(1)(c)), 55, 57, 60, 72, 73, 86; Annexes I, III, IV). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .