What is Deployer?
Governance & ControlThe EU AI Act role for an organisation that uses an AI system rather than placing it on the market. An employer running a high-risk screening tool is a deployer, which carries its own duties independent of the vendor's.
Why It Matters
The AI Act splits responsibility between the organisation that builds a system and the organisation that uses it, and the split matters because buying a compliant product does not make the buyer compliant. A provider answers for the model, its documentation, and its conformity. A deployer answers for how the system is used, who it is used on, and what happens when it goes wrong.
For employers this is the operative role. A company that runs a screening tool inside its own hiring process is a deployer, even when the tool came from a vendor with extensive documentation, and even when the company is outside the EU but screens candidates inside it.
What the Duties Are
Use as instructed. Operate the system within its intended purpose, which makes an undocumented repurposing a compliance failure rather than a configuration choice.
Human oversight. Assign people with the competence, training and authority to actually oversee the system, which is a capability standard rather than a checkbox.
Monitoring and reporting. Watch the system’s operation, and report serious incidents, which presumes you have logs to watch.
Informing workers’ representatives. Inform them and the affected workers before putting certain high-risk systems into use. The duty comes before deployment, not after.
Keeping logs. Retain the records the system produces for the required period, because the deployer is the party that will be asked to produce them.
Where It Breaks
The first failure is assuming the vendor’s conformity covers you. A supplier can be entirely compliant and the deployer still non-compliant, because the deployer duties are about use, oversight, and disclosure rather than the model.
The second is oversight as a rubber stamp. An approval step that takes seconds and never disagrees does not meet a standard written around the ability to intervene, and reviewer behaviour is measurable.
The third is disclosure after the fact. Informing workers’ representatives before use is a sequencing requirement, and a works council that learns about a screening system from its outcomes has a grievance rather than a briefing.
The fourth is no logs. Monitoring and incident reporting both depend on records of what the system did, and a deployment that keeps none cannot discharge either duty.
How Flytebit Handles It
We build the deployer duties into the workflow: the intended purpose is written down and enforced at runtime, reviewers are assigned with the criteria and the evidence in front of them and their time on task is recorded, notices and retention are properties of the run, and the logs a deployer has to produce are the same decision records the system writes for its own operation. The industry application is on our HR & Workforce Technology page, and the control design is our AI governance and risk work.
More info
- EU AI Act: Annex III, high-risk areas The listed use cases, including employment and workers' management.
- Job-related AI systems classified as high-risk (Law Society of Ireland) How a national supervisor describes employers' duties and the oversight it expects.